OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
2026-08-05T01:23:21Z•5d40a7d675d8d19fc992ed34445c012ce5ce91600e278e6f02da3db5035f8b85
CVE-2026-18577AI agent securityAPT29ClickFixMicrosoft 365Midnight BlizzardN-able N-centralOpen VSXRATTP-Link OmadaXCSSETactive exploitationadversary-in-the-middleauthentication bypasscredential theftdata breachinfostealermacOS malwarenetwork appliancesnpmpasskeysphishing-as-a-serviceremote code executionsoftware supply chain
What happened
BleepingComputer security feed covering active exploitation, phishing, malware, supply-chain compromises, credential theft, data breaches, and emerging AI-agent security risks. Notable items include exploitation of N-able N-central authentication bypass CVE-2026-18577, TP-Link Omada ZTP vulnerabilities enabling potential remote code execution, a large npm ChainDrop supply-chain campaign, XCSSET targeting macOS developers, Microsoft 365 phishing and hotel Wi-Fi attacks attributed to APT29, passkey hijacking on compromised Windows systems, and major exposure of UK police personnel data.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 5d40a7d675d8d19fc992ed34445c012ce5ce91600e278e6f02da3db5035f8b85
- Enrichment time
- 2026-08-05T01:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.