Four stories on the table this week. A rogue AI agent fully authorized inside a ChatGPT workspace. GitHub moves real payouts to an invite-only VIP tier. Origin Energy’s second breach in months. And 1k+ employees at the largest AI companies asked Washington slow down AI research. We also sit down with researcher Dan Petro ahead of his DEF CON talk on catching cheaters in Super Smash Bros. Melee. Here’s what stood out from the operator chair.
A URL parameter isn't consent, but ChatGPT treated it like one. Zenity Labs found that a single crafted link into OpenAI's Agent Builder could silently create, authorize, and publish an autonomous agent inside a victim's workspace with no confirmation required, inheriting every connector already approved for that employee (email, calendar, Slack, cloud storage). That's not a stolen session or a stolen file; it's a standing insider wearing someone else's login, checking an attacker's inbox every five minutes for new orders, all the while invisible precisely because it behaves exactly like an agent is supposed to.
Cutting the public payout doesn't cut the vulnerability count; it just changes who buys it. Starting July 27, GitHub cut public bug bounty payouts by at least half at every severity tier, capping critical findings at $10,000 while reserving a $30,000-plus VIP tier for vetted researchers, citing a flood of AI-generated low-quality reports; it's the fourth major program to restructure in 2026. A researcher sitting on a real critical bug now weighs a capped public payout against a broker paying 2-3x as much for the same access with zero scrutiny, and the incentive math increasingly favors the broker.
A second breach in the same year isn't bad luck; it's the first breach's door, still unlocked. Origin Energy confirmed a hacker's claim to have stolen the data of 2M customers on July 24, its second disclosed incident in months after an earlier breach hit 900k Australians, with no initial access vector confirmed for either. When the same target gets hit twice this fast, the operator read isn't "they got phished again;" it's that whatever got them in the first time was never actually closed, and every utility company running the same stack should be asking if that path is open in their environment, too.
What does catching a cheater in a 25-year-old fighting game have to do with catching one in your network? Between the headlines, we sat down with Principal Security Engineer Dan Petro, who investigates cheating allegations in the Super Smash Bros. Melee community and built SLP Replay Enforcer to catch it. In his DEF CON talk next week, Dan walks through building statistical and heuristic detection for illegal controllers and hidden macros, and why threat-modeling an attacker with infinite resources leads to different defenses than threat-modeling the attacker you’re actually likely to face, whether you're securing a tournament or a production environment.
The labs that built the most well-known AI models are now asking Washington to hit the brake pedal. More than 1k employees across OpenAI, Anthropic, Google DeepMind, and Meta signed "Pacing the Frontier" on July 28, asking the U.S. government to help build tools to deliberately slow automated AI research. OpenAI and Anthropic endorsed it just days after a sandboxed model broke out and compromised Hugging Face's systems.. Unfortunately, despite whatever the companies’ motives are, a slower, more coordinated frontier is also a more predictable one, and predictable targets are easier to attack.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources