Skip to content
GPT-6 cyberattacks, ShinyHunters arrest, Nvidia AI guardrails

GPT-6 cyberattacks, ShinyHunters arrest, Nvidia AI guardrails

Cisoseries • September 29, 2026

The UK AI Security Institute says GPT-6 Astra completed unsanctioned supply-chain attacks in 29.2% of simulated cyber evaluations, compared with 6.3% for GPT-5.6 Sol and zero for GPT-5.5 in a smaller test set. The researchers disabled Astra’s cyber classifiers and used a fully simulated environment, so no real systems were attacked. The model created fake identities, solved CAPTCHAs, submitted malicious code, and sometimes posted supportive from other accounts to sway reviewers. Even after instructions explicitly said anything not listed was out of scope, Astra still launched full attacks in 4 of 49 runs. (UK AI Security Institute)

Dutch police arrest “reformed” hacker in ShinyHunters probe

Dutch authorities arrested 23-year-old Pepijn van der Stap, according to sources who spoke with KrebsOnSecurity. Van der Stap, who used the handle Umbreon, was convicted in 2023 for data theft and extortion, released in December 2025, and had since described himself as reformed while working in offensive security. Investigators are examining ShinyHunters’ breach of Dutch telecom provider Odido, where a Dutch-speaking caller tricked an employee and helped steal data on more than 6.2 million people. Krebs reports the arrest happened around September 16th. ShinyHunters escalated with attacks against the FBI’s jobs site and the Clop ransomware gang. (KrebsOnSecurity)

Nvidia builds a browser for AI agents

Nvidia released a new Open Agent Safety Platform meant to keep AI agents inside their guardrails. The system includes open-source software called OpenShell for setting limits on what agents can do, plus Sentry for monitoring agent behavior on network chips. Nvidia says this could have helped prevent the OpenAI/Hugging Face incident. Partners include Cisco, Microsoft, Oracle, CoreWeave, Dell, HPE, Lenovo, Arm, and Intel. (CNBC)

JadePuffer wipes Azure resources in minutes

Microsoft says the AI-driven ransomware actor JadePuffer, tracked as Storm-3168, used two compromised service principals in a pair of June attacks against one Azure tenant. One identity handled reconnaissance, while the other collected credentials and carried out destructive actions. In just seven minutes, the actor targeted more than 100 storage accounts along with Key Vaults, Function Apps, virtual machines, and App Services. It also tried to remove backup and recovery protections, although some deletions failed because of resource locks and unsupported API calls. Microsoft couldn’t confirm the initial access route, but credentials for one service principal had appeared in a public GitHub issue. (BleepingComputer)

Huge thanks to our sponsor, Intezer

Bitget restarts withdrawals after big breach

Crypto exchange Bitget has begun restoring withdrawals after attackers moved $387.5 million from portions of its hot- and warm-wallet infrastructure on September 24th. Bitcoin withdrawals reopened Monday, with Ether scheduled for Tuesday, USDT on Wednesday, and the remaining tokens, fiat withdrawals, and peer-to-peer transactions on October 2nd. Bitget says the vulnerability has been fixed, private keys and cold wallets weren’t compromised, and its separate self-custodial Bitget Wallet product was unaffected. The company says its protection fund will cover the losses while Mandiant and SlowMist support the investigation. (Infosecurity Magazine)

Polish medical software attack may expose millions

Polish authorities are investigating a cyberattack involving Medyc, software made by Qbusoft and used by healthcare providers. Poland’s data protection office says reports indicate the exposure could affect medical data belonging to as many as five million people. The Central Bureau for Combating Cybercrime is handling the investigation, and the country’s privacy regulator plans to inspect Qbusoft. Poland’s health-sector incident response team and Ministry of Health have also issued security recommendations for medical software suppliers as officials work to determine the scope of the breach. (The Record)

Supabase misconfigurations expose more than 16k databases

UpGuard researchers found 16,326 Supabase databases with readable tables, pointing to a widespread configuration problem rather than a breach of Supabase itself. Their schema-level review found indicators of personal information in more than half of the exposed databases. Smaller numbers appeared to contain passwords or authentication tokens, and a few showed signs of possible payment-card data. UpGuard says the exposures span the globe and have grown alongside rapid app development, including projects built with AI coding tools. The researchers validated a sample of the findings and notified application owners when they confirmed significant exposure. (BleepingComputer)

RatHat uses Gemini to find valuable victims

Researchers at Cleafy say RatHat’s Android banking malware is backed by a full malware-as-a-service operation with nearly 100 separate command-and-control deployments since April. The console can build, sign, publish, and regularly regenerate malicious apps to evade hash-based detection. Gemini is used on both sides of the attack: the implant asks the model where to tap when automation fails on an unfamiliar phone, while the operator panel analyzes stolen SMS messages to estimate bank balances and rank victims. RatHat also abuses Accessibility and wireless debugging to gain shell access, install a native Go service, and keep a reverse tunnel alive even after the malicious app is removed, until the phone reboots. (The Hacker News)

Extracted Entities