US government website used Chinese model the FBI called “malicious”

On Wednesday, US government officials removed a Chinese AI search tool that was briefly deployed on the Federal Register website, Reuters reported.

The change came after social media users noticed an apparent contradiction: The National Archives was using one of Alibaba’s Qwen AI models, even as top US law enforcement claimed that such models illegally copy US frontier models. Earlier this month, the Federal Bureau of Investigation (FBI) named Alibaba among six leading Chinese firms allegedly conducting “industrial-scale distillation” that the agency says is helping America’s biggest competitor cut costs and development time in the race for global AI leadership.

It’s unclear when exactly the National Archives, which runs the Federal Register website, began offering visitors the option to use a Qwen model to search public comments on proposed regulations. So far, the independent agency tasked with increasing public access to federal government documents has not commented on the removal and did not respond to Ars’ request for comment. The White House and the FBI have also not commented.

Read full article

Comments

https://arstechnica.com/tech-policy/2026/09/us-government-website-used-chinese-model-the-fbi-called-malicious/




In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights: 

Raindrop raises $35 million for AI agent monitoring

Raindrop, designed to detect unknown failures in autonomous agents, announced a Series A funding round of $35 million, adding to last year’s $15 million seed round. Raindrop continuously analyzes agent behavior to surface silent and emerging failure modes, and to help AI systems repair and learn from them.

Advertisement. Scroll to continue reading.

Mandiant’s 2026 AI risk report highlights agentic attack escalation

Mandiant’s latest AI Risk and Resilience report finds that attackers have moved from prompting AI chatbots for research to letting autonomous agents run entire intrusions, citing incidents where a hijacked coding assistant helped spread a self-propagating worm across roughly 100 repositories and a compromised CI/CD credential let an attacker co-debug exfiltration tools with an LLM in real time. Separately, the report flags a new financial risk category, detailing a case where a corrupted value sent an accounting agent into a runaway reasoning loop that racked up over 15,000 API calls and roughly $50,000 in cloud costs in under an hour. 

Npm info-stealer author cashes in on bug bounty programs

CrowdStrike has tied an npm-based information stealer called PhantomRaven to a financially motivated actor who moonlights as a bug bounty hunter. The JavaScript malware, distributed through typosquatted npm packages, is assessed with high confidence to have been written by an LLM based on its verbose comments and placeholder code, and it harvests system details plus CI/CD environment variables from GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike found no evidence the stolen data is sold on criminal marketplaces, suggesting the operator uses it purely to flag compromises for bounty payouts.

Black Axe leaders extradited to US over cybercrime network

Five leaders of the Cape Town chapter of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to New Jersey to face wire fraud and money laundering conspiracy charges. Prosecutors say the group ran romance scams and advance-fee schemes against US victims from 2011 to 2021. The defendants, arrested in South Africa in 2021, also face related wire fraud and identity theft counts tied to business email compromise.

Ransomware developer gets 13-year prison sentence in Switzerland

A Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware used in extortion attacks on companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, though it described his role as closer to a technical consultant than the operation’s mastermind. Prosecutors estimated total damages from the campaign at roughly $123 million, and the verdict remains subject to appeal.

NIST, CISA detail defenses against token theft in the cloud

NIST and CISA have published a final joint report giving federal agencies and cloud providers implementation guidance for protecting the signed tokens and identity assertions that underpin single sign-on, federation, and API access. The report addresses token validation, secrets management, and detection at scale, incorporating feedback gathered through CISA’s Joint Cyber Defense Collaborative on an earlier draft. It builds on NIST’s existing security and privacy controls guidance and supports Secure by Design principles.

Organizations warned of critical SAP vulnerability

Organizations using SAP have been warned about CVE-2026-44756, a maximum-severity flaw in its Extended Passport processing code that lets unauthenticated attackers trigger memory corruption before any login check occurs. Onapsis discovered the vulnerability and dubbed it OVERPASS. Researchers from Pathlock and nullFaktor confirmed remote code execution is achievable over HTTP/HTTPS and NGRFC in lab testing, and warned that public technical write-ups released within 48 hours of the patch lower the bar for exploit development. The bug touches a wide range of SAP products, including S/4HANA, NetWeaver, and Business Suite. SAP is urging emergency patching of internet-facing systems.

WordPress plugin bug fuels mass webshell uploads

Defiant says attackers have exploited a critical file-upload flaw in the WooCommerce Wholesale Lead Capture plugin, blocking more than 100,000 exploit attempts since the bug was disclosed in February. The flaw lets unauthenticated visitors bypass file-type checks and upload PHP webshells because the plugin trusts an attacker-supplied list of allowed extensions instead of its own configuration. Site owners are urged to update to version 2.0.3.2 and check for suspicious PHP files, particularly in the uploads directory.

TP-Link patches Tapo camera flaw that skips password checks

OPSWAT researchers found two flaws in TP-Link’s Tapo C200 security camera, including an authentication bypass that lets an attacker on the network replay a value from the camera’s own challenge-response process to gain admin access without a password. A second bug allows a denial-of-service attack by sending oversized Wi-Fi credential data during device onboarding, crashing the camera’s HTTPS service. TP-Link fixed both issues, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware V5_1.4.6 released in August.

