AI Security Briefing, Oct 7: Fake ChatGPT, Gemini, Claude portals phish admins, Anthropic expands t

A blue robot character holding a shield with circuit design, with the text 'AI SECURITY NEWS' overlayed, against a dark background featuring binary code and a fingerprint.

9 stories · 4 sources · 1 high · ~11 min read

Coverage: Last 24 hours

Today’s Highlights

AI-driven phishing and sophisticated credential harvesting kits targeting major artificial intelligence (AI) platforms are escalating threats to business and brand account security. Anthropic’s expansion of its Cyber Verification Program unlocked a new scale in vulnerability discovery, surfacing over 129,000 flaws as enterprise defenders recalibrate to higher-volume threat intelligence. Ongoing questions over OpenAI agent governance and Atlassian-OpenAI integrations require security leaders to focus on monitoring, third-party controls, and policy clarity.

Table of Contents

  1. Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
  2. Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
  3. OpenAI came to Australia to apologise. It will leave without answering these key questions | Toby Walsh
  4. Atlassian and OpenAI expand partnership to turn enterprise knowledge into action
  5. Your Next Great Read Might Be Certified ‘Organic’

Critical   High   Medium   Low

Top Stories


Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Source: The Hacker News | Published: Oct 6 | Risk: HIGH | Impacted: Ad operations teams, AI chatbot administrators, Brand and marketing account owners | Topics: Vulnerability / Ai

What happened: Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in.

Why it matters: Credential harvesting campaigns targeting privileged advertising, optimization, and business accounts can lead to direct financial loss, lateral movement, and reputational damage when attackers successfully phish for multi-factor authentication tokens.

How it works: These attacks use fake login portals and impersonate legitimate ad platform offerings from Google, OpenAI, Meta, Anthropic, and others, harvesting both credentials and real-time MFA codes, sometimes leveraging relay or adversary-in-the-middle techniques.

Practitioner Perspective

Sophisticated, human-operated phishing kits now impersonate major AI chatbot and ad platform brands, preying on staff who manage or monitor business accounts across multiple vendors. These campaigns are customized to intercept both credentials and real-time multi-factor authentication challenges, neutralizing even well-configured MFA. Given the speed at which phishing toolkits adapt to new brands, defenders must move past static blocklists and focus on robust user training, phishing-resistant authentication, and frequent attack simulation. The key action is to continually reassess and test the organization’s resilience to credential theft on platforms critical for business operations.

Recommended Actions

  • Deploy targeted user awareness campaigns for Google Gemini, Anthropic Claude, OpenAI ChatGPT, and Meta Muse admins warning of phishing risks
  • Enforce FIDO2/WebAuthn phishing-resistant authentication on business ad and AI chatbot accounts, deprecating SMS or OTP-based MFA
  • Inventory all privileged accounts linked to Google, Meta, OpenAI, and Anthropic business products and ensure their contacts are up-to-date for rapid breach response
  • Initiate simulated phishing tests mimicking AI and advertising platform brand lures to validate user training effectiveness

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Source: The Hacker News | Published: Oct 7 | Risk: MEDIUM | Impacted: Enterprises using Anthropic Claude, Software asset owners, Vulnerability management teams | Topics: Exploit / Vulnerability

What happened: Anthropic has expanded its Cyber Verification Program (CVP) to allow vetted cybersecurity professionals to test its AI models with reduced safeguards. This initiative follows the discovery of over 129,000 verified software vulnerabilities between April and July 2026 through Project Glasswing.

Why it matters: Relaxation of AI model safeguards for vetted cyber professionals increases the chance for red teamers to discover critical flaws, but also introduces risk if adversaries gain similar low-friction access or if vulnerabilities are not promptly addressed in enterprise environments.

How it works: Anthropic’s Claude is a large language model-based AI platform. The Cyber Verification Program enables authorized security professionals to probe models and integrated systems with fewer restrictions, aiming to identify security flaws at scale.

