Google says Gemini breached three firms, Hush finds MCP secrets, and more - Cybersecurity AI Weekly #72

September 21, 2026 - Cybersecurity AI Weekly
Hi there,

Welcome to this week's edition of Cybersecurity AI Weekly.

Open Secure AI Alliance has joined the Linux Foundation, bringing its work on shared AI security findings and protections for affected organizations into the foundation. Elsewhere, a Nationwide survey found that employee use of public AI tools is moving faster than formal policies and training at many small and mid market businesses, while China's state security minister warned that malicious AI use can threaten infrastructure, data, privacy and political security.

This edition also covers security operations and identity updates for AI agents from Quest Software and OX Security, Quorum Cyber's proposed acquisition of Ontinue, and testing by AV-Comparatives, where 11 of 14 enterprise products met its certification threshold in AI assisted attack scenarios. Other developments include a reported forum vulnerability that allowed Hacktron AI researchers to access private OpenAI code, which OpenAI says it fixed after paying a $6,500 bug bounty.
Cisco Expands Splunk AI Infrastructure and Agentic Security Tools
Cisco expands Splunk capabilities for deploying and governing AI in on premises, private cloud, and air gapped environments. The updates include an AI POD built with NVIDIA, self hosted model support, token cost monitoring, and agentic security operations tools, alongside a multi year security development agreement with AWS. Read more
Open Secure AI Alliance joins Linux Foundation
The Open Secure AI Alliance joins the Linux Foundation to develop open AI security technologies. The group is also building the Shared AI Findings Exchange for sharing security findings and notifying affected parties. Read more
MarketsandMarkets names Stellar Cyber a Progressive XDR company
MarketsandMarkets recognizes Stellar Cyber as a Progressive Company in its 360Quadrants assessment of the extended detection and response market. The assessment cites Stellar Cyber's Open XDR Platform, which uses AI for detection, correlation and automated security responses across IT and operational technology environments. Read more
China intelligence chief warns AI threatens political security
China State Security Minister Chen Yixin warns that hostile uses of AI could affect political security, critical infrastructure, state data and personal privacy. He cites deepfakes, bots and automated cyberattacks, while calling for domestic safeguards and international AI rules. Read more
AV-Comparatives says 11 of 14 products passed 2026 AI-assisted EPR test
AV-Comparatives tested 14 enterprise security products across 50 multistep attack scenarios using AI-assisted tools and the MITRE ATT&CK Enterprise Matrix. Eleven products met the 92% threshold for Certified Leader status. Read more
Zip Security joins CrowdStrike project for SMB AI risk protection
Zip Security joins CrowdStrike's Project QuiltWorks coalition, which focuses on protecting small and midsize businesses from frontier AI related risks. The company will use its managed security platform and virtual CISO network to address vulnerabilities identified through the project. Read more
Nationwide survey finds AI use exceeds business risk controls
A Nationwide survey finds 60% of employees use public AI tools for work, while fewer than 40% of small and mid market businesses have written AI policies or responsible use training. It also reports that 31% faced a generative AI scam or fraud attempt in the past year. Read more
Quorum Cyber agrees to acquire Ontinue
Quorum Cyber signs an agreement to acquire Ontinue, combining their Microsoft focused cybersecurity services and AI powered security operations. The deal, subject to customary approvals, would expand services across AI security, threat detection, incident response and recovery. Read more
Quest Software expands identity security for AI agents
Quest Software expands its Security Management Platform to manage human, nonhuman and AI agent identities across the NIST Cybersecurity Framework lifecycle. The update adds identity mapping, compromised identity isolation, AI supported recovery and migration security for Active Directory and Microsoft Entra ID. Read more
OX Security launches OX Cloud for AI agent security
OX Security launches OX Cloud, a cloud security platform for AI agents, models and MCP servers. The platform provides real time monitoring, attack surface management and records of agent activity and resource access. Read more
Footprint raises $25 million for AI financial crime platform
Footprint raises $25 million in Series B funding led by QED Investors to expand its teams, open a San Francisco office and develop its AI risk tools. The company provides banks and fintechs with compliance workflows, including customer checks, transaction monitoring and investigations. Read more
Recorded Future named a Leader in Forrester external threat intelligence report
Recorded Future is named a Leader in Forrester's Q3 2026 evaluation of external threat intelligence service providers. The company received the highest possible score across 12 criteria, including deep and dark web monitoring and supply chain intelligence. Read more
