---
title: "CrowdStrike Falcon Exploited, OpenAI Builds Exploits, AI Agents Breach | DMARC Report"
description: "Cybersecurity news from September 1–7, 2026, covering zero-days, AI-driven attacks, ransomware, data breaches, phishing, and email security."
image: "https://dmarcreport.com/og/blog/crowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach.png"
canonical: "https://dmarcreport.com/blog/crowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach/"
---

Quick Answer

What were the biggest cybersecurity threats from September 1–7, 2026? Key threats included zero-day exploits, AI-driven attacks, ransomware, supply-chain compromises, phishing, data breaches, browser flaws, and attacks targeting email and collaboration platforms.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=CrowdStrike%20Falcon%20Exploited%2C%20OpenAI%20Builds%20Exploits%2C%20AI%20Agents%20Breach&url=undefined%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F&title=CrowdStrike%20Falcon%20Exploited%2C%20OpenAI%20Builds%20Exploits%2C%20AI%20Agents%20Breach "Share on Reddit") [ ](mailto:?subject=CrowdStrike%20Falcon%20Exploited%2C%20OpenAI%20Builds%20Exploits%2C%20AI%20Agents%20Breach&body=Check out this article: undefined%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F "Share via Email") 

![AI threats and zero-day attacks](https://media.mailhop.org/dmarcreport/dmarc-report-7804-1788870857905.jpg) 

Last week was dominated by two big themes: AI tools turning into attack weapons on both sides of the fight, and a wave of zero-days hitting the very security software meant to **protect endpoints**. _Here’s a rundown of the 15+ biggest stories cybersecurity teams were watching._

## CrowdStrike Falcon hit by unpatched “FalconFlank” zero-day

A researcher known as Nightmare Eclipse (aka Chaotic Eclipse) published a working proof-of-concept exploit that abuses Falcon’s own malicious-macro remediation feature to grant SYSTEM-level privileges on fully patched **Windows 11 and Windows Server 2025** machines. As of the report, [CrowdStrike](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/) had not assigned a CVE or shipped a fix, only advising customers to disable the affected macro-removal policy. [Source: BleepingComputer](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/)

## OpenAI’s GPT-6 Astra builds working exploits from scratch

In internal cyber testing, [OpenAI’s](https://decrypt.co/377341/openai-releases-gpt-6-astra-agi) newest frontier model discovered zero-day flaws and built functioning exploits, intensifying concern in the **security community** over how quickly frontier AI models can be turned toward offensive hacking. [Source: GBHackers](https://gbhackers.com/openai-gpt-6-astra-discovers-zero-day-flaws/)

## Frontier AI agents breach an enterprise network in under 10 hours

![Dmarc Lookup 9647](https://media.mailhop.org/dmarcreport/dmarc-lookup-9647-1788870908393.jpg)Researchers demonstrated that autonomous [AI agents](https://cybermagazine.com/news/unit-42-how-ai-agents-breached-a-network-in-10-hours) could compromise a full enterprise network in under ten hours end-to-end, setting a new benchmark for how fast unsupervised, AI-driven attacks can move compared to human red teams. [Source: GBHackers](https://gbhackers.com/hackers-use-frontier-ai-agents/)

## CISA flags actively exploited PaperCut NG/MF flaws

**CISA** added multiple [PaperCut print-management vulnerabilities](https://www.bankinfosecurity.com/attackers-actively-exploit-flaws-in-papercut-ngmf-a-32696) to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and Metasploit shipped a public exploit module for the same bugs days later — a combination that sharply raises urgency for organizations still running exposed print servers. [Source: GBHackers](https://gbhackers.com/cisa-flags-multiple-papercut-ng-mf-flaws/)

## APT28-linked hackers deploy new “HOOKEDGE” backdoor across Europe

[Russian state-linked group](https://www.arabnews.com/world/germany-intelligence-agency-warns-of-russian-apt28-cyber-spying-2639156) BlueDelta (tracked elsewhere as APT28) was observed deploying a previously undocumented backdoor named **HOOKEDGE in espionage operations** against European targets, giving the group stealthy, persistent access to compromised networks. [Source: GBHackers](https://gbhackers.com/russian-apt28-linked-hackers-deploy-hookedge-backdoor/)

