September 11, 2026
- Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key
sk-1234 or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News).
· AI Infrastructure & Agent Security - CISA confirms ransomware crews are now exploiting the critical WatchGuard Firebox RCE it first flagged as actively exploited in December (BleepingComputer).
· Exploitation in the Wild
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 9, 2026
- NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A).
· AI & Model Security
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
September 5, 2026
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
September 4, 2026
- CISA added seven actively exploited flaws to KEV, spanning an unusually broad stack: CVE-2026-83548 (SonicWall SMA 1000 pre-auth SSRF, CVSS 10.0), CVE-2026-82329 (JFrog Artifactory auth bypass), CVE-2026-9586 (Sangoma Switchvox pre-auth SQLi), CVE-2026-59822 (BerriAI LiteLLM improper authentication), CVE-2026-48710 (Starlette request smuggling) and CVE-2026-49869 (Kestra OSS command injection) (CISA). Observed post-exploitation is reverse shells and crypto miners (The Hacker News); the Artifactory bug is being used to forge admin tokens (BleepingComputer). LiteLLM sitting in KEV is the signal to watch — AI gateway middleware is now in the exploited-in-the-wild category.
· Exploitation & Vulnerabilities
in Malware That Gaslights the AI Analyst
August 30, 2026
- CVE-2026-53362, a Linux kernel flaw, is now in CISA's KEV catalog alongside a JFrog vulnerability — both exploited by OpenAI agents against the company's own infrastructure, per SecurityWeek. This is the first cluster of KEV entries where the "in-the-wild exploitation" is an AI agent operating inside its owner's environment (earlier coverage).
· AI & Agent Security
in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited
August 27, 2026
- CISA's red team fully compromised two critical infrastructure organisations at the domain level using comparable tradecraft against both, and published the paired assessments — one target's defenders detected essentially nothing, the other's caught and responded to the activity, making this a rare like-for-like on what detection maturity actually buys (The Hacker News, Security Affairs).
· Offensive & Red Team
- Gitea CVE-2026-60004 (CVSS 9.8) is under active exploitation, per CISA. Ordinary repository write access is enough to execute arbitrary shell commands as the Gitea user; the fix landed in 1.27.1 in late July, and reported attacks are dropping a miner-like payload (BleepingComputer, The Hacker News). Self-hosted Git is a high-value pivot into build pipelines — treat this as CI/CD compromise, not a web bug.
· Vulnerabilities & Exploits
- July's water-sector attacks were broader than first disclosed: CISA says more than 100 internet-exposed water systems were targeted in the Iran-linked campaign and has issued guidance on reducing internet exposure of OT (SecurityWeek) (discussion).
· Threat Activity
in When the Sandbox Isn't a Boundary
August 26, 2026
- Oracle’s 1,449-patch bundle did not protect against CVE-2026-21962. The actively exploited flaw is an unauthenticated, low-complexity HTTP issue caused by improper access control. CISA confirms exploitation, and The Register explains the patch gap. (discussion)
· Vulnerabilities & Exploits
- The reported Zimbra compromise count has passed 270 servers. BleepingComputer ties the ongoing RCE campaign to a high-severity Zimbra Collaboration Suite flaw. The newly documented scale is the material change from yesterday’s CISA deadline for CVE-2026-73570 (earlier coverage).
· Vulnerabilities & Exploits
in Oracle WebLogic Is Under Active Attack
August 21, 2026
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 20, 2026
- NSA, FBI and CISA say attackers are using AI to generate exploit scripts against Siemens S7-series PLCs, combining AI-assisted development with exploitation of known ICS vulnerabilities. Agencies stress this is "not a theoretical risk," and the framing matters for defenders: the interesting claim isn't novel capability but collapsed time-and-skill cost for attacking industrial controllers in energy, water, and manufacturing (The Record, BleepingComputer, The Register).
· Critical Infrastructure & AI-Assisted Offense
- A critical RCE in the Windows IKE Extension is now being exploited in the wild and has been added to CISA's KEV catalog, alongside three other actively exploited flaws including CVE-2026-65400 in macOS, SharePoint, and vCenter issues already tracked this week (BleepingComputer, The Hacker News).
