OpenBao fixed a four-bug chain in 2.6.3 and 2.7.0 that lets unauthenticated attackers seize servers with a Raft snapshot policy set. A dev.to post says HashiCorp Vault has no fix yet, so Vault operators have to close network paths to the API themselves.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives
- Insufficient
- Confidence25
Commercial AI models refused every query from Hugging Face's breach responders, Veracode's Chris Wysopal wrote, forcing them onto a self-hosted Chinese model. Security leaders now have to settle which AI model their responders can use before an intrusion starts.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 45%
- Investor
- Investor 33%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence50
Faav, a 16-year-old researcher, reached admin SQL over 17.3 trillion rows on Microsoft's Titan service because it never checked login-token signatures. Microsoft locked the endpoint four days after his report and paid a $5,000 bounty.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives55
- Confidence55
Copilot Autofix swapped an env-var-and-jq pattern for inline interpolation in a public GitHub Actions file, and Wiz's autonomous agent exploited it inside a week.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+35
- Incentives65
- Confidence62
Cloudflare has fixed a flaw in Containers that let a Workers Paid account read the 60 KiB it had not written inside each 64 KiB disk block it touched. The fleet-wide fix needed no customer configuration changes.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence62
Adversa AI says its Cryptographic Context Injection recovers hostile prompts inside the code sandbox, where filters do not look. xAI has not replied; Google scopes jailbreaks out entirely.
Perspective Coverage
6 publishers
- Builder
- Builder 34%
- Operator
- Operator 55%
- Investor
- Investor 11%
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence55
CVE-2026-75501 puts an unauthenticated UPnP control endpoint on the WAN side of a premium ISP gateway. With no patch and no vendor reply, the carriers own the mitigation.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Olivier Laflamme walked an unpaired Bluetooth write up to root on the G1 EDU's Locomotion PC by way of a Unitree cloud API that decrypted key material for any logged-in account. Unitree fixed that check in July, but no patched firmware has been named.
Perspective Coverage
4 publishers
- Builder
- Builder 38%
- Operator
- Operator 50%
- Investor
- Investor 12%
Reality
- Evidence72
- Adoption38
- Hype gap+8
- Incentives45
- Confidence62
CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.
Perspective Coverage
8 publishers
- Builder
- Builder 19%
- Operator
- Operator 73%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption45
- Hype gap+18
- Incentives30
- Confidence72
MikroTik published RouterOS fixes in four branches with no CVE and no technical detail. The same upgrade runs a compromise check and writes a critical log entry marking the device Flagged.
Publishers:cert.pl · forum.mikrotik.com · helpnetsecurity.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 71%
- Investor
- Investor 7%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap−40
- Incentives45
- Confidence72
CISA lists 14 CVEs in two Botslab G980H dashcam firmware lines, including session flaws that can give an attacker on the camera's network privileged access. Botslab has not answered CISA, so operators have no fix date to plan around.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
CERT Polska rebuilt the MikroTrick attack chain from MikroTik's unlabeled September 3 patch and had a working exploit for CVE-2026-86060 in about an hour. The fix quietly disables a rogue "ops" account, evidence the chain was already exploited in the wild.
Reality
- Evidence68
- Adoption62
- Hype gap+8
- Incentives45
- Confidence60
Two flaws disclosed on September 23rd let anyone on the network path read repository objects in transit, and let a connecting peer claim a Node ID it does not own. Radicle tells users to treat anything already sent as leaked.
Reality
- Evidence62
- Adoption28
- Hype gap−8
- Incentives65
- Confidence58
Anthropic says Claude Mythos Preview found and exploited previously unknown flaws in every major operating system and web browser during a month of testing. Its disclosure process keeps the rest unnamed until patches ship.
Publishers:red.anthropic.com
Reality
- Evidence36
- Adoption20
- Hype gap+35
- Incentives78
- Confidence55
A University of British Columbia team showed that three selection functions in Soatok's constant-time-js leak their condition through V8's cache behaviour. He shipped version 0.5.0 and requested a CVE.
Publishers:soatok.blog
Reality
- Evidence72
- Adoption6
- Hype gap−18
- Incentives42
- Confidence70
Siemens ProductCERT reported the traversal itself, and fixed builds are out for four SIMOVE Fleetmanager branches and SIPLANT V3.1. For SIPLANT V1.7, V2.2 and V3.0 the advisory's remedy is an email to support.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence72
CVE-2026-50093 lets an attacker upload arbitrary files to the Open Interface Services web module and take root on the host running Siveillance Control. Siemens reported it to CISA and has fixed builds out for all four affected branches.
Reality
- Evidence66
- Adoption28
- Hype gap+14
- Incentives58
- Confidence64
CVE-2026-18963 sits in the Keycloak reset-credentials flow that Siemens embeds in Industrial Edge Management. Siemens closed its own Cloud service on September 2, and owners of self-hosted IEM Pro and IEM Virtual patch or block the path themselves.
Reality
- Evidence72
- Adoption35
- Hype gap−10
- Incentives55
- Confidence70
Oren Yomtov of Accomplish found two ways out of the Codex sandbox, both silent and neither stopped by an approval prompt. OpenAI patched them within eight days, and other researchers have found the same design in rival agents.
