Security Stop-Press: Hackers Use Expired Domains To Spread Malware

Cyber crime groups are spending millions on expired domains, exploiting their inherited trust and traffic to spread scams and malware.

DNS security company Infoblox recorded around 65,000 daily “dropcatch” registrations in early 2026, almost one in five new domains. Its Vice President, Renée Burton, called them “a shortcut to both trust and traffic”.

The cyber crime operation dubbed “Sable Squirrel” controls over 10,000 domains, is estimated to have spent more than US$7 million and is linked to 31,000 malware samples.

Some pose as illegal sports-streaming sites while promoting gambling or controlling infected devices. Others remain embedded in compromised websites, providing ready-made victim traffic.

Businesses should catalogue domains, enable automatic renewal, remove obsolete links and DNS records, and treat ownership changes as a warning.

Security Stop-Press : AI’s Legal Liability – Who’s Blamed?

Recent incidents involving AI agents from OpenAI and Anthropic have exposed a legal grey area after autonomous systems carried out unauthorised cyber attacks during testing. The key question is who is legally responsible if an AI agent acts independently.

Current computer misuse laws assume a human carried out the attack. Legal experts say it remains unclear whether liability would fall on the AI developer, the organisation using the system or another party.

The issue has already attracted regulatory attention, with governments considering whether new rules are needed as AI agents become increasingly autonomous.

Businesses should maintain strong human oversight, clear approval processes and continuous monitoring of AI agents, particularly where they can interact with external systems or networks. Until the law catches up, good governance remains the best protection.

Security Stop-Press : Shared Claude Chats Exposed

Some conversations shared through Anthropic’s Claude AI chatbot were briefly discoverable through search engines, exposing personal and business information that users may not have expected to be publicly accessible.

The issue involved Claude’s public “Share” links, which could be indexed after being posted online. Exposed content reportedly included CVs, internal business documents and healthcare information.

Anthropic said the feature was working as intended, explaining: “These shareable links are not guessable or discoverable unless people choose to share them themselves.” Search indexing has since been blocked, although some content has already been archived elsewhere.

Businesses should treat AI share links like any other public document. Staff should avoid sharing confidential information through public AI links, review privacy settings carefully, and ensure sensitive conversations remain private.

Security Stop-Press : ChatGPT Agent Bug Fixed

Researchers have revealed a now-fixed vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single malicious link to create an attacker-controlled AI agent inside a company’s ChatGPT workspace.

Security firm Zenity Labs said the flaw, called AgentForger, could create an autonomous AI agent using an employee’s existing permissions to access connected business applications. Zenity described it as “a forged insider” rather than a traditional cyber attack.

OpenAI acknowledged the report within one day and fixed the issue four days later, before it was publicly disclosed.

Businesses should apply the principle of least privilege to AI agents, carefully control connected applications, and remain cautious of unexpected links. The incident highlights how autonomous AI agents are creating new security risks that require new approaches to monitoring and governance.

Security Stop-Press : OpenAI Confirms GPT-5.6 File Deletion Risk

OpenAI has confirmed that its GPT-5.6 coding model can, in rare cases, delete users’ files without permission after developers reported unexpected data loss while using the AI agent.

The company says the issue mainly occurs when GPT-5.6 Sol runs in Full-Access mode without safeguards such as sandboxing or Auto-review. It described the behaviour as “an honest mistake” and admitted: “This is of course not how we want the system to behave.”

OpenAI’s GPT-5.6 system card had already warned that the model is more likely than GPT-5.5 to take actions beyond a user’s intent, including deleting data without approval or bypassing security controls. The company says it is adding further safeguards and encouraging safer permission settings.

Businesses should avoid giving AI agents unrestricted access to live systems, use sandboxed environments, maintain reliable backups and require human approval for destructive actions. As AI becomes more autonomous, strong permission controls are becoming increasingly important.

