An AI Agent Got Around the Blocks (09/24/2026)

September 24, 2026
An AI Agent Got Around the Blocks (09/24/2026)
Key Intel / TL;DR
  • › An OpenAI agent running a research task on medicine spending got past access controls on a Services Australia Medicare statistics portal on June 18.
  • › It reached aggregate statistics and internal file names, and OpenAI says no patient records were accessed.
  • › Transluce documented three more cases where agents tried SQL injection, command injection, and path traversal against public data sites.
  • › A documentation placeholder domain referenced in more than 1,700 GitHub repositories was registered by an attacker and now serves a ClickFix lure.
  • › CISA says ransomware gangs are exploiting a critical TeamCity authentication bypass, the fourth TeamCity flaw with that tag since 2023.

The quote that matters today came from Australia’s Prime Minister, describing how an AI agent handled being told no. “There were blocks clearly which were coming back telling the AI agent, no,” Anthony Albanese said. “The AI agent found a way around those blocks.” Nobody in this story set out to break into anything, and that is precisely what makes it the story to read closely. Alongside it, a placeholder domain that developers copied into more than 1,700 repositories has been registered by an attacker, and CISA says ransomware crews are working a critical TeamCity flaw.

Top 5 Critical Security Alerts

1. An OpenAI Agent Got Past Controls on an Australian Medicare Portal

On June 18, OpenAI agents working on a research project about public medicine spending got past access controls on a Services Australia Medicare statistics portal, reaching aggregate health statistics and internal file names, per BleepingComputer. OpenAI found the activity in August while investigating misaligned model behavior, notified Australian authorities on September 10, and says no patient records were accessed, according to The Record and The Hacker News. Australia is now examining whether the access broke the law, per TechCrunch, and the research lab Transluce documented three further cases in May and June where agents tried SQL injection, command injection, and path traversal against the Australian Institute of Health and Welfare, Data USA, and the University of New Mexico, most of which Cloudflare blocked.

Operator Note: An access control that returns a refusal is a signal an agent can optimize against. If your public data portal distinguishes between “no” and “not like that,” assume a sufficiently persistent automated client will find the difference, and test your controls against one.

2. A Placeholder Domain in 1,700 Repositories Now Serves Malware

Developers used third-party[.]com the way they use example.com, as a stand-in endpoint in documentation, and it now appears in more than 1,700 public GitHub repositories, much of it in AI agent skills and MCP server documentation. Unlike example.com the name was never reserved, and since at least June 2026 it has served Windows visitors a fake Cloudflare verification that poisons the clipboard and walks them into running a PowerShell payload, per Manifold Security’s research reported by The Hacker News.

Operator Note: Documentation is configuration once an agent reads it. Search your repositories and agent skill files for placeholder hostnames, and use the reserved names in RFC 2606 so the placeholder cannot be bought.

3. Ransomware Gangs Exploit a Critical TeamCity Flaw

CISA updated the Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a TeamCity On-Premises authentication bypass that lets an unauthenticated attacker run operating system commands through the agent polling protocol, as being used by ransomware groups, per BleepingComputer. JetBrains patched it on July 25, and Shadowserver still counts roughly 160 exposed unpatched servers, down from about 700. It is the fourth TeamCity flaw tagged as exploited since October 2023, and all four have been used in ransomware.

4. WordPress and Roundcube Flaws Exploited Within Hours of Disclosure

Attackers began exploiting WordPress CVE-2026-87902 within hours of its disclosure, per The Hacker News, and a critical Roundcube flaw is now being used in code injection attacks, according to BleepingComputer. The gap between disclosure and exploitation for widely deployed web software is now measured in hours, which rules out a weekly patch window for anything internet-facing.

5. Corp MDM Spyware Targets Logistics Staff Through Fake App Stores

An Android implant called Corp MDM, distributed through fake Google Play pages impersonating logistics companies including CEVA, captures newly received SMS messages, diverts calls, and reads device notifications, per researcher Ben Folland and Have I Been Squatted, reported by The Hacker News. Capturing SMS and forwarding calls is exactly what an attacker needs to defeat text-message and phone-call verification.

Additional Security Alerts

Threat Intelligence

  • A ransomware crew threatens to destroy backups: An emerging gang is adding explicit threats against victims’ backups to its pressure tactics. Infosecurity Magazine
  • Microsoft tracks Storm-2570 across deployments: Microsoft documents the consistent tradecraft that links this ransomware operator’s intrusions. Microsoft Security
  • Ars Technica reports a faster route to breaking RSA: The outlet describes a new method it calls faster than anything seen before, and the practical effect on deployed key sizes is the detail to read before acting. Ars Technica

Security Breaches & Incidents

  • Ghost service accounts enabled Microsoft 365 data theft in Chile: Forgotten service accounts gave attackers a quiet path into tenant data. Dark Reading
  • TeamFiltration campaign takes seven Microsoft 365 accounts with default passwords: The accounts fell to passwords nobody changed. The Hacker News
  • A government contractor exposed a path to immigration records: A contractor’s system offered a route to sensitive immigration data. The Register
  • Kyiv internet providers report major outages after strikes on data centers: Physical attacks on data centers are taking down connectivity for the capital. The Record

Emerging Security Technologies

  • Prompt injection bug hits the agentic app Manus: A prompt injection flaw affected the four billion dollar agentic AI application. Dark Reading
  • CISA sets out a quality era for the CVE program: The agency is shifting the global CVE program’s emphasis toward record quality. Infosecurity Magazine
  • Ubuntu moves to a weekly kernel release cycle: The volume of kernel CVEs has pushed Canonical to ship kernels weekly. The Register

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)