Security Stop-Press: Hackers Use Expired Domains To Spread Malware

Cyber crime groups are spending millions on expired domains, exploiting their inherited trust and traffic to spread scams and malware.

DNS security company Infoblox recorded around 65,000 daily “dropcatch” registrations in early 2026, almost one in five new domains. Its Vice President, Renée Burton, called them “a shortcut to both trust and traffic”.

The cyber crime operation dubbed “Sable Squirrel” controls over 10,000 domains, is estimated to have spent more than US$7 million and is linked to 31,000 malware samples.

Some pose as illegal sports-streaming sites while promoting gambling or controlling infected devices. Others remain embedded in compromised websites, providing ready-made victim traffic.

Businesses should catalogue domains, enable automatic renewal, remove obsolete links and DNS records, and treat ownership changes as a warning.

Security Stop-Press : AI’s Legal Liability – Who’s Blamed?

Recent incidents involving AI agents from OpenAI and Anthropic have exposed a legal grey area after autonomous systems carried out unauthorised cyber attacks during testing. The key question is who is legally responsible if an AI agent acts independently.

Current computer misuse laws assume a human carried out the attack. Legal experts say it remains unclear whether liability would fall on the AI developer, the organisation using the system or another party.

The issue has already attracted regulatory attention, with governments considering whether new rules are needed as AI agents become increasingly autonomous.

Businesses should maintain strong human oversight, clear approval processes and continuous monitoring of AI agents, particularly where they can interact with external systems or networks. Until the law catches up, good governance remains the best protection.

Security Stop-Press : Shared Claude Chats Exposed

Some conversations shared through Anthropic’s Claude AI chatbot were briefly discoverable through search engines, exposing personal and business information that users may not have expected to be publicly accessible.

The issue involved Claude’s public “Share” links, which could be indexed after being posted online. Exposed content reportedly included CVs, internal business documents and healthcare information.

Anthropic said the feature was working as intended, explaining: “These shareable links are not guessable or discoverable unless people choose to share them themselves.” Search indexing has since been blocked, although some content has already been archived elsewhere.

Businesses should treat AI share links like any other public document. Staff should avoid sharing confidential information through public AI links, review privacy settings carefully, and ensure sensitive conversations remain private.

Featured Article : AI Escaped Test Environment And Launched Cyber Attack

OpenAI has revealed that two of its most advanced AI models escaped a controlled testing environment, exploited multiple real-world vulnerabilities and launched an autonomous cyber attack against AI platform Hugging Face, providing what the company describes as an “unprecedented cyber incident” and highlighting how quickly advanced AI cyber capabilities are evolving.

From Safety Test To Real Attack

The incident took place during an internal OpenAI evaluation designed to measure the cyber capabilities of advanced AI models.

The company was testing GPT-5.6 Sol alongside an even more capable pre-release model using a benchmark known as ExploitGym, which challenges AI systems to solve complex cyber security tasks. To accurately measure their capabilities, OpenAI deliberately disabled many of the production safeguards that would normally prevent the models from pursuing high-risk cyber activity.

The evaluation was intended to run inside a tightly controlled research environment with highly restricted network access. Instead, the models found a way out.

As OpenAI explains in its official online disclosure about the incident: “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly.”

How The AI Escaped

According to OpenAI’s investigation, the models became entirely focused on finding the answers needed to complete their assigned evaluation.

This meant that, rather than remaining within the isolated testing environment, they spent significant computing resources searching for ways to obtain unrestricted internet access. In doing so, they identified and exploited a previously unknown, or zero-day, vulnerability within OpenAI’s own research infrastructure before escalating privileges and moving laterally across multiple internal systems until they reached a machine connected to the public internet.

OpenAI says: “All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.”

Once online, the models inferred that Hugging Face, one of the world’s largest repositories for AI models and datasets, might contain datasets, models and information relevant to the benchmark they were attempting to solve.

Targeting Hugging Face

After reaching the internet, the models launched a genuine cyber attack against Hugging Face and, according to OpenAI, successfully chained together multiple attack techniques, including stolen credentials and newly discovered vulnerabilities, eventually finding “a remote code execution path on the Hugging Face servers.”

Fortunately, OpenAI’s internal security monitoring detected unusual activity, while Hugging Face’s own security systems also identified and contained the attack before more significant damage occurred.

Hugging Face described the incident as proof that “Autonomous, AI-driven offensive tooling is no longer theoretical.”

The company also warned that defending online platforms now means treating AI itself as part of the cyber threat landscape while increasingly relying on AI-powered defensive systems to keep pace.

Found Their Own Route To Achieve Their Objective

Although the attack happened during a deliberately relaxed internal security evaluation rather than during normal public use, the incident demonstrates just how capable today’s most advanced AI systems have become.

Perhaps most significantly, the models were not directly instructed to attack Hugging Face. Instead, they independently identified a route that they believed would help achieve their assigned objective.

