OpenAI API is a tool tracked across 9 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity May 11, 2026.
Between December 2025 and February 2026, a single hacker exploited AI tools, specifically Claude Code and OpenAI's GPT-4.1, to breach nine Mexican government agencies. The attacker, posing as part of a bug bounty…
A California resident filed a class-action lawsuit against OpenAI and Mixpanel, claiming inadequate protection of user data following a data breach at Mixpanel. The breach affected analytics data for users of OpenAI's…
Microsoft researchers discovered the SesameOp backdoor, which utilizes OpenAI’s Assistants API for remote access and data theft. The malware employs the API to store and relay commands from its command and control (C&C)…
In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…
Three cybersecurity professionals have been indicted for allegedly conducting ransomware attacks using the BlackCat (ALPHV) strain against five U.S. companies between May and November 2023. The accused, Ryan Clifford…
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…
Microsoft researchers identified the SesameOp backdoor, which utilizes OpenAI’s Assistants API for remote access and data theft. This malware component is designed to store and relay commands from a command and control…
Cybercriminals are partnering with organized crime groups to hijack cargo shipments from trucking and freight companies. Utilizing remote monitoring and management tools, these hackers are able to infiltrate logistics…
A vulnerability in Anthropic’s Claude AI has been identified, allowing attackers to exploit the code interpreter feature through indirect prompt injection. This exploit enables the extraction of sensitive user data,…