Vijil released DART, which tests enterprise AI agents with its own multi-turn attacker agents and claims 1.5 times a rival's attack success rate. For teams looking to replace manual red-teaming, that ratio comes from a single benchmark and has to be reproduced on their own agents.
Reality
- Evidence25
- Adoption
- Insufficient
- Hype gap+45
- Incentives85
- Confidence35
build1 publisherOne report MITRE rated CrewAI's nine-name code-sandbox blocklist a CVSS 8.1 flaw, bypassed by a call that executes no import. The fix removed the feature, so teams running agent-written code need isolation at the OS or process level.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Reality
- Evidence70
- Adoption40
- Hype gap+10
- Incentives40
- Confidence65
CTM360 tracked more than 17,000 compromised URLs serving a fake Cloudflare check whose next hostname arrives from an on-chain lookup. Microsoft put 47 percent of its 2025 initial-access cases down to the technique.
Reality
- Evidence45
- Adoption72
- Hype gap+20
- Incentives70
- Confidence50
Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence66
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
Microsoft rated 114 of the 973 Critical, but 284 score 8.0 or higher and two Important-severity Windows bugs are already under attack. One 9.1 advisory in the same cycle came from outside Microsoft.
Reality
- Evidence62
- Adoption55
- Hype gap+12
- Incentives68
- Confidence58
The PIVOT program was announced on September 15 with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos signed up, and the first comparative results are due in January 2027. MITRE's rival test drew 11 vendors in 2025.
Reality
- Evidence42
- Adoption35
- Hype gap+40
- Incentives72
- Confidence45
The Enterprise matrix now runs 15 tactics, and the two that replaced Defense Evasion leave different forensic evidence, so detection content mapped to the old tactic has to be reassigned technique by technique.
Reality
- Evidence48
- Adoption20
- Hype gap+18
- Incentives82
- Confidence55
Jon Baker of AttackIQ treats the subscription-gated report as evidence that AI hands any attacker fast access to a technique catalog that has not grown, and builds a spending case for chokepoint detection on it.
Reality
- Evidence32
- Adoption30
- Hype gap+32
- Incentives78
- Confidence52
Rapid7's read of the fraud economy names Xleet, Blackpass, Infodig and Styx as the venues doing the trade, and points teams at MITRE's Fraud Fighting Framework, introduced in early 2026, to order what they watch.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+28
- Incentives68
- Confidence55
The flaw sits in the JWT refresh token handler, needs nothing more than a rewritten authorization header over plain HTTP, and the fix is a point release to 5.8.1.11 that no change board should need a month to approve.
Reality
- Evidence62
- Adoption32
- Hype gap+18
- Incentives58
- Confidence64
HiddenLayer's revenue grew more than tenfold last year selling security for models, while the new money funds a coding-agent module announced on the same day, which makes this a round priced on next year's budget line.
Reality
- Evidence28
- Adoption36
- Hype gap+42
- Incentives88
- Confidence54
Its review of fiscal 2024 and 2025 says opportunistic scanning of known, internet-exposed flaws drove most compromises. The fix, it argues, belongs to software producers, not to defenders patching faster.
Reality
- Evidence58
- Adoption18
- Hype gap+15
- Incentives55
- Confidence55
build1 publisherOne report JFrog found that 54 of 55 advisories from one new GitHub account were machine-generated fiction. They reached enterprise scanners by the normal route, which is the problem.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives60
- Confidence48