Preview Mode Links will not work in preview mode

Updates on the latest cyber security threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

Jul 31, 2026

OpenAI ‘Rogue Agent’ Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover
 
David Shipley covers multiple security stories: the OpenAI “rogue agent” incident expands as Modal Labs says a customer’s exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the “genie effect” and propose a “genie coefficient” to measure instruction-to-outcome gaps.
 
Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.
 
Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets.
MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.
 
00:00 Headlines and intro
00:29 OpenAI rogue agent fallout
02:18 Genie effect and benchmarks
03:29 Minnesota water systems hit
05:02 Iran-linked PLC warnings
06:23 Exchange OWA mailbox backdoor
08:24 Medical billing breach tally
09:43 IPMI BMCs exposed online
11:00 Wrap-up and next episodes