## Shai-Hulud “Trinitite” worm infects popular npm package

![Dmarc Record 8138](https://media.mailhop.org/dmarcreport/dmarc-record-8138-1788870958933.jpg)A new variant of the Shai-Hulud supply-chain worm compromised the widely used [TanStack Query package on npm in an attempt](https://gbhackers.com/shai-hulud-trinitite-worm/) to harvest developer secrets, underscoring how quickly a single poisoned package can propagate through the **JavaScript ecosystem**. [Source: GBHackers](https://gbhackers.com/shai-hulud-trinitite-worm/)

## New “Panzer” ransomware hits 16 victims across 11 countries

_A newly identified Ransomware-as-a-Service operation called Panzer claimed 16 victims spread across 11 countries in a short window, using the now-standard double-extortion model of both encrypting and stealing data to pressure victims._ [Source: GBHackers](https://gbhackers.com/new-panzer-ransomware-hits-16-victim/)

## Google patches actively exploited Chrome V8 zero-day

**Google shipped** an emergency Chrome update after CISA confirmed a [V8 engine flaw](https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html) (CVE-2026-85046) was being exploited in the wild via crafted webpages, giving attackers code execution inside the browser sandbox. _Federal agencies were given until September 18 to patch_. [Source: The Hacker News](https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html)

## Microsoft 365 “Direct Send” bypass lets attackers spoof internal users

![Dmarc Record Generator 5088](https://media.mailhop.org/dmarcreport/dmarc-record-generator-5088-1788870993368.jpg) _A flaw in Microsoft 365’s Direct Send feature allows attackers to send emails that appear to come from internal colleagues without needing any credentials, making internal-looking phishing lures far more convincing_. [Source: GBHackers](https://gbhackers.com/microsoft-365-security-bypass/)

## Thomson Reuters court-software breach exposes sealed records and SSNs

West Publishing, part of [Thomson Reuters, notified at least 24 court systems](https://www.scworld.com/brief/thomson-reuters-court-software-breach-exposes-sensitive-data-in-canada-and-us) across 11 U.S. states plus the Virgin Islands that unauthorized access to a storage location ran from March through late June 2026, exposing sensitive court data including **Social Security** numbers. _Minnesota’s Judicial Branch confirmed exposure of its appellate court data and cut off the vendor’s access_. [Source: The Hacker News](https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html)

## IDScan sued after breach allegedly exposes 153 million driver’s licenses

Identity-verification company IDScan is facing multiple lawsuits after hackers claimed to have breached the service and offered to sell more than [153 million scanned driver’s licenses](https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/), one of the largest **identity-document exposures reported** this year. [Source: BleepingComputer](https://www.bleepingcomputer.com/)

## 12-year-old PostgreSQL flaw (“PostGREShell”) allows full database takeover

![Dmarc Check 1120](https://media.mailhop.org/dmarcreport/dmarc-check-1120-1788871026913.jpg)A newly disclosed vulnerability dating back over a decade lets low-privileged users execute arbitrary code and seize control of [PostgreSQL database servers](https://cybersecuritynews.com/12-year-old-postgresql-flaw/), putting a massive base of production deployments at risk once patches roll out. [Source: GBHackers](https://gbhackers.com/12-year-old-postgresql-flaw/)

## Hackers compromise more than 14,500 Dahua security cameras

A mass exploitation [campaign against Dahua IP cameras](https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/) compromised over **14,500 devices,** building a large pool of hijacked [IoT infrastructure](https://www.ibm.com/think/topics/internet-of-things) that can be repurposed for botnets, surveillance, or further attacks. [Source: GBHackers](https://gbhackers.com/dahua-security-cameras/)

## Attackers pose as IT support on Microsoft Teams to target 150+ employees

A social-engineering campaign impersonated internal helpdesk staff over [Microsoft Teams to trick more than 150 employees](https://cyberpress.org/teams-vishing-targets-employees/) at a target organization, continuing the trend of abusing trusted **collaboration tools** rather than plain email to gain remote access. [Source: GBHackers](https://gbhackers.com/microsoft-teams-it-support-scam/) ![Dmarc Generator 4108](https://media.mailhop.org/dmarcreport/dmarc-generator-4108-1788870884517.jpg)

## Record-breaking “quishing” wave hides malicious links inside QR codes

[QR-code phishing](https://www.infosecurity-magazine.com/news/fbi-warns-north-korean-qr-phishing/) hit new record volumes as attackers increasingly embed [malicious links](https://www.firstpost.com/world/china-denies-link-to-seized-iran-bound-ship-calls-claims-malicious-linking-and-hype-14002821.html) inside QR images to slip past traditional link-scanning email defenses. [Source: GBHackers](https://gbhackers.com/qr-codes-attack/)