Reality
- Evidence68
- Adoption45
- Hype gap−5
- Incentives55
- Confidence62
Researchers at AIR found that four AI coding agents accepted a Git checkout they never verified, and because no marketplace can close the gap, the repair now travels through agent version numbers inside each enterprise.
Reality
- Evidence62
- Adoption38
- Hype gap+18
- Incentives60
- Confidence55
Earlier coverage
- Opening a stranger's repo in OpenAI Codex handed its author commands on the host
Security · September 20, 2026 · 1 publisher
- CISA moves vulnerability coordination off CERT/CC's VINCE onto its own platform
Security · September 18, 2026 · 2 publishers
- A CNAME left pointing at a deleted S3 bucket hands the subdomain to whoever registers the name first
Build · September 17, 2026 · 1 publisher
- Replaying camera traffic on the LAN gets admin on TP-Link's Tapo C200
Security · September 16, 2026 · 1 publisher
- A crafted URL runs attacker script inside an authenticated Teamcenter session
Security · September 16, 2026 · 1 publisher
- Researchers Show Encrypted Reasoning Blocks From OpenAI, Anthropic and Google Can Be Decrypted Using a Weaker Sibling Model
Build · September 15, 2026 · 1 publisher
- Two of seven unpatched CareCam CM2507 camera flaws let anyone on the network view live video
Security · September 15, 2026 · 1 publisher
- ENISA puts weaponisation of a disclosed vulnerability at 15 minutes
Security · September 14, 2026 · 1 publisher
- Ten days of maintainer time bought Core Lightning a two-week embargo on AI-found bugs
Invest · August 27, 2026 · 3 publishers
- Opening the cohttp fix PR drew traversal probes within ten minutes
Build · September 11, 2026 · 1 publisher
- An encrypted payload turns Grok's own navigation tool into the exfiltration path
Build · September 10, 2026 · 1 publisher
- Authenticated SQL in Mirth Connect hands over the credentials for the systems it connects to
Security · September 10, 2026 · 1 publisher
- Anthropic hands an unreleased bug-finding model to more than 50 organisations
Security · September 9, 2026 · 1 publisher
- Gamers Nexus teardown finds LG TVs inventorying the LAN they sit on
Security · September 8, 2026 · 2 publishers
- Ledger's lab took about 125 days to walk a laser flaw in Trezor's chip into public view
Invest · September 7, 2026 · 1 publisher
- Apple's report cap blocked a seven-person firm with a patched Mac bug to its name
Product · September 5, 2026 · 1 publisher
- Community maps in MECCHA CHAMELEON could write files anywhere on a player's disk
Security · September 5, 2026 · 1 publisher
- Rockwell's ControlFLASH installer gave the Everyone group write access to its own program folder
Security · September 3, 2026 · 1 publisher
- Rockwell answers a 1756-ENBT crash bug with a hardware swap instead of firmware
Security · September 3, 2026 · 1 publisher
- A dropped authorization check exposes GeoNetwork geoportal backends to unauthenticated RCE
Security · September 2, 2026 · 1 publisher
- OpenAI holds two unpatched zero-days its own benchmark run produced
Invest · September 2, 2026 · 1 publisher
- Rockwell's redundancy config tool loads a standard user's DLL as SYSTEM
Security · September 1, 2026 · 1 publisher
- Cosmos Labs ran incident command for forty chains it does not operate
Leadership · August 30, 2026 · 1 publisher
- Polygon fixed a validator-stalling bug in two hard forks before saying what it was
Invest · August 29, 2026 · 2 publishers
- MIT's TONTOU attack reaches protected Linux memory through a two-instruction window
Product · August 28, 2026 · 1 publisher
- Xiiaozet's LK100W lets an unauthenticated caller switch on its admin services
Security · August 27, 2026 · 1 publisher
- N-able Passportal leaked whole vaults to any page: v3.49.6 stops the leak, not the tokens
Security · August 26, 2026 · 1 publisher
- CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering
Security · August 25, 2026 · 1 publisher
- Provenance's marker module let anyone with zero tokens claim admin over 82 live financial assets
Security · August 25, 2026 · 1 publisher
- A machine found the bug and set the clock: Ledger disputes TestMachine's timeline
Security · August 25, 2026 · 1 publisher
- Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache
Security · August 23, 2026 · 1 publisher
- Your edge speaks HTTP/3, your origin speaks HTTP/1.1: that gap is now a DoS primitive
Build · August 21, 2026 · 1 publisher
- MLflow's default server hands out cloud credentials to anyone who asks nicely
Leadership · August 20, 2026 · 1 publisher
- Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions
Security · August 20, 2026 · 1 publisher
- Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band
Security · August 19, 2026 · 1 publisher
- A config file that runs shell commands: "open this in Claude Code" needs a review gate
Leadership · August 19, 2026 · 1 publisher
- A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply
Build · August 19, 2026 · 1 publisher
- Kimi Desktop's second binary: mutable CDN path, no Windows checksum, no signer check
Build · August 18, 2026 · 1 publisher
- Windows 11's secure kernel trusts a RAM chip that never checks who is writing to it
Security · August 17, 2026 · 1 publisher
- White-on-white PDF makes Atlassian's Rovo leak Jira and Confluence data; the org switch does not help
Build · August 15, 2026 · 1 publisher