Close Menu
AndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ‘Teen Vogue’ moves under Vogue.com, 6 staffers are laid off : NPR

    November 4, 2025

    Is your phone on the list? LineageOS adds Android 16 support for more devices

    November 4, 2025

    Google Maps is adding live lane guidance for the Polestar 4

    November 4, 2025
    Facebook X (Twitter) Instagram
    Trending
    • ‘Teen Vogue’ moves under Vogue.com, 6 staffers are laid off : NPR
    • Is your phone on the list? LineageOS adds Android 16 support for more devices
    • Google Maps is adding live lane guidance for the Polestar 4
    • The top-end Apple Watch Ultra 3 gets a rare $100 discount
    • Best MacBook deals for November 2025
    • How fast is the OnePlus 15 charging speed?
    • Samsung Pass might try to replace your digital wallet with this update
    • The Arduboy credit card-sized Game Boy now supports USB multiplayer
    Tuesday, November 4
    AndroidTelecom – Latest Android News, Reviews, Apps & Tech UpdatesAndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates
    • Home
    • Apps
    • Gadgets
    • News
    • Phones
    • Reviews
    • Technology
    • Tips
    • Updates
    AndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates
    Home»Gadgets»Microsoft warns a key OpenAI API is being exploited to launch cyberattacks
    Gadgets

    Microsoft warns a key OpenAI API is being exploited to launch cyberattacks

    adminBy adminNovember 4, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    OpenAI logo on a smartphone screen
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • SesameOp malware uses OpenAI’s Assistants API as a covert command-and-control channel
    • It enables persistent access, runs commands, and exfiltrates data via encrypted API traffic
    • Microsoft urges firewall audits, tamper protection, and endpoint detection to mitigate threats

    To be able to operate properly, malware needs a way to communicate with its “headquarters” – the command & control (C2) server – which is one of the usual ways cybersecurity researchers identify malware – by looking at suspicious communications – which is why crooks go to lengths to try and hide these “conversations” in plain sight.

    Recently, security researchers from Microsoft discovered a new piece of malware that uses a creative way of hiding this dialogue, abusing OpenAI’s Assistants API, a programming interface that lets developers integrate OpenAI’s AI “assistant” capabilities into their own applications, products, or services.

    “Instead of relying on more traditional methods, the threat actor behind this backdoor abuses OpenAI as a C2 channel as a way to stealthily communicate and orchestrate malicious activities within the compromised environment,” the Microsoft Incident Response team said in the report. “To do this, a component of the backdoor uses the OpenAI Assistants API as a storage or relay mechanism to fetch commands, which the malware then runs.”


    You may like

    Used for espionage

    The malware is named SesameOp, and was discovered in July 2025. It grants its attackers persistent access to the compromised environment, as well as usual backdoor capabilities. All of the information grabbed in the attacks is then encrypted and shipped back through the same API channel.

    It is also worth emphasizing this is not a vulnerability in OpenAI’s platform, but rather a built-in capability of the Assistants API which is being abused. According to BleepingComputer, the API itself is scheduled for deprecation in August 2026 anyway.

    “The stealthy nature of SesameOp is consistent with the objective of the attack, which was determined to be long term-persistence for espionage-type purposes,” Microsoft added.

    Those worried about potential SesameOp malware attacks should audit their firewall logs, enable tamper protection, and configure endpoint detection in block mode. Furthermore, they should also monitor for unauthorized connections to external services.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Via BleepingComputer

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    API cyberattacks exploited key launch Microsoft OpenAI Warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIt’s Been a Year Since Trump Was Elected. Democrats Still Don’t Get the Internet
    Next Article WTA Finals tennis: Sabalenka v Pegula; Gauff beats ailing Paolini in straight sets – live | WTA Finals
    admin
    • Website

    Related Posts

    Gadgets

    Google Maps is adding live lane guidance for the Polestar 4

    November 4, 2025
    Gadgets

    Top 10 Features of iOS 26.1 You Shouldn’t Miss

    November 4, 2025
    Gadgets

    This £139 AOC gaming monitor deal is an absolute steal for 1440p gaming with a 240Hz refresh rate — 30% saving brings it to lowest-ever price

    November 4, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    New study settles 40-year debate: Nanotyrannus is a new species

    October 30, 20253 Views

    Better Sound Than Bone Conduction—But at a Cost

    October 30, 20252 Views

    OXS Storm A2 Review – Trusted Reviews

    October 30, 20251 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    New study settles 40-year debate: Nanotyrannus is a new species

    October 30, 20253 Views

    Better Sound Than Bone Conduction—But at a Cost

    October 30, 20252 Views

    OXS Storm A2 Review – Trusted Reviews

    October 30, 20251 Views
    Recent Posts
    • ‘Teen Vogue’ moves under Vogue.com, 6 staffers are laid off : NPR
    • Is your phone on the list? LineageOS adds Android 16 support for more devices
    • Google Maps is adding live lane guidance for the Polestar 4
    • The top-end Apple Watch Ultra 3 gets a rare $100 discount
    • Best MacBook deals for November 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 androidtelecom. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.