September 16, 2026
Cisco Secure Email Gateway suffers from CVE-2026-76461, an unauthenticated SQL injection flaw in AsyncOS being actively exploited for root-level command execution; CISA has added it to KEV. CVE-2026-39364 enables mass scanning of exposed Vite development servers to harvest cloud secrets from AWS, Azure, and Terraform configurations. n8n patched two agent authorization bypasses (CVE-2026-65015 and CVE-2026-59207) that allowed read-only users to execute arbitrary nodes and bypass domain restrictions to steal credentials. Iranian state actors deployed CHOSEN BRICK spyware against dissidents and journalists using fake MRI results as a social-engineering lure, while UTA0560 exploited a Chrome–Windows zero-day chain to deliver GRIMWEDGE against NGOs on September 1.
September 2, 2026
- OpenAI's Astra scored 100% on ExploitBench and, on a fresh internal benchmark of 20 recent high-severity V8 bugs built to control for contamination, hit ~39% arbitrary-code-execution versus ~1% for GPT-5.6 Sol at comparable token spend, per @AiBattle_. In expert evaluations the model reportedly escaped a hardened browser sandbox from a single HTML file and chained OS bugs from unprivileged user to root, and discovered two previously unknown V8 vulnerabilities during the eval itself (@kimmonismus). Read the numbers with care: the strongest results reflect elevated Daybreak Blue access rather than the default public configuration, and full exploit capability goes to alpha testers and Daybreak partners like Cisco and Cloudflare first (@TokenGremlin, @IntCyberDigest). OpenAI says public release is "soon" with cyber capabilities restricted.
· AI & Model Security
- Nimbus Manticore / Mirage Kitten is now cross-platform, delivering the previously undocumented NodeRabbit and PollCat Node.js/JavaScript RATs to Windows, Linux, and macOS via LinkedIn spear-phishing with trojanized coding-challenge archives. Kaspersky reports targeting of aviation and FinTech in Afghanistan, Egypt, and Ethiopia, with C2 blended into Azure and Cloudflare traffic (Securelist, The Hacker News).
· Threat Activity
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
August 31, 2026
- TerminalFix chains a fake Cloudflare CAPTCHA (ClickFix) lure into DLL sideloading and a reverse tunnel for persistent access, with Microsoft publishing detections and hunting queries (Microsoft, The Hacker News). Kevin Beaumont notes the same entry technique is being run by a ransomware-as-a-service operation that is reaching some of the world's largest companies (discussion).
· Threat Activity
in Fully Patched, Still Domain Admin
August 20, 2026
- A Spectre-class attack against Cloudflare Workers leaks JWTs from co-located workers at roughly 12 bits/second, a reminder that multi-tenant serverless isolation still rests on microarchitectural assumptions (The Hacker News).
· Exploitation & Vulnerability Research
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 8, 2026
- Check Point detailed five memory-safety bugs in Cloudflare's
workerd enabling cross-tenant data leaks and sandbox escapes in the runtime behind Cloudflare's agentic "Code Mode" and Workers; Cloudflare has shipped fixes, with the research presented at Black Hat. Check Point Research
· AI & Model Security
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 7, 2026
- N-able N-central attackers are persisting via Cloudflare Tunnels even after patching, per Gossi — check N-central servers for Cloudflare Tunnel traffic. CISA also added the auth-bypass (CVE-2026-18577) to KEV alongside Langflow and Tomcat (earlier coverage). Kevin Beaumont
· Vulnerabilities & Exploits
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
July 5, 2026
- Cloudflare quietly killed the NWHStealer campaign. A researcher deobfuscating a BUN-bundled stealer (spread via fake GTA 6 ads) found its C2 (
unauth-amper[.]cc) already taken down by Cloudflare, ending the campaign. vx-underground
· Threat Activity
in Confidential Computing's Root of Trust May Be Unfixable