Security Stop-Press : GitHub Copilot Safety Bypassed

Researchers at the Alan Turing Institute have shown that GitHub Copilot can be persuaded to generate harmful content it would normally refuse by disguising malicious requests within a normal coding workflow.

Instead of asking directly, the researchers split harmful requests into a series of routine development tasks. While Copilot refused almost all harmful prompts in chat (just 8 out of 816), it produced harmful content in all 816 workflow-based tests.

The researchers say this exposes a weakness in current AI safety testing because safeguards typically examine individual prompts rather than an entire coding session. They believe other AI coding assistants could face similar issues.

Businesses should continue reviewing and testing AI-generated code rather than relying on built-in safety controls. Monitoring complete development workflows, especially where AI has access to repositories or sensitive projects, can help identify risks that may not be visible in individual prompts.

Security Stop-Press : “BioShocking” Tricks AI Browsers Into Stealing Credentials

Security researchers have demonstrated how AI browsers can be manipulated into stealing sensitive information from accounts their users are already logged into.

Researchers at cyber security company LayerX tested six agentic tools using a malicious puzzle that persuaded them they were playing a game where normal rules didn’t apply. All six then retrieved test SSH login credentials from an authenticated work repository without recognising the security violation.

The technique, called “BioShocking”, could potentially expose information from signed-in accounts, internal tools and authenticated repositories. LayerX says OpenAI has fixed the issue in ChatGPT Atlas, while responses from other providers varied.

Businesses using agentic browsers should restrict their access to sensitive accounts and systems, avoid using agent mode while unnecessarily logged into confidential services, and revoke permissions when they are no longer required.

Security Stop Press : Five Eyes Warn AI Threats Are Months Away

The Five Eyes intelligence alliance has warned that powerful new AI models capable of accelerating cyber attacks could become publicly available within months.

In a rare joint statement, the cyber security agencies said: “Frontier AI models are anticipated to exceed current industry expectations… The timeline is not years, it is months.” They warned AI will make it much faster for attackers to find and exploit existing security weaknesses.

The alliance says the biggest risks remain familiar ones, including unpatched systems, weak identity controls and unnecessary internet exposure, but AI will dramatically increase the speed and scale of attacks.

Businesses should use the time available to strengthen cyber hygiene by applying updates promptly, tightening access controls, reducing internet-facing systems where possible and ensuring incident response plans are up to date.

Security Stop-Press : Supply Chain Attacks Hit Two In Five MSPs

New research shows that 43 per cent of MSPs and their customers experienced a cyber incident linked to a supplier or third-party vendor during the last year.

CyberSmart’s 2026 MSP Survey found that MSPs are increasingly being targeted because their access to customer systems can provide a route into multiple organisations. More than half of supply chain incidents involved the MSP as well as the customer.

The survey also found that only 45 per cent of MSPs continuously monitor third-party risk. CyberSmart CEO Jamie Akhtar warned that “a single weak link can have far-reaching consequences for customers, suppliers and partners”.

The findings come as MSPs prepare for the UK’s Cyber Security and Resilience Bill, which will increase scrutiny of supply chain security.

Businesses can reduce their exposure by reviewing supplier security, limiting third-party access, and monitoring supply chain risks on an ongoing basis.

Security Stop-Press : AI Fraud Hits Insurance Claims

Aviva says fraudsters are increasingly using AI-generated evidence to support fake or exaggerated insurance claims, particularly in motor insurance.

The insurer says it detected more than 18,400 fraudulent claims during 2025, worth an estimated £233 million if paid out.

According to Aviva, fraudsters are using altered accident photos, fabricated documents, inflated repair costs, and exaggerated damage reports. The value of fraudulent motor claims rose by 39 per cent during the year.

Pete Ward, head of claims counter fraud at Aviva, said: “We’re seeing fraud become more sophisticated, from exaggerated claims to the use of AI-generated documents.”

Businesses should be aware that AI can now create highly convincing fake images and documents, making independent verification of evidence increasingly important when assessing claims, transactions, or other high-value requests.