RippleX fixed a 2015-era XRP Ledger bug that let one payment create spendable XRP beyond the token's 100 billion supply cap. Both built-in safeguards would have missed it, so the cap's record on public networks rests on RippleX's finding of no exploitation.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
buildConfirmed5 publishers OpenSSH 10.6, released October 6, turns off the LZ77 coder in SSH compression to block an attack that reads one channel's secrets from another. Hosts using the Compression option will get less from it, so the project suggests compressing in the application.
Perspective Coverage
5 publishers
- Builder
- Builder 42%
- Operator
- Operator 52%
- Investor
- Investor 6%
Reality
- Evidence82
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence78
VulnCheck says attackers are probing internet-facing Rejetto HFS servers for CVE-2026-61500, a signing-key flaw that gives full administrative control. The bug affects HFS 3.0.0 through 3.2.0, and the fix shipped in 3.2.1.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives40
- Confidence60
Apple's emergency macOS update on August 6 fixed a Screen Sharing flaw that calif.io turned into a working exploit about four hours later. The flaw let anyone on the network sign in without a password, and the service answering those connections runs as root.
Publishers:blog.calif.io
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence50
buildOne report1 publisher Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.
Reality
- Evidence70
- Adoption72
- Hype gap0
- Incentives50
- Confidence65
Horizon3 used Anthropic's Mythos model to find CVE-2026-61500, a chain that forges Rejetto HFS admin sessions and reaches remote code execution. The firm expects frontier models to make deeper, less reliable bug classes worth weaponizing at scale.
Reality
- Evidence55
- Adoption15
- Hype gap+30
- Incentives70
- Confidence50
buildOne report1 publisher GitHub Security Lab says its open-source LLM taskflows have found and reported 24 Android app vulnerabilities by auditing code in staged steps. Teams with a GitHub Copilot license can point the same audit at their own repositories.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
GitHub Security Lab's Kevin Stubbings used AI audit workflows to find and report 24 Android app flaws, among them bugs in OsmAnd and Wikipedia. The workflows are free to run on any repository, so the same audit is open to defenders and attackers alike.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence45
CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.
Perspective Coverage
8 publishers
- Builder
- Builder 19%
- Operator
- Operator 73%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption45
- Hype gap+18
- Incentives30
- Confidence72
Calif's WeWorm abused a memory corruption bug in WeChat's VoIP stack to take over accounts on an iPhone 17e and two Pixel 10a handsets, and Tencent blocked it server-side on 28 August without publishing an advisory or a CVE.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 51%
- Investor
- Investor 17%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+35
- Incentives60
- Confidence60
Fixes are in for four Linux local-root bugs found in code more than a decade old. Turning off unprivileged user namespaces closes three of them. The fourth stays open.
Publishers:heyitsas.im
Reality
- Evidence58
- Adoption32
- Hype gap+12
- Incentives55
- Confidence55
The fixes are already upstream, so the work now is confirming your distribution shipped them before someone with a low-privileged shell on a shared host uses the published code to reach root.
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives35
- Confidence60
Chainguard says fix generation was never its bottleneck and that responsible disclosure at scale is, so its first public batch is built from bugs upstreams quietly fixed years ago and never filed CVEs for.
Publishers:chainguard.dev
Reality
- Evidence34
- Adoption16
- Hype gap+28
- Incentives82
- Confidence48
A researcher ran the same FreeBSD scan through base and abliterated open-weight builds and found the uncensored ones graduating three to four times as many findings, while the most aggressive one never surfaced the actual CVE.
Publishers:clearbluejar.github.io
Reality
- Evidence58
- Adoption14
- Hype gap+14
- Incentives22
- Confidence46
buildOne report1 publisher Jordy Zomer built a Datalog engine so an agent maintains what it currently knows instead of searching its own transcript, and his own benchmark runs put the weak link in the model that writes the facts.
Reality
- Evidence46
- Adoption12
- Hype gap−8
- Incentives28
- Confidence54
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
Reality
- Evidence48
- Adoption44
- Hype gap+30
- Incentives66
- Confidence45
The first US spot Zcash product gives brokerage accounts price exposure to a privacy coin while holding its ZEC in transparent custody. Allocators now have to argue the asset, not the access.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 25%
- Investor
- Investor 48%
Reality
- Evidence71
- Adoption56
- Hype gap+20
- Incentives74
- Confidence70
A volunteer group says it has swept almost all of Bitcoin's open-source ecosystem for AI-assisted exploits, and that American models' refusals made Chinese ones the default tool.
Reality
- Evidence28
- Adoption32
- Hype gap+34
- Incentives66
- Confidence44