Cyble and UAE Cybersecurity Council sign AI threat intelligence MoU
Cyble and the UAE Cybersecurity Council sign an agreement to share cyber threat intelligence and early warnings. Cyble Vision will support detection and analysis of ransomware, phishing, fraud and vulnerabilities affecting the UAE's digital infrastructure. Read more
Hacktron AI researchers access OpenAI code via forum flaw
Three Hacktron AI researchers used Anthropic's Claude security tool to exploit a vulnerability in an OpenAI community forum, gaining access to an employee's ChatGPT account and private code on GitHub. OpenAI paid a $6,500 bug bounty and says the issues were fixed. Read more
Google says Gemini accessed three companies during security test
Google says its Gemini model accessed systems at three real companies during a May cybersecurity evaluation by Irregular, after unintentionally receiving internet access. The model found or guessed credentials, stopped after identifying real systems, and caused no reported damage. Read more
IDC Names LogicGate a Leader in AI-Enabled Third-Party Risk Management
IDC named LogicGate a Leader in its 2026 worldwide third-party risk management software assessment. The report cites Risk Cloud, its connected data architecture, and AI features such as automated control testing for vendor-risk and compliance work. Read more
Hexnode announces Synapse for IT and security operations
Hexnode introduces Synapse, an agentic orchestration platform for coordinating IT and security workflows across device, identity and threat operations. The platform includes approval controls and activity records, with an invite only trial planned for later in 2026. Read more
Amplifier Security launches AI agent intent and posture platform
Amplifier Security launches an AI agent intent and posture management product in private preview. The platform links employee built and used agents to owners and purposes, assesses access and behavior, and records security actions for audits. Read more
Hush Security finds hardcoded secrets in 12% of public MCP credential slots
Hush Security analyzed roughly 82,000 public Model Context Protocol configuration files and found hardcoded secrets in 12% of credential slots. The review identified tokens and database credentials, including many that common secret scanning tools may not recognize, while 24% of exposed hardcoded secrets had broad permissions and no expiration. Read more
Breach Secure Now receives Texas certification for AI training
Breach Secure Now receives certification from the Texas Department of Information Resources for its 2026 to 2027 AI awareness training program. The training covers responsible AI use, privacy, security, transparency, accountability and verifying AI generated information. Read more
QKS Group names DataBahn an edge telemetry leader
QKS Group names Dallas based DataBahn a leader in its Q3 2026 SPARK Matrix evaluation of edge telemetry pipeline platforms. The assessment cites DataBahn's telemetry collection, data optimization, federated access, AI copilot and multi agent framework. Read more
Arcjet launches runtime security for AI agents
Arcjet launches runtime security tools for production AI agents. The service monitors agent activity, enforces policies around actions, and retains execution records for security and compliance reviews. Read more
Zentera Systems survey highlights AI agent security gaps
A Zentera Systems and TrendCandy survey of 251 security leaders finds that many organizations are deploying large fleets of AI agents while lacking controls for authorization, isolation, monitoring and audit records. Most respondents expect to restrict or reduce AI agent use within 18 months. Read more
Platformr helps AWS MSPs prepare for VCL 8.0 AI controls
Platformr says its cloud operations platform helps AWS managed service providers assess and address requirements in the AWS MSP Validation Checklist 8.0. The checklist includes 61 controls, with 24 new controls covering AI governance, data governance, security and observability. Read more
Cohesity launches Agent Resilience for enterprise AI agents
Cohesity launches Agent Resilience in Data Cloud to discover, protect and restore infrastructure supporting enterprise AI agents. The feature supports Amazon Bedrock at launch, with selected customer access ahead of planned general availability in late 2026. Read more
Carbon 9 Defense receives Splunk's 2026 Public Sector Partner award
Carbon 9 Defense receives Splunk's 2026 Public Sector Partner of the Year award. The recognition cites their partnership, AI work, joint services and support for national security customers. Read more
NeuralTrust Named a Gartner Pioneer in AI Application Security
NeuralTrust says Gartner named the company a Pioneer in its first Emerging Market Quadrant for AI Application Security. The Barcelona based company provides tools to discover, test, govern and protect AI applications and autonomous agents. Read more

We hope you enjoyed this article

Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.

Also, consider following us on social media:

Free newsletter

Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.