September 1, 2026
JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.
August 25, 2026
- Rapid7 published analysis of SharePoint RCE CVE-2026-63520. CERT-EU's updated advisory covers the wider on-prem SharePoint chain, noting public PoC code and observed exploitation of CVE-2026-50522 alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — and recommends rotating credentials on any exposed server, not just patching (Rapid7, CERT-EU).
· Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 21, 2026
- Citrix NetScaler CVE-2026-19490 (CVSS 9.3) is an alternate-path authentication bypass exploitable by remote, unauthenticated attackers with no user interaction, affecting appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Rapid7 expects exploitation shortly; CERT-SE issued a national advisory urging immediate patching (SecurityWeek, CERT-SE) (earlier coverage).
· Exploited in the Wild
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 13, 2026
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 12, 2026
- Rapid7 disclosed an AI-assisted SharePoint exploit chain reaching unauthenticated RCE, tracked as CVE-2026-63520, discovered during a 0-day research project against the platform (The Hacker News). Separately, CISA confirmed ransomware crews are now abusing a high-severity SharePoint RCE that has been flagged as exploited since early July (BleepingComputer).
· AI, Agents & Offensive Security
in When the AI Is the One Finding the Zero-Days
August 8, 2026
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 4, 2026
- Rapid7 dropped a technical teardown of the Rails Active Storage RCE (CVE-2026-66066). "KindaRails2Shell" allows unauthenticated file reads and potential RCE via image processing; the analysis details the exploitation path (Rapid7). Builds on earlier coverage.
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
July 30, 2026
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 29, 2026
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
July 21, 2026
- A WebDAV-based malware delivery lab exposed by Rapid7 revealed a systematic, AI-assisted phishing operation using LOLBINs and a WebDAV server to stage payloads — a "product-like" delivery pipeline whose OPSEC failures laid the whole operation bare. Rapid7. @mttaggart calls ClickFix/EtherHiding "the initial access epic team-up of the year." (discussion).
· Threat Activity & Tradecraft
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 18, 2026
- "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST
/batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory.
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 17, 2026
- SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr's honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr's advice: patch immediately and hunt logs for successful exploitation.
· Vulnerabilities & Exploits
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 15, 2026
- Rapid7 disclosed CVE-2026-55040, a SharePoint JWT authentication bypass allowing user impersonation, now fixed. A researcher notes it chains with the Flow2Shell bug (CVE-2026-47298) for a full pre-auth path. Rapid7, MSRC
· Vulnerabilities & Exploits
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.