Citizen Lab highlighted concerns about OpenAI’s Pentagon contract, noting expert skepticism that bulk user-data collection can be effectively ruled out and warning that feeding commercially available personal data into opaque AI systems can amplify harm through errors, bias, and weak accountability. Separately, CSO Online reported on OpenAI’s security-related initiatives, including a claim that Codex Security identified 11,000 “high-impact” bugs in a month and a report that OpenAI plans to acquire Promptfoo to strengthen AI agent security testing.
Most other items in the set are opinion/feature or promotional content rather than incident-driven threat intelligence: CIO and CSO Online ran general enterprise AI and security management pieces (e.g., “shadow AI” governance, identity decisioning, OT/IoT/zero trust challenges, cloud security culture/process issues, and pen-test automation lessons learned), while Red Canary published an RSAC 2026 session guide. One CSO Online headline referenced a critical HPE Aruba CX switch flaw enabling admin control without credentials, but the provided text does not include details sufficient to confirm it as the same story as the OpenAI items and it appears as a sidebar link rather than the primary subject of the referenced pages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In March 2026, Citizen Lab senior researcher Wolfie Christl said in comments to Forbes that an OpenAI deal with the Pentagon permits the gathering of bulk user data. He warned that feeding purchased personal data into opaque AI systems could amplify harms through errors, bias, and weak accountability, despite OpenAI CEO Sam Altman reportedly saying the deal would not enable mass surveillance.
A Citizen Lab report analyzing the shared documents was dated January 16, 2023. The analysis said some communications involved representatives of Iran’s Communications Regulatory Authority.
The Intercept shared internal documents with Citizen Lab researchers in October 2022 for analysis. The materials described apparent plans to develop and launch an Iranian mobile network, including subscriber management and integration with a lawful intercept solution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.