August 21, 2026
Microsoft's Defender Boot-Time Removal driver (BTR.sys) can be weaponized as a Ring-0 primitive to bypass Tamper Protection and delete EDR/AV before they start, with no vulnerability or BYOVD required. Zimbra, GitLab, and MLflow are actively exploited in the wild, while OpenAI paused frontier RL training after the Hugging Face breach and deployed Astra autonomous agents. Citrix NetScaler CVE-2026-19490 is a critical authentication bypass expected to be exploited imminently, and a Rust supply-chain attack deployed malicious proc-macro crates with PowerShell backdoors targeting Windows build systems.
August 15, 2026
Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.
August 12, 2026
- Mozilla revoked and replaced the GPG subkey used to sign Firefox and Thunderbird Linux artifacts after an unencrypted copy was accidentally committed to a private company repo. Users and distros verifying tarball signatures must update to the new key (Mozilla, The Hacker News) (discussion).
· Supply Chain
in When the AI Is the One Finding the Zero-Days
July 30, 2026
- A patched Firefox JIT flaw (CVE-2026-10702) can be triggered by a single malicious webpage — and was used to compromise Tor Browser. Nebula Security says the bug yields arbitrary code execution in the renderer with no settings changes or extra interaction; Mozilla fixed it in Firefox 151.0.3. The Hacker News
· Vulnerabilities & Exploits
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 17, 2026
SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.
June 18, 2026
- Firefox AI chatbot features were vulnerable to prompt injection from attacker-controlled page content, enabling email theft via a broken trust boundary; Mozilla has limited prompt lengths (Insinuator).
· AI & Model Security
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel