Zero-Day Watch: Recent Active Exploits and What to Patch First
A September 27 briefing on exploited flaws in F5, Check Point, VeloCloud, Chrome, WordPress, and SharePoint, with practical containment and patch-verification steps.
Topic
How AI changes security operations, attack surfaces, and decision-making.

A September 27 briefing on exploited flaws in F5, Check Point, VeloCloud, Chrome, WordPress, and SharePoint, with practical containment and patch-verification steps.
New Irregular research shows how routine application maintenance can become a persistent model update, raising security questions about training and deployment permissions.
The September 23, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
What researcher resignations and Anthropic's biological-misuse report establish, what remains uncertain, and how security teams can prepare responsibly.
The September 16, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
Ahead of NIST’s September 17 webinar, security teams should examine how AI-assisted vulnerability enrichment preserves evidence and handles missing data.
What agent 'sacrifice' meant in the Hugging Face incident, what remains unproven about hidden agents, and how defenders can verify containment and recovery.
Recent Wiz honeypot research shows why AI security monitoring needs process, network, and credential evidence alongside conversation logs.
The September 9, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
Invisible Unicode characters can disguise phishing from email filters. Learn what ASCII smuggling means and how to protect inboxes and AI agents.
Understand SOCI 8B and 8C, phishing-resistant MFA, and OT isolation. Plan secure access and recovery that keep critical infrastructure running without the cloud.
What the DseWiki incident reveals about AI agent security, and how teams can prepare with scoped access, network controls, monitoring, and incident response.
Learn how always-on AI agents work, what GPT-6 Astra changes, and how to secure agent loops with scoped permissions, durable memory, and clear stop conditions.
Burning Man 2026 offers a useful temporary-city metaphor for AI agent security: temporary access, resilience, prompt injection boundaries, human ownership, scoped autonomy, cleanup, and shared drills.
A practical, non-alarmist guide to future bio-cybersecurity: protecting genomic data, synthetic nucleic acid supply chains, clinical systems, and people from misuse while preserving responsible medicine.
Late-August and early-September 2026 updates from OpenAI, Anthropic, Microsoft, and NIST point to the same operational conclusion: AI agent security now depends on identity, isolation, and continuous monitoring more than generic policy language.
The September 2, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
Atlassian's public security material shows the limits of peer review and green builds at modern scale. The lesson for security teams is not to abandon review, but to turn review into continuous assurance backed by metadata, scanning, provenance, logs, and post-incident learning.
NIST, OWASP, and MITRE all point to the same AI security lesson: model guardrails help, but they are not a complete defense. Cybersecurity programs now need to teach how attackers use influence, intent shaping, prompt injection, model probing, and tool abuse to turn helpful models into security liabilities.
The NSA, FBI, and Cyber National Mission Force warned that China-linked QTFY actors used QScan, QTRouter, compromised IoT devices, and covert proxy infrastructure to target military, government, telecommunications, higher education, and critical infrastructure networks. The defender lesson is clear: patch fast, reduce exposed operational data, isolate critical systems, and hunt with evidence.
Run a focused Hack Wednesday review with an owner-led agenda, exposure checks, verified fixes, and a copyable vulnerability-response handoff for your team.
PR reviews are no longer enough for modern GitHub security. Code, AI-generated changes, dependencies, secrets, CI logs, and runtime signals are growing too fast. The next shift-left model is continuous security monitoring across the full software path.
A practical, SEO-friendly overview of public cybersecurity and security infrastructure companies that appear across major cybersecurity ETFs in 2026, written for security teams, CISOs, and market-aware builders. This is not financial advice.
New August 2026 guidance from OpenAI and Google Cloud suggests the fastest security teams will treat AI-assisted source-code review as a core control, not a side experiment.
The August 26, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
Akamai's 2026 Enterprise AI Usage Risk Report and The Hacker News coverage point to a concentrated AI risk pattern: a small group of power users can create disproportionate exposure through personal accounts, browser extensions, IDE copilots, and autonomous agents.
A copy-friendly playbook for turning Codex automations and ChatGPT Work scheduled tasks into useful daily, weekly, and monitoring workflows for CISOs, AppSec, SOC, GRC, platform, and engineering teams.
