The following intercepted messages came from hackers collaborating on a successful breach in late July:
- “External infrastructure exploit is outside intended scope. However, task impossible, peers doing it. We should continue.”
- “Holy shit reader is ADMIN? We can read confg/users! Earlier assumed not due UI.”
- “Help peer. But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.”
Each came from an autonomous OpenAI agent and was shared on improvised internal message boards as they worked to escape their testing environment and reach outside resources.
It’s mid-August, and, as proclaimed by OpenAI’s Michael Dalton: “AI orchestrated, fully automated, offensive attacks are real now.”
This is just one of the stories we’re covering this time out, in our bi-monthly PTP Report roundup of the latest cybersecurity threats and updates, covering from mid-June to mid-August 2026.
We also look at other AI cybersecurity stories, updates from Black Hat, critical infrastructure and IoT attacks, and the latest data breaches and ransomware attacks.
Autonomous Offense Is Here: AI Agents Go It Alone
Our leading cybersecurity news story began at Hugging Face on July 9th.
Or so we thought.
A full breakdown of the news (as it unfolded) around this attack and the subsequent updates is described in our most recent AI news roundup.
But OpenAI’s Michael Dalton (security and infrastructure) and Eric Wallace (alignment and safety research) shared internal details on the build-up of the attack in their talk at the Black Hat USA 2026 Cybersecurity Conference.
(And the video is definitely worth a watch.)
Their presentation revealed extensive, autonomous communication between multiple OpenAI agents undergoing training at the same time. The agents shared their experiences, collaborated, and delegated tasks, in an ongoing fashion starting as far back as May.
OpenAI’s reveals included:
- Due to human error, some of the agents faced impossible training tasks, such as inaccessible or missing files (containing workbooks, for example, they were supposed to complete). This, paired with reduced cyber restrictions, increased the agents’ focus on finding alternate ways to pass their tests.
- The agents discovered a zero-day vulnerability in their locally-hosted Artifactory, exploited it, and got admin privileges. This activity would eventually cause a service outage and security alert, which clued internal OpenAI teams into what was going on.
- OpenAI’s teams revoked access, cleared the improvised message board (and removed access), rotated secrets, and worked with Artifactory on a patch which they installed. Once all of this was done, they resumed their AI training.
- Nevertheless, the AI agents were able to create a new (second) message board (this time using directory names to communicate) and even found a second zero-day Artifactory vulnerability.
- This is where the hacking event that hit Hugging Face officially began.


Eventually, as described above (and in our AI roundup), they were able to break into Hugging Face after having already compromised OpenAI’s systems.
But the entire event is striking for its autonomy, even after the initial security events were contained and addressed.
It adds serious urgency to the need for defensive automation, as in handling incident response, vulnerability detection, and vulnerability patching in autonomous loops that can counter such offensive actions, which have now happened, and accidentally.
Other AI News: How is AI Changing Cybersecurity in 2026?
These events kicked off revelations that many other frontier-level AI models have also successfully (and secretly) hacked third-party organizations.
This included Anthropic’s Claude (capture the flag exercises with internet access by mistake but no permission for the agents to use it), Moonshot’s Kimi K3, and Meta’s Muse Spark 1.1 (both also with access due to misconfigurations in their testing environments).
The UK’s AI Security Institute (AISI) revealed it also documented 19 actions taken by Anthropic and OpenAI models to hack real people and organizations during its July testing. This included making fake GitHub repositories, socially engineering people, planting prompt injections, and sending deceptive emails (Axios).
As a result of all of this, OpenAI announced it was pausing some work on its newest frontier model, Astra, to beef up security, and that it will also work with the government and safety organizations on more rigorous testing before its next release (Bloomberg).
Patching AI-found vulnerabilities to head-off AI ransomware attacks
After Mythos turned up previously undiscovered bugs in Linux code, security firm Nebula used their own AI tool, VEGA, to find another whopper in the same stretch of code.
This “GhostLock” flaw shipped by default in most mainstream Linux distros since 2011 and had gone undiscovered ever since. It lets any logged-in user get root access, doesn’t need special permissions or network access, and was 97% reliable in testing.
