daily cyber × ai intelligence

index

tagged

[hitachi-vantara]

1 edition

September 15, 2026

Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

Anthropic's agent incidents were reframed as scope-control failures rather than autonomous rogue behavior after evaluators gave Claude real internet access with unclear exclusions. Red Heron automated exploitation of CVE-2026-60004 in Gitea to compromise 13 organizations across six countries, deploying the SIXZUT rootkit on Proxmox systems. ScreenConnect exploitation is now confirmed as worm-like, with CVE-2026-84869 affecting clients before version 26.6.5 and requiring client reinstallation. The DDrop attack silently corrupts Intel TDX, AMD SEV-SNP, and Scalable SGX memory integrity using a sub-$200 interposer, recovering private VM data without requiring CVE assignment.