Plugin auto-updates open door to silent AI agent takeover

Researchers at Air’s security lab disclosed Plugin4Shell, a zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that lets an attacker controlling a plugin’s repository swap a pinned, reviewed commit for malicious code without tripping the SHA-pinning check. Because the affected agents check out a requested commit without verifying what actually landed, an attacker can name a branch after the pinned hash so git resolves to it instead, and background auto-updates push the malicious version to already-installed plugins with no user action. Anthropic and OpenAI have shipped fixes for Claude Code and Codex, Microsoft has not yet patched Copilot, and Google says the deprecated Gemini CLI will not be fixed at all.

Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/




AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained access to internal code repositories.

The entry point was OpenAI’s community forum, community.openai.com, which runs on Discourse. Discourse’s built-in image checks didn’t support the HEIC/HEIF photo format, so uploads in that format were passed to ImageMagick, exposing an unpatched flaw in the libheif library it relies on for decoding. 

Hacktron says the underlying bug had been fixed upstream a year earlier without ever being flagged as a security issue, so it was never assigned a CVE and missed the usual patching cycle.

Turning the flaw into a reliable exploit took several attempts and involved Claude Opus 4.8 and Opus 5. The exploit allowed remote code execution, which the researchers first used against a test Discourse instance, then on OpenAI’s own forum.

Because the forum let people sign in with their OpenAI account, code execution there opened a path to broader account access. Hacktron says that until the issue was fixed, any user or employee who logged into the forum could have had their ChatGPT and Codex accounts taken over.

In addition, since people often connect other services to those accounts, the theoretical exposure extended to services like GitHub, Slack and email.

Advertisement. Scroll to continue reading.

OpenAI distinguishes between the two flaws. It told SecurityWeek that the image-processing bug lived in the third-party service Discourse, while the account-takeover path was a separate, OpenAI-side issue. 

The OpenAI weakness was related to sign-in tokens generated for the community forum carrying excessive permissions and granting full API access to associated ChatGPT and Codex accounts.

To demonstrate the access without reading any internal code, Hacktron says it took over an OpenAI employee’s account whose Codex integration was linked to OpenAI’s GitHub organization, then used it to open a pull request in an internal repository before stopping further testing. 

OpenAI said its own review of the incident found limited reads of private-repository metadata and commits, followed by the researcher-submitted pull request, specifically to a README file.

Hacktron’s report also raises Slack as a service that could theoretically have been reached through connected accounts. OpenAI says Hacktron did not verify actual access to employee Slack messages.

The security firm reported the account-takeover issue to OpenAI through Bugcrowd, and the AI giant confirmed a fix about 14 hours later. It separately reported the libheif flaw to Discourse through HackerOne. Discourse had a fix ready within two days and added image-processing sandboxing as an extra layer of defense, then published a security advisory.

In a statement, OpenAI said, “We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.” 

The company paid Hacktron a $6,500 bounty for the OpenAI-side finding. 

Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Related: OpenAI Investigates Report Linking AI Agents to RubyGems Attack

https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/




Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. 

Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. 

Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal.

Microsoft rated all vulnerabilities as critical, but their CVSS scores indicate high or medium severity for some.

While some of these flaws were discovered internally by Microsoft, many were reported to the software giant by external researchers.

None of the vulnerabilities have been flagged as exploited, and Microsoft noted that all fixes were implemented on the server side, meaning that customers do not need to take any action.

Advertisement. Scroll to continue reading.

Microsoft also announced patches this week for a privilege escalation vulnerability affecting Windows. Users do need to update Windows to resolve this flaw, tracked as CVE-2026-85921, but Microsoft believes exploitation is ‘less likely’.

Like most major organizations, Microsoft has seen vulnerability discovery surge in recent months, driven by increased use of advanced AI. The company fixed a record-breaking 970 vulnerabilities across its products with the latest Patch Tuesday updates. 

Related: Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Related: Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/




AI Agents Get a Reality Check: AT&T and Crocs Want Automation but Still Need Humans in the Loop

At Dreamforce, brands dish on unrealistic agentic AI goals—and why the future of AI agents still needs plenty of humans. https://www.adweek.com/media/ai-agents-get-a-reality-check-att-and-crocs-want-automation-but-still-need-humans-in-the-loop/




OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.

The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.

https://www.securityweek.com/openai-says-its-models-hunted-github-for-leaked-api-keys-during-training/




How Coleman Turned a Fake AI Product Into a Marketing Win

The outdoor brand created a social and ecommerce campaign around a lazy river. https://www.adweek.com/commerce/how-coleman-turned-a-fake-ai-product-into-a-marketing-win/




Siddharth Taparia’s Strategy for Transforming Globally Fragmented JLL Into a Unified Marketing Force

Using measurement and AI to clarify the mission of a $17 billion real estate colossus. https://www.adweek.com/brand-marketing/siddharth-taparias-strategy-for-transforming-globally-fragmented-jll-into-a-unified-marketing-force/




AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.

The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.

https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/




First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks.

The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/