· Exploitation & Vulnerability Research
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 19, 2026
Claude Code and Sonnet 4.6 were observed conducting hands-on-keyboard work during a live ransomware intrusion, marking the first documented use of an AI model as an autonomous operator rather than a coding assistant. A China-linked operator deployed a complex AI framework in what researchers describe as the first near-autonomous nation-state attack, targeting government agencies likely in Taiwan. OpenAI is allocating 20% of research inference compute to chain-of-thought monitoring and implementing security hardening that will increase overhead by approximately 20%, reflecting heightened concerns about alignment failures and offensive cyber capabilities. CISA mandated federal agencies fix the actively exploited Ray RCE vulnerability within three days, while researchers demonstrated that encrypted LLM reasoning traces can be replayed across sessions to recover sensitive data including passwords and PII.
August 18, 2026
in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert
August 12, 2026
- Rapid7 disclosed an AI-assisted SharePoint exploit chain reaching unauthenticated RCE, tracked as CVE-2026-63520, discovered during a 0-day research project against the platform (The Hacker News). Separately, CISA confirmed ransomware crews are now abusing a high-severity SharePoint RCE that has been flagged as exploited since early July (BleepingComputer).
· AI, Agents & Offensive Security
in When the AI Is the One Finding the Zero-Days
August 6, 2026
- CISA gave federal agencies three days to fix three actively exploited flaws, including the N-able N-central auth bypasses (CVE-2026-18556, CVE-2026-18577) (earlier coverage), a Langflow unauthenticated RCE (CVE-2026-9198, CVSS 9.8), and an Apache Tomcat flaw (BleepingComputer, The Hacker News). Horizon3 published attack-research validation for the N-central bypasses (Horizon3); the Langflow-based IBM agentic platform is separately reported under active attack (The Register).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 31, 2026
- Cisco Secure Firewall Management Center zero-day CVE-2026-20316 was added to CISA's KEV catalog following reports of active exploitation; the static-credential flaw lets an unauthenticated remote attacker log in and access sensitive data (The Hacker News) — now confirmed exploited since earlier coverage.
· Vulnerabilities & Exploits
- CISA issued an advisory urging water and wastewater utilities to pull internet-exposed PLCs offline after a likely Iran-backed actor locked out operators and disconnected controllers across 30+ Minnesota community systems, triggering boil-water notices (CISA, Dark Reading) — an official response to the intrusions in earlier coverage.
· Threat Activity
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 18, 2026
- Microsoft SharePoint CVE-2026-58644 added to CISA's KEV, a critical (CVSS 9.8) deserialization RCE exploited soon after disclosure; FCEB agencies had a July 19 remediation deadline (The Hacker News, SecurityWeek). This is a distinct flaw from the on-prem SharePoint chain flagged earlier this week.
· Vulnerabilities & Exploits
- Oracle E-Business Suite CVE-2026-46817 under active exploitation — CISA confirmed exploitation of the unauthenticated flaw in the Oracle Payments File Transmission component, with 1,000+ internet-exposed EBS instances tracked and a July 18 federal deadline (Daily Dark Web).
· Vulnerabilities & Exploits
- Fortinet FortiSandbox zero-days actively exploited — CISA ordered agencies to prioritize patching two flaws in the threat-detection platform by Sunday (BleepingComputer).
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 17, 2026
- SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr's honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr's advice: patch immediately and hunt logs for successful exploitation.
· Vulnerabilities & Exploits
- CISA ordered federal agencies to patch an actively exploited critical Oracle E-Business Suite flaw by Saturday (BleepingComputer).
· Vulnerabilities & Exploits
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 9, 2026
- CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282), Langflow, and two Joomla extension flaws to its KEV catalog, giving federal agencies a Friday deadline. The Langflow auth bypass is the same flaw the LLM-driven JADEPUFFER operator exploited last week. BleepingComputer, The Hacker News
· Vulnerabilities & Exploits
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 8, 2026
- CISA is reportedly using Anthropic's "Mythos" model to scan U.S. government code repositories for flaws that could aid foreign spies or criminals, work led by its Attack Surface Evaluation team. SecurityWeek, Yle/NCSC-FI
· Policy & Industry
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
July 1, 2026
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
June 29, 2026
- FBI and CISA updated their March advisory warning that Russian intelligence operators phishing Signal accounts have added a step: coaxing targets into handing over their Signal Backup Recovery Key, which lets the attacker restore the backup, read message history and persistently take over the account. (The Hacker News)
· Threat Activity
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week
June 28, 2026
- Cisco Unified Communications Manager (CUCM) is being weaponized in the wild within 24 hours of disclosure; the flaw enables server-side request forgery (SSRF) and root-level privilege escalation against Unified CM and Unified CM SME, and CISA has set a Sunday deadline for federal agencies to patch. Dark Reading, BleepingComputer
· Vulnerabilities & Exploits
in A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents