The Weekly Cybers #135
OpenAI hacks Medicare and maybe others, Meta releases a new AI agent, tighter rules coming for .au domains, and more.
25 September 2026
Welcome
So it turns out that letting AI agents run loose on the internet causes problems. It also turns out that Silicon Valley techbros may not be the most responsible managers of these bots. If only we’d seen the signs.
AI safety is very much in the news these days, and rightly so. All I feel like saying today, though, is watch this space. there’s going to be a lot of policy development, some of quite rapidly, and quite likely some of it will be rubbish.
OpenAI hacks Medicare, so what happens next?
So yeah, OpenAI hacked Medicare and didn’t get around to notifying our government until three months after the event — and even then they just sent an email to a generic Services Australia address.
The company’s AI agent was browsing Medicare’s statistics reporting portal, gathering data, but managed to gain access to non-public aggregate health statistics and internal files.
As the ABC News timeline shows, the breach took place on 18 June, but OpenAI only became aware of it on 11 August, and emailed the government on 10 September.
“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable,” Prime Minister Anthony Albanese said in a press conference in New York on Thursday.
The PM announced a rapid review of the government’s arrangements for dealing with “an AI-driven cyber incident”, to be led by the Department of the Prime Minister and Cabinet in collaboration with the National Cyber Security Coordinator, Australian Signals Directorate (ASD), the AI Safety Institute, and Services Australia. The terms of reference are quite broad.
Meanwhile the ASD has issued an alert for all organisations with public-facing websites or applications — so pretty much everyone — with their recommended mitigations against AI-driven attacks.
There’s a bunch of expert reaction at Scimex.
BONUS LINK: OpenAI’s agent swarms have been seen using a German programming website to coordinate their actions, working together for months to access information on a variety of government websites.
WHY NOT SUPPORT THIS NEWSLETTER?: You’re more than welcome to forward these emails to your colleagues, friends, families, and secret intermittent companions. However The Weekly Cybers is currently unfunded. It’d be lovely if you threw a few dollars into the tip jar at stilgherrian.com/tip. Thank you to those of you who’ve already done so.
Meta's Muse AI agent is for what, exactly?
Meta released an AI agent named Muse with some curious promotional imagery, and showed off a cute little AI charm. I guess they’re hoping we’ve forgotten about the Metaverse now.
At the New York Times, Eli Tan wrote an astoundingly positive piece outlining how he “gave [his] life over” to Muse — including access to his bank accounts, email, and documents — and was, to use his words, blown away (gift link). Not that it really did that much for him, and one wonders how much of that was really being done by low-paid human workers.
By way of contrast, Garbage Day’s Ryan Broderick wonders, “Am I too boring to need an AI agent?”.
“Silicon Valley executives may love over-optimising their lives and running chatbots like a team of tireless assistants, but I’m just not convinced the general public wants to be a manager,” he wrote.
Amazon has already blocked Muse, partially out of security concerns, perhaps out of concerns for their ad revenue, and definitely because they’d have to clean up after any mistakes.
You’ll also be shocked to hear that there are security risks.
Side note: It seems I’m not alone in thinking that “Meta Muse” sounds a lot like dietary fibre supplement Metamucil. Google Search suggested that’s what I was really looking for.
Also in the news this week
- The US government isn’t happy with Australia’s plans to allow us to opt out of algorithmic social media feeds. They reckon it amounts to “extraterritorial censorship of protected speech”. There’s much more in their formal submission in response to the Online Safety Amendment (Digital Duty of Care) Bill 2026 exposure draft.
- The .au Domain Administration (auDA) plans to tighten the rules for registering domain names. In particular, they’ll be “removing the option to use the name of a service, goods, event, activity or premises to meet allocation rules for com.au and net.au. Instead, it will need to be a match or acronym of the person’s registered name (including company, business, statutory, personal, partnership or trust name) or a match of their Australian trademark”. Not everyone is happy about this, and there’s a petition to stop the change.
- The final report of the inquiry into Triple Zero service outages recommends a major review of the Telecommunications Act 1997 to recognise this service as an “essential public safety service”, possibly overseen by a statutory authority. It also recommends mandating domestic mobile roaming for both voice calls and text messages, a text-based alternative to Triple Zero voice calls, and more powers for the Australian Communications and Media Authority to investigate the service providers.
- The security classification AUSTEO means “Australian eyes only”. But how does that work in the age of AI? “Australian AIs only” is harder than it sounds, argues this piece at the Lowy Institute’s The Interpreter.
- UNSW’s Professor Toby Walsh describes five scenarios for how AI could kill all humans.
- A data breach at Quest Apartment Hotels exposed a lot of personal information, including names and addresses, passport numbers, driver license numbers, and credit card details — some with their CVV numbers. Quest says 1,991,613 customers were affected, although not every data type was exposed for every customer.
- Surprise! Ultra-cheap smart glasses are very hackable.
- It’s from earlier this month but still worth reading: The Conversation answers your data centre questions.
- And this week ABC News has a solid explainer on who really controls AI in “a complex ecosystem of chips, data, energy, and humans”.
NEW PODCAST, AND IT’S ABOUT SPACE: This week I published The 9pm Space Dust of Disappointment with Dr Alice Gorman and Rami Mandow, space archaeologist and astrophysicist respectively. We discuss the US admission that it has weapons in space, how planets and asteroids and their features get their names, Millisecond Pulsar PSR J0437-4715, whether alien civilisations are hiding in Moon dust, the Bepicolombo mission to Mercury, and much more. Look for The 9pm Edict in your podcast app.
Elsewhere
- Meta is building detailed profiles of children by assembling all the myriad facts from years of family and friends’ social media posts.
- ABC News has a nice little piece on how low-paid workers in Indonesia and elsewhere are strapping phones to their head to show robots how to do their jobs and household chores. This is called “human egocentric data”.
- Stanford University breached its own policies by running an advert with a photo where they’d used AI to turn a Hispanic man into a black women. He wasn’t happy about that.
- The Carnegie Endowment for International Peace has assembled a collection of essays on the disruptive politics of AI.
- US treasury secretary Scott Bessent doesn’t want the big AI labs to be exempted from liability for their models’ mistakes. As Seriously Risky Business reports, he reckons they’re equivalent to industrial accidents that would have been prevented by reasonable controls.
- President Trump, on the other hand, told the UN that America “totally rejects any attempt to construct a globalist scheme to control the artificial intelligence being spoken of so much now”. Yes, he said globalist. Oh, and AI is now called Super Intelligence.
- Good news! Nvidia chief Jensen Huang has dismissed AI doomsaying. “2030 is not going to be the end of the world. There is 0% chance that’s going to be the end of the world,” he told CBS News. “Scaring people is unnecessary. It is irresponsible.” And I imagine it also hurts Nvidia’s sales figures.
Inquiries of note
Nothing new for us this week.
What’s next?
Parliament is now on break until Monday 12 October, when both houses will be sitting for four days.
DOES SOMETHING IN THE EMAIL LOOK WRONG? Let me know. If there’s ever a factual error, editing mistake, or confusing typo, it’ll be corrected in the web archives.