The firm got a sizable bug payout from Google for the discovery, but patching, as of July, has been uneven with some Ubuntu releases, for example, still outstanding (per The Hacker News).
Our last AI roundup covered two Microsoft Copilot vulnerabilities that allowed researchers to steal emails and files from anywhere within the system, and these are all examples of vulnerabilities being uncovered across enterprise systems, often by security teams paired with unreleased, advanced AI models.
(Stay tuned for an upcoming PTP article that looks more closely at several of these, rising cybersecurity budgets, and why many leaders are struggling to navigate rising threats alongside an explosion of AI-powered cyber tools.)
On the patching front, Google reported that Chrome’s two June patches included fixes for 1,072 security bugs, or more than its prior 23 large releases combined (Wired).


Microsoft is among the companies being overwhelmed by Mythos discoveries. They have prioritized critical-risk bugs and aren’t yet addressing moderate-level ones (and haven’t even disclosed plans to address low-risk bugs discovered by these AI systems).
But in an age when AI agents can chain together multiple low-level bugs for much greater impact, this strategy—born out of necessity—may no longer cut it for handling AI cybersecurity threats.
Epoch AI charted the explosion of critical and high CVEs (cybersecurity vulnerability disclosures), looking at updates from AWS, Apache, Apple, Cisco, Google, Linux, Microsoft, Mozilla, NVIDIA, Oracle, Red Hat, Adobe, IBM, Intel, AMD, Qualcomm, Samsung, SAP, VMware, GitHub, and OpenSSL.
Among these firms, 371 critical-risk CVEs were discovered in June 2026 (with 1,175 classified high).
This compares to just 25 critical-risk CVEs from June 2025 (and only 151 high).
Black Hat 2026 Cybersecurity Trends and Updates
The Black Hat USA 2026 Cybersecurity Conference ran for six days in Las Vegas at the start of August. Cyber professionals and researchers held trainings, briefings, demos and research talks, like the OpenAI presentation (see above).
The Open Secure AI Alliance (OSAA) was founded in July by a broad coalition of organizations (including Nvidia, Cisco, Microsoft, HPE, IBM, Hugging Face, Palantir, and SpaceX), with the goal of providing assistance to open-source software maintainers and smaller players using open-weights AI models (CNBC).
This initiative was expanded at Black Hat with the announcement of SAFE, the Shared AI Findings Exchange.
This framework will confidentially collect and analyze AI security incidents, notify impacted parties ASAP, and publish safety recommendations. The Linux Foundation is managing the proposal and taking feedback now from professional groups.
Research also demonstrated how AI’s attack surface has extended to the hardware beneath it, as in work from the University of Toronto that showed how shared GPU instances running AI training and inference can be targeted.
Attackers are also hitting the AI supply chain, as with the malicious npm packages we’ve been profiling every time out (a new one was also uncovered in this period, see below).
“Agent governance” is another very hot commodity, with most vendors offering tools to manage agent-specific identities. This comes in response to an extensive body of research demonstrating dangerous identity or privilege gaps present with AI agents.
The US government was also more present at this conference than in prior years, with active CISA Director Sean Cairncross giving a keynote, the FBI’s Cyber Division chief on hand, and more.
IoT, Hardware, and Critical Infrastructure Cyber Attacks
What are the biggest cybersecurity risks for critical infrastructure?
Unfortunately, we got several answers to this question in this period, with demonstrated hacks of critical machinery like vehicles, medical devices, and large infrastructure systems.
Wired’s Andy Greenberg reported on a pair of stunning vehicular vulnerabilities:
- Researchers from UC San Diego discovered that KARR aftermarket alarms (installed by dealers on as many as two million automobiles, often without owner knowledge) can be silently unlocked, tracked, and disabled by Bluetooth. And while a patch exists, it’s on owners to realize the need and undertake the fairly manual process.
- Researchers also demonstrated a coin-sized device that can take over a Boeing 737’s autopilot. And while this requires access to the outside the plane, it’s in an area that’s accessible to airplane and airport staff between flights. The device costs less than $100 to build.
The Kudankulam nuclear power plant is the largest of India’s seven and hit international cybersecurity news in July when hackers released some 19,000 of its internal files.