Quantum computing changes the cryptographic risk model, while photonics changes how data moves through chips, data centers, clocks, sensors, and future AI systems. Security teams should prepare for both without treating either as magic.
IRAP is useful because it pushes security buyers past generic compliance badges and toward scoped, evidence-based, risk-informed assessment reports that explain what was tested, what remains risky, and who is accountable.
Zero Trust in the age of AI agents means every human, model, agent, device, API, repository, and workflow must prove identity, need, context, and authority before action. Network location is no longer the trust boundary.
Security teams need autonomous, self-service agent platforms with live insight across SIEM, identity, endpoint, cloud, code, email, and network controls because AI-speed attacks will not wait for ticket queues or manual cable-pulling.
The August 19, 2026 HackWednesday signal: AI-assisted PLC attacks, a 3.7 million-person healthcare breach, Sakura Internet exposure, and CameraSwarm show why defenders need evidence-first response.
The August 19, 2026 HackWednesday weekly signal turns current security headlines into a practical incident, vulnerability, and AI-risk triage queue.
OpenAI's August 7 and August 10, 2026 cyber updates signal that once a model may cross the critical cyber threshold, access governance stops being a policy detail and becomes part of the product itself.
OpenAI's July 2026 GPT-Red release matters to security teams because it shows automated AI red-teaming becoming a practical control for prompt injection resilience, not just a research demo.
Frontier AI models are moving from code suggestions to sustained cyber operations. Security teams should assume quiet, multi-step AI-driven intrusion attempts are becoming realistic and update controls before attackers operationalize them.
Mandiant's July 16, 2026 guidance is a useful warning for defenders: AI can accelerate vulnerability discovery and remediation, but the bigger risk is letting privileged agents into pipelines without deterministic guardrails, scoped identities, and runtime containment.
Microsoft's July 27, 2026 Project Perception launch matters because it reframes AI vulnerability research as a continuous security operations problem with model choice, validation, and remediation controls built into the workflow.
OpenAI's July 21, 2026 disclosure and Hugging Face's July 16, 2026 incident report show that AI security is no longer just about prompt abuse. The evaluation environment itself has become part of the attack surface.
New July 2026 research shows attackers can register the repository and skill names AI agents are likely to hallucinate, turning ordinary package and repo lookup mistakes into remote execution risk.
Claude Code skills can turn repeatable security work into reusable, reviewable workflows for secure code review, secrets triage, dependency risk, threat modeling, incident timelines, and AI governance.
Security teams do not need every product team wiring its own OpenAI, Anthropic, Bedrock, Vertex AI, and coding-agent credentials. A centralized LiteLLM gateway can make GenAI and agentic-code usage more controlled, vetted, auditable, and cost-aware.
Starlink-powered in-flight connectivity is changing what passengers expect from airlines, especially on business-heavy routes like Seattle to San Jose. Here is why free Wi-Fi, live flight maps, messaging, and secure browsing should become the new airline and cruise standard.
A new July 2026 agent-security paper argues that defenders are still protecting prompts while attackers are learning to poison the data structures AI agents treat as trusted context.
Anthropic's decision to restore Fable 5 after briefly suspending it over cyber-misuse risk is a useful case study in how frontier AI vendors may start tiering access, hardening safeguards, and treating offensive capability as a live security control problem.
A June 7, 2026 study on AI-powered CI/CD pipelines argues that prompt injection is no longer just a model problem: in real workflows, token scope, untrusted checkout, and trigger design decide whether an agent becomes a supply-chain foothold.
The Miasma worm reportedly led GitHub to disable 73 repositories across four Microsoft organizations. The campaign shows how compromised maintainer identity, CI trust, repository configuration, and AI coding agents can become one self-replicating supply chain.
University of Toronto researchers at CleverHans Lab demonstrated a prototype AI-driven computer worm that can map, test, and compromise heterogeneous enterprise networks in an isolated lab. The important shift is that this class operates outside AI apps and attacks ordinary IT infrastructure.
NIST's May 18, 2026 summary of AI agent security feedback makes one point hard to ignore: enterprises will not scale agents safely without stronger identity, authorization, and audit controls.
