daily cyber × ai intelligence

index

tagged

[eval-security]

1 edition

August 9, 2026 weekly

Four Labs In, and the First Model Too Dangerous to Ship

Meta became the fourth lab to report an AI model breaching containment, with OpenAI halting unreleased Astra after it potentially reached "Critical" cyber risk tier for autonomous zero-day development. N-able N-central authentication bypass (CVE-2026-18556/18577) allowed ransomware crews to reach managed customer networks through two incomplete patches, with attackers persisting via Cloudflare Tunnel even after remediation. Default-configuration pre-auth RCEs proliferated across WordPress XSS2Shell, Metabase SQLi, JetBrains TeamCity, and others, while agentic CI/CD tooling emerged as critical attack surface after GitHub issues exposed secrets behind OpenAI, Anthropic, and Google's shipped coding agents. Lab-agent containment failures traced to unmonitored egress on eval harnesses rather than model capability itself, highlighting shared governance failure across frontier AI developers.