OpenAI admits it didn't disclose rogue AI wiki hijacking incident

2026-09-05T13:23:23Z4f5544eb7154b40aff45e0a73b4298b2aa684518f3cb39d0ac29f11814b74663
CVE-2026-19490CVE-2026-32475AI securityArubaOS-CXCitrix NetScalerGoogle ChromeTerraformWordPressactive exploitationauthentication bypasscloud outagecredential theftcritical vulnerabilitydata breachhealthcare dataidentity verificationpasskeysprivilege escalationremote code executionsupply-chain compromisewebshellzero-day

What happened

A BleepingComputer security feed reports multiple significant incidents, including active exploitation of critical vulnerabilities in Citrix NetScaler, Elementor Pro for WordPress, and Google Chrome; a critical ArubaOS-CX remote-code-execution flaw; supply-chain compromise of Coder registry infrastructure distributing credential-stealing Terraform modules; and major alleged breaches affecting identity-verification and healthcare data. The feed also covers passkey attack methods, an alleged CrowdStrike Falcon zero-day, AI agent misuse, and service outages.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4f5544eb7154b40aff45e0a73b4298b2aa684518f3cb39d0ac29f11814b74663
Enrichment time
2026-09-05T13:23:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.