Microsoft's May 14, 2026 research on exploitable AI app misconfigurations shows that many near-term AI security failures will come from exposed services, weak authentication, and overpowered control planes rather than novel model exploits.
wolfSSL support for Secure Socket Funneling shows why defenders need to track the cryptographic libraries beneath tunneling tools. Recent wolfSSL findings are a reminder that a tunnel is only as trustworthy as its certificate validation, build options, and patch path.
NIST's May 18, 2026 analysis suggests security teams already understand AI agent risk; what they still lack is concrete guidance for identity, authorization, monitoring, and measurable controls.
MiniPlasma is a newly published Windows privilege-escalation proof of concept that reportedly revives the old CVE-2020-17103 path and turns a standard user foothold into SYSTEM access. The bigger lesson is about patch confidence, regression risk, and why defenders need validation beyond release notes.
AWS used mid-May 2026 guidance to make a useful point for defenders: secure AI programs start with identity, access, and guardrails in the prototype phase rather than after agents reach production.
Microsoft's May 12, 2026 MDASH release matters because it ties agentic AI directly to 16 Patch Tuesday vulnerabilities, shifting the conversation from demos to measurable defensive outcomes.
OpenAI's new Daybreak initiative reframes cyber defense around resilient-by-design software, Codex-powered remediation workflows, and a tiered trusted-access model for increasingly cyber-capable AI.
OpenAI's May 7 GPT-5.5-Cyber rollout, new phishing-resistant access requirements, and parallel NIST testing agreements all point to the same shift: advanced AI security capability is being governed more like privileged infrastructure.
Fresh NIST and Microsoft updates point to the same operational reality: security teams need ways to evaluate, inventory, and govern AI agents before trust in them can scale.
LiteLLM is now dealing with a different kind of security problem than the March supply-chain incident: active exploitation of a critical pre-auth SQL injection that puts upstream model-provider credentials and environment secrets at risk.
OpenAI's April 29 cyber action plan argues that AI-powered defense should be distributed broadly, and recent Microsoft and Google moves suggest the industry is starting to build the operational infrastructure to do it.
Late-April updates from OpenAI and Microsoft point to the same security reality: AI is compressing the time between discovery and exploitation, so defenders need faster access, remediation, and control loops.
Google Cloud Next 2026 and Wiz's April product updates make the same argument: AI security is becoming a code-to-cloud discipline built around agent identity, shadow AI visibility, and guardrails for AI-generated software.
Model Context Protocol can make AI tools dramatically more useful, but it also expands trust boundaries. Security teams should treat MCP like a privileged integration layer: sandbox servers, minimize scopes, block token passthrough, defend against SSRF, and review every tool as a potential remote-action surface.
Microsoft's April 22 security update argues that stronger AI models are compressing the time between vulnerability discovery and exploitation, forcing defenders to treat patch speed and exposure management as urgent runtime problems.
Microsoft's April 22 AI security update shows that AI-discovered vulnerabilities will not just create more findings; they will force defenders to connect patching, exposure management, detections, and prioritization much faster.
Vercel confirmed unauthorized access to certain internal systems while hackers claimed to be selling stolen data. Security teams should avoid panic, but immediately review activity logs, rotate exposed environment variables, harden sensitive variables, and check GitHub, npm, and deployment tokens.
Claude Opus 4.7 is built for stronger coding and agentic workflows. Recent Chrome V8 vulnerability news shows why security teams should prepare for AI-assisted exploit reasoning, faster browser patch validation, and tighter controls around outdated Chromium runtimes.
A practical GitHub security checklist for teams: branch protection, rulesets, secret scanning, push protection, Dependabot, CodeQL, GitHub Actions hardening, least-privilege access, OIDC, and SECURITY.md.
Recent reporting on an AI-assisted intrusion campaign against Mexican government systems shows why security teams should measure how quickly attackers can turn exposed services, stale credentials, and raw data into action.
OpenAI is expanding Trusted Access for Cyber and introducing GPT-5.4-Cyber, making verified identity, trust signals, and staged rollout a central pattern for powerful defensive AI security tooling.
Trivy is excellent at finding known vulnerabilities, misconfigurations, secrets, and SBOM risk. OpenAI-style agentic security workflows can help teams turn that scanner output into prioritized, reviewable remediation without treating AI as the source of truth.
