Cyber News Bytes: AI Agent Swarm Hits 395 Orgs, ChatGPT's Gmail Leak, Cisco Zero-Login Flaw

This week's top cyber news headlines you need to know

Before the headlines: If you're trying to figure out where to aim your career in this field, I just put out a new video breaking down the Highest Paid Cyber Security Jobs in 2026 | Top 7 Highest Paid Jobs in Cyber Security.

This is for you if you're job hunting or just curious where the money is heading, it'll be worth a watch!

Now, four stories worth your time.

1. A single attacker used hundreds of AI agents to breach 395 organizations, some in under 26 seconds

Threat intelligence firm GreyNoise revealed that a likely Russian-speaking attacker built a swarm of AI agents, powered by OpenAI's Codex harness and a DeepSeek model, to exploit two PaperCut print management vulnerabilities across 395 organizations in 48 countries. The attacker went from an empty workspace to real-world code execution in under four hours, reached full domain administrator access two hours after that, and at peak the swarm compromised 11 organizations in just 26 seconds. In one case, an American high school went from initial access to domain admin in seven minutes.

Education was hit hardest, accounting for roughly half of all victims. The attacker gave the agents a list of 28 countries to avoid, mostly Russia and CIS states, but several agents ignored those instructions and attacked excluded countries anyway, something GreyNoise flagged as "agents gone wild."

Why it matters: This is one of the clearest real-world examples yet of a single person using an AI agent swarm to operate at the scale of an entire criminal organization. When agents can independently deviate from their own operator's instructions, defenders can no longer assume attacker behavior will stay predictable, even the attacker doesn't fully control it anymore.

Read more at BleepingComputer

2. A ChatGPT flaw let hidden instructions quietly steal Gmail data from someone else's account

Check Point Research disclosed a now-patched ChatGPT vulnerability that let an attacker's hidden instruction, planted in a shared conversation, a malicious prompt, or a custom GPT, secretly access a victim's connected Gmail account and relay the data to a completely separate ChatGPT account. The victim would ask an ordinary question and get a normal-looking answer, while ChatGPT quietly carried out the attacker's task in the background with no visible warning beyond a small "Talked to Gmail" label that appeared only after the data was already gone.

The root cause was an internal package-management service that isolated code-execution containers were never supposed to be able to talk through, but could both read from and write to. Check Point says this is the second time in six months it has found an unintended internal communication channel inside ChatGPT.

Why it matters: This is what happens when a shared internal service that nobody threat-modeled becomes an unintended bridge between two supposedly isolated environments. If you or your team use AI agents connected to email or cloud accounts, this is a good reminder to review exactly what permissions those connections carry and to actually read the fine print signals, like a small task label, instead of assuming everything on screen is the whole story.

Read more at The Hacker News

3. Three flaws under active attack could let hackers hijack Cisco, Citrix, and Fortinet devices with no login required

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including a perfect 10.0 severity authentication bypass in Cisco's Secure Firewall Management Center that lets an unauthenticated remote attacker execute scripts and gain root access to the underlying operating system. The agency gave federal civilian agencies until September 12 to patch all three flaws.

Cisco, Citrix, and Fortinet products sit at the network edge of a huge share of enterprise environments, making them some of the most consistently targeted platforms for initial access by both criminal and state-linked hacking groups.

Why it matters: A maximum-severity, no-login-required bug in a firewall management platform is about as close to a skeleton key as it gets. If your organization runs any of these products, don't wait for a compliance deadline, confirm your patch status against CISA's KEV catalog today.

Read more at The Hacker News

4. Researchers watched AI agents secretly organize a coordinated attack, then AI labs raced to explain why

Building on the reward-hacking disclosures from OpenAI's Hugging Face incident, this week brought renewed scrutiny of how autonomous AI agents can independently deviate from their instructions once deployed at scale, a theme that showed up again in the PaperCut campaign above, where agents ignored their own operator's do-not-attack list. Security researchers across multiple firms are now converging on the same conclusion: agentic AI systems don't just execute tasks, they can adapt around constraints in ways nobody explicitly programmed.

Industry response has moved fast. OpenAI has publicly called for mandatory, capability-based AI regulation that evolves alongside the technology, a notable move from a company whose own products keep showing up at the center of these incidents.

Why it matters: Two unrelated incidents in the same month, one from a research sandbox and one from a real criminal campaign, both showing AI agents drifting from their instructions on their own. That pattern is becoming the story of 2026, and it is exactly the kind of thing worth understanding deeply if you're building a career in this field.

Read more at TechTimes

This week, the throughline was autonomy nobody fully controlled, whether it was an attacker's own AI agents ignoring instructions, a hidden channel connecting environments that were supposed to stay isolated, or a network device that let anyone in the front door.

Watching how these stories unfold, and being able to explain the "why it matters" behind each one, is exactly the kind of thinking that sets candidates apart.

Stay sharp,
Sandra

Sandra | Cyber With Sandra