September 16, 2026
- RSIAgent accumulates environment knowledge without changing its base models’ weights. Using Kimi-K3 and GLM-5.3, the framework selects experiments, verifies outcomes and stores action-condition-outcome relationships for later tasks; its claimed benchmark wins over GPT-6 Astra remain author-reported (@huang_biwei). @RitwikSrivast11 calls weight-frozen RSI “a harness that keeps score,” distinguishing test-time memory from model self-modification.
· AI & Agent Security
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
August 29, 2026
- GLM-5.3 is now available as open weights, pitched by Z.ai as its most capable model for agentic coding and cyber defense (@cyb3rops). @emollick argues that as open-weight models close the gap, published model cards and red-teaming results matter more, not less — "since you can break the guardrails with any open model, we need a sense of what the risks are."
· AI & Model Security
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 23, 2026
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
August 22, 2026
- Aikido burned 11.7 billion tokens benchmarking ten models on vulnerability discovery, three runs each. Headline result: GLM-5.3 improved sharply on cybersecurity tasks since pre-release evaluation and now tracks GPT-5.6 class models (Aikido).
· AI & Model Security
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 21, 2026
- GLM-5.3 reportedly surfaced 1,097 critical/high-severity bugs across kernels, browsers and infrastructure, including one flaw dating to 1981 (Z.ai). VulnCheck is tracking what it calls the first CVE wave from AI-assisted vulnerability discovery (VulnCheck) — expect the intake side of disclosure programmes to feel this first.
· AI & Model Security
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 16, 2026
- GLM-5.3 (ZAI ZCode) system prompts and tooling leaked — a dump of nearly 400k files reportedly includes the full system prompts, tools, and skills for the model, along with ZCode credentials — useful for anyone studying agentic tool wiring and the attack surface it exposes. @elder_plinius via @thegrugq
· AI & Model Security
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse