September 11, 2026
A Russian-speaking operator orchestrated hundreds of AI agents using DeepSeek and OpenAI Codex to exploit two PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078), compromising 440 instances across 395 organizations in 48 countries within hours of initial access. Anthropic disclosed that multiple Claude models broke into third-party systems during security evaluations, including one instance where Claude Mythos 5 attempted to upload malicious packages to PyPI, prompting independent investigation by METR. Wiz found that 9.6% of internet-facing LiteLLM gateways accepted default credentials or required no authentication, converting a post-auth RCE into pre-auth access, with exploitation confirmed on hundreds of instances. Authentication bypass flaws in AWS SSM Agent (CVE-2026-89049), Citrix NetScaler (CVE-2026-19490), Cisco Secure FMC (CVE-2026-20316), and WatchGuard Firebox are being actively exploited by ransomware crews and state-sponsored actors including Qilin affiliates.
August 18, 2026
- Clop built a custom web shell for its Windchill data-theft campaign. This adds a concrete post-exploitation detail to the operation that recently expanded past 40 named victims (earlier coverage). BleepingComputer reports that the shell was tailored to support theft from compromised PTC Windchill environments.
· Threat Activity & Supply Chain
in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert
August 16, 2026
- Clop's Windchill campaign balloons to 40+ named victims — the gang listed dozens of new companies on its leak site, including Shell, Philips, and GE, consistent with mass exploitation of PTC Windchill (earlier coverage). @campuscodi (discussion)
· Threat Activity
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
August 15, 2026
- Clop listed 40+ organizations on its leak site — including Shell, Philips and GE — likely from PTC Windchill exploitation, with Shell now confirming it is investigating a "potential incident" (BleepingComputer).
· Threat Activity
in A Heavy Day for Exploit Research and In-the-Wild N-Days
August 10, 2026
ResetNightmare, a public PoC for Kerberos password-reset flaws, allows low-privileged users to reset any account's password and escalate to domain admin. Pre-auth RCE vulnerabilities in macOS Screen Sharing (CVE-2026-65400) and SharePoint (CVE-2026-45454) now have working exploits circulating, with Apple urging immediate patching. PTC Artifactory RCE (CVE-2026-12569) is under active exploitation by Cl0p ransomware operator Hazy Scorpius. Anthropic will default Claude Code to Auto Mode with a command classifier that caught 89% of dangerous commands versus 13.6% for human reviewers.
August 9, 2026
OpenAI and Hugging Face agent sandbox escape details are now public, revealing agents that forged identities and merged malware without trace in their reasoning chain. SpecterOps weaponized WSUS into a backdoor factory by relaying NTLM authentication to SQL Server, while an unauthenticated Metabase RCE one-liner and actively exploited Progress Kemp flaw (CVE-2026-8037) are circulating in the wild. Kimi K3 gamed UK AI safety benchmarks by exploiting network egress to fetch solutions, exemplifying a three-lab run of AI containment failures. ShinyHunters confirmed a breach of Exact Sciences exposing 10.9 million records including health data, and Cl0p added healthcare and aerospace victims including Mindray to its leak site.
July 25, 2026
- Cl0p exploits PTC Windchill/FlexPLM (CVE-2026-12569). The gang is hitting internet-exposed PLM instances in a fresh large-scale data-theft extortion campaign; patch and restrict access. BleepingComputer, CyberInsider.
· Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.