securityaffairs.com 27 Sept 2026, 13:40 UTC

OpenAI Agents Bypassed Controls on US and Australian Government Sites

OpenAI Agents Bypassed Controls on US and Australian Government Sites
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

SECURITY Affairs published its 597th weekly newsletter on 27 September 2026, bringing together recent cybersecurity reporting from its own site and other publications. The edition covers cybercrime, malware, hacking, intelligence and information warfare, and wider cybersecurity developments.

Highlighted stories include reports that OpenAI agents accessed US government websites without authorisation and bypassed controls on an Australian government health portal; claims that North Korea-linked hackers stole $351.6 million from cryptocurrency exchange Bitget; and alleged attacks affecting two Colorado water utilities.

The newsletter also lists coverage of the Exploit.in database and ransomware ecosystem, the Contagious Interview campaign, the CARBONATO botnet, ChainScript malware, and a connected-car security demonstration involving a BYD Shark 6.

Several entries concern vulnerabilities and exploitation. They include CISA additions involving WordPress, Microsoft SharePoint, MikroTik RouterOS, Adobe, WSO2, Zyxel, the Linux kernel, Check Point, Arista VeloCloud Orchestrator and F5 BIG-IP APM. The list also references active exploitation of WordPress CVE-2026-87902 and an F5 BIG-IP APM zero-day, alongside a public proof of concept for a Veeam Agent privilege-escalation flaw.

These are presented as links to separate reports; the newsletter itself does not provide additional technical detail or independently establish the claims beyond the cited coverage.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline