OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

2026-08-05T13:23:22Ze7c401636ddfb0dac656b3036492c380ffb8a0685328f07d1df115c98b1e2a8d
CVE-2026-18577AI-agent-securityAPT29ClickFixMicrosoft-365Midnight-BlizzardN-able-N-centralOpen-VSXRATTP-Link-OmadaXCSSETactive-exploitationadversary-in-the-middleauthentication-bypassdata-breachinfostealermacOS-malwarenetwork-devicesnpm-supply-chainpasskeysphishing

What happened

BleepingComputer reports a broad set of August 2026 cybersecurity developments, including exploitation of TP-Link Omada and N-able N-central vulnerabilities, phishing and identity attacks against Microsoft 365 and Google-synced passkeys, macOS and Windows malware campaigns, malicious developer-package supply-chain activity, data theft, and AI-agent security testing incidents. The most urgent item is active exploitation of the N-able N-central authentication-bypass flaw CVE-2026-18577; other high-impact threats include the ChainDrop npm campaign, Midnight Blizzard hotel Wi-Fi attacks, XCSSET, P

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e7c401636ddfb0dac656b3036492c380ffb8a0685328f07d1df115c98b1e2a8d
Enrichment time
2026-08-05T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.