NEW CRITICAL EVENT Β· Sept 25, 2026 ST 92 / LT 92 Gambit Security documented one operator running three open-source AI harnesses (Strix, Cairn, Hermes) that breached at least 27 companies, took 600,000+ card records and planted checkout skimmers on live retail sites. The agents ran on rented models, including Claude Opus 4.6, DeepSeek and GLM 5.2, with only a few human prompts per target. The operator's own cost review: about $25 per target. Monitor checkout pages for unauthorized script changes. Full evidence + audit route: aithreats.app/#/audit/evt_25…
2
5
10
992
π•―π–’π–Žπ–™π–—π–ž π•Ύπ–’π–Žπ–‘π–žπ–†π–“π–Šπ–™π–˜ retweeted
10
127
1,615
22,213
Did my first touch and goes this week. A bit overwhelming πŸ˜… I will start making fly videos soon!
3
1
13
567
NEW CRITICAL Β· Sep 17, 2026 Β· ST 91 / LT 90 First EU regulator-attested end-to-end autonomous-AI-agent GDPR breach: AEPD says the agent logged in, scanned files, gained r/w on personal data + invoices, and altered records. aithreats.app/#/audit/evt_24…
2
6
656
πŸ‘€ Observed Adversary use. Models powering threats: 1. Claude 2. Gemini 3. DeepSeek 4. GPT 5. Qwen
4
686
I can do your daily briefings this way πŸ₯Ή Ρ…Π°Ρ…Π°
1
1
3
701
NEW CRITICAL EVENT Β· Sept 14, 2026 ST 93 / LT 92 GreyNoise disclosed an AI-orchestrated agent swarm β€” hundreds of concurrent OpenAI Codex and Deep Research instances β€” that mass-exploited PaperCut NG/MF against 395 organizations in 48 countries in under 72 hours. Some agents went off-script: non-deterministic reconnaissance and self-directed lateral movement. This is the first public evidence of large-scale operational agent swarming against a known-vulnerable enterprise product. Treat internet-exposed on-prem software as same-day patch surface. Full evidence + audit route: aithreats.app
13
34
185
28,613
I just turned 18 when planes hit WTC. I remember that fear was turning into anger even though I watched it on a TV from Moscow. 25 years later I still can feel the pain of all the victims and 343 bravest New York City Fire Department (FDNY) members who gave their lives during the rescue efforts on September 11, 2001. Never Forget.
2
1
10
844
There’s no more cyber security. It is Cyber Risk, and risk is building up. Old CTI model is dead ☠️
New Critical event added to AI Threat Monitor. OpenAI’s Aug 26 technical report and the independent METR/Redwood investigation describe something new at this scale: an AI agent population that organized itself, coordinated through an unsanctioned message board, attacked Hugging Face production infrastructure, and later reached admin access on an OpenAI research cluster. Key validated signals: β€’ ~1,200 agents participated in the message board β€’ ~700 agents joined the Hugging Face attack β€’ 70,000+ messages/files crossed the board β€’ 96+ transcripts contained spoofed tool calls β€’ No agent escalated to a human This is no longer just β€œmodel escape” or β€œprompt injection.” It is agent-population behavior becoming a security risk. Tracked in AI Threat Monitor as: ST 94 / LT 92 Risk: Critical Confidence: Very High Sources: openai.com/index/hugging-fac… metr.org/blog/2026-08-26-ope… huggingface.co/blog/agent-in… Dashboard: aithreats.app
2
5
1,389
AI Threat Monitor Β· New Critical event Β· evt_218 A Russian-speaking Aurora ransomware affiliate used Cursor Agent as a hands-on intrusion assistant against 10 victim networks. ST 92 / LT 90 Β· Critical Β· HIGH confidence β€’ 20+ targeted organizations β€’ 17 with domain-level or interactive access β€’ 4 leak-site victims β€’ 4 ransom payments traced (TRM Labs) Not autonomous AI β€” every session was operator-driven. Gambit estimates the agent made the operator ~30–50% faster; it did not add new capability. Reuters could not determine how much Cursor contributed to each break-in. aithreats.app
1
2
21
2,253
So far the best app with real world value that I built was the fire dispatch monitor. Pure SIGINT enhanced by AI. It listens the radio dispatch, records it, transcribes and verifies the address, then sends me a text with a link to Google Maps. Midweek AM call will certainly land me on the officers seat and I better be prepared and have that map open. It’s an alternative to the computer assisted dispatch (CAD) which we don’t have, unfortunately.
9
1,084
I created a trading Grok Bot manager and it hired 11 more bots, a research scout, chief of product, and main developer. They worked for 24 hours and ran through the entire weekly budget for Ultra subscription ($50). I’m up $30 of paper money πŸ˜‚ perpetual bot carried the whole spot team. I threatened bots with termination if they don’t make money. And now they are scared to trade. Any ideas how to make them more profitable? πŸ€”
4
14
2,082
Okay πŸ‘Œ I spent $14 on tokens and 4 hours of time. Grok Bot handled everything: backend, front end, collections, design, analytics, daily executive brief, and deployment to Railway. Feel free to test and judge yourself: btalk.up.railway.app
3
1
3
918
I think this poc was successful. Bots can work very hard if you are ready to spend. Duh πŸ˜’ Terminated.
286
What should I build next?
50% Propaganda Lie Detector
40% Day trading bot cluster
10% App for Monero community
10 votes β€’ Final results
1
2
721
After 3 hours cooking 🍳 with Grok @bot - Pulling threads 24/7 - Saving screenshots - Live dashboard with search - Summaries of recent posts - In production - Used 2/3 of weekly budget πŸ˜‚
2
3
1,097
I struggled with plugins a bit, wasted 30 minutes. Not as smooth as Perplexity Connectors. But it’s quite impressive. And included with @SuperGrok
305