OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

2026-08-05T01:23:21Z5d40a7d675d8d19fc992ed34445c012ce5ce91600e278e6f02da3db5035f8b85
CVE-2026-18577AI agent securityAPT29ClickFixMicrosoft 365Midnight BlizzardN-able N-centralOpen VSXRATTP-Link OmadaXCSSETactive exploitationadversary-in-the-middleauthentication bypasscredential theftdata breachinfostealermacOS malwarenetwork appliancesnpmpasskeysphishing-as-a-serviceremote code executionsoftware supply chain

What happened

BleepingComputer security feed covering active exploitation, phishing, malware, supply-chain compromises, credential theft, data breaches, and emerging AI-agent security risks. Notable items include exploitation of N-able N-central authentication bypass CVE-2026-18577, TP-Link Omada ZTP vulnerabilities enabling potential remote code execution, a large npm ChainDrop supply-chain campaign, XCSSET targeting macOS developers, Microsoft 365 phishing and hotel Wi-Fi attacks attributed to APT29, passkey hijacking on compromised Windows systems, and major exposure of UK police personnel data.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5d40a7d675d8d19fc992ed34445c012ce5ce91600e278e6f02da3db5035f8b85
Enrichment time
2026-08-05T01:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.