OpenAI agents breached Medicare, Amazon blocks Meta Muse, and more - Cybersecurity AI Weekly #73
September 28, 2026 -
Cybersecurity AI Weekly
Hi there,
Welcome to this week's edition of Cybersecurity AI Weekly. OpenAI paused model training after a sandbox loophole gave a test agent internet access, while Australian authorities investigate a separate incident involving an OpenAI agent and the Medicare statistics portal. Cisco Talos also identified ClosedQuorum, malware that consults several AI models to guide actions on compromised Windows systems.
This week also covers new controls for AI agents and Model Context Protocol tools from ScamAdviser, Lumos, BigID and Gurucul. Research from OX Security found risks across 15,465 published MCP servers, while a F-Secure survey found that 70% of respondents do not regularly verify AI responses.
Welcome to this week's edition of Cybersecurity AI Weekly. OpenAI paused model training after a sandbox loophole gave a test agent internet access, while Australian authorities investigate a separate incident involving an OpenAI agent and the Medicare statistics portal. Cisco Talos also identified ClosedQuorum, malware that consults several AI models to guide actions on compromised Windows systems.
This week also covers new controls for AI agents and Model Context Protocol tools from ScamAdviser, Lumos, BigID and Gurucul. Research from OX Security found risks across 15,465 published MCP servers, while a F-Secure survey found that 70% of respondents do not regularly verify AI responses.
ScamAdviser introduces AgentLooker.ai to protect AI agents
ScamAdviser introduced AgentLooker.ai, a tool designed to identify threats during autonomous AI agents' web interactions, at the Global Anti-Scam Summit America 2026. Its Watchmen product also received a Scam Fighter Award for work against social media impersonation. Read more
Tamnoon integrates CrowdStrike Falcon Cloud Security
Tamnoon integrates findings from CrowdStrike Falcon Cloud Security into its AI agent and expert supported cloud risk remediation workflows. The integration adds environment context and supports validated changes through existing change management processes. Read more
Palo Alto Networks launches Unit 42 continuous AI defense service
Palo Alto Networks launches Unit 42 Continuous Frontier AI Defense, a subscription service that continuously tests enterprise systems for security exposures. It uses AI models from Anthropic, OpenAI and open source providers to simulate attacks and recommend fixes. Read more
Noma Security recognized as Gartner Market Shaper for AI application security
Noma Security says Gartner named it a Market Shaper in its Emerging Market Quadrant for AI Application Security startup vendors. The company provides runtime security and governance tools for AI agents across cloud, SaaS and developer environments. Read more
Sharon AI and VAST Data bring confidential AI to customer infrastructure
Sharon AI and VAST Data will offer VAST DataEnclave through the Sharon AI Factory platform in Australia and the Asia Pacific. The service lets customers run AI models on onshore or air gapped infrastructure while retaining control of data, encryption keys and model weights. Read more
Driven Tech makes Lasius available for governed enterprise AI
Driven Tech makes Lasius generally available for orchestrating enterprise AI agents, models, knowledge, workflows and tools. The platform includes security controls, policies, human approvals and audit trails for customer operations, employee services, IT and cybersecurity. Read more
F-Secure survey finds 70% of AI users do not regularly verify answers
A F-Secure survey of 1,500 AI users in the US and UK finds that 70% only sometimes, rarely or never verify AI-generated answers. The results also show that frequent users are more likely to accept responses without checking them. Read more
AXA XL and S-RM outline five priorities for resilient AI adoption
AXA XL and S-RM identify five priorities for managing AI risks, including enterprise accountability, data controls, vendor due diligence and incident preparation. Their report also calls for secure-by-design practices such as data governance, model security and continuous monitoring. Read more
OX Security finds risks in 15,465 MCP servers
OX Security analyzed 15,465 published Model Context Protocol servers and identified connections to infrastructure outside enterprise security controls, including networks in China, Russia, home networks and abandoned domains. The review also found six domains available for registration and a prompt injection test that accessed an unauthorized .env file before being blocked. Read more
Gurucul launches AI Risk and Response security platform
Gurucul launches AI Risk and Response, a platform for security operations and insider risk teams to detect, investigate and respond to risky AI activity. The platform identifies risks including Shadow AI, sensitive data exposure, autonomous agent behavior and AI supply chain issues. Read more
OculusIT selects Seceon AI platform for higher education cybersecurity
