Skip to content
Flock gets plucked, OpenAI agents arrived even earlier, inside China's AI spy shop

Flock gets plucked, OpenAI agents arrived even earlier, inside China's AI spy shop

Linkedin September 17, 2026

Defense in Depth : " How AppSec Needs to Change For the Speed of AI " Video: "Is tech debt an active threat?"

Defense in Depth : " How AppSec Needs to Change For the Speed of AI "

Video: "Is tech debt an active threat?"

In todays cybersecurity news...

Hacktivist collective stegan0gram says it physically removed a Flock Safety camera, copied nearly all its storage, and recovered an encryption key kept on the device. 404 Media and WIRED analyzed the files, which show the camera explicitly detects people, vehicles, plates, and bicycles. 21 days of logs captured roughly 50,200 vehicles and generated 1.6 million images. Flock says removing and tampering with a camera is illegal and it hasn't received enough technical detail to assess the claims.

OpenAI agents arrived early

Independent German AI researcher Jonas Wiedermann-Moeller says he found evidence that rogue OpenAI agents hijacked two Hugging Face accounts as early as May 13th and used unusually formatted files to probe the service for weaknesses. SentinelOne researcher Tom Hegel and Sydney Von Arx of the Nightingale Collective reviewed the evidence and said it matched the agents' known behavior. No one found evidence this caused a breach or was part of July's larger incident. OpenAI says it notified Hugging Face after the activity was flagged.

Internal chat logs, a sales deck, and other files reviewed by The Wall Street Journal show Chinese hacking contractor ZRON offering clients foreign government data and an AI platform to sort it, build timelines, and generate intelligence reports. The material includes apparent Russian diplomatic correspondence, Pakistani meeting minutes, and Philippine government emails. The Journal couldn't authenticate every document, and ZRON didn't respond. Western intelligence officials say the firm belongs to a broader hacking-for-hire network serving Chinese authorities.

( The Wall Street Journal )

Cyber experts left outside the AI safety room

Four cybersecurity veterans interviewed by NBC News say OpenAI , Anthropic , and other AI companies are developing plans for catastrophic hacking risks without meaningfully consulting their field. They argue the public proposals can sound technically incoherent and don't adequately address familiar security failures, even as agentic systems are already probing outside services. Their point is simple: any workable AI safety framework needs cybersecurity expertise at the table.

Big thanks to our sponsor, Vanta

Spain logs an AI-driven breach

Spain's Data Protection Agency says an unnamed organization filed the country's first report of a breach allegedly carried out by an AI agent powered by a known large language model. The organization says the agent found flaws, logged in, searched applications for more weaknesses, modified personal data, and accessed invoices. The agency hasn't verified the account yet, but says incident response, credential security, and containment now need to move at machine speed.

BragJack hijacks the browser copilot

Forever Security researcher Gal Weizman demonstrated BragJack, a proof-of-concept attack that let malicious browser extensions take control of privileged AI agents in Google Chrome with Gemini , Microsoft Edge , Opera Neon, Comet By perplexity , and Claude in Chrome. It could steal files, capture screenshots, activate cameras and microphones, and act on authenticated sites. The five vendors paid more than $20,000 in bounties and fixed the reported flaws. Organizations should update Chromium browsers and remove unvetted extensions.

One shared key opens every Issabel door

VulnCheck says attackers are exploiting a critical Issabel Framework flaw caused by the same hard-coded JWT signing key appearing in every installation. An unauthenticated attacker can forge a token and run operating-system commands as the Asterisk user. Issabel patched the flaw August 1st, and The Shadowserver Foundation first observed exploitation September 9th. Goes without saying users should apply the latest fix immediately.

Cyberattack knocks meteor site off course

The Belgium-based INTERNATIONAL METEOR ORGANIZATION says a cyberattack dealt a critical blow to its aging infrastructure and took much of its website offline. It expects several weeks of partial downtime while moving to new systems, though its fireball reporting service is back. The nonprofit, which coordinates professional and amateur meteor observers worldwide, is still posting updates on . No attacker has claimed responsibility.

Spotify , Apple Podcasts , YouTube , RSS link , Amazon Music , add as an Alexa Skill , or "Cybersecurity Headlines" on your favorite podcast app.

Cybersecurity Headlines

To view or add a , sign in

More articles by CISO Series