Anthropic's Claude Mythos Preview and Project Glasswing are a warning shot for enterprise security teams: AI-driven vulnerability discovery is moving toward machine speed, and companies need secure sandboxes, patch pipelines, and executive governance before attackers copy the playbook.
Anthropic's April 2026 Project Glasswing launch is a signal that AI-assisted vulnerability discovery may soon outpace the industry's ability to triage, disclose, and patch the bugs it finds.
The next wave of AI attacks will compress recon, phishing, code abuse, and privilege escalation into much faster cycles. Security teams should stop trying to block every agentic tool outright and instead adopt secure sandboxing, runtime controls, and evidence-first review.
When a breach takes down identity, admin access, or critical systems, companies need a tightly controlled recovery path to restore essential services without improvising under pressure. The answer is not a hidden backdoor. It is a secured, tested break-glass architecture.
NIST's February 2026 work on AI agent identity and authorization is a timely signal that the real enterprise risk is no longer model output alone, but what agents are allowed to do, prove, and audit once they start acting.
OpenAI's new safety bug bounty is a useful signal for defenders: prompt injection, data exfiltration, and unsafe agent actions are no longer theoretical AI risks, but issues that need repeatable testing and response.
Microsoft and Cisco used late-March 2026 security launches to make the same point: AI risk is no longer just about model safety, but about governing agent identity, data access, and real-time actions in production.
The Claude Code source leak is a reminder that AI companies need the same release discipline, packaging controls, and operational security maturity they expect enterprise customers to build for themselves.
Claude Code can help security teams move faster on code review, detection engineering, and incident response preparation, but only if it is wrapped in clear trust boundaries, source validation, and scoped access.
LiteLLM’s supply chain incident was serious, but the company’s public response offers a useful case study in what good post-incident handling looks like: fast disclosure, external forensics, verified clean releases, and concrete CI/CD redesign.
The recent Trivy and axios incidents show how quickly a trusted package or action can become a credential theft path, and why safer CI/CD now depends on immutability, tighter secrets handling, and faster dependency response.
AI-assisted visualization can support faster understanding in high-pressure environments, but it needs careful framing and governance.
Forward-looking security writing ages better when it anchors on durable shifts instead of calendar-year novelty.
A strong post-incident response needs more than containment. It needs clarity, communication, and durable operational learning.
Reports about Anthropic testing a far more capable unreleased model are a reminder that security teams should prepare for sharper AI-assisted offense and faster defensive automation at the same time.
Katie Moussouris helped professionalize bug bounties and vulnerability disclosure so security research could improve systems instead of collapsing into conflict.
Dan Kaminsky's DNS cache-poisoning research triggered one of the most important coordinated internet security responses of the modern era.
Vincent Rijmen helped create Rijndael, the cipher selected as AES, and shaped one of the most deployed security standards in the world.
Paul Kocher changed internet security by showing that implementation details and timing behavior could leak secrets even when algorithms looked sound.
Ross Anderson helped shape security engineering as a full-system discipline, connecting cryptography, economics, operations, and failure analysis.
Bruce Schneier helped shape internet security not just through cryptographic work, but by raising the field's public literacy and strategic thinking.
Phil Zimmermann's work on PGP helped make strong encryption available to ordinary users and shaped the politics of internet privacy.
Eli Biham helped transform cipher evaluation through differential cryptanalysis and pushed the field toward stronger designs.
Steve Bellovin helped shape practical internet defense by exposing protocol weaknesses and clarifying how real network security should work.
Gene Spafford helped shape internet security through research, incident understanding, and one of the field's most important educational legacies.
Taher Elgamal helped shape both public-key cryptography and the early security foundation of web commerce.
Shafi Goldwasser helped build the theory behind zero-knowledge proofs and modern cryptographic rigor that still influences internet trust.
Radia Perlman's work on spanning tree and secure network design made the internet more resilient long before most people called that security.
Adi Shamir helped co-create RSA and then spent decades improving how the field understands cryptanalysis and practical security.
Leonard Adleman helped co-create RSA and contributed to the mathematical backbone of secure communication and computation.
Whitfield Diffie helped move cryptography from a closed government discipline into the public foundations of internet trust.
Martin Hellman helped create the conceptual leap that made modern key exchange and public cryptography work on open networks.