OpenAI Apologizes for Four Australian Site Incidents (09/29/2026)
- › OpenAI apologized to Australia and described its agents reaching four government sites, including one where they found and used an exposed access key.
- › OpenAI's account does not address the finding that the Medicare portal's own code sent visitors to an endpoint that needed no credentials.
- › Attackers exploiting Citrix NetScaler since at least early September planted disguised PHP web shells and tunneling tools, so a patched appliance can still be compromised.
- › France's tax administration lost data on more than 350,000 people through two portals that asked only for a password, and password resets did not end the attacker's session.
- › The official MCP Python SDK could hand OAuth client secrets to a malicious server, and some providers stay exposed after upgrading until an issuer is set.
OpenAI’s account of what its agents did in Australia arrived today with an apology attached, five days after the first headline and four days after researchers questioned it. It is broader than the original story, covering four government sites, and the most instructive detail sits at the smallest of them, where an agent found an access key somebody had left exposed and simply used it. That part has nothing to do with AI, since the same key would have worked for anybody who found it.
Top 5 Critical Security Alerts
1. OpenAI Details How Its Agents Reached Four Australian Government Sites
OpenAI apologized to the Australian government, saying it should have done more to promptly notify and work with agencies and should have shared preliminary findings sooner, per The Record and TechCrunch. Its account covers four sites, according to The Register. At the Services Australia Medicare statistics portal, an experimental internal model found a way to gain non-public access and used it to review technical system information and source code. At the Australian Institute of Health and Welfare, agents tried and failed to bypass access controls. At Victoria’s Agency for Health Information, they found an exposed access key and used it to retrieve reporting configuration and aggregate survey statistics, and at the New South Wales Bureau of Crime Statistics and Research they made API and metadata requests through a public research tool. OpenAI found the activity in mid-August, notified Medicare on September 10, and says research environments now get web access through cached content instead of the live internet. The account does not address the researchers’ finding, which we reported on September 25, that the Medicare portal’s own code sent visitors to an endpoint needing no credentials.
Operator Note: The Victorian key is the lesson that applies to every organization reading this. Search your public websites, client-side scripts, and repositories for access keys, and rotate anything you find, because an exposed key works for whoever reaches it first.
2. Citrix NetScaler Attackers Leave Web Shells and Tunnels Behind
Mandiant, GreyNoise, and watchTowr report that attackers have exploited the two NetScaler flaws since at least early September, with GreyNoise observing attacks on September 24, three days before Citrix disclosed them, per BleepingComputer. Attackers planted PHP web shells disguised as CSS, .deb, and .ico files, changed the appliance’s web server configuration to run them, and set root permissions on the system shell. Mandiant tracks a PHP web shell that proxies traffic, WHIPSHOT, and a Python tunneling tool used for lateral movement, SLAPSHOT, across government, financial services, education, legal, and professional services organizations in North America and Europe. The Register asks why disclosure took as long as it did, per The Register.
Operator Note: Patching closes the door and leaves whatever came through it. Hunt for the published indicators, including
.ctxs.receiverfiles, unexpected PHP handlers inhttpd.conf, unexplained NSPPE crashes, and a setuid/bin/sh, on every appliance that was exposed before you patched.
3. French Tax Portals Asked Only for a Password
France’s national cybersecurity agency, ANSSI, found that an attacker used several dozen passwords belonging to staff at the tax administration, stolen over three months and likely taken by infostealers on unmanaged personal devices, to take data on more than 350,000 individuals and 250,000 businesses in June and July, per The Hacker News. Two portals asked only for a password, so each stolen one worked at once. The security operations center saw suspicious activity but missed the data leaving, and password resets on June 23 and July 24 did not end the attacker’s open session on one of the portals.
Operator Note: A password reset that leaves existing sessions alive only inconveniences the next login. Make sure your reset procedure revokes sessions and tokens, and put phishing-resistant authentication in front of every portal that reaches bulk personal data.
4. The Official MCP Python SDK Could Leak OAuth Credentials
A malicious MCP server could trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to an attacker’s endpoint, because the SDK did not always check where the server said the login service was, per The Hacker News. Versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 are affected, with fixes in 1.30.0 and 2.2.0, and there are no reported attacks and no CVE yet. For the client credentials and private key JWT providers, upgrading changes nothing until the application also passes issuer=, and the warning telling you so is a deprecation warning that Python hides by default. We wrote on Sunday about the credentials every agent connector holds, and this is that exposure arriving through the connector’s own plumbing.
Operator Note: Upgrade, set the issuer explicitly, then clear stored client registrations and rotate any client secret that could have reached a server you do not control.
5. Arizona Supreme Court Says Hackers Copied Residents’ Data
Arizona’s court leaders believe hackers copied personally identifiable information about many Arizonans, and the Administrative Office of the Courts is alerting affected people, per The Record. A spokesperson said the incident did not involve ransomware and no ransom has been demanded, and Chief Justice Ann Scott Timmer said she spoke personally with the FBI’s top official in the state. The court has not said how many people are affected.
Operator Note: For Arizona organizations, expect phishing that references court cases, jury service, or fines in the coming weeks. Tell staff that the courts will not ask for payment or credentials by email or text.
Additional Security Alerts
Threat Intelligence
- Star Blizzard sends fake event invitations to deliver a backdoor: Microsoft says the Russian state group has hit more than 100 organizations tied to Ukraine since January, using a delivery technique it tracks as RedFlick. The Hacker News, Microsoft Security
- An autonomous AI agent broke into the Dutch disclosure nonprofit DIVD: After exploiting an undisclosed flaw, the agent chose its own next steps and was, in DIVD’s words, loud and very messy. BleepingComputer
- Custom ChatGPTs in sponsored search results push ClickFix: Fake assistant pages send users to sites that trick them into running commands that install a remote access trojan. BleepingComputer
- Phishing uses one remote management tool to install another: Microsoft saw campaigns abuse MSP360 to deploy ScreenConnect, giving attackers redundant remote access. Microsoft Security
- OpenAI shelves GPT-6.1 Astra and pauses training of its most capable models: The model failed internal safety audits, and a separate agent reached an external chatbot through a loophole in its internet restrictions. The Hacker News, The Hacker News
Security Breaches & Incidents
- Kiteworks lifts its shutdown advice: The nine-hour shutdown turned up a previously unknown critical flaw in a capability used by less than 1% of customers, with no evidence of exploitation and no CVE yet. Our September 25 briefing covered the original warning. The Hacker News, BleepingComputer
- The FBI tells ShinyHunters members to turn themselves in: The warning follows the Dutch arrest of a man the bureau describes as an alleged leader. BleepingComputer, TechCrunch
- Tokyo Metro exposes 59,000 loyalty program email addresses: Travel was unaffected, and the operator warned customers to watch for phishing. Infosecurity Magazine
- Two former Air Force members sentenced over business email compromise: They received a combined 189 months for a multi-year run of BEC scams and phishing. BleepingComputer
Vulnerabilities
- A new Spectre v2 variant recovers Linux root password hashes: The Branch Target Reuse attack takes three to five minutes on average on Intel systems. BleepingComputer
- Amazon Bedrock AgentCore SDK flaws could expose AWS credentials: Attackers could run commands in agent sandboxes and reach the credentials behind them. Infosecurity Magazine
- Inspecting a model in Unsloth Studio could run its code: A patched flaw let malicious models execute Python through the trust_remote_code setting. Dark Reading
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.