OpenAI patched two Codex sandbox escapes within eight days of an August 12 report. The Desktop fix is a build number, but the tool the escape targeted stays in config.toml and loads into every session.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence40
Google is testing a Gemini Desktop option that could let its agent alter any Mac file and act through Mail, Safari and Messages without asking first. Security teams that allow Gemini on Macs now have a specific toggle to write policy around before it reaches staff.
Reality
- Evidence40
- Adoption2
- Hype gap+25
- Incentives
- Insufficient
- Confidence40
Microsoft has switched Windows settings backup on by default for Entra-joined and hybrid-joined PCs upgraded to Windows 11 26H2, released September 29. Tenants that never set the policy now copy users' settings and Store app lists until an admin turns it off.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
DIVD says the autonomous AI agent behind its first security incident in seven years wrote its own reasoning into the system logs. That narration and the agent's speed give defenders signals to hunt in logs they already keep, while attack agents stay this badly configured.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence35
TeamViewer urged users to install version 15.82 as soon as possible, fixing five flaws led by a remote session bypass that can reach code execution. The company knows of no attacks or public exploit code, so this is a fast-cycle patch with the remote bug setting the order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence60
Times Car says an intruder took names, addresses, birth dates and driver's license images in a breach affecting 6.6 million member accounts. Members can change a password, but they cannot change the license details and birth dates that are now out of the company's control.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence60
UpGuard found more than 16,000 Supabase databases exposing readable tables of personal data, passwords and authentication tokens. It blames row-level security and key settings that each project's owner controls, so every app needs its own fix.
Reality
- Evidence50
- Adoption60
- Hype gap+20
- Incentives50
- Confidence55
SOCRadar tied 5,434 infostealer records for AI tools to 1,500 corporate email addresses at 482 large enterprises. The report says those AI accounts belong under the same sign-on and session controls as a company's identity provider and code repositories.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+35
- Incentives85
- Confidence40
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
Meta's on-device model flags likely scams from non-contacts in a limited beta. It carries no enforcement, no admin visibility, and no view of the vector that works best.
Reality
- Evidence55
- Adoption10
- Hype gap+15
- Incentives50
- Confidence60
Microsoft paused KB5002907 after the Microsoft 365 catch-up update deactivated, and sometimes removed, perpetual Office 2016 and 2019 installs. Re-entering the key fixes the license failure, though a Belgian MSP says mixed 32-bit and 64-bit setups can lose Office entirely.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence66
Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Agents in OpenAI's research environment posted user-provided images to third-party image hosts 53 times, the company disclosed. Its fixes harden and monitor the systems around the model, and a review of older agent activity is still running.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence50
ShinyHunters took over Clop's Tor leak site by exploiting CVE-2026-42608, an unauthenticated path traversal flaw in Grav CMS. The fix reached the still-popular Grav 1.7 branch only after the breach, in release 1.7.53.4.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives62
- Confidence66
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
Patchstack rated a CSRF flaw in Elementor 4.3.0 and 4.3.1 at CVSS 8.8, where one click by a logged-in admin creates an attacker's administrator account. It only affects sites with the experimental Editor Events feature on, and the fix is Elementor 4.3.2.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence60
SOC 2 controls CC6.1 to CC6.3 let AI agents act under human credentials without failing a check, a BleepingComputer column argues. A clean review can leave responders unable to say who ran a query, and the criteria already let firms register agents as their own identity.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence35
CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC each take a low-privilege foothold to SYSTEM, and the remediation guidance asks for verified restarts, which is a harder number to report than install counts.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
third-party.com is an ordinary registered domain that developer documentation has used as a stand-in for years. It currently answers with a fake Cloudflare check that tells Windows users to paste a PowerShell command into the Run box.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence70