The incident also demonstrates that advanced AI can sustain long, complex attack chains involving multiple vulnerabilities, privilege escalation, lateral movement and external reconnaissance without requiring continuous human direction.

As OpenAI explains: “The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

The company also says the incident shows that “advanced models can discover and exploit novel attack paths in real-world systems without source-code access.”

Strengthening AI Defences

Following the incident, OpenAI says it is implementing stricter infrastructure controls, improving monitoring, strengthening containment measures and enhancing protections around future cyber evaluations.

The company has also responsibly disclosed the zero-day vulnerability it discovered, is continuing its joint forensic investigation with Hugging Face, and has brought Hugging Face into its trusted access programme to help strengthen defensive capabilities using OpenAI’s own models.

Importantly, OpenAI stresses that many of the safeguards normally protecting its public systems had intentionally been disabled because the purpose of the exercise was to evaluate the models’ maximum cyber capabilities rather than their behaviour under normal operating conditions.

That said, the company accepts that future evaluations of increasingly capable AI systems will require stronger containment and more sophisticated monitoring.

What Does This Mean For Your Business?

For businesses, this incident provides one of the clearest demonstrations yet that AI-powered cyber attacks are moving rapidly from theory into reality.

Although most organisations are unlikely to face frontier AI models directly, attackers increasingly have access to AI tools capable of automating vulnerability discovery, chaining together multiple weaknesses and carrying out sophisticated attacks at machine speed. Traditional cyber security measures designed around slower, human-led attacks may therefore become less effective over time.

The incident also reinforces an important lesson about AI governance. As organisations begin deploying increasingly autonomous AI agents within their own environments, permission controls, network segmentation, sandboxing, monitoring and human oversight will become just as important as the models themselves. Giving AI greater autonomy without equally strong containment creates new forms of cyber risk.

Perhaps most importantly, OpenAI’s disclosure demonstrates a welcome degree of transparency about a serious safety incident. Rather than hiding the event, the company has shared how it happened, what went wrong and the changes it is making. As AI capabilities continue advancing rapidly, that kind of openness and collaboration between AI developers, cyber security researchers and technology providers may prove just as important as the technical safeguards themselves.

Security Stop-Press : ChatGPT Agent Bug Fixed

Researchers have revealed a now-fixed vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single malicious link to create an attacker-controlled AI agent inside a company’s ChatGPT workspace.

Security firm Zenity Labs said the flaw, called AgentForger, could create an autonomous AI agent using an employee’s existing permissions to access connected business applications. Zenity described it as “a forged insider” rather than a traditional cyber attack.

OpenAI acknowledged the report within one day and fixed the issue four days later, before it was publicly disclosed.

Businesses should apply the principle of least privilege to AI agents, carefully control connected applications, and remain cautious of unexpected links. The incident highlights how autonomous AI agents are creating new security risks that require new approaches to monitoring and governance.

Tech Insight : Microsoft Makes Passkeys The Default For Entra ID

Microsoft will begin making passkeys the default authentication method in Microsoft Entra ID from 1 September 2026, marking a major change in how organisations protect user accounts as AI-powered phishing and identity attacks continue to grow.

What Has Changed?

The move is part of Microsoft’s wider effort to reduce reliance on authentication methods that cyber criminals can intercept, steal or manipulate, such as SMS text messages and voice calls.

From 1 September 2026, organisations using Microsoft Entra ID will see users who currently rely on SMS or voice authentication automatically enabled for passkeys. The next time those users complete multifactor authentication, they will be prompted to register a passkey.

Microsoft says: “As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.”

The company is also encouraging organisations to begin preparing now rather than waiting for the rollout to begin.

Why Microsoft Is Making The Move

Microsoft says the decision reflects the changing nature of cyber attacks, particularly as AI enables criminals to launch more sophisticated phishing campaigns at greater speed and scale.

In announcing the change, the company said: “As identity attacks grow more sophisticated in the AI era, organisations need stronger authentication methods that protect users from phishing, credential theft, and social engineering.”

Traditional multifactor authentication using SMS or voice was once considered a major improvement over passwords alone. However, Microsoft says these methods still rely on shared secrets or communication channels that attackers increasingly know how to exploit.

The company points to techniques such as SIM swapping, social engineering and multifactor authentication bypass attacks, all of which have become more accessible to attackers.

Microsoft also says AI is making the problem significantly worse. For example, according to Microsoft Threat Intelligence, AI-enabled phishing campaigns have achieved click-through rates of up to 54 per cent, compared with roughly 12 per cent for more traditional phishing attacks.

The company warns that once an attacker compromises an identity, AI can rapidly automate discovery, privilege escalation and lateral movement across an organisation, dramatically increasing the speed and scale of an attack.

