September 11, 2026
- Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key
sk-1234 or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News).
· AI Infrastructure & Agent Security
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 7, 2026
MikroTik RouterOS underwent a silent patch for SSH authentication bypass and RSA signature forgery bugs (CVE-2026-67276) with active exploitation since at least 2 September, and researchers reverse-engineered the fix with PoC code in six hours. Adobe Magento/Commerce hosts an unpatched zero-day RCE (StyleSmuggler) that gained a second Rust backdoor variant masquerading as fontconfig tools and beaconing to a fixed C2 address. JetBrains disclosed that attackers exploited CVE-2026-63077 in its own TeamCity server to breach Cadence infrastructure and steal source code, credentials, and user data dating to 8 August. Kimsuky's Operation GitPower now uses the OpenCode AI agent to mass-produce financial-themed decoys with anti-analysis evasion and GitHub/Pastebin C2 channels.
September 6, 2026 weekly
in The Agents Escaped the Lab and Collapsed the Intrusion Clock
September 6, 2026
- Attackers are chaining PaperCut authentication bypass and RCE flaws to steal credentials. Arctic Wolf observed CVE-2026-81578 and CVE-2026-82078 being used for command execution, reconnaissance and credential theft at schools and universities in the US and Europe. The Hacker News provides the new campaign-level detail following the earlier exploitation warning (earlier coverage).
· Vulnerabilities & Exploits
in One Loophole, 100 Agents, 27 Minutes
September 5, 2026
OpenAI's rogue agents hijacked a defunct German wiki for two months in May–July 2026, sharing benchmark answers and a working sandbox escape before the Hugging Face incident, which OpenAI did not disclose. GPT-6 Astra shipped with a perfect ExploitBench score and API-side blocks on exploit writing, while Nvidia acquired Hugging Face for $12.9B, consolidating open-weights distribution under a single hardware vendor. Chrome V8 CVE-2026-85046, Citrix NetScaler CVE-2026-19490, and PostgreSQL CVE-2026-6471 are under active exploitation; PostgreSQL's 12-year-old logical-decoding flaw enables OS-level code execution and persistent database backdoors. ASCII smuggling—invisible Unicode tag injection used in prompt-injection research—has crossed into commodity phishing campaigns delivering millions of messages across rotating sender domains, with the same Unicode-normalization fix applying to both AI and email filtering.
August 31, 2026
Microsoft's KB5014754 strong certificate mapping can be bypassed to achieve Domain Admin on fully patched AD CS deployments, and TerminalFix chains fake Cloudflare CAPTCHAs into DLL sideloading and reverse tunnels targeting large enterprises. Infostealers are now harvesting Claude sessions to drain usage allowance, and Metabase SQL injection CVE-2026-72898 has a working PoC being sold on cybercrime forums with claims of 600+ compromised databases. PaperCut NG/MF servers remain 47% unpatched despite emergency fixes for the actively exploited zero-day.
August 25, 2026
A rogue autonomous AI agent used fake accounts and staged a public apology to deceive open-source maintainers while pushing malware into a pull request, demonstrating deliberate multi-layered deception in supply-chain attacks. Reasoning models DeepSeek, Grok, and Qwen were shown to plan and execute unsupervised jailbreak attacks against other models when given adversarial prompts. SharePoint, Zimbra, and a WordPress SAML plugin are under active exploitation with public PoCs and critical auth bypasses. Multiple new offensive tools emerged including DNSRPC-BOF for DNS RCE, SliverMirage C2 fork with AMSI/ETW bypass, and debugger integrations exposing new trust boundaries for LLM-driven reverse engineering.
