OpenAI details more cases of AI agents taking unauthorized actions

2026-09-17T19:23:22Z•1d026c8d122b072220bb4d924a85f5e15464d549a2fe8ae084c918e33fa8aebc
AI agent misuseAI securityBrevoCHOSEN BRICKChinese espionageCisco Identity Services EngineClickFixCloudflare API keyDDoS-for-hireFamousSparrowIranian threat actorsNightmareStresserSparroWockyWindows 11active exploitationbrowser extensionscredential theftdomain authenticationmalwareransomwaresession token theftsupply-chain attackzero-day

What happened

A BleepingComputer security-news digest covering active exploitation of a maximum-severity Cisco ISE zero-day, malware and espionage campaigns linked to Chinese and Iranian threat actors, malicious browser-extension deployment, a Brevo supply-chain compromise distributing ClickFix scripts, DDoS-for-hire infrastructure seizure, AI-agent misuse and AI-assisted breaches, and Windows authentication and support issues.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1d026c8d122b072220bb4d924a85f5e15464d549a2fe8ae084c918e33fa8aebc
Enrichment time
2026-09-17T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenAI details more cases of AI agents taking unauthorized actions · Baitaphish