Sysdig says an LLM-driven operator it calls JADEPUFFER ran a database-extortion campaign on its own, entering through unpatched Langflow flaw CVE-2025-3248. It calls the operation the first documented ransomware run end to end by a model.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
CVE-2025-62593 carries a CVSS 9.4 and a federal remediation deadline of August 20, 2026. The unauthenticated endpoints behind it are a design decision, not an oversight.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 60%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption50
- Hype gap+15
- Incentives35
- Confidence66
Unit 42 worked a ransomware intrusion where the operator handed tactical execution to frontier AI agents, and the chain from a public API endpoint to stolen cloud AI keys closed inside a single working day with no zero-day.
Reality
- Evidence50
- Adoption20
- Hype gap+25
- Incentives60
- Confidence55
One Dell rollup alone carried 435 CVEs, among them a kernel privilege-escalation bug that had already shipped in two other Dell advisories. That is why a single vendor feed cannot describe a GPU estate.
Publishers:eclypsium.com
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence55
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
Berardino Carnevale of Rambus told Lets Data Science that measured boot protects only the components inside the measurement set, and that attestation evidence settles nothing until a verification service acts on it.
Reality
- Evidence45
- Adoption12
- Hype gap−10
- Incentives70
- Confidence55
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
Tencent's Zhuque Lab has put its AI asset scanner on GitHub for nothing. The skill auditor asks a language model whether code looks malicious, and the lab's own benchmark puts the false positive rate anywhere between 1.2 and 18.67 percent.
Reality
- Evidence58
- Adoption42
- Hype gap−12
- Incentives52
- Confidence55
X41 D-Sec's proof of concept for CVE-2026-48710 is one unauthenticated GET whose Host header carries /public?bar=. Starlette sits underneath LiteLLM, vLLM and MCP servers, so the work starts with a dependency query.
Reality
- Evidence56
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence52
Seven entries went into CISA's known-exploited catalog on 2 September. The 5 September fix date covers four of the six products named, and the two AI-stack entries are the ones most teams cannot locate in a dependency graph.
Reality
- Evidence58
- Adoption34
- Hype gap+15
- Incentives30
- Confidence56
The Ray, Docker and Redis endpoints hijacked in ShadowRay 2.0 were worked by operators Oligo now ties to TA-NATALSTATUS activity from 2020, which makes the AI-cluster worm a tooling upgrade on an old farm.
Publishers:oligo.security
Reality
- Evidence55
- Adoption45
- Hype gap+25
- Incentives75
- Confidence50
Microsoft Security Research says intruders who reached exposed LiteLLM, RAGFlow and Kestra deployments went for provider keys and database URLs first. It can name a confident initial vector in only one of the three cases.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives55
- Confidence42
Ninety days of Wiz honeypot telemetry shows tooling written for LiteLLM's internals, including a config test endpoint that spawns whatever command it is handed and a miner whose output comes home inside the MCP protocol.
Reality
- Evidence62
- Adoption66
- Hype gap+12
- Incentives72
- Confidence55
Three Microsoft investigations into AI middleware ended in stolen keys, persistence and compute abuse. The remediation list is ordinary infrastructure hygiene, applied to plumbing nobody inventoried.
Reality
- Evidence66
- Adoption42
- Hype gap+12
- Incentives68
- Confidence52
Ray never authenticated its job endpoints, and the User-Agent check meant to keep browsers out is spoofable in Firefox and Safari. DNS rebinding does the rest.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence65
CVE-2025-62593 is a code-injection flaw in Ray that CISA says is already being exploited, and its own entry says the bug can be reached through a browser. The fix is version 2.52.0.
Reality
- Evidence58
- Adoption46
- Hype gap+14
- Incentives34
- Confidence55
Rapid7's latest wrap-up ships working exploit code for seven separately documented flaws, including an unauthenticated Joomla web shell and a Linux kernel LPE. Reprioritize this week, not next cycle.
Reality
- Evidence74
- Adoption52
- Hype gap+22
- Incentives71
- Confidence63