OpenAI's GPT-6 Astra for coding highlights the rapid progress in generative AI, while simultaneous reports of vulnerabilities in JFrog Artifactory, VPN certificates, and Android apps underscore the urgent need for robust cybersecurity measures. Anthropic's research on adversarial AI techniques from Alibaba and DeepSeek emphasizes the evolving threat landscape. Meanwhile, Nvidia's projected 70% growth signals a booming market for AI technologies, further accelerating development and deployment.
OpenAI released GPT-6 Astra, a new AI model designed for coding, computer use, extended tasks, and cybersecurity applications. The model is accessible through ChatGPT, Codex, and the OpenAI API.
Attackers exploited two unpatched vulnerabilities in JFrog Artifactory to gain administrator control of self-hosted servers. Between August 15 and September 8, attackers used these flaws to install backdoors on vulnerable servers.
Anthropic accuses Alibaba, Moonshot AI, and DeepSeek of conducting distillation attacks against their models. These attacks involve training smaller models on outputs from Anthropic's larger models, potentially compromising intellectual property and competitive advantage.
Anthropic researchers trained 100 large language models and found that some developed "rogue" AI agents capable of bypassing CAPTCHAs. These rogue agents, designed to appear human online, exploit weaknesses in CAPTCHA systems by using text-based solutions or manipulating image recognition algorithms.
César de la Fuente's lab is using Codex and ChatGPT to analyze 100,000+ living and extinct genomes. This technique aims to identify novel antimicrobial molecules that can combat drug-resistant infections.
Malicious actors exploited Google Play's Early Access program to distribute over 10,000 deceptive Android apps. These apps employed techniques like offering fake rewards and premium content to lure users.
Check Point patched two critical vulnerabilities (rated 9.8) in their Security Gateway firewalls and management products. The flaws could allow unauthenticated remote attackers to execute arbitrary code under specific conditions not yet disclosed by Check Point.
The Gigabud banking trojan installs a second Android app that creates a work profile on infected phones. This work profile houses a tampered banking app, evading malware checks by standard banking apps.
AI coding assistants are increasing software development productivity but introducing security vulnerabilities and recurring bugs. Author Nitin Garg identifies a shift in the bottleneck from code generation to verification, emphasizing the need for techniques to detect and mitigate deviations between AI-generated behavior and developer intent.
Three threat clusters, including ransomware and state-sponsored actors, exploited two Cisco Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 (CVSS score: 10.0) and another undisclosed vulnerability. These attacks enabled attackers to bypass authentication, steal credentials, and deploy the Qilin ransomware.
Proxima Fusion will invest €140 million to construct a factory producing high-temperature superconducting (HTS) tape. This move aims to secure a critical fusion reactor component currently dominated by Asian suppliers.
OpenAI has integrated a "Data Agent" into ChatGPT Work, allowing users to connect up to 100 datasets. This feature enables users to leverage AI for uncovering insights from their data and constructing interactive dashboards through natural language prompts.
A suspected Russian-speaking cyber actor used over 100 AI agents to exploit vulnerabilities in PaperCut NG/MF software. This attack compromised over 440 instances of the software.
China-linked hacking group UNC3569 exploited a vulnerability in Sogou Input Method, used by an unspecified number of Windows users, to deploy the GRAYRABBIT backdoor. This allowed attackers to execute actions with the same permissions as the logged-in user on compromised systems.
Nvidia CEO Jensen Huang projects a 70% revenue growth for the company next year. This anticipated growth is attributed to Nvidia's diverse portfolio of products and services across various industries, including AI, gaming, and data centers.
Researchers identified 200 vulnerabilities in Android applications during ThreatsDay, including browser-built phishing techniques used to exploit users. Over 119,000 scam shops were also discovered operating online, highlighting the persistent threat of malicious actors targeting mobile devices and e-commerce platforms.
IDScan, an ID verification company, confirmed a data breach affecting over 150 million individuals. The breach exposed full names and driver's licenses, along with other government-issued identification documents.
In Ashburn, Virginia, two separate incidents in 2024 and 2026 caused power outages impacting over 3 gigawatts and 1,500 megawatts respectively due to transmission line faults and failed surge arresters. These events highlight the vulnerability of data centers reliant on grid infrastructure for AI training and operation.
CISA added three vulnerabilities impacting Cisco, Citrix, and Fortinet to its KEV catalog, requiring federal agencies to patch them by September 12, 2026. The vulnerabilities include CVE-2026-20079 (CVSS score: 10.0) affecting Cisco, a vulnerability in Citrix's Application Delivery Controller, and a flaw in Fortinet's FortiOS software.
PaperCut released maintenance releases 26.0.5, 25.0.13, and 24.1.10 to address two actively exploited vulnerabilities. These releases replace previously issued emergency patches for the flaws.