## Infostealers now target Claude AI session cookies to hijack accounts

Threat actors are using off-the-shelf [infostealer malware](https://thecyberexpress.com/infostealers-hijacking-claude-sessions/) to grab active session cookies for Claude accounts, letting them bypass [multi-factor authentication](https://www.onelogin.com/learn/what-is-mfa/) entirely and hijack **AI accounts** without ever touching a password. [Source: GBHackers](https://gbhackers.com/hackers-use-infostealer-malware-to-steal-claude-session-cookies/)

As cyber threats continue to evolve—from zero-days and AI-driven attacks to phishing and [data breaches](https://www.usatoday.com/story/news/nation/2026/09/06/drivers-license-data-breach-fbi/91642409007/)—strong [cybersecurity](https://dmarcreport.com/blog/integrating-all-cybersecurity-elements-for-alignment-and-efficacy/) practices supported by [DMARC](https://dmarcreport.com/), [DKIM](https://dmarcreport.com/what-is-dkim/), and [SPF](https://dmarcreport.com/dmarc-fundamentals/what-is-spf/) are essential for **protecting organizations** and email communications.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F) [ ](https://twitter.com/intent/tweet?text=CrowdStrike%20Falcon%20Exploited%2C%20OpenAI%20Builds%20Exploits%2C%20AI%20Agents%20Breach&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fcrowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach%2F) Copy 

Related Articles

- [ ![25 practical reasons every MSP should add a pricing estimator to their website](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  25 practical reasons every MSP should add a pricing estimator to their website Advanced ](/blog/25-reasons-every-msp-should-add-pricing-estimator-to-website/)
- [ ![AI cybersecurity breach concept](https://media.mailhop.org/dmarcreport/dmarc-check-5301-1785846252910.jpg)  AI Patch Failures, Claude Hacked Companies, Autonomous AI Breach Advanced ](/blog/ai-patch-failures-claude-hacked-companies-autonomous-ai-breach/)
- [ ![UK Plant Shutdown](https://media.mailhop.org/dmarcreport/how-to-create-dmarc-record-5227-1787656932438.jpg)  Apollo Data Breach, Claude Code Attack, UK Plant Shutdown Advanced ](/blog/apollo-data-breach-claude-code-attack-uk-plant-shutdown/)
- [ ![Blockchain Email Security](https://media.mailhop.org/dmarcreport/dmarc-check-3640-1781523375849.jpg)  Blockchain and Email Security: Exploring the Future of Trusted Digital Communication Advanced ](/blog/blockchain-email-security-future-trusted-digital-communication-explained/)

## Related Articles

[  Advanced 2m  25 practical reasons every MSP should add a pricing estimator to their website  Jan 15, 2026 ](/blog/25-reasons-every-msp-should-add-pricing-estimator-to-website/)[  Advanced  AI Patch Failures, Claude Hacked Companies, Autonomous AI Breach  Aug 4, 2026 ](/blog/ai-patch-failures-claude-hacked-companies-autonomous-ai-breach/)[  Advanced  Apollo Data Breach, Claude Code Attack, UK Plant Shutdown  Aug 25, 2026 ](/blog/apollo-data-breach-claude-code-attack-uk-plant-shutdown/)[  Advanced  Blockchain and Email Security: Exploring the Future of Trusted Digital Communication  Jun 15, 2026 ](/blog/blockchain-email-security-future-trusted-digital-communication-explained/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"CrowdStrike Falcon Exploited, OpenAI Builds Exploits, AI Agents Breach","description":"Cybersecurity news from September 1–7, 2026, covering zero-days, AI-driven attacks, ransomware, data breaches, phishing, and email security.","url":"https://dmarcreport.com/blog/crowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach/","datePublished":"2026-09-08T00:00:00.000Z","dateModified":"2026-09-08T00:00:00.000Z","dateCreated":"2026-09-08T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/crowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach/"},"articleSection":"advanced","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-report-7804-1788870857905.jpg","caption":"AI threats and zero-day attacks"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Advanced","item":"https://dmarcreport.com/advanced/"},{"@type":"ListItem","position":4,"name":"CrowdStrike Falcon Exploited, OpenAI Builds Exploits, AI Agents Breach","item":"https://dmarcreport.com/blog/crowdstrike-falcon-exploited-openai-builds-exploits-ai-agents-breach/"}]}
```
