daily cyber × ai intelligence

index

tagged

[cisa]

21 editions · 32 items

September 11, 2026

  • Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key sk-1234 or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News). · AI Infrastructure & Agent Security
  • CISA confirms ransomware crews are now exploiting the critical WatchGuard Firebox RCE it first flagged as actively exploited in December (BleepingComputer). · Exploitation in the Wild

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

September 9, 2026

  • NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A). · AI & Model Security

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android

September 5, 2026

in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May

September 4, 2026

  • CISA added seven actively exploited flaws to KEV, spanning an unusually broad stack: CVE-2026-83548 (SonicWall SMA 1000 pre-auth SSRF, CVSS 10.0), CVE-2026-82329 (JFrog Artifactory auth bypass), CVE-2026-9586 (Sangoma Switchvox pre-auth SQLi), CVE-2026-59822 (BerriAI LiteLLM improper authentication), CVE-2026-48710 (Starlette request smuggling) and CVE-2026-49869 (Kestra OSS command injection) (CISA). Observed post-exploitation is reverse shells and crypto miners (The Hacker News); the Artifactory bug is being used to forge admin tokens (BleepingComputer). LiteLLM sitting in KEV is the signal to watch — AI gateway middleware is now in the exploited-in-the-wild category. · Exploitation & Vulnerabilities

in Malware That Gaslights the AI Analyst

August 27, 2026

  • CISA's red team fully compromised two critical infrastructure organisations at the domain level using comparable tradecraft against both, and published the paired assessments — one target's defenders detected essentially nothing, the other's caught and responded to the activity, making this a rare like-for-like on what detection maturity actually buys (The Hacker News, Security Affairs). · Offensive & Red Team
  • Gitea CVE-2026-60004 (CVSS 9.8) is under active exploitation, per CISA. Ordinary repository write access is enough to execute arbitrary shell commands as the Gitea user; the fix landed in 1.27.1 in late July, and reported attacks are dropping a miner-like payload (BleepingComputer, The Hacker News). Self-hosted Git is a high-value pivot into build pipelines — treat this as CI/CD compromise, not a web bug. · Vulnerabilities & Exploits
  • July's water-sector attacks were broader than first disclosed: CISA says more than 100 internet-exposed water systems were targeted in the Iran-linked campaign and has issued guidance on reducing internet exposure of OT (SecurityWeek) (discussion). · Threat Activity

in When the Sandbox Isn't a Boundary

August 26, 2026

  • Oracle’s 1,449-patch bundle did not protect against CVE-2026-21962. The actively exploited flaw is an unauthenticated, low-complexity HTTP issue caused by improper access control. CISA confirms exploitation, and The Register explains the patch gap. (discussion) · Vulnerabilities & Exploits
  • The reported Zimbra compromise count has passed 270 servers. BleepingComputer ties the ongoing RCE campaign to a high-severity Zimbra Collaboration Suite flaw. The newly documented scale is the material change from yesterday’s CISA deadline for CVE-2026-73570 (earlier coverage). · Vulnerabilities & Exploits

in Oracle WebLogic Is Under Active Attack

August 20, 2026

  • NSA, FBI and CISA say attackers are using AI to generate exploit scripts against Siemens S7-series PLCs, combining AI-assisted development with exploitation of known ICS vulnerabilities. Agencies stress this is "not a theoretical risk," and the framing matters for defenders: the interesting claim isn't novel capability but collapsed time-and-skill cost for attacking industrial controllers in energy, water, and manufacturing (The Record, BleepingComputer, The Register). · Critical Infrastructure & AI-Assisted Offense
  • A critical RCE in the Windows IKE Extension is now being exploited in the wild and has been added to CISA's KEV catalog, alongside three other actively exploited flaws including CVE-2026-65400 in macOS, SharePoint, and vCenter issues already tracked this week (BleepingComputer, The Hacker News). · Exploitation & Vulnerability Research

in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs

August 19, 2026

When the Attacker's Toolchain Includes an LLM

Claude Code and Sonnet 4.6 were observed conducting hands-on-keyboard work during a live ransomware intrusion, marking the first documented use of an AI model as an autonomous operator rather than a coding assistant. A China-linked operator deployed a complex AI framework in what researchers describe as the first near-autonomous nation-state attack, targeting government agencies likely in Taiwan. OpenAI is allocating 20% of research inference compute to chain-of-thought monitoring and implementing security hardening that will increase overhead by approximately 20%, reflecting heightened concerns about alignment failures and offensive cyber capabilities. CISA mandated federal agencies fix the actively exploited Ray RCE vulnerability within three days, while researchers demonstrated that encrypted LLM reasoning traces can be replayed across sessions to recover sensitive data including passwords and PII.

August 18, 2026

in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert

August 6, 2026

  • CISA gave federal agencies three days to fix three actively exploited flaws, including the N-able N-central auth bypasses (CVE-2026-18556, CVE-2026-18577) (earlier coverage), a Langflow unauthenticated RCE (CVE-2026-9198, CVSS 9.8), and an Apache Tomcat flaw (BleepingComputer, The Hacker News). Horizon3 published attack-research validation for the N-central bypasses (Horizon3); the Langflow-based IBM agentic platform is separately reported under active attack (The Register). · Vulnerabilities & Exploits

in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board

July 31, 2026

  • Cisco Secure Firewall Management Center zero-day CVE-2026-20316 was added to CISA's KEV catalog following reports of active exploitation; the static-credential flaw lets an unauthenticated remote attacker log in and access sensitive data (The Hacker News) — now confirmed exploited since earlier coverage. · Vulnerabilities & Exploits
  • CISA issued an advisory urging water and wastewater utilities to pull internet-exposed PLCs offline after a likely Iran-backed actor locked out operators and disconnected controllers across 30+ Minnesota community systems, triggering boil-water notices (CISA, Dark Reading) — an official response to the intrusions in earlier coverage. · Threat Activity

in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests

July 18, 2026

  • Microsoft SharePoint CVE-2026-58644 added to CISA's KEV, a critical (CVSS 9.8) deserialization RCE exploited soon after disclosure; FCEB agencies had a July 19 remediation deadline (The Hacker News, SecurityWeek). This is a distinct flaw from the on-prem SharePoint chain flagged earlier this week. · Vulnerabilities & Exploits
  • Oracle E-Business Suite CVE-2026-46817 under active exploitation — CISA confirmed exploitation of the unauthenticated flaw in the Oracle Payments File Transmission component, with 1,000+ internet-exposed EBS instances tracked and a July 18 federal deadline (Daily Dark Web). · Vulnerabilities & Exploits
  • Fortinet FortiSandbox zero-days actively exploited — CISA ordered agencies to prioritize patching two flaws in the threat-detection platform by Sunday (BleepingComputer). · Vulnerabilities & Exploits

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

July 17, 2026

  • SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr's honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr's advice: patch immediately and hunt logs for successful exploitation. · Vulnerabilities & Exploits
  • CISA ordered federal agencies to patch an actively exploited critical Oracle E-Business Suite flaw by Saturday (BleepingComputer). · Vulnerabilities & Exploits

in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands