August 16, 2026 weekly
The Week AI Started Finding the Zero-Days — and Attackers Started Weaponizing Everything Else
An AI agent discovered the Zoom zero-click RCE chain (CVE-2026-53413/53414/53415) in under 24 hours, while Rapid7 used AI to chain an unauthenticated SharePoint RCE (CVE-2026-63520), marking AI's shift to offensive exploitation. Near-autonomous agents attributed to suspected Chinese operators targeted Taiwan's nuclear and energy sectors with autonomous attack capabilities. Enterprise appliances including VMware vCenter (CVE-2026-59310/59309), SAP Commerce Cloud, Metabase, GeoServer, NetScaler, and Adobe Commerce suffered continuous exploitation, while the LiteLLM supply-chain incident—reattributed to SANDCLOCK/TeamPCP via a backdoored Trivy GitHub Action—compromised ~2,500 organizations with terabytes of CI/CD credentials exfiltrated before malicious packages shipped. The Lazarus Group deployed a Windows kernel zero-day (CVE-2026-68820 in afd.sys) hidden behind post-quantum cryptography, Kimsuky built an offline private-LLM malware stack, and Black Hat Kerberos flaws (CVE-2026-27912/CVE-2026-25177) matured into weaponized cross-platform domain-takeover chains.