Cantina released apex-flash-1, an open-weights vulnerability-research model it says solved 40 of 60 tasks for $2.38, against $74.68 for Claude Opus 5 High. There is no hosted endpoint, so teams download the 321-billion-parameter weights, pay for their own inference and verify the numbers themselves.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence40
GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 59%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
Cloudflare fixed a Containers flaw that let paying customers read other tenants' leftover disk data, found on 18 of 24 production tries. Sandboxes, the product it sells for running untrusted and AI-written code, was affected too.
Perspective Coverage
3 publishers
- Builder
- Builder 42%
- Operator
- Operator 48%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence70
Aikido found a dozen live GitLab 'email work item' addresses in public docs, each carrying a long-lived token that lets any mailbox act as its owner. GitLab calls it intended behavior, so maintainers must pull the address and reset the token.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 52%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption28
- Hype gap+10
- Incentives52
- Confidence60
Four HackerOne reports cited in a dev.to analysis trace to S3 write scope set wider than the one object an upload needs. Only one of them is the starts-with key condition that turns a signed upload form into write access across a whole prefix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
Copilot Autofix swapped an env-var-and-jq pattern for inline interpolation in a public GitHub Actions file, and Wiz's autonomous agent exploited it inside a week.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+35
- Incentives65
- Confidence62
Wiz says its Red Agent found and exploited a GitHub Actions injection that an AI "autofix" commit introduced five days earlier, reaching Snowflake's internal Jira with no human in the loop.
Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 42%
- Investor
- Investor 15%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence62
WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.
Perspective Coverage
7 publishers
- Builder
- Builder 29%
- Operator
- Operator 62%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence70
Cloudflare has fixed a flaw in Containers that let a Workers Paid account read the 60 KiB it had not written inside each 64 KiB disk block it touched. The fleet-wide fix needed no customer configuration changes.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence62
Adversa AI says its Cryptographic Context Injection recovers hostile prompts inside the code sandbox, where filters do not look. xAI has not replied; Google scopes jailbreaks out entirely.
Perspective Coverage
6 publishers
- Builder
- Builder 34%
- Operator
- Operator 55%
- Investor
- Investor 11%
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence55
The billion is credit against OpenAI's own products rather than cash, aimed at water, grid, local government and open-source defenders, and OpenAI wants it consumed within six months, which turns model-assisted triage into a procurement question.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 54%
- Investor
- Investor 22%
Reality
- Evidence55
- Adoption30
- Hype gap+30
- Incentives70
- Confidence60
An Anthropic alignment lead put the chance of AI killing all humans within a decade above 10 percent. The four containment failures his company has disclosed are countable. Security practitioners say those are the numbers to work from.
Perspective Coverage
4 publishers
- Builder
- Builder 35%
- Operator
- Operator 41%
- Investor
- Investor 24%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+40
- Incentives60
- Confidence55
CrowdStrike says the npm stealer's author has been active since November 2022, claims bounties from at least nine companies, and that none of the stolen logs have turned up for sale. It assesses with high confidence that an LLM wrote the code.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence58
ReversingLabs found tw-pkgprobe-7731 claiming to be an authorized Twilio HackerOne research probe while it tried to exfiltrate data, and its 2026 count of malicious npm packages passed all of 2024 by the end of August.
Reality
- Evidence60
- Adoption25
- Hype gap+15
- Incentives78
- Confidence55
Exploitation is now the top initial-access vector at 31% of breaches. The median defender needs 43 days to close a known-exploited flaw. Both figures reach operators through a guide selling the fix.
Reality
- Evidence45
- Adoption22
- Hype gap+40
- Incentives88
- Confidence58
In HackerOne 121461 a researcher created the missing bucket in their own AWS account and served files on a2.bime.io. The state that allowed it is a name sitting in the DNS zone with no matching bucket in the account.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives85
- Confidence60
The case that generated code fails without the usual warning signs comes from two practitioner accounts, while the only measured series is curl's inbound bug reports, and Daniel Stenberg stopped taking those in January 2026.
Reality
- Evidence38
- Adoption58
- Hype gap+34
- Incentives62
- Confidence46
In HackerOne report #3022516 the trail was multi-region, the metric filter for unauthorised API calls existed and the alarm published to an SNS topic, while threat_detection.enabled read false. Turning it on costs one CLI call.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence60
A two-week, $1m escape challenge against Vercel's Firecracker sandbox produced 1,285 reports. The most valuable one hit the Linux kernel networking stack that many clouds use to isolate tenants, and its CVEs are pending.
Reality
- Evidence45
- Adoption35
- Hype gap+25
- Incentives80
- Confidence45
A pool created with the defaults treats a password as the whole authentication factor and scores no risk on the sign-in. In the HackerOne chain a dev.to writeup walks through, either setting turned on would have stopped the takeover.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives68
- Confidence52
Earlier coverage
- An encrypted payload turns Grok's own navigation tool into the exfiltration path
Build · September 10, 2026 · 1 publisher
- cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root
Security · September 9, 2026 · 1 publisher
- IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop
Build · September 6, 2026 · 1 publisher
- Recorded Future's half-year data shows adversaries continuing to favor abusing legitimate tools and trusted platforms already inside the enterprise
Security · September 3, 2026 · 1 publisher
- Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test
Security · August 31, 2026 · 1 publisher
- Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name
Product · August 27, 2026 · 1 publisher
- GitLab ships five security fixes and keeps the details sealed until October
Build · August 23, 2026 · 1 publisher
- Grok still hands over whole chat histories 11 weeks after disclosure, Adversa says
Invest · August 20, 2026 · 1 publisher
- Cursor runs a repository's own git.exe on Windows, and has done for months
Science · August 19, 2026 · 1 publisher
- The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation
Security · August 19, 2026 · 1 publisher
- The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.
Product · August 17, 2026 · 1 publisher