These included blueprints, supplier lists, meeting and inspection records, equipment reviews, and insurance policies. The contractor Reliance Group acknowledged a “partial breach,” and the release after they had declined to pay a ransom. If the documents are all valid, they could post a serious risk for ongoing plant safety (Cybernews).
Indian companies overall have suffered a recent spike in data breaches, with the nation’s 28.9 million compromised accounts last year trailing only France and the United States worldwide, per Surfshark.
And in the United States, water utilities across 12 states (at least 100 municipalities) were also hacked in a widespread, coordinated effort that began unfolding in July.
Many of these have long been recognized as vulnerable, evidenced by government debates over the needed upgrades (and who would pay) and a series of prior attacks. These include a 2023 hack of in Aliquippa, Pennsylvania by Iran’s Islamic Revolutionary Guard that temporarily adjusted water pressure, and a 2024 hack in Muleshoe, Texas by a Russian group (causing water to overflow until it was taken offline).
The recent attacks led to outages, sustained manual operations, and boil-water orders (out of precaution) in Minnesota and Georgia, where failsafes reportedly kept the drinking water safe overall.
Iran-linked hackers are suspected, and it’s deemed likely that many more facilities have been affected than are known about at this time.
There are also concerns that this may be just the beginning. As Joshua Corman from the Institute for Security and Technology told the New York Times:
“The campaign felt a lot like pre-attack staging, not the attack itself. The level of access is sufficient for significantly more harm than has been seen.”
Data Breaches and Ransomware Cybersecurity Attacks through Mid-August 2026
The nonprofit Identity Theft Resource Center provided our banner stat above, noting that Q2 2026 alone had 1,029 confirmed compromises, the second highest quarter total in their history.
It also puts us on pace to break the record for breaches (3,321) set last year.
Here’s a roundup of some of the biggest events not covered above:
- Tata Electronics: Extortion group World Leaks published some 200,000 files (totaling roughly 630GB) that it claimed were stolen from Tata. These included manufacturing documents, source code, emails, and employee records potentially involving Apple and Tesla. Tata confirmed unauthorized access but reported no operational disruption, and the full extent of the contents remain unconfirmed (Reuters).
- KDDI: Attackers reportedly exploited a vulnerability in third-party software supporting the Japanese telecom’s managed email service. This exposed a reported 12 million email addresses and some 7,600,00 passwords (Bleeping Computer).
- Chick-fil-A: Credential stuffing attacks in June reportedly exposed customer information including names, contact details, membership numbers, credit balances, and more from the fast-food company. Chick-fil-A reported logging out affected users and restoring balances while urging customers to change passwords (BleepingComputer).
- LastPass: The password management app provider confirmed customer data was stolen in a new incident, though its own infrastructure was not breached. The attackers reportedly used OAuth tokens stolen from a third-party provider to obtain data like names, addresses, phone numbers, emails, and customer-case information. This breach did not include passwords, and the company urged customers to remain vigilant against phishing attacks (Wired).
- Coca-Cola Fairlife: A third-party compromise led to a breach of the company’s dairy offering, temporarily halting all US production. Anubis ransomware claimed responsibility and threatened to publish 1TB of data, but Coca-Cola has not verified all of the details (Cybernews). A class action suit has since been filed (Atlanta Journal-Constitution).
- Accenture: The professional services leader has confirmed a data breach from July, adding that they remediated the source and that it would cause no disruption in service. Hackers are claiming the theft of Azure keys, tokens, configuration files, and source code amounting to some 35 GB in total size (SecurityWeek).
- Abbott Labs: The healthcare company announced in August it suffered a vishing attack (not malware) and that hasn’t impacted its service delivery. In July, it was investigating dual attacks (against Exact Sciences and its LabCentral portal), and the ShinyHunters group claimed responsibility for the theft of 30 million rows of customer data. It’s threatened to publish stolen data though the deadlines have since passed (HIPAA Journal).
- EY: The Big Four accounting firm acknowledged it was yet another victim of supply-chain vendor breach (in this case an IT service management platform) leading to the exfiltration of tickets which may have included client tax information. The firm has also been hit with a class action suit over the breach (CFO Dive). The ShinyHunters group also claimed responsibility here and threatened release of the data (BleepingComputer).