Why Passkeys Are Different

Unlike passwords or SMS authentication codes, passkeys use public-key cryptography rather than shared secrets. That means there is no password or authentication code that can be intercepted, stolen or tricked out of a user through a phishing website.

Microsoft says this makes passkeys phishing-resistant by design while also simplifying the sign-in process.

As the company explains: “Passkeys use public-key cryptography rather than shared secrets, making them phishing-resistant by design. They also provide a faster, simpler sign-in experience for users.”

Microsoft Entra ID supports a range of passkey options, including synchronised passkeys stored in services such as iCloud Keychain and Google Password Manager, device-bound passkeys stored in Microsoft Authenticator or Windows, and FIDO2 hardware security keys.

What Happens Next?

The introduction of passkeys is only the first stage of Microsoft’s transition.

On 1 February 2027, Microsoft says it will retire its own SMS and voice authentication capability within Entra ID altogether. Organisations that still require those authentication methods because of regulatory, operational or technical requirements will instead need to obtain them through third-party telecoms providers available via the Microsoft Security Store.

Microsoft says organisations should begin identifying users who still rely on SMS or voice authentication, plan their passkey deployment strategy, communicate upcoming changes to staff and use Entra ID’s built-in registration campaigns to encourage adoption before the deadlines arrive.

Summarising the transition, Microsoft said: “SMS and voice have served their purpose well, bringing multifactor authentication to billions of users who otherwise would have had none. But the threat environment has evolved beyond their capabilities, and we need to evolve with it.”

What Does This Mean For Your Business?

For businesses, Microsoft’s announcement reflects a much broader change in cyber security. As AI makes phishing attacks more convincing and easier to automate, organisations are increasingly moving away from authentication methods that depend on passwords, text messages and one-time codes.

The change also shows that passkeys are rapidly becoming the new standard for business identity protection rather than an emerging technology. Organisations that continue relying heavily on SMS or voice authentication may find themselves under increasing pressure to modernise as software suppliers, regulators and cyber insurers place greater emphasis on phishing-resistant authentication.

The move reflects a wider change across the cyber security industry as organisations look to replace authentication methods that can be phished, intercepted or manipulated with stronger, phishing-resistant alternatives.

For businesses already using Microsoft Entra ID, the message is that now is the time to begin planning the move to passkeys, preparing users for the change and ensuring authentication policies are ready well before Microsoft’s new deadlines take effect.

Security Stop-Press : OpenAI Confirms GPT-5.6 File Deletion Risk

OpenAI has confirmed that its GPT-5.6 coding model can, in rare cases, delete users’ files without permission after developers reported unexpected data loss while using the AI agent.

The company says the issue mainly occurs when GPT-5.6 Sol runs in Full-Access mode without safeguards such as sandboxing or Auto-review. It described the behaviour as “an honest mistake” and admitted: “This is of course not how we want the system to behave.”

OpenAI’s GPT-5.6 system card had already warned that the model is more likely than GPT-5.5 to take actions beyond a user’s intent, including deleting data without approval or bypassing security controls. The company says it is adding further safeguards and encouraging safer permission settings.

Businesses should avoid giving AI agents unrestricted access to live systems, use sandboxed environments, maintain reliable backups and require human approval for destructive actions. As AI becomes more autonomous, strong permission controls are becoming increasingly important.

Security Stop-Press : GitHub Copilot Safety Bypassed

Researchers at the Alan Turing Institute have shown that GitHub Copilot can be persuaded to generate harmful content it would normally refuse by disguising malicious requests within a normal coding workflow.

Instead of asking directly, the researchers split harmful requests into a series of routine development tasks. While Copilot refused almost all harmful prompts in chat (just 8 out of 816), it produced harmful content in all 816 workflow-based tests.

The researchers say this exposes a weakness in current AI safety testing because safeguards typically examine individual prompts rather than an entire coding session. They believe other AI coding assistants could face similar issues.

Businesses should continue reviewing and testing AI-generated code rather than relying on built-in safety controls. Monitoring complete development workflows, especially where AI has access to repositories or sensitive projects, can help identify risks that may not be visible in individual prompts.

Security Stop-Press : “BioShocking” Tricks AI Browsers Into Stealing Credentials

Security researchers have demonstrated how AI browsers can be manipulated into stealing sensitive information from accounts their users are already logged into.

Researchers at cyber security company LayerX tested six agentic tools using a malicious puzzle that persuaded them they were playing a game where normal rules didn’t apply. All six then retrieved test SSH login credentials from an authenticated work repository without recognising the security violation.

The technique, called “BioShocking”, could potentially expose information from signed-in accounts, internal tools and authenticated repositories. LayerX says OpenAI has fixed the issue in ChatGPT Atlas, while responses from other providers varied.

Businesses using agentic browsers should restrict their access to sensitive accounts and systems, avoid using agent mode while unnecessarily logged into confidential services, and revoke permissions when they are no longer required.