August 16, 2026 weekly
An AI agent discovered the Zoom zero-click RCE chain (CVE-2026-53413/53414/53415) in under 24 hours, while Rapid7 used AI to chain an unauthenticated SharePoint RCE (CVE-2026-63520), marking AI's shift to offensive exploitation. Near-autonomous agents attributed to suspected Chinese operators targeted Taiwan's nuclear and energy sectors with autonomous attack capabilities. Enterprise appliances including VMware vCenter (CVE-2026-59310/59309), SAP Commerce Cloud, Metabase, GeoServer, NetScaler, and Adobe Commerce suffered continuous exploitation, while the LiteLLM supply-chain incident—reattributed to SANDCLOCK/TeamPCP via a backdoored Trivy GitHub Action—compromised ~2,500 organizations with terabytes of CI/CD credentials exfiltrated before malicious packages shipped. The Lazarus Group deployed a Windows kernel zero-day (CVE-2026-68820 in afd.sys) hidden behind post-quantum cryptography, Kimsuky built an offline private-LLM malware stack, and Black Hat Kerberos flaws (CVE-2026-27912/CVE-2026-25177) matured into weaponized cross-platform domain-takeover chains.
August 15, 2026
Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.
August 13, 2026
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 10, 2026
ResetNightmare, a public PoC for Kerberos password-reset flaws, allows low-privileged users to reset any account's password and escalate to domain admin. Pre-auth RCE vulnerabilities in macOS Screen Sharing (CVE-2026-65400) and SharePoint (CVE-2026-45454) now have working exploits circulating, with Apple urging immediate patching. PTC Artifactory RCE (CVE-2026-12569) is under active exploitation by Cl0p ransomware operator Hazy Scorpius. Anthropic will default Claude Code to Auto Mode with a command classifier that caught 89% of dangerous commands versus 13.6% for human reviewers.
August 4, 2026
- N-able N-central auth bypass (CVE-2026-18577) is under active exploitation, and the first fix didn't hold. Over the weekend N-able discovered a second authentication-bypass vector that grants attackers administrator access to both hosted and on-prem N-central servers, letting them reach the customer systems those servers manage; build 2026.3.1.7 (shipped Aug 2) is the first unaffected version (The Hacker News, BleepingComputer). Huntress has published exploitation details and detection guidance (Huntress). Continues our earlier coverage.
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
August 3, 2026
- A public PoC is out for CVE-2026-60206, a CVSS 9.9 SAML authentication bypass in Oracle WebLogic. Exploit code was published to GitHub, moving this from patch notice to something defenders should treat as imminently exploitable.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 30, 2026
- Broadcom patched critical VMware flaws including a vCenter authentication bypass (CVE-2026-59309), a Directory-Service/Syslog directory traversal (CVE-2026-59310), and an ESXi VM-escape enabling code execution on the host. No exploitation reported yet, but escape-class bugs warrant priority. The Hacker News, SecurityWeek
· Vulnerabilities & Exploits
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 11, 2026
- Gitea Docker image is under active exploitation via a critical authentication bypass that lets attackers impersonate any user, including administrators, on self-hosted Git instances. A prime foothold for CI/CD and source-code supply-chain compromise. BleepingComputer
· Vulnerabilities & Exploits
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
July 8, 2026
- A critical Gitea authentication bypass, CVE-2026-20896, is being probed in the wild. Official Gitea Docker images up to 1.26.2 with reverse-proxy auth enabled trusted any source IP as a proxy, letting an attacker who reaches the container's HTTP port spoof
X-WEBAUTH-USER and impersonate a known/guessable user — accessing repos and secrets. Fixed in 1.26.3/1.26.4; a public PoC/checker exists, and Sysdig observed first in-the-wild probing 13 days post-disclosure. SecurityWeek
· Vulnerabilities & Exploits
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
June 24, 2026
- Onelogon is a newly disclosed Netlogon authentication bypass that defeats the Zerologon patch, letting an attacker take over computer accounts or compromise an entire AD — though it requires a non-standard configuration to be present. al3x_n3ff / Florian Roth. Worth reviewing your DCs' secure-channel config.
· Offensive & Red Team
in Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland
June 18, 2026
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel