Saturday, July 25, 2026

BREAKING: OpenAI confirms ChatGPT is down worldwide | BleepingComputer

ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations.
This outage also affects OpenAI's coding platform, Codex. Thankfully, OpenAI is aware of these issues and has already acknowledged them on the status page.

OpenAI confirms ChatGPT is down worldwide

ChatGPT

The outage started at approximately 5 AM ET and is affecting users worldwide, including those in the US and Europe.

If you are affected, ChatGPT will get stuck at loading animations for the sidebar, and you won't be able to send messages due to "too many concurrent requests" errors.

"We are investigating the issue for the listed services," the company said in an update posted at 5:30 AM ET.
  • OpenAI says it has applied a fix and is monitoring the situation, but we continue to run into issues in our tests.
  • The outage also affects the OpenAI API, with as many as 12 API endpoints listed as having issues on the company's status page.
  • Update 1: ChatGPT has fully recovered and is back online as of 6 AM ET. The outage affected ChatGPT and API services for almost 50 minutes.

ChatGPT is unable to load chats
Source: BleepingComputer

Related Articles:

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

Leak confirms OpenAI is testing a ChatGPT for Science subscription

OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Fake Claude app promoted by Bing ads pushes SectopRAT malware


Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsBy

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.

The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.

Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia.

Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information,  communications, and private documents.
“We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail- confirming this isn't sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest says.
  • The researchers believe this activity is similar to the FrostArmada router-based campaigns attributed to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard).

Attack chain

It is unclear how initial access to the Wi-Fi appliances was gained, but ReliaQuest says the threat actor could have exploited weakly protected, exposed management interfaces (e.g., SSH, SNMP, web admin dashboards) or vulnerabilities.
Once the attacker gains administrator access, they can modify the gateway’s DNS settings to redirect connections to legitimate domains to infrastructure under the attacker's control.
ReliaQuest says that the attacker registered at least four domains for setting up fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.
With DNS settings changed, users trying to access legitimate Microsoft login portals would land on the hacker's phishing pages and enter their credentials.
  • In some cases, the researchers observed a device-code authentication flow in which targets were redirected to a fake Microsoft page with a prompt.
"What the user can't see is that approving the prompt authorizes a session initiated by the attacker," ReliaQuest says. 
  • The researchers note that authorizing the attacker-initiated request causes a legitimate OAuth token to be issued to the attacker's client.
This bypasses the multi-factor authentication (MFA) protection without stealing any credentials or intercepting access tokens.
The attack steps
The attack steps
Source: ReliaQuest
In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows' automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.
  • This theoretically would route traffic from Windows apps, including Chrome, through an attacker-controlled proxy, but ReliaQuest couldn’t confirm that these attacks were successful.
  • The researchers also emphasized that using public DNS servers such as Google’s 8.8.8.8 does not prevent this attack, as the gateway forges the plain-text requests before they reach the intended resolver.
ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode as solid protection measures against these attacks.
Additionally, the cybersecurity company recommends disabling WPAD, reviewing logs for suspicious activity, and disabling Device Code authentication flow in Microsoft Entra ID when not needed.
LATEST ARTICLES

No comments:

BREAKING: OpenAI confirms ChatGPT is down worldwide | BleepingComputer

ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations. This outage also affects OpenA...