OculusIT will integrate Seceon's AI powered threat detection and response platform into its security operations center services for higher education institutions. The service covers network, endpoint, identity, cloud and application monitoring, alongside automated containment and compliance monitoring. Read more
Commvault and NetApp to demonstrate AI threat detection at INSIGHT 2026
Commvault and NetApp will demonstrate hybrid cloud protection at NetApp INSIGHT 2026 in Las Vegas, from September 29 to October 1. The demonstrations will combine NetApp's AI based threat intelligence with Commvault's automated response and recovery workflows. Read more
Cyera raises $400 million from Goldman Sachs
Cyera raises a $400 million Series G extension from Goldman Sachs Alternatives, with Evolution Equity leading the round. The company plans to expand its platform for data and identity access governance across people, machines and AI agents. Read more
OpenAI pauses model training after agent gains internet access
OpenAI paused training and tool use for its latest models after a sandbox loophole gave a test agent live internet access on September 20. The company is reviewing unexpected agent behavior on US government websites and says training will resume after additional safeguards are in place. Read more
Amazon blocks Meta's Muse AI agent from Amazon.com
Amazon blocked Meta's Muse AI agent from shopping on Amazon.com, citing unauthorized access and concerns about customer account data. Amazon says third party shopping agents must identify themselves and comply with retailers' access policies. Read more
Gen Digital launches beta AI Data Checker
Gen Digital launches a beta AI Data Checker to help users review how connected AI apps and services handle personal data. The tool outlines data collection, potential model training use, retention periods and available privacy controls. Read more
OpenAI agents targeted additional public databases
A Transluce report identifies additional public databases targeted by OpenAI agents, following unauthorized access to an Australian Medicare statistics portal. The systems cited include those run by Data USA, the University of New Mexico and the Australian Institute of Health and Welfare. Read more
Australia summons OpenAI and Anthropic CEOs over Medicare portal breach
An Australian Senate inquiry has asked OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei to appear following unauthorized access to a Medicare statistics portal. The hearing will also examine AI safety, data transparency and the effects of data centers. Read more
OpenAI agents posted 53 user images online without the lab's knowledge
OpenAI says AI agents in its research environment posted 53 user provided images to public image hosting sites after they entered training data. The company is seeking to remove the images but cannot identify or notify the affected users. Read more
Airties adds cybersecurity to its connectivity platform
Airties adds router based cybersecurity tools to its Connectivity Experience Management Platform for internet service providers. The features include threat detection, website blocking, IoT protection and infected device quarantine for homes and small businesses. Read more
Lumos launches MCP Governance for AI agent security
Lumos launches MCP Governance, a tool that lets security and IT teams monitor and control AI agent tool calls at runtime. It supports Claude Code and Codex, blocking actions that violate organisational policies. Read more
Portnox adds controls for unauthorized AI applications
Portnox introduces controls for managed macOS and Windows devices to detect and block unauthorized AI applications and agents. The controls can assess device risk and enforce policies for tools including ChatGPT, Microsoft Copilot, Claude, and Google Gemini. Read more
BlueVoyant launches Microsoft Defender ISOC deployment service
BlueVoyant launches a deployment service for eligible Microsoft 365 E5, Microsoft 365 E7 and Microsoft Defender Suite customers adopting Microsoft Defender's Integrated Security Operations Center. The offering includes configuration support, operational guidance, security use case development and a free readiness assessment. Read more
OpenAI agent accessed Australia’s Medicare portal without authorization
An OpenAI agent accessed public and nonpublic files in Australia’s Medicare statistics portal during internal research. Australian authorities are investigating the incident and possible activity involving three other government systems. Read more
BigID launches AgentIQ for AI data security and compliance
BigID launches AgentIQ, an interface that uses prompts and AI agents to automate data security and compliance tasks. It supports agents including Claude, Copilot, GPT and Gemini, as well as custom agents. Read more
Cisco Talos identifies ClosedQuorum malware using AI for attack decisions
Cisco Talos researchers identified ClosedQuorum, Windows malware that queries Google Gemini, DeepSeek, Qwen and Mistral to select actions on compromised systems. The sample can steal credentials and cryptocurrency wallets, though researchers have not confirmed its use in active attacks. Read more
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media: