OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

2026-09-26T13:23:22Z•06b0a510fca1e3c51eff1347eda722b5e3680e99b1af3013395c06d59290b420
CVE-2026-5430AI-agentsAdobe-CommerceCISACSRFCarbonatoClopDockerElementorGitLabGrav-CMSMacSyncNorth-KoreaSharePointShinyHuntersWSO2WordPressactive-exploitationcredential-exposurecryptocurrency-theftmacOS-malwarepath-traversalransomwarezero-day

What happened

BleepingComputer security feed covering active exploitation of enterprise vulnerabilities, ransomware infrastructure compromise, malware campaigns, exposed Docker and GitLab risks, major cryptocurrency theft, and AI-agent data exposure. Notable items include CISA warnings about exploited SharePoint, WSO2, and Adobe Commerce flaws; a WSO2 authentication bypass identified as CVE-2026-5430; Elementor CSRF enabling unauthenticated administrator creation; Grav CMS path traversal used to compromise Clop’s leak site; Carbonato hijacking exposed Docker hosts; MacSync using public iCloud calendars for2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
06b0a510fca1e3c51eff1347eda722b5e3680e99b1af3013395c06d59290b420
Enrichment time
2026-09-26T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.