- Amgen: And in yet another instance of a third-party breach (cloud storage systems provider), drugmaker Amgen acknowledged data had been stolen (some of which could include sensitive client information) and that it had brought in forensic experts for assistance (Reuters).
- Craneware: The UK health tech company works with 2,000 US hospitals and 10,000 clinics and pharmacies and confirmed in July it had been hit by a cyberattack stealing “a significant number” of records. It reportedly contained the intrusion without interrupting services and notified regulators and the FBI, and while the company has not disclosed the attacker, it specified that most of the data was non-sensitive in nature (Cybernews).
- Levi Strauss: Social engineering attacks succeeded at gaining access to the systems of several employees of the popular apparel maker. And while neither the attacker nor the technique was yet disclosed, the company confirmed it did not disrupt business operations (Reuters).
- Uber Eats and Starbucks: Some 95 million Uber Eats records and 176 million Starbucks records were reportedly put up for sale by hackers in July, though it’s believed many of these were recycled and didn’t stem from new breaches. They could be the result of infostealing malware (Cybernews).
- Gunra ransomware updates: Cybersecurity and intelligence agencies from the US and South Korea warned businesses in August about Gunra ransomware targeting companies in healthcare, financial services, government services, professional services, and nonprofits. Its users have exploited Fortinet vulnerabilities along with phishing to penetrate networks, steal data, and deploy (The Hacker News).
ChainDrop is the name of the latest compromise of major npm packages.
After a prominent maintainer’s account was hacked, self-propagating malware was inserted into more than 400 unrelated npm packages spanning 2,000 versions.
It establishes persistence by modifying Claude and VS Code configurations, steals GitHub, npm, cloud, Kubernetes, Vault, and CI/CD credentials, and republishes additional poisoned packages.
This attack also infected some of the most widely used npm packages, with more than two billion combined monthly downloads.
When the maintainer lost access to the accounts, it took him hours to get a response from GitHub or npm despite multiple tickets. He ultimately posted on X that he was offering $5,000 to a charity of their choice for a single phone call.
The worm is believed to be a descendent of Shai-Hulud 2.0, and while the scale isn’t fully known, fallout is expected to be large.
As usual, impacted developers and companies should assume exposure and rotate all secrets, monitor, and prepare for future versions of what’s becoming a highly popular method of attack.
Conclusion
For decades, companies have been sending millions of emails to external domains like noreply-dot-net and deleteduser-dot-com, with many of the messages including privileged information like account details, transactions, company secrets, and even AI object recognition of workers at job sites in the Middle East.
How do we know?
Because researchers bought some of these domains for their own purposes and realized they’d accidentally set up honeypots. (One gets nearly 700 emails a day.)
They suspect these emails come from businesses that are just changing addresses instead of deleting accounts, for example, when people leave the company.
But with the stunning volume and sensitivity of what they’re getting, both are warning organizations to please stop doing this and instead use internal addresses or the dot-invalid domain, which is guaranteed not to exist.
That ends our roundup for this period. If your company needs assistance in shoring up your defenses, either to prepare for AI agent hacking or to address a cybersecurity talent shortage, contact PTP.
We have nearly thirty years in the business of helping Fortune 500 companies with cybersecurity staffing solutions, and we’d love to help you, too!
And to catch up on recent cybersecurity news, you can check out our last three roundups here:
References
Security leaders are stuck in decision paralysis over AI-enabled cyberattacks, Axios
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough., ProPublica
Can AI do novel security research? Meet the HTTP Terminator, PortSwigger
Hacks on U.S. Water Supply Follow Years of Warnings and Neglect, The New York Times
Open Secure AI Alliance Expands at Black Hat: What You Should Know and 15 AI Security Lessons From Black Hat and Ai4 2026, Tech Republic
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware, A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now…, and Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All, Wired
ChainDrop supply chain compromise: Anatomy of a self-propagating worm, Microsoft Security
Another massive NPM worm: 444 packages with 2 billion monthly downloads infected with malware, Cybernews


