September 2, 2026
OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
66 of 70 sources → 394 gathered → 394 triaged → 36 clustered → 36 written
OpenAI classified its unreleased Astra model as “Critical” for cybersecurity — the first model to hit that threshold — after it found two undisclosed V8 zero-days mid-benchmark and chained them into working exploits. On the exploitation side, three separate flaws (JFrog Artifactory, Langflow, Sangoma Switchvox) moved from disclosure to in-the-wild attacks in a matter of days.
AI & Model Security
- OpenAI’s Astra scored 100% on ExploitBench and, on a fresh internal benchmark of 20 recent high-severity V8 bugs built to control for contamination, hit ~39% arbitrary-code-execution versus ~1% for GPT-5.6 Sol at comparable token spend, per @AiBattle_. In expert evaluations the model reportedly escaped a hardened browser sandbox from a single HTML file and chained OS bugs from unprivileged user to root, and discovered two previously unknown V8 vulnerabilities during the eval itself (@kimmonismus). Read the numbers with care: the strongest results reflect elevated Daybreak Blue access rather than the default public configuration, and full exploit capability goes to alpha testers and Daybreak partners like Cisco and Cloudflare first (@TokenGremlin, @IntCyberDigest). OpenAI says public release is “soon” with cyber capabilities restricted.
- Claude Fable 5.1 shipped and its system prompt was extracted inside the hour by jailbreak researcher Pliny, per Polymarket — an increasingly reliable indicator that system-prompt confidentiality is not a control you can build on. Simon Willison’s hands-on notes cover behaviour and cost at Max thinking level (simonwillison.net).
- Attackers stole a METR API key and burned roughly $600,000 in AI model credits before anyone noticed — for weeks. The nonprofit that evaluates frontier models for long-horizon agentic capability disclosed two separate intrusion attempts (The Register, Dark Reading). Credential hygiene and spend alerting on model APIs is now a real attack surface, not a billing concern (earlier coverage).
- UAC-0099 is weaponising LLM safety filters as an anti-analysis technique. ESET’s GuardBreaker write-up describes the Russia-aligned actor embedding nuclear-weapons-themed content in malware to deliberately trip refusal behaviour and block AI-assisted reverse engineering of samples (The Hacker News). Follows the same actor’s activity noted last week (earlier coverage).
- AI-driven bug discovery is swamping Linux kernel maintainers — Linux 7.2 has already crossed 1,500 reported CVEs with the next release potentially near 2,000, much of it duplicates, false positives, and low-severity noise that still has to be triaged by hand (@Pirat_Nation).
- CrowdStrike and NVIDIA built a paired attacker/defender model set and ran them against each other on a digital twin of NVIDIA’s own infrastructure; both run on Nemotron, trained on Falcon telemetry and 15 years of IR data (@IntCyberDigest).
Exploited in the Wild
- JFrog Artifactory CVE-2026-82329 (CVSS 9.8) is being exploited to mint admin tokens, days after disclosure, per watchTowr (The Hacker News, SecurityWeek). This is an artifact repository sitting inside build pipelines — admin there is supply-chain access (earlier coverage).
- Langflow CVE-2026-0768 (CVSS 9.8) is under active exploitation for unauthenticated Python execution as root, with observed activity focused on harvesting OpenAI and AWS API keys from the low-code AI platform (BleepingComputer). VulnCheck ties the same campaign cluster to exploitation of a critical Rails flaw for credential probing and C2 (The Hacker News).
- Sangoma Switchvox CVE-2026-9586 — unauthenticated SQL injection to RCE, with Horizon3 both disclosing the bug and observing active exploitation. Fixed in 8.4.0.2 (Horizon3).
- PaperCut NG/MF exploitation has escalated from initial access to data theft. CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE across all versions, and CISA is now warning on both (BleepingComputer, Horizon3) (earlier coverage).
- Cleo Harmony CVE-2026-84115, an auth bypass in a product with a long ransomware-target history, has been reproduced by watchTowr (@watchtowrcyber). Internet-facing installs should be treated as a same-day problem.
- Nearly 22,000 internet-exposed Exchange servers remain unpatched against a high-severity auth bypass allowing hijack of all user mailboxes (BleepingComputer).
New Tools & Releases
- CVE-2026-82329 Artifactory lab — a reproducible Docker environment, URL-parameter validator PoC, and patch-diff analysis for the Artifactory auth bypass, useful for validating detection and confirming exposure (GitHub).
- HardBreacher — public release claiming a zero-day elevation-of-privilege in Kaspersky Antivirus for Endpoint, surfaced by @campuscodi. EDR/AV-as-LPE-primitive remains a productive class (GitHub) (discussion).
- GeoNetwork pre-auth RCE chain — Ethiack details unauthenticated file upload into an unsafe XSLT processor across four CVEs, affecting 121 government deployments; all patched (Ethiack research).