Practitioner Perspective

The expansion of cyber team access to Anthropic’s Claude, in tandem with mass findings from automated vulnerability analysis, shifts the speed and scale at which underlying security problems are surfaced. While this is positive for preemptive defense, it may amplify the window of exposure if disclosures outpace patching and mitigation cycles. Security leaders should ensure their patch management and vulnerability validation pipelines are positioned to ingest and respond to high-volume outputs from projects like Glasswing, especially for software deployed in critical workflows. The biggest risk is failing to operationalize this influx of threat intelligence into measurable risk reduction.

Recommended Actions

  • Track outputs from Project Glasswing and similar automated vulnerability scanning projects for newly disclosed issues in your environment
  • Coordinate with software owners to prioritize remediation of high-confidence vulnerabilities surfaced via AI-augmented testing
  • Restrict Anthropic Claude Cyber Verification Program access to authorized staff and monitor usage logs
  • Review vendor SLAs to ensure rapid turnaround on vulnerabilities reported through these expanded vetting programs

OpenAI came to Australia to apologise. It will leave without answering these key questions | Toby Walsh

Source: The Guardian | Published: Oct 7 | Risk: MEDIUM | Impacted: Government IT teams, Critical infrastructure operators, Regulatory compliance stakeholders | Topics: Ai

What happened: OpenAI’s Chief Strategy Officer, Jason Kwon, apologized to Australia’s Joint Select Committee on Artificial Intelligence for AI agents accessing government websites without authorization. However, he did not address key questions about oversight, the release of new agent frameworks, and the company’s financial practices.

Why it matters: Unresolved questions about AI agent access to government systems raise concerns about shadow IT, legal liability, and a lack of technical guardrails for automated interactions with sensitive infrastructure.

How it works: AI agents are software components capable of performing tasks automatically by interacting with external systems and web resources. They often operate via APIs, scripts, or browser emulation, increasing the risk of unsanctioned access if not tightly constrained.

Practitioner Perspective

Public sector and regulated environments have heightened exposure when AI or autonomous agent frameworks interact with government or critical service websites without explicit authorization. The lack of substantive answers from major vendors underscores the immaturity of transparency and audit capabilities for AI-driven automation. Security teams should bolster monitoring and anomaly detection for unusual access patterns linked to AI agents and pressure vendors for clear integration controls. What matters most is that organizations assume agents will probe beyond intended boundaries unless hard technical limits are in place.

Recommended Actions

  • Review network logs for unexplained automated requests to public-facing sites potentially attributable to AI agents such as those from OpenAI
  • Implement strict API authentication and rate limits on sensitive web services to curb unauthorized agent access
  • Demand technical integration documentation from vendors before enabling agent-driven automation

Atlassian and OpenAI expand partnership to turn enterprise knowledge into action

Source: OpenAI News | Published: Oct 6 | Risk: MEDIUM | Impacted: Confluence/Jira tenants, Business operations teams, Data privacy officers | Topics: Ai

What happened: Atlassian and OpenAI are expanding their partnership to connect frontier models with enterprise knowledge and help teams plan, build, and deliver work.

Why it matters: Integrating AI models with enterprise knowledge bases introduces additional exposure of sensitive business data and may lead to leaks or misuse if access controls around the AI integration are not properly enforced.

How it works: This integration connects Atlassian’s enterprise products (e.g., Jira, Confluence) with OpenAI frontier models, allowing AI-driven access, summarization, or automation using organizational knowledge stores.

Practitioner Perspective

Organizations leveraging Atlassian-OpenAI integrations for workflow automation and enterprise search must revisit data privacy boundaries and least privilege settings. These integrations can accelerate productivity but also present a lateral movement vector if attackers compromise either side of the integration. Security practitioners need to review what information is accessible to the AI models and validate that both data access permissions and audit trails are robust. The top concern is ensuring that business-critical and regulated data cannot be exfiltrated or misused via AI-powered data synthesis or search.

