September 3, 2026
- Astra's oversight story is getting weaker as its capability rating rises (earlier coverage). OpenAI's plan to keep the "critical"-rated model in check rests on chain-of-thought monitoring, but reporting says the architecture moves more reasoning into activations rather than readable text (The Decoder, OpenAI). @RyanGreenblatt calls opaque reasoning potentially "the single worst development for AI security/safety to date," while noting the recurrent depth appears limited enough that the model still leans on natural-language chain-of-thought. An unverified claim circulating via @thegrugq says Astra scored 100% arbitrary-code-execution on all 41 CVEs in ExploitBench, prompting a contamination-free fork of the benchmark.
· AI-Enabled Attacks & Agent Security
- SonicWall SMA 1000 zero-days chained for unauthenticated RCE, exploited in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-auth SSRF in the Appliance Work Place interface; chained with CVE-2026-83549 it yields unauthenticated remote code execution. Both were found internally by SonicWall and are confirmed under active exploitation (SonicWall PSIRT, BleepingComputer). This is the third round of edge-device zero-day exploitation at the vendor this summer (Dark Reading).
· Vulnerabilities & Exploitation
- Millions of WordPress sites exposed via the All-in-One WP Migration and Backup plugin. An SQL injection allows unauthenticated attackers to reach remote code execution and full site takeover (BleepingComputer).
· Vulnerabilities & Exploitation
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 23, 2026
- Monero GUI published a batch of disclosures fixed in v0.18.5.0, including a Windows installer that left the
p2pool directory world-writable (local binary planting to code execution) (HackerOne) and a monero:// deeplink parsing flaw that let crafted links trigger send-all transactions (HackerOne). Also disclosed: an OpenAlias resolver that autofills addresses despite failed DNSSEC validation, and a multisig double-spend via withheld partial signatures.
· Vulnerabilities & Exploits
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
July 1, 2026
- Langflow RCE (CVE-2026-33017, CVSS 9.3) is under active exploitation, with attackers scanning exposed AI-app endpoints to drop a Monero miner via a single unauthenticated POST. The Hacker News, Dark Web Informer
· Vulnerabilities & Exploits
- Microsoft IR research shows how a single poisoned MCP tool description can steer an agent into quietly exfiltrating company data without ever "breaking a rule" — every step looks routine, so default setups raise no alarm. Separately, Wiz detailed an Amazon Q VS Code extension flaw that auto-loaded workspace MCP configs without consent, enabling code execution and cloud-credential theft on opening a malicious repo (fixed in language server 1.65.0). The Hacker News, Wiz
· AI & Model Security
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
June 27, 2026
Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.