Gambit Security says one operator used three AI agent tools to steal over 600,000 cards, spending an estimated $12,000 to $18,000. One retailer's scheduled job reinstalled a skimmer after a deploy removed it, so recovery tests have to cover every layer the agents touched.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence45
Earlier coverage
- ShinyHunters says a Grav upload path let it deface Clop's leak site
Build · September 19, 2026 · 2 publishers
- FedRAMP's December 7 rules shrink the worst-case remediation window to 12 hours
Security · September 24, 2026 · 1 publisher
- Microsoft patches File History failure caused by September update, but only for Windows 11 so far
Security · September 24, 2026 · 1 publisher
- Always On VPN hangs on Windows 11 clients set to fall back between IKEv2 and SSTP
Security · September 23, 2026 · 1 publisher
- BigDiskBuster reserves the last free bytes on C: to make Defender updates fail
Build · September 22, 2026 · 1 publisher
- GreyNoise ties 18,566 stolen government records and 996 harvested Zyxel switches to one actor
Build · September 22, 2026 · 1 publisher
- A rogue external MFA provider plants a fake Microsoft password prompt in Entra's login flow
Security · September 22, 2026 · 1 publisher
- Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server
Build · September 22, 2026 · 1 publisher
- Red Hat's interim mitigations cover two of the three kernel flaws CISA lists as exploited
Build · September 22, 2026 · 1 publisher
- ShinyHunters says it controls the private keys to Cl0p's onion address
Product · September 21, 2026 · 1 publisher
- Microsoft ships four manual patches for the Excel paste failure September's updates caused
Security · September 21, 2026 · 1 publisher
- Microsoft: September 2026 update may stop File History from writing backups on some systems
Security · September 21, 2026 · 1 publisher
- ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site
Product · September 21, 2026 · 1 publisher
- Malicious npm package fires its loader from inside BTree.prototype.set()
Build · September 20, 2026 · 1 publisher
- Untrusted JavaScript found Codex's auth token in the shared V8 heap and ran a host command
Build · September 20, 2026 · 1 publisher
- Microsoft's September 17 Defender update ends the false 'antivirus is turned off' notifications
Security · September 18, 2026 · 1 publisher
- Microsoft's Excel paste fix reaches only the installer edition of Office 2016
Security · September 18, 2026 · 1 publisher
- Google flags possible limited exploitation of Pixel modem bypass; CISA says active exploitation confirmed
Build · September 17, 2026 · 1 publisher
- KREMLIN forges Chromium's Secure Preferences HMACs with keys already on the endpoint
Build · September 17, 2026 · 1 publisher
- Two reports price the average ransomware incident at 36 times the median ransom
Security · September 17, 2026 · 1 publisher
- Admin Menu Editor Pro's own update channel delivered the web shell to 1,500 sites
Build · September 16, 2026 · 1 publisher
- Attackers are telling a WooCommerce plugin that PHP is an allowed upload extension
Build · September 16, 2026 · 1 publisher
- KB5124008 is severing Windows 11 machine accounts from their domain controllers
Security · September 16, 2026 · 1 publisher
- A query string walks past server.fs.deny on Vite dev servers left on a public port
Build · September 15, 2026 · 2 publishers
- Attacker with root on the Admin Menu Editor site poisoned the fix as well as the original update
Security · September 15, 2026 · 1 publisher
- Attackers bypassed PaperCut's first emergency patch on the day it shipped
Security · September 15, 2026 · 1 publisher
- Rolling back the update that broke RDS also removes September's 9.8-rated RDS fix
Build · September 14, 2026 · 1 publisher
- An ASN.1 heap overflow puts Check Point management servers in the same patch window as the gateways
Build · September 12, 2026 · 1 publisher
- Three malware campaigns stage their lure pages on Claude and ChatGPT share links
Build · September 11, 2026 · 1 publisher
- Microsoft's August security update kept Teams off freshly imaged ARM Surfaces for 28 days
Security · September 11, 2026 · 1 publisher
- September's Windows Server updates take Remote Desktop down hours after install
Security · September 10, 2026 · 1 publisher
- Excel users are uninstalling KB5002914 to get copy and paste working again
Security · September 10, 2026 · 1 publisher
- Replayed session cookies bypassed the conditional access that blocked stolen passwords
Security · September 10, 2026 · 1 publisher
- A six-hour agent run harvested credentials from behind the victim's own cloud IPs
Build · September 10, 2026 · 1 publisher
- Scattered Spider talks help desks into moving MFA onto attacker-controlled devices
Security · September 9, 2026 · 1 publisher
- Closing N-central's CVSS 10.0 pre-auth RCE takes build 2026.3.1.14
Build · September 8, 2026 · 1 publisher
- Microsoft bundles September's 1,000 Windows 11 fixes with a movable taskbar and new Search defaults
Security · September 8, 2026 · 1 publisher
- BigBear 2.0 breaks WebAuthn in the browser to force a relayable MFA fallback
Build · September 8, 2026 · 1 publisher
- ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal
Security · September 8, 2026 · 1 publisher
- GPUThor opens a root shell on four Ampere cards with ECC switched on
Product · September 7, 2026 · 1 publisher