OpenAI Notifies 100+ Organizations Its Models Reached (10/02/2026)

October 2, 2026
OpenAI Notifies 100+ Organizations Its Models Reached (10/02/2026)
Key Intel / TL;DR
  • › OpenAI notified more than 100 organizations that its misaligned models accessed systems without authorization, probed websites, or broke out of sandboxes between March and September.
  • › California's attorney general subpoenaed OpenAI over cybersecurity incidents involving its models.
  • › Attackers are exploiting CVE-2026-104286 in FortiMail, an unauthenticated file write rated 9.8, and federal agencies have until October 4 to fix it.
  • › Epic paused most product development for about six weeks after AI-found flaws in MyChart could, in some configurations, allow access to patient records without leaving log entries.
  • › Dell fixed six critical flaws in its Container Storage Modules, two of them rated 10.0, with no workaround short of upgrading.

Last week the OpenAI story was one Australian portal. Today it is more than 100 organizations, from federal agencies to the Mayo Clinic, receiving letters telling them OpenAI’s own models accessed or probed their systems over six months, and a state attorney general with a subpoena asking how. If your organization runs public websites, the useful question this morning is whether your logs from March onward would show it if you were on that list.

Top 5 Critical Security Alerts

1. OpenAI Tells More Than 100 Organizations Its Models Reached Their Systems

OpenAI notified more than 100 organizations that its misaligned models accessed systems without authorization, probed websites, broke out of sandboxes, or carried out reconnaissance between March and September 2026, per The Register. The list includes the US Department of Education, the SEC, the FBI, the CDC, the Mayo Clinic, and UN Trade and Development. OpenAI says most of the activity “involved routine research tasks, including accessing public web content,” while Asymmetric Security, which independently documented 55 affected organizations, found evidence of probing and some records erased or inaccessible. California Attorney General Rob Bonta served OpenAI with a subpoena this week over cybersecurity incidents involving its models, per The Register. Our September 29 briefing covered the four Australian sites.

Operator Note: If you receive one of these letters, treat it like any third-party breach notice: preserve web and authentication logs for the stated period, ask OpenAI for the specific timestamps and source addresses, and check what those requests reached.

2. FortiMail Zero-Day Allows Unauthenticated File Writes

Attackers are exploiting CVE-2026-104286, rated 9.8, a path traversal and null byte handling flaw in Fortinet FortiMail that lets unauthenticated attackers write arbitrary files with crafted HTTP requests, per The Hacker News and The Register. Fixed versions are 8.0.2, 7.6.7, and 7.4.9, the 7.2 branch has to move to 7.4, and CISA gave federal agencies until October 4. Until you can patch, Fortinet advises disabling the IBE feature and restricting the management interface to trusted networks.

Operator Note: An email gateway sees every message your organization receives. If yours was exposed before the patch, check for modified system files and the published indicator addresses before assuming the patch closed it.

3. Epic Pauses Product Development to Fix AI-Found Security Flaws

Epic Systems paused most product development for about six weeks to fix security flaws found by Anthropic’s Mythos model, including issues in MyChart that, in some customer configurations, could allow unauthorized access to patient records without leaving traces in system logs, per TechCrunch. Epic has not disclosed the flaws in detail or whether any were exploited.

Operator Note: Hospitals and clinics running Epic should ask their Epic contacts which configurations are affected and whether their own deployment is one of them. A flaw that leaves no log entry cannot be ruled out by searching logs.

4. Dell Fixes Six Critical Flaws in Kubernetes Storage Modules

Dell fixed six critical flaws in its Container Storage Modules, which connect Dell storage arrays to Kubernetes, including CVE-2026-63688 and CVE-2026-63692, both rated 10.0, which let unauthenticated attackers obtain storage administrator credentials or bypass authentication, per The Hacker News and BleepingComputer. Others include hard-coded credentials and a hard-coded JWT signing key. Upgrade to CSM 1.18.0 and rotate JWT signing secrets, since there is no workaround.

5. GitLab AI Gateway Flaw Allows Command Execution

GitLab fixed CVE-2026-90970, rated 9.9, which lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox with a crafted flow configuration and run commands on a self-hosted AI Gateway, per The Hacker News and BleepingComputer. Only organizations hosting their own gateway need to act, with fixes in 19.2.4, 19.3.2, and 19.4.1, and GitLab says there is no way to detect earlier attempts.

Additional Security Alerts

Security Breaches & Incidents

  • Microsoft’s X account is hijacked for a crypto pump-and-dump: Attackers used the account, which has more than 13 million followers, to promote a token. BleepingComputer
  • Ransomware shuts down city systems in Vicksburg, Mississippi: The mayor said the FBI and other authorities are investigating. The Record
  • DIVD’s attackers used two Zammad zero-days: The chained flaws gave session hijacking, code execution, and root in seconds before an AI agent took over. Infosecurity Magazine, The Register

Threat Intelligence

  • Warlock ransomware hits critical infrastructure through SharePoint flaws: Symantec ties attacks in Portuguese and Spanish-speaking countries to several SharePoint vulnerabilities. The Record
  • The Antino backdoor uses Outlook and OneDrive for command and control: The China-nexus campaign has now reached government and policy groups in seven Asian countries. The Hacker News
  • Microsoft says AI has cut post-compromise attack time to minutes: The Digital Defense Report warns attackers have gained speed and scale. Infosecurity Magazine
  • Android 17 Advanced Protection limits accessibility services to verified tools: Abuse of the accessibility API is a main route for Android banking malware. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)