ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
CVE-2026-94545 lets attacker-supplied text in an Open Graph image reach Next.js dependencies. Vercel shipped the fix on September 22 in 16.3.6; a day later, npm audit still passed affected builds.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
The affected releases stretch back to Next.js 13.4, and for Windows self-hosters the only remedy Vercel offers is the version bump. The AVIF bug shipped in the same release at least has a config gate.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence58
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
According to Microsoft Threat Intelligence, every stage after the consent prompt runs on software the environment already trusts, which puts the choke point on Teams federation policy and remote-support install rights.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence65
Attackers using AI can fix and retest a failed cloud privilege escalation in minutes instead of hours, according to an analysis in The Hacker News. The cost it puts on defenders is the hours spent rebuilding each alert's context before anyone acts.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence35
Enterprise AI tooling now trips about one SOC alert in 230, the fastest-growing class in the stream, and 94.1% of what it fires is legitimate work hitting detection rules written before agents existed. The bill is tuning and triage capacity.
Reality
- Evidence45
- Adoption50
- Hype gap+15
- Incentives60
- Confidence50
GitGuardian's 2026 State of Secrets Sprawl Report says commits identified as AI-assisted leak secrets at about twice the rate of human-written ones. Agent and MCP config files also keep plaintext keys on developer machines where commit scanning and code review never look.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence35
Bitget says attackers took over a wallet backend, faked transaction data and got the exchange's own authorization process to move $351.6 million out. No key was reported stolen, so the failure is in where the approvers got their facts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence50
OpenSourceMalware says WeaselBiscuit borrows functions from DPRK's BeaverTail and OtterCookie but strips out the persistence and the wallet drainer. It runs from memory on an npm import and takes Chrome's extension storage.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
ISC fixed fourteen flaws in BIND 9.20.29 and 9.21.26, with no workarounds for any of them. The unauthenticated crash is one of only two that never reached the end-of-life 9.18 branch.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence72
Koi Security counted 126 npm packages and more than 86,000 installs since August 2025, with 80 still live when it published. npm pulled the stealer from the attacker's host at install time. That put it outside the package a scanner reads.
Publishers:scworld.com · web.archive.org Reality
- Evidence60
- Adoption35
- Hype gap+20
- Incentives55
- Confidence60
CERT Polska's breakdown of the September RouterOS compromises names two bugs, CVE-2026-67279 and CVE-2026-86060, and the forum logs that match the chain start on September 2, a day before MikroTik shipped fixes.
Reality
- Evidence74
- Adoption52
- Hype gap−8
- Incentives35
- Confidence70
The flaw reaches code execution only where the active theme has a top-level directory starting with page- and a readable local .php file such as pearcmd.php sits on the server. Previdian has logged 68 attempts.
Reality
- Evidence66
- Adoption45
- Hype gap+12
- Incentives68
- Confidence60
Year two of the EU's operational resilience rules moves the test from documented governance to demonstrated detection. The reporting deadline runs from the entity's own classification decision, and the evidence behind that call is the SOC's.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives65
- Confidence50
Zscaler ThreatLabz says the Pakistan-aligned group worked government and defense targets in India and Afghanistan with four undocumented tools, one of them a Rust backdoor that takes its orders from files in a private repo.
Reality
- Evidence40
- Adoption25
- Hype gap+18
- Incentives65
- Confidence45
Air Security's Plugin4Shell lets a plugin be swapped during a background refresh while the agent reports the audited commit. Anthropic and OpenAI have patched, Copilot has no fix, and Google is retiring Gemini CLI.
Reality
- Evidence60
- Adoption65
- Hype gap+20
- Incentives70
- Confidence58
CVE-2026-28326 scores 8.8 and affects every build of Access Rights Manager up to 2026.2. The fix is ARM 2026.2.1, and it lands weeks after SolarWinds patched a SAML bypass in Web Help Desk and 16 flaws in Serv-U.
Reality
- Evidence52
- Adoption22
- Hype gap+12
- Incentives55
- Confidence58
Earlier coverage
- Verizon's 43-day median patch time, against a five-day weaponization clock
Security · September 17, 2026 · 1 publisher
- N0va captures refresh tokens from sign-ins the identity provider itself approved
Security · September 16, 2026 · 1 publisher
- KREMLIN installers forge Chrome's Secure Preferences HMACs to register a stealer extension
Security · September 15, 2026 · 1 publisher
- Exploitation catalogues logged 495 of the 35,853 CVEs published in the first half of 2026
Security · September 15, 2026 · 1 publisher
- An attacker kept root inside Thai broadband provider 3BB with a hidden MeshCentral install
Security · September 14, 2026 · 1 publisher
- Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest
Build · September 14, 2026 · 1 publisher
- An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud
Build · September 12, 2026 · 1 publisher
- SecurityBridge's co-founder makes the SAP agent case on one survey and two prior incidents
Leadership · September 10, 2026 · 1 publisher
- cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root
Security · September 9, 2026 · 1 publisher
- Bitdefender counts 55.2% of breached practitioners asked to keep the incident quiet
Security · September 8, 2026 · 1 publisher
- September 11 puts a 24-hour clock on knowing what software actually shipped
Product · September 3, 2026 · 1 publisher
- GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs
Security · September 3, 2026 · 1 publisher
- Approving one coding agent doesn't cover what's installed inside it
Security · September 2, 2026 · 1 publisher
- Attackers ran ClickFix into 47% of the initial access Microsoft logged last year
Security · September 1, 2026 · 1 publisher
- The CRA's 24-hour exploitation clock starts 456 days before its engineering rules do
Security · September 1, 2026 · 1 publisher
- Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials
Security · August 31, 2026 · 1 publisher
- DoJ rewrites its QTFY seizure release to move seven agencies from victims to targets
Security · August 31, 2026 · 1 publisher
- ZBT router firmware ships two factory implants that beacon out on UDP/10000
Security · August 28, 2026 · 1 publisher
- A survey of 250-plus SOC practitioners puts 135 minutes between an alert firing and an answer
Security · August 27, 2026 · 1 publisher
- An agent beat a client-side booking limit in 9 of 10 runs, and cancelled strangers twice
Security · August 26, 2026 · 1 publisher
- Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor
Security · August 26, 2026 · 1 publisher
- Time to revoke: the two timestamps a closed ticket cannot give you
Build · August 26, 2026 · 1 publisher
- Mirage2FA: 4,532 domains later, "we have MFA" is not an answer to the auditor
Security · August 25, 2026 · 1 publisher
- QUICSILVER runs its C2 over QUIC, and most port-443 inspection is scoped to TCP
Security · August 24, 2026 · 1 publisher
- U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first
Security · August 24, 2026 · 1 publisher
- The Meta Sev 1 that argues approval is a snapshot, not a control
Security · August 20, 2026 · 1 publisher
- Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects
Security · August 20, 2026 · 1 publisher
- A vCenter bug patched on July 29 is already a ransomware chain, not a ticket
Security · August 17, 2026 · 1 publisher
- Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout
Build · August 16, 2026 · 1 publisher