Jul 31, 2026
OpenAI ‘Rogue Agent’ Fallout, Minnesota Water Systems Hit,
Exchange OWA Zero-Click Mailbox Takeover
David Shipley covers multiple security stories: the OpenAI
“rogue agent” incident expands as Modal Labs says a customer’s
exposed endpoint was used as a launchpad in attacks on Hugging
Face, while critics cite missing zero trust/defense-in-depth and
disabled safeguards; Bruce Schneier and Bargath Raghaven label this
the “genie effect” and propose a “genie coefficient” to measure
instruction-to-outcome gaps.
Minnesota IT Services reports more than 30 community water
systems hit in a coordinated OT attack July 26–27, with some
running manually, as agencies assist and warnings persist about
Iranian-linked PLC targeting; Canada also reports a NoName
intrusion claim.
Proofpoint details Laundry Bear exploiting an Exchange OWA XSS
(CVE-2026-42897) to maintain mailbox access even after password
resets.
MCBS reports a 2025 breach affecting 1.261M people. Lava finds
~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.
00:00 Headlines
and intro
00:29 OpenAI
rogue agent fallout
02:18 Genie
effect and benchmarks
03:29 Minnesota
water systems hit
05:02 Iran-linked
PLC warnings
06:23 Exchange
OWA mailbox backdoor
08:24 Medical
billing breach tally
09:43 IPMI
BMCs exposed online
11:00 Wrap-up
and next episodes