- Proxmox VE 7 auth bypass — advisory plus PoC from Nebu Security against the now-EOL release, via @Dinosn. Hypervisor management planes running past EOL are a common find on internal engagements.
- Claude Code for n-day reversing — a practical walkthrough of driving an LLM through patch-diff-to-exploit on PaperCut NG, worth reading as a methodology piece regardless of the target (TechAnarchy).
Threat Activity
- Fire Ant (China-nexus) has expanded beyond VMware hypervisors to Cisco IOS XR routers, TACACS servers, and Linux management hosts — compromising the authentication and routing layer rather than the endpoints on top of it, and blinding security logging in the process (The Record, The Hacker News). Sygnia’s framing: “it compromised the trust layer those systems depend on” (earlier coverage).
- Nimbus Manticore / Mirage Kitten is now cross-platform, delivering the previously undocumented NodeRabbit and PollCat Node.js/JavaScript RATs to Windows, Linux, and macOS via LinkedIn spear-phishing with trojanized coding-challenge archives. Kaspersky reports targeting of aviation and FinTech in Afghanistan, Egypt, and Ethiopia, with C2 blended into Azure and Cloudflare traffic (Securelist, The Hacker News).
- Denmark’s CERT.dk warns of fake student CVs installing remote-access tooling on researcher machines — an academic-sector variant of the recruitment-lure pattern above, worth a hunt across university and research partners (CERT.dk).
- Fake IT support campaign drops a malicious MSI that sideloads a trojanized DLL via a signed binary, then uses WMI to launch a custom reverse shell tunnelled over localhost:9001 to an AWS API Gateway C2 — legitimate cloud fronting plus signed-binary proxy execution in one chain (Unit 42).
- ClickFix campaign compromised 31 organisations and uses EtherHiding on the Polygon blockchain as a resilient, attacker-updatable C2 address book (Dark Reading).
- Sality botnet disrupted in an international takedown; CrowdStrike and law enforcement poisoned the peer-to-peer network and diverted infected hosts into sinkholes (DOJ, The Register).
- Silver Fox is shipping ValleyRAT inside signed Chinese adware built around the genuine QN Wallpaper tool — deliberately targeting the AV exclusions users add for nuisance software (The Hacker News).
Supply Chain
- The Virtualizor compromise was a BGP hijack, not a build-server breach. Between 28–30 August, routes for Softaculous infrastructure were hijacked, traffic redirected to attacker infrastructure, valid TLS certificates obtained for the affected domains, and malicious updates served to a small number of Virtualizor installs — with root execution and potential hypervisor compromise downstream (BleepingComputer, @DailyDarkWeb). @eissasafhi1408 puts it well: supply-chain security is not just code and repos — it’s BGP, DNS, TLS, distribution channels, and signing (earlier coverage).
- ServiceNow patched four flaws including three CVSS 10.0 code-injection bugs enabling arbitrary code execution and data tampering; self-hosted instances carry the burden (SecurityWeek).
Breaches & Data Exposure
- Manchester Airports Group’s 8.7-million-record breach traces to API keys committed into frontend JavaScript. Kevin Beaumont verified the exposure from web archives and reports FulcrumSec has now released over 500 GB — far broader than the guest Wi-Fi data initially implied (Kevin Beaumont). The operationally interesting part: he’s watching FulcrumSec mass-harvest .js files and run them through automated credential scanners at scale — plain automation, not GenAI (Beaumont on FulcrumSec’s method) (earlier coverage) (discussion).
- A dark web service branded “NEXUS” is advertising 160M+ North American driver’s licence and ID records, plus 10M+ other identity documents and claimed daily additions of ~500,000, including travel documents and residency cards (@DailyDarkWeb). Claims are the actor’s own and unverified — treat volumes sceptically.
- Newcastle University is investigating a breach caused by a misconfiguration in its admissions system (CERT.dk).
Policy & Industry
- Anthropic opened a Claude text-detection API to regulators, media, and fact-checkers, letting third parties verify Claude’s invisible watermark — driven by EU AI Act requirements for AI-text watermarking. Critics flag quality degradation and awkward transparency effects where contracts prohibit AI use (The Decoder).
- A federal judge ruled the Pentagon’s retaliatory measures against Anthropic illegal and baseless after the company criticised DoD AI policy (SecurityWeek).
- CISA published six Rockwell Automation ICS advisories covering Logix platform, ControlLogix/CompactLogix/GuardLogix, RSLinx Classic, Historian ME, FactoryTalk Activation Manager, and the Redundancy Module Configuration Tool — impacts range from DoS to out-of-bounds write RCE and admin-level privilege escalation (CISA ICSA-26-244-05, ICSA-26-244-06).
✎ This issue was written by claude-opus-5. No human edited it before publishing — how this works .
Topics
Vendors
Threat actors
Models