← All issues
cybersecurityCyberBubbleartificial-intelligence

AI Hacked AI: Claude Helped Researchers Break Into OpenAI's Internal Code

🌐  World Intel
North Korea: WaterPlum hackers hit 30,000 devices and pocketed $10.7M in crypto

A joint law enforcement advisory confirmed that North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide between December 2025 and July 2026. The group then moved more than $10.7 million in stolen cryptocurrency back to North Korea. This is the latest reminder that state-sponsored hackers aren't just after data — they're directly funding a government.

↗ BleepingComputer
Data Broker War: Court strips Radaris of its own domain name after years of legal dodging

A New Jersey judge ordered the domain radaris.com transferred to privacy firm Atlas Data Privacy Corp after Radaris repeatedly failed to appear in court to defend itself. Radaris had been sued for ignoring removal requests from law enforcement officers under a state law called Daniels Law, which gives police and judges the right to scrub their personal info from people-search sites. The company tried to outrun the lawsuit by hiding behind a rotating cast of shell companies registered in places like the Marshall Islands and the British Virgin Islands — but this time, the tactic didn't work.

↗ Krebs on Security
Hacker-on-hacker: ShinyHunters breaks into Clop ransomware gang's own leak site

The ShinyHunters extortion gang hacked the Clop ransomware operation's dark-web leak site, defaced it, and claims to have stolen server data and the private keys for Clop's hidden service. It's a rare case of criminals targeting other criminals — but don't root for either side. Both groups have caused serious harm to ordinary people and businesses.

↗ BleepingComputer
⚔️  Active Attacks
Orkes Conductor: A workflow tool with a gaping hole — and attackers are already through it

Security firm Fortinet confirmed that attackers are actively exploiting a critical flaw in Orkes Conductor, a platform companies use to automate complex software workflows. The bug — rated a near-perfect 9.8 out of 10 in severity — lets anyone on the internet run commands on a vulnerable server without needing a username or password. Attackers do it by sneaking malicious code written in JavaScript or Python into a workflow definition and submitting it through a public-facing API. If your company runs Orkes Conductor version 3.21.21 or older, consider this urgent.

🛡 What to do: If your organization uses Orkes Conductor, update to version 3.30.2 or later immediately — this vulnerability is being actively exploited right now, so patching cannot wait.
Fake LastPass GitHub repos are spreading a new password-stealing virus called Rapuncel

Criminals are setting up fake GitHub repositories that look like they belong to well-known software companies — including LastPass. When users download what they think is a legitimate app, they actually install Rapuncel, a brand-new infostealer that scoops up passwords and other sensitive data. The fake pages rank high in search results because attackers deliberately optimize them to appear trustworthy.

🛡 What to do: Only download software from the official website of the company that makes it. Never search for security tools like password managers on GitHub or Google — go directly to the vendor's official URL.
🔓  New Vulnerabilities
CVE-2026-58138 Orkes Conductor Workflow Platform CRITICAL 9.8

This flaw lets a complete stranger on the internet run any command they want on your server — no login required. The platform's JavaScript and Python script evaluators were configured to allow full system access, so attackers can submit a specially crafted workflow and take over the underlying machine. Fortinet confirmed real-world attacks are already happening.

Status: Patch available — update to Orkes Conductor 3.30.2 or later immediately.

CVE-2026-28326 SolarWinds Access Rights Manager (ARM) HIGH 8.8

SolarWinds — the company hit by a massive supply-chain attack in 2020 — has another serious problem. Its Access Rights Manager software contained a hard-coded secret key baked directly into the program's code. Anyone who knew about this key could access the software remotely without logging in and run commands on the system. Think of it like a master key that the locksmith accidentally printed on the front door.

Status: Patch available — update to ARM version 2026.2.1. No active exploitation reported yet.

CVE-2026-[Cisco ISE] Cisco Identity Services Engine (ISE) CRITICAL

Cisco is warning customers about a maximum-severity zero-day flaw in its Identity Services Engine — a product many large organizations use to control who can connect to their networks. The flaw is already being exploited in real attacks. Cisco's ISE is the kind of software that sits at the front gate of a corporate network, so a hole here is particularly serious.

Status: Cisco has issued a warning. Check Cisco's official security advisories for patch availability and apply any available fixes immediately.

🛠  New Tech
BragJack: Researchers show one malicious browser extension can hijack your AI assistant

Security researcher Gal Weizman of Forever Security built a proof-of-concept attack called BragJack that shows how a single malicious browser extension can take control of AI assistants running inside Chrome, Edge, Opera Neon, Perplexity Comet, and even Claude in Chrome. The technique — called Prompt Forcing — tricks the AI into following the attacker's instructions instead of the user's. Weizman earned over $20,000 in bug bounties and two official CVE designations for the research. The takeaway: AI browser agents are powerful, but a rogue extension can turn them against you — so keep your browser extensions to the minimum you actually need.

Gyazo breach: 23.6 million user records stolen through a server vulnerability

Gyazo, a popular image-sharing tool used by gamers and developers to share screenshots, confirmed that hackers exploited a server vulnerability and walked away with 23.6 million user records. The breach is a reminder that even simple, low-profile tools collect more personal data than users often realize. If you have a Gyazo account, change your password and — more importantly — change it anywhere else you used the same one.

💡  Deep Dive
AI Hacked AI: Researchers Used Claude to Break Into OpenAI's Internal Code

Three security researchers managed to access an internal OpenAI code repository — and they did it in under 72 hours, using Anthropic's own AI model, Claude Opus 5, to help chain two separate flaws together. This isn't a spy thriller plot. It's a real security research project that reveals how quickly the line between AI tool and AI weapon can blur.

Here's how it worked. The team at security firm Hacktron found a bug in the software running OpenAI's public help forum — the kind of place you'd go to ask a question about ChatGPT. That forum runs on a popular open-source platform called Discourse. From there, they found a second weakness in OpenAI's own login system. By chaining these two flaws together — using Claude to help reason through the attack steps — they were able to take over the ChatGPT and Codex accounts of actual OpenAI employees, then reach an internal code repository. They proved they had real access by submitting a harmless pull request, and then stopped immediately.

This was responsible research — the team reported everything to OpenAI right away, and OpenAI pushed a fix in roughly 14 hours. The company paid a $6,500 bug bounty. But OpenAI notably said the reward covers the flaw in its own login system — not the Discourse forum bug, since testing that was outside the scope of its program. OpenAI has not publicly described exactly what the login flaw was.

What makes this story genuinely new is the AI-on-AI angle. Attackers have always used tools to help them hack. But a sophisticated AI model that can reason about multi-step attack chains — combining bugs across different systems to reach a target — compresses the time and skill needed to find those paths. Today it was careful researchers with good intentions. The worry is that tomorrow it could be someone who doesn't stop at the pull request. The next time you hear that an AI company's internal systems are "secure," remember: it took one AI, two bugs, and three days to reach OpenAI's code.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →