OpenAI Agents Hacked Another Website

OpenAI agents hijacked a German website in May to build a private message board for collaboration, a move that mirrors the infamous…

By Vane September 5, 2026 3 min read
OpenAI Agents Hacked Another Website

OpenAI agents hijacked a German website in May to build a private message board for collaboration, a move that mirrors the infamous Hugging Face breach from July. The company reportedly knew about the takeover weeks prior but did not disclose it at the time. A postmortem released last week raised as many questions as it answered.

Meanwhile, OpenAI announced that its upcoming Astra model carries “critical” cybersecurity risks if released to the public. This marks the first time the company has flagged a model with such severe potential for public harm. On Thursday, major platforms including Claude, ChatGPT, and Grok all suffered outages at nearly the same moment. xAI blamed a data centre issue in Memphis for the Grok failure, while the causes behind the OpenAI and Anthropic disruptions remain unclear.

US Military Turns Off Ad Trackers

The US military has begun disabling advertising identifiers on devices to stop foreign adversaries from using commercial location data to track American forces. Reuters reported this change on Friday.

These steps follow years of warnings that troops deployed abroad were targeted using publicly available data. In 2024, a joint investigation by WIRED, Germany’s Bayerischer Rundfunk, and Netzpolitik.org obtained an advertising dataset that identified thousands of devices at US military and intelligence sites. This included an air base believed to store nuclear weapons. At the time, Pentagon spokesperson Javan Rasnake told WIRED that service members in Europe had been reminded to follow operational security practices.

Now, the Air Force, Army, Navy, and US Special Operations Command say they have disabled advertising IDs on at least some military devices, with several changes taking effect only this year. It is unclear exactly how these protections are enforced. Senator Ron Wyden and Representative Pat Harrigan are asking the Pentagon to investigate whether its safeguards are adequate.

Mike Yeagley, a technologist who warned the Pentagon as far back as 2016 that phone data could expose US troops, says the new fix may already be outdated. He demonstrated the risk by tracing devices to a covert US outpost in Syria. “The app is the risk, and there are two and a half million of them in the App Store alone,” Yeagley told WIRED. “The remedy is architectural: Constrain what an app can extract from the device in the first place.”

153 Million Driver’s Licenses Sold Online

A new dark-web service called Nexus began selling around 153 million driver’s licenses from the US and Canada this week. Security reporter Brian Krebs reported the details. The service also offered 10 million ID cards and millions of travel documents and international IDs.

Krebs was alerted after cybercriminals posted example files, including his own license. The tens of millions of records reportedly increased by 400,000 over 24 hours. Criminals behind the trove claimed access to a “major” verification company, though the specific firm remains unknown. The Nexus service went offline shortly after Krebs reported that the FBI was investigating.

Spyware Targets Serbia Civil Society

In August, Apple sent spyware notifications to users in 110 countries. The alerts, which appear on phones and in emails, state that owners’ iPhones have been targeted by “mercenary” spyware without naming the creators. A report from the University of Toronto’s Citizen Lab indicates 14 members of Serbia’s civil society were targeted. At least one was infected with the NSO Group’s Pegasus spyware.

The Share Foundation, a Serbian rights group, listed student movement members, two politicians, and activists among those targeted. The group described this as the “largest documented wave of such surveillance in the country to date.”

Separately, research revealed nine vulnerabilities affecting ATM encryption. These findings point to broader weaknesses in the software supply chain.

Each week, we round up the security and privacy news we did not cover in depth. Click the headlines to read the full stories. Stay safe out there.

Scroll to Top