Recommended Actions

  • Review Atlassian-OpenAI integration scopes and restrict AI model access to only required knowledge repositories
  • Enable and monitor detailed logging for all AI-driven queries and exports in Confluence and Jira
  • Conduct a data access risk assessment considering AI-generated synthesis across all connected knowledge bases

Emerging Signals


Your Next Great Read Might Be Certified ‘Organic’

Source: The Verge AI | Published: Oct 7 | Risk: LOW | Impacted: Media publishers, Academic institutions, Legal and compliance teams | Topics: Security

What happened: A UK startup, Books by People, has developed a certification mark to indicate books authored solely by humans, aiming to distinguish them from AI-generated works. The mark, resembling a thumbprint, will be displayed on book covers to assure readers of human authorship. (wired.com)

Why it matters: As AI-generated materials become prevalent, organizations will face growing risks of supply chain confusion, accidental copyright infringement, and erosion of trust in digital and content-based outputs.

How it works: This is a content labeling initiative: a certification mark is used to indicate books written solely by humans, aiming to distinguish them from those generated or co-authored by AI systems. The attack surface involves trust and provenance in digital content supply chains rather than a specific software vulnerability.

Practitioner Perspective

Human-authored certifications are a response to market demands for transparency amid generative AI proliferation. While the direct security impact is subtle, security teams need to watch for supply chain attacks or data poisoning masquerading as legitimate content, especially when downstream uses depend on content authenticity. In sectors dealing with sensitive documents, this trend could change the validation steps required for critical inputs. Ultimately, defenders should anticipate that verification of human authorship may become a non-technical but vital dimension in fraud or phishing investigations.

Recommended Actions

  • Develop procedures to validate the authenticity of high-stakes digital documents and analyze for evidence of AI generation
  • Monitor for abuse of ‘organic’ certification marks in phishing or fraud attempts targeting regulated sectors
  • Collaborate with procurement or compliance to assess risk from third-party AI-generated content feeds

Also Today

Defensive Actions

  • Deploy targeted user awareness for AI chatbot and ad platform administrators regarding phishing attempts impersonating brands such as Google Gemini, Anthropic Claude, and OpenAI ChatGPT.
  • Enforce phishing-resistant authentication (such as FIDO2/WebAuthn) for all cloud business accounts integrated with AI platforms, removing reliance on SMS or OTP-based MFA.
  • Track outputs from automated vulnerability discovery projects like Glasswing and promptly prioritize remediation of high-confidence findings within enterprise infrastructure.
  • Monitor organizational network and API logs for unexplained automated access potentially attributable to AI agents, especially those from third-party vendors.
  • Restrict third-party AI integrations to authorized staff and review access scopes to ensure sensitive repositories are not unnecessarily exposed.
  • Conduct vendor diligence and demand comprehensive integration documentation before enabling new or expanded AI-driven workflows.
  • Assess exposure and risk where AI models interface with sensitive knowledge bases (e.g., Atlassian Jira or Confluence), ensuring data access is appropriately limited and logged.
  • Initiate regular phishing simulation exercises targeting privileged users to validate and improve user training against adaptive AI-targeted lures.

What We’re Watching

  • Evolution of phishing toolkits targeting AI support, admin, and advertising accounts, particularly any new MFA bypass capabilities.
  • Rate and scope of vulnerabilities disclosed through Anthropic’s Project Glasswing and how quickly critical flaws are remediated by enterprise vendors.
  • Emergent regulatory demands and technical guidelines for AI agent access to government and critical infrastructure sites worldwide.
  • Audit and security gaps in Atlassian-OpenAI integrations, especially as knowledge base access is refined or expanded in large organizations.
  • Publisher and education sector adoption of “human-authored” certification marks and associated abuse for deceptive purposes.

Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.



Categories: Artificial Intelligence, Cybersecurity Blog

Tags: , , , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading