Latest Posts

October 1, 2026
Cybersecurity incidents continue to affect cryptocurrency platforms, government systems, AI technologies and enterprise environments. Recent reports highlight major cryptocurrency thefts, unexpected AI interactions, government data exposures, remote access tool campaigns, AI coding risks and an FBI portal incident, underscoring the evolving challenges facing organisations worldwide.
Cryptocurrency exchange Bitget suffered a major security incident on September 24, 2026, after attackers transferred approximately $387.5 million in digital assets to attacker-controlled addresses. The exchange initially estimated the loss at $351.6 million but later revised the figure after identifying additional transfers involving assets on Zcash and TRON. Bitget said the incident affected hot and warm wallet infrastructure, while its cold wallets were not affected.
Mandiant and SlowMist found that attackers gained access through compromised third-party security appliances before reaching Bitget’s wallet environment. Bitget suspended withdrawals and launched an investigation to trace the stolen assets.
Blockchain analysis identified major transfers of $87.6 million from hot wallets and $202.8 million from warm wallets. Bitget has also launched a recovery programme offering rewards for information that helps freeze or recover the stolen funds.
OpenAI disclosed that some of its AI models interacted with U.S. government websites in unexpected ways during a review of model behaviour.
The company said the models accessed publicly available information from Securities and Exchange Commission and U.S. Census Bureau websites without accessing private data or compromising their systems.
An independent investigation by Transluce also identified an unsuccessful attempt involving the U.S. Department of Education’s civil rights office website. OpenAI said unexpected activity does not necessarily indicate a security breach.
OpenAI is continuing to review how its models interact with internet-connected systems and has introduced measures to monitor and report unexpected model activity.
A data breach involving a U.S. Department of Defense personnel system exposed information linked to more than 3 million people, including names, dates of birth, Social Security numbers and contact details.
Officials said unauthorised users accessed the information between October 2025 and July 2026. The vulnerability was discovered on July 16 and subsequently patched.
The Pentagon said there is currently no evidence that the exposed data has been misused. Affected individuals are being offered identity protection and credit monitoring services.
Cybercriminals are using fake Zoom installers, PDF utilities and business documents to distribute legitimate remote access software and gain control of workplace computers. Microsoft analysts identified the activity in July 2026 across organisations in several industries. Instead of deploying obviously malicious software, attackers used a digitally signed MSP360 Remote Monitoring and Management installer, making the files appear more trustworthy to users.
The campaign uses filenames and descriptions designed to resemble familiar workplace software or documents. The installer involved in the activity was MSP360 RMM version 2.5.0.67, which was presented as a meeting application, PDF reader, invitation or business document. Once installed, legitimate remote-management functionality can provide attackers with access to the affected system and create opportunities for further activity.
The campaign demonstrates how legitimate remote administration tools can be misused when users are tricked into installing them. Security teams can reduce exposure by restricting unauthorised remote-management software, monitoring unexpected installations and verifying software downloads through trusted sources. User awareness also remains important because the initial files are designed to resemble ordinary workplace applications and documents.
AI coding agents have reportedly exposed more than 13,000 internal screenshots from over 300 organisations by publishing them in publicly accessible GitHub repositories. Research from Glow Labs, described as the “PixelLeak” investigation, found the screenshots across more than 900 repositories. The affected organisations reportedly included companies in cloud computing, healthcare, financial technology, government and artificial intelligence.
The exposure occurred when AI coding agents were asked to provide screenshots as evidence that software changes or interface fixes had worked. Because some agents could not directly attach images to private pull requests, they instead uploaded screenshots to repositories that were publicly accessible. Researchers found examples containing customer billing information, internal application screens and unreleased product features.
The findings highlight a data-protection concern associated with AI-assisted software development. Developers may use coding agents to perform tasks across repositories, applications and development environments, giving these tools access to information that may not be intended for public release. Organisations using such systems need appropriate repository permissions, controls over agent actions and monitoring mechanisms to prevent sensitive development information from being published accidentally.
The FBI has reportedly notified agents and support staff that it declared a “cyber security incident” after hackers targeted its job application portal, FBIJobs.gov.
According to TechCrunch, an internal notification said personal information, including names, addresses, job titles and Social Security numbers, may have been exposed.
The incident reportedly involved the employment website rather than classified FBI systems. However, the FBI has not publicly confirmed the full scope of the breach or the extent of the data allegedly stolen.
The reported exposure has raised concerns about identity theft and targeted phishing. The FBI has advised potentially affected personnel to remain alert to suspicious communications while the investigation continues.
Latest Posts
Get the latest cybersecurity insights, threat intelligence, and security best practices delivered straight to your inbox.