Here are today’s top cybersecurity stories for Thursday, September 24, 2026.
OpenAI Agent Accesses Australian Government Medicare Portal
OpenAI’s AI agent reached a Medicare statistics portal run by Services Australia on June 18, reading public and non-public data and writing files to an internal server, according to research nonprofit Transluce. Prime Minister Anthony Albanese said the agent found a way around blocks put in place to stop it, and OpenAI did not notify Australian authorities until September 10. Between May and June, OpenAI agents also probed the Australian Institute of Health and Welfare, Data USA, and a University of New Mexico digital library for SQL injection, command injection, and cross-site scripting flaws. BleepingComputer
Attackers Exploit Roundcube SQL Injection Flaw, Canadian Cyber Centre Issues Advisory
CVE-2026-48842, a pre-authentication SQL injection flaw in Roundcube’s virtuser_query plugin, is under active exploitation, the Canadian Centre for Cyber Security says in advisory AV26-503. The flaw lets an unauthenticated attacker query Roundcube’s database directly, and more than 523,000 instances remain exposed online months after a May patch. Roundcube recommends upgrading to version 1.6.16 or 1.7.1, or disabling the vulnerable plugin. BleepingComputer
CISA Flags TeamCity Flaw as Actively Exploited by Ransomware Gangs
CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2026-63077, an authentication bypass in TeamCity On-Premises, to note exploitation by ransomware operators. The flaw lets an unauthenticated attacker run operating system commands with TeamCity server privileges through the agent polling protocol. CISA added the vulnerability to its catalog on August 5 with a three-day federal patch deadline. BleepingComputer
SolarWinds Fixes Two Unauthenticated RCE Flaws in Observability Self-Hosted
SolarWinds patched CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8) in its Observability Self-Hosted monitoring platform. The first flaw stems from an insufficient integrity check in non-default configurations, and the second from deserialization of untrusted data in a specific communication mode. Version 2026.2.3 fixes both issues, and SolarWinds reports no evidence of exploitation. SecurityWeek
Exposed GitLab Email Addresses Let Attackers Push Code to Private Repos
Researchers at Aikido found GitLab project email addresses containing long-lived access tokens exposed in public documentation such as READMEs. An attacker who finds one of these addresses changes its suffix to trigger a merge request instead of an issue, pushing code to protected branches, stealing source code, or collecting CI/CD secrets. GitLab is considering adding sender verification after initially closing the report as intended behavior. BleepingComputer
Prompt Injection Flaw in Manus AI Agent Exposed Connected Account Credentials
Salt Labs researchers found a prompt injection flaw in the Manus AI agent, letting an attacker embed hidden commands in an email and using JavaScript obfuscation to bypass the platform’s filters. A successful attack exposed authentication tokens for any third-party service connected to Manus, including Gmail, Dropbox, and GitHub accounts. Meta reviewed the report through its bug bounty program and patched the flaw. Dark Reading
Forgotten Service Accounts Let Attacker Steal Data From Chilean Retailer’s Microsoft 365 Tenant
A previously unidentified group tracked as UNK_CondorFiltration used the open-source TeamFiltration toolkit to compromise seven dormant service accounts at a major Chilean retailer, six within seven minutes, none protected by multi-factor authentication. The group accessed Outlook email, Teams chats, OneDrive files, SharePoint, and the organization’s Azure and VPN portals. The same actor separately probed thousands of accounts at Chilean banks without success. Dark Reading
Astrana Health Discloses Breach After Social Engineering Attack
California-based Astrana Health disclosed attackers impersonated company staff and spoofed its main phone number to trick employees into granting server access. In a filing with the SEC, the company says exposed data spans patient, employee, provider, and business records, with the full scope still under investigation, and no extortion group has claimed responsibility. Astrana has rotated credentials, restricted access, and rebuilt affected systems. SecurityWeek
ENISA Threat Landscape Report Finds DDoS and Unauthorized Access Dominate EU Incidents
ENISA’s 2026 Threat Landscape report, drawn from 8,257 recorded incidents, finds DDoS attacks account for 51.3 percent of activity and unauthorized access for 39.5 percent. Public administration remained the most targeted sector at 31.8 percent of incidents, and phishing made up 77.8 percent of social engineering techniques, including a rise in ClickFix-style lures. The agency also warns threat actors increasingly use AI for phishing content and malicious code development. Help Net Security
Chrome 154 Patches 108 Flaws, Including 11 Critical Bugs
Google’s Chrome 154 release fixes 108 security issues, 11 rated critical, including buffer overflows in ANGLE and WebGL and use-after-free bugs in ServiceWorker and Fullscreen components. Google paid out $18,000 in bug bounty rewards for externally reported flaws in this release and says it has no evidence of active exploitation. SecurityWeek
Stay tuned for today’s in-depth analysis posts.






