Epic has stopped most product development for roughly six weeks while it fixes MyChart flaws that an AI model uncovered, according to TechCrunch. No list of affected portal setups is public yet, so hospitals cannot check theirs against one.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence55
- Adoption25
- Hype gap+15
- Incentives40
- Confidence60
Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
Core Lightning told operators on October 2 to upgrade from version 26.06.7 or older after reports that attackers are targeting unpatched nodes. MetaMask's precautionary exit from Lido that week lost no reported funds but will likely forgo rewards on ETH that can take up to 45 days to return.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence48
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Palo Alto Networks pointed Anthropic's unreleased Mythos at its own systems and found 75 vulnerabilities in a month, against a usual rate below five. The defense business it built on that result depends on Anthropic's model and on customers choosing a security vendor over the lab.
Reality
- Evidence45
- Adoption30
- Hype gap+35
- Incentives80
- Confidence50
The EUR2.1m pre-seed is roughly 0.16% of what 360 Capital and PranaVentures manage between them - a check sized to option a research method, before Bynario has a finished security platform to bet on.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence40
Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.
Publishers:chainguard.dev
Reality
- Evidence40
- Adoption25
- Hype gap+10
- Incentives75
- Confidence45
Google's PageBreak agent confirmed over 500 XSS flaws in ordinary Google web apps and two in hundreds built on its hardened frameworks. The gap supports building defences into frameworks, and the agent that measured it had more inside access than an outside attacker would.
Reality
- Evidence55
- Adoption20
- Hype gap+20
- Incentives65
- Confidence55
The kernel fixed CVE-2026-80521 on August 6. Ubuntu has shipped nothing for 22.04, 24.04 or 26.04, including its AWS, Azure and GCP kernels, and DepthFirst's exploit for 26.04 went public on September 22.
Publishers:linuxjournal.com · thehackernews.com Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence68
iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 close 29 flaws with no known attacks. Publication is the trigger event, and 21 of the 29 sit in WebKit.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 58%
- Investor
- Investor 10%
Reality
- Evidence82
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence78
Z.ai says every gain in GLM-5.3 came from post-training on an unchanged base. If that holds, refresh cadence for self-hosted weights is set by RL runs, not pretraining runs.
Perspective Coverage
5 publishers
- Builder
- Builder 58%
- Operator
- Operator 33%
- Investor
- Investor 9%
Reality
- Evidence40
- Adoption30
- Hype gap+35
- Incentives70
- Confidence55
The invitation-only service takes read access to authorized repositories and ranks findings by whether the route is deployed, busy and already covered by a WAF rule, then proposes a fix, pre-checks it, and hands you the approval.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives80
- Confidence60
A record count that Microsoft's own AI bug-hunting produced arrives with two flaws already under attack, and the affected-product lists an operator would use to scope them are the part of the record two vendors read differently.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC each take a low-privilege foothold to SYSTEM, and the remediation guidance asks for verified restarts, which is a harder number to report than install counts.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
A GET asks a site for a page and a POST tells it to act, so the change Akamai measured over 30 days puts verified AI bots on the request type behind store logins, carts and checkouts. Akamai did not break those requests down by action; retailers have that in their own logs.
Reality
- Evidence36
- Adoption42
- Hype gap+28
- Incentives80
- Confidence40
Oracle put ChatGPT Enterprise and OpenAI's Codex in front of about 160,000 employees in April, and 80 percent were using them within three months. Then the bills arrived and, the CIO said, surprised the company.
Reality
- Evidence40
- Adoption68
- Hype gap+15
- Incentives68
- Confidence46
AI-assisted code analysis keeps finding old bugs in software that certified and unsupported OT cannot update. Talos answers with deep packet inspection on the path in and VLAN segmentation built on how little OT talks.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives75
- Confidence45
A post at The Hacker News puts published CVEs up roughly 49 percent year over year and observed exploitation at 495. For operators the figure that changes triage is the 116 attacked on the day they went public.
Reality
- Evidence30
- Adoption20
- Hype gap+30
- Incentives85
- Confidence40
Project Glasswing surfaced an estimated 6,202 high or critical vulnerabilities in foundational open source, with 97 confirmed fixed in two months. What the confirmation count actually measures decides how much of that gap is real.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives60
- Confidence28
Project Glasswing gives twelve launch partners and more than forty critical-infrastructure maintainers access to Claude Mythos Preview, which Anthropic says has already found thousands of high-severity vulnerabilities.
Reality
- Evidence30
- Adoption25
- Hype gap+45
- Incentives80
- Confidence60
Earlier coverage
- AI bug-hunting models pushed Microsoft's four-month patch total to 4.5 times its old baseline
Product · September 8, 2026 · 1 publisher
- Sysdig credits Anthropic's Mythos preview with 181 working Firefox exploits
Security · September 6, 2026 · 1 publisher
- Arista tells network teams to staff for months of batched EOS and VeloCloud advisories
Security · September 6, 2026 · 1 publisher
- August's 398-CVE Patch Tuesday moves the bottleneck to the test bench
Security · September 4, 2026 · 1 publisher
- Maintainers shipped 97 fixes against the 23,019 bugs Claude Mythos flagged
Security · September 3, 2026 · 1 publisher
- A bug drought would push backdoor mandates back onto product roadmaps
Product · August 31, 2026 · 1 publisher
- The exploit was the toll gate: Gartner's top emerging risk moved five places in one quarter
Security · August 26, 2026 · 1 publisher
- Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.
Security · August 19, 2026 · 1 publisher
- Cheap bug-hunting arrives: GLM 5.3 puts near-frontier vulnerability discovery on your own hardware
Product · August 18, 2026 · 1 publisher
- Anthropic found 10,000 critical bugs. The bottleneck is now the person reading the report
Build · August 17, 2026 · 1 publisher
- Z.ai's GLM-5.3 beats Claude on CyberGym, then hands out the weights
Product · August 15, 2026 · 1 publisher
- GLM-5.3 Buys Buyers Time: Z.ai's Coding Model Cuts Tokens, Not the Closed-Model Lead
Invest · August 14, 2026 · 1 publisher