September 15, 2026
- An Apache HTTP Server PoC is public for CVE-2026-42536. The PoC repository demonstrates a heap overflow in mod_xml2enc’s
xml2StartParse handling of untrusted content; no in-the-wild use is reported.
· New Tools & Releases
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents
September 3, 2026
- "The Validator Can Lie": SSRF through URL parser differentials in GitLab, Mealie, Apache ShenYu and Thumbor — the validator and the fetching library disagree about the same URL. Good pattern material for anyone auditing allowlist-based SSRF defences (xclow3n).
· Vulnerabilities & Exploitation
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 8, 2026
- A researcher dropped an RCE for the latest Apache httpd, told people to "use it in the wild," and left on a three-week vacation before publishing the exploit — a textbook irresponsible-disclosure situation defenders should be aware of. @cyb3rops
· Vulnerabilities & Exploits
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 6, 2026
- CISA gave federal agencies three days to fix three actively exploited flaws, including the N-able N-central auth bypasses (CVE-2026-18556, CVE-2026-18577) (earlier coverage), a Langflow unauthenticated RCE (CVE-2026-9198, CVSS 9.8), and an Apache Tomcat flaw (BleepingComputer, The Hacker News). Horizon3 published attack-research validation for the N-central bypasses (Horizon3); the Langflow-based IBM agentic platform is separately reported under active attack (The Register).
· Vulnerabilities & Exploits
- Others worth noting: a CVSS 10.0 cross-tenant flaw in HashiCorp's Terraform MCP Server (one user's token reusable by later users) plus a CVSS 9.5 unauthenticated Veeam Service Provider Console bug, among 11 patched (The Hacker News); and an unfixed path-traversal in Apache Dubbo 3.0.0–3.3.6 (SecureLayer7).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 5, 2026
- Apache ActiveMQ RCE bypass chain published. Research covering CVE-2026-34197 and CVE-2026-42588 documents a bypass chain against ActiveMQ Classic, plus audit findings on the "hardened" 6.2.6 release showing some remote exploitation remains feasible despite tightened URI parsing and restricted Jolokia access. GitHub
· Vulnerabilities & Exploits
in Confidential Computing's Root of Trust May Be Unfixable