Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
LevelBlue says attackers are exploiting NetScaler flaw CVE-2026-88771, rated 9.5, to create a hidden superuser account and plant web shells. The patch closes the injection but removes neither, so already-exposed appliances need a compromise check.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence60
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Attacker server logs show the Coruna iOS WebKit kit compromising a live iPhone's browser in six seconds, two months after Google published its teardown. It fired with no tap from the user, on a phone still running iOS 15.8.3.
Publishers:c2huntersresearch.com
Reality
- Evidence62
- Adoption12
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 58%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives58
- Confidence74
Mandiant says ShinyHunters has planted web shells on dozens of Oracle PeopleSoft systems by URL-encoding one character to get past firewall rules. Employers that treated June's stopgap as the fix now have to patch and also look for any access the attackers left behind.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives20
- Confidence70
ShinyHunters is exploiting an unpatched CVSS 9.8 pre-login flaw in Oracle PeopleSoft, encoding one URL character to slip past WAF rules matching the raw path. Mandiant has confirmed JSP web shells on dozens of systems.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Google says UNC6671 split its extortion into Redact, Pink, Helix and Falcon on shared infrastructure while still working finance, legal and med tech. It averages 1.5 new victims a day.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence55
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
The firm says intruders reached its cloud platforms in July and took names, birth dates and Social Security numbers. Google attributes the campaign to BlackFile, a Com affiliate with four extortion brands.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Google Threat Intelligence and Mandiant put the Brazilian crew's route to Pix and STR at password spraying plus a fake IT support call, which means the controls that bite here are RMM allow-listing and out-of-band verification of the help desk.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Attackers using AI can fix and retest a failed cloud privilege escalation in minutes instead of hours, according to an analysis in The Hacker News. The cost it puts on defenders is the hours spent rebuilding each alert's context before anyone acts.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence35
The September threat report puts 151 million Claude exchanges on 3,500 accounts Anthropic links to Alibaba, about 469 a day per account. The only figure denominated in money anywhere near it is a 2.7% share move.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 35%
- Investor
- Investor 37%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence50
Spain's AEPD published the account but has not yet verified it. In it, the agent scanned for flaws, logged in, altered personal data and opened invoices. The agency's own position is that AI adds speed and scale, not new threats.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence35
- Adoption15
- Hype gap+35
- Incentives40
- Confidence40
SlowMist says its evidence for the iPhone Safari attack on crypto wallet keys covers iOS 18.4 to 18.6.2 and that it has confirmed no theft victim. The firm calls this week's iOS 13 to 26.5 warnings preliminary and still tells iPhone users to install security updates.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+45
- Incentives
- Insufficient
- Confidence50
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
Earlier coverage
- A $10 limit stored as text on a Kinde token cut the agent off after four calls
Build · September 22, 2026 · 1 publisher
- Google put an undercover analyst inside TeamPCP's inner circle during its 1,000-company campaign
Security · September 21, 2026 · 1 publisher
- Google says an agent framework harvested thousands of third-party credentials in under six hours
Security · September 17, 2026 · 1 publisher
- Attackers went from stolen cloud credentials to mass credential harvest in under six hours
Leadership · September 16, 2026 · 2 publishers
- Mandiant's testers talked an internal AI assistant into pushing private repos to their own GitHub
Security · September 16, 2026 · 1 publisher
- Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source
Leadership · September 15, 2026 · 1 publisher
- IBM prices the AI-assisted breach at a million dollars more than the rest
Invest · September 14, 2026 · 1 publisher
- An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud
Build · September 12, 2026 · 1 publisher
- Four espionage crews picked up the same Chrome and Windows exploit chain within days
Product · September 11, 2026 · 1 publisher
- A six-hour agent run harvested credentials from behind the victim's own cloud IPs
Build · September 10, 2026 · 1 publisher
- Stealer logs now carry AI session tokens that replay straight past MFA
Security · September 9, 2026 · 1 publisher
- Google clocks TeamPCP standing up a mass credential-harvesting campaign in under six hours
Security · September 9, 2026 · 1 publisher
- Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks
Security · September 8, 2026 · 1 publisher
- Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours
Security · September 8, 2026 · 3 publishers
- Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager
Security · September 8, 2026 · 1 publisher
- Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks
Product · September 8, 2026 · 1 publisher
- TeamPCP poisoned more than 1,000 packages with tactics anyone can copy
Security · August 28, 2026 · 1 publisher
- Every one of thirteen named 2025-26 incidents ran on a credential that still worked
Build · August 31, 2026 · 1 publisher
- Three Russian clusters phish the grant, not the password, and MFA completion changes nothing
Build · August 23, 2026 · 1 publisher
- Russia-linked crew keeps winning with app passwords and device codes
Leadership · August 22, 2026 · 1 publisher
- Google: Russia-linked crews get targets to hand over app passwords, OAuth codes and WhatsApp devices
Build · August 21, 2026 · 1 publisher
- The arrayref compromise turned cargo update into the delivery channel
Product · August 21, 2026 · 1 publisher
- After Arup, a face on a video call is not a credential
Product · August 21, 2026 · 1 publisher
- The extortion call now comes from your help desk, and the fix is a procedure you own
Leadership · August 19, 2026 · 1 publisher
- UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones
Leadership · August 19, 2026 · 1 publisher
- Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.
Security · August 19, 2026 · 1 publisher