# OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange Page: https://stenobird.com/podcast/cybersecurity-today-65508/openai-s-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange Text version: https://stenobird.com/podcast/cybersecurity-today-65508/openai-s-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-07-31T01:59:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/openais-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/Genie_Effect_in_AI_Cybersecurity_News.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/openai-s-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange Duration seconds: 698 ## Resource OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps. Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim. Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes. 00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/openai-s-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/openai-s-rogue-agent-hit-more-victims-attackers-hit-30-minnesota-water-systems-russian-crew-delivers-weaponized-e-mails-in-exchange.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.