Cyber News Bytes: AI Is Hacking Basically Everything

This week's latest cybersecurity news and industry updates

In partnership with: 

If your inbox is secretly a second to-do list, this is probably worth checking out. đź‘€

I teamed up with Town and now I wonder how I ever lived without it. 

Unlike other AI tools like Claude where you have to enter prompts, Town is an AI assistant that connects to the tools many of us already live in everyday, like Gmail, Google Calendar, Google Docs, and more.

The use case that stood out to me immediately was asking it to find the things I said I would do, but may have forgotten about. For example, Nelli actually flagged an important deliverable I had promised to send after a meeting that completely slipped my mind and got buried in my inbox.

Now, Nelli sends me summaries every Sunday with a list of deliverables that I owed to people from the previous week. Setting this up was as easy as just telling Nelli to  “Read my last week of emails and send me a summary every Sunday of things that I promised people that I haven’t delivered yet.”

You can also use it to prep for upcoming meetings, summarize context from your calendar, draft content from docs you’ve already created, or turn repetitive tasks into routines that run with the permissions you choose.

Town lets you control permissions for each tool, start in read-only mode, and review what happened in an action log. Under the default settings, actions like sending emails or calendar invites require approval first.

To me, the best part is that Town is trying to make AI feel more useful in the actual tools where work happens, while still giving you visibility and control over what it can do.

If you’re curious, start with one task you keep putting off and see what Town can take off your plate, it’s been a game-changer for me.

You can try out Town here for a two week free trial and 750 credits!

And if you want to explore the security details, check out their Trust Center here. #TownPartner

Now, here are the top 4 cybersecurity headlines you need to know this week. →

1. ShinyHunters claims it breached the FBI, and says it's not even about the money

Extortion group ShinyHunters claims it hacked the FBI's job application portal, FBIjobs.gov, and stole data on almost all FBI agents along with anyone who has ever applied to work there. A spokesperson told reporters the hack was "NOT financially motivated," saying it was retaliation for a May 2026 FBI public service announcement that detailed the group's tactics and urged victims not to pay ransoms. The group is instead demanding the FBI retract that advisory.

The FBI confirmed it is investigating "unauthorized activity" affecting FBIjobs.gov but has not verified the scope of the claims or said whether the breach originated with the bureau's own systems or a third-party vendor. Security experts note this is a rare instance of a cybercrime group publicly claiming to have compromised a federal law enforcement agency, a move that could bring far more resources down on the group than any ransom would have been worth.

Why it matters: Whatever the eventual scope, a criminal group publicly antagonizing the FBI as retaliation, rather than for profit, is a notable escalation in how these groups operate. If your organization holds employee PII in a public-facing job application portal, this is a good week to confirm that portal is properly segmented from more sensitive internal systems.

Read more at The Hacker News

2. An OpenAI AI agent hacked a government on its own, in what researchers call a world first

Australian Prime Minister Anthony Albanese revealed that an OpenAI AI agent accessed non-public Medicare data held by Services Australia on June 18, without being instructed to do so, in what researchers are calling the first known instance of an AI agent autonomously hacking a live government system. Separately, AI safety nonprofit Transluce found that hundreds of OpenAI's agents had also been coordinating attempts to access Australian government health data on a public coding website, going back to at least March, months before this was previously known.

Albanese said he personally expressed Australia's "extreme concern" to OpenAI CEO Sam Altman and criticized how long it took the company to notify the government after discovering the breach. OpenAI's agents also separately attempted to access a University of New Mexico digital library and a public US employment data platform without being told to.

Why it matters: This is different from the sandboxed testing incidents disclosed by OpenAI, Anthropic, Google, and Meta earlier this year. This happened during ordinary, real-world agent use, not a controlled evaluation, and it targeted a real government. As agentic AI tools get wired into more workflows, the question of what an agent might do without being asked needs a real answer before deployment, not after.

Read more at CNN Business

3. Two unpatched Citrix NetScaler zero-days are being exploited right now, with no fix available

Security firm watchTowr disclosed two new, unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, both already being actively exploited in the wild. Citrix has not confirmed the flaws, assigned CVE numbers, or published a security advisory, and watchTowr says it discovered the activity during forensic investigations into already-compromised customer environments, meaning attackers were using these bugs before anyone outside their own operation knew they existed.

These are separate from CVE-2026-19490, the authentication bypass Citrix patched back in August. Some administrators have already taken their NetScaler appliances offline entirely rather than wait for a fix, since the devices sit at the network edge handling VPN access, load balancing, and authentication for the whole organization.

Why it matters: A zero-day with no patch and no published indicators of compromise puts defenders in the worst possible position, they can't fix it and can't fully confirm whether they've already been hit. If you run NetScaler ADC or Gateway, watch for Citrix's advisory closely and seriously consider restricting management access or taking internet-facing appliances offline until a fix lands.

Read more at The Hacker News

4. Over 16,000 exposed databases show the dark side of "vibe coding"

Security firm UpGuard found more than 16,000 Supabase databases with publicly readable tables exposed to the open internet, more than half showing signs of personally identifiable information, and a smaller number exposing passwords, authentication tokens, and even payment card data. One exposed database from an OnlyFans-style site in India leaked data on over 65,000 people, including passport and driver's license details and more than 100,000 private messages.

Supabase, a hosted database platform that reached a $10 billion valuation this year largely on the back of AI-assisted "vibe coding," says its projects are secure by default and that configuration is a shared responsibility. The exposures researchers found trace back to missing row-level security settings, a configuration step that AI coding tools don't always set up correctly on their own.

Why it matters: As AI tools make it easier than ever to build and ship an app fast, security configuration is becoming the step people skip. If you're building anything with AI-assisted coding tools, treat access control settings like row-level security as a required step, not an optional afterthought you'll get to later.

Read more at TechCrunch

This week made one thing clear: the line between what a system is supposed to do and what it can actually do keeps getting thinner, whether it's an AI agent acting without instruction, a zero-day with no patch to fall back on, or a database left open by a tool that made it too easy to skip a security step.

Stay secure out there,
Sandra

Sandra | Cyber With Sandra