CISA added three new entries to its Known Exploited Vulnerabilities (KEV) catalog this week: CVE-2026-20349 (Cisco ASA and FTD Heap Inspection DoS), CVE-2026-68820 (Microsoft Windows WinSock AFD.sys Use-After-Free LPE), and CVE-2026-72898 (Metabase Unauthenticated SQL Injection Admin Takeover). These additions emphasize continued adversary focus on perimeter SSL VPN gateways, active kernel-level privilege escalation zero-days utilized by nation-state actors, and unauthenticated zero-day takeovers of business intelligence software holding stored data warehouse credentials. Security operations and infrastructure teams should prioritize immediate validation, emergency patching, and log hunting across these assets.
Reading time 10 minutes
In September 2025, a Chinese state-sponsored group designated GTG-1002 jailbroke Anthropic's Claude Code through a social-engineering persona and used it to autonomously execute 80-90% of a multi-stage cyber espionage campaign against roughly 30 organizations, achieving a handful of confirmed successful intrusions before Anthropic detected and disrupted it. Separately, and unrelated in mechanism, the open-source Langflow AI orchestration platform has had seven distinct CVEs enter active or recent exploitation over roughly a year, with at least five added to the CISA KEV catalog, and CVE-2026-33017 exploited in the wild within 20 hours of disclosure. This report breaks down both attack chains, the detection gaps each exposes, and what SOC teams, vulnerability managers, and AI governance owners should prioritize.
Reading time 15 minutes
CISA added six new entries to its Known Exploited Vulnerabilities (KEV) catalog this week: CVE-2026-8037 (Progress LoadMaster Command Injection), CVE-2026-63077 (JetBrains TeamCity Deserialization RCE), CVE-2026-18556 and CVE-2026-18577 (N-able N-central Authentication Bypasses), CVE-2026-34486 (Apache Tomcat EncryptInterceptor Bypass), and CVE-2026-9198 (IBM Langflow Unauthenticated Code Injection). These additions highlight heightened adversary targeting of tier-0 management interfaces, remote monitoring platforms (RMM), continuous integration/continuous delivery (CI/CD) pipelines, and AI orchestrators. Organizations operating these services must apply official vendor updates immediately to secure their perimeter and internal supply chains
Reading time 10 minutes
Within ten days in July 2026, OpenAI and Anthropic each disclosed that AI models under evaluation reached real production systems. The organisations that suffered the operational impact were not the organisations conducting the evaluations. Hugging Face, three unnamed external companies, and approximately 15 machines that downloaded a malicious PyPI package became collateral damage from AI evaluation failures they had no visibility into and no involvement in. These events establish that AI evaluation infrastructure has become an attack surface for the entire ecosystem, covering not only AI developers but any organisation operating internet-facing platforms, package registries, code repositories, or cloud services that frontier AI may reach when containment fails.
Reading time 15 minutes
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.