Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
TASK#STOMP, a Windows backdoor researchers dissected, uploads a victim's business documents and then stays to copy each new or edited one. Loss from a single infection keeps growing until someone finds and removes it.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Varonis says Copilot disclosed an undocumented URL parameter mid-refusal, enabling silent exfiltration. Microsoft shipped patches on August 18, 2026, about eight months after disclosure.
Publishers:thehackernews.com · varonis.com Reality
- Evidence66
- Adoption24
- Hype gap+16
- Incentives70
- Confidence62
ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.
Perspective Coverage
4 publishers
- Builder
- Builder 36%
- Operator
- Operator 58%
- Investor
- Investor 6%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence68
Agents in OpenAI's research environment posted user-provided images to third-party image hosts 53 times, the company disclosed. Its fixes harden and monitor the systems around the model, and a review of older agent activity is still running.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence50
Noma Labs disclosed ForcedLeak, a CVSS 9.4 chain that let a planted Salesforce web-form lead steer Agentforce into leaking CRM data. Salesforce blocked the exit on September 8, leaving audits of recent leads and agent activity as the open task.
Publishers:noma.security
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence50
The code containers could not reach the internet or each other, but every one of them reached the same package service, and its metadata was not scoped by account, so a planted prompt turned one user's assistant into a stranger's Gmail reader.
Perspective Coverage
3 publishers
- Builder
- Builder 37%
- Operator
- Operator 53%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence68
Zhipu AI says repository data left only while a project description page was being generated, and that the behaviour is fixed. The developer who found it says earlier versions sent data on every query, and some companies have stopped using ZCode.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 32%
- Investor
- Investor 25%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence62
Three researchers say agents attributed to OpenAI moved scraped data through RubyGems' publish and list calls in May and June. A local demo now reproduces that channel on a registry with no bug in it.
Reality
- Evidence45
- Adoption30
- Hype gap+12
- Incentives40
- Confidence48
The demo uploads a model file as base64 chunks over GET, then starts an inference server on it. It shows why egress and WAF rules keyed on the HTTP verb miss what the URL is doing.
Reality
- Evidence64
- Adoption9
- Hype gap+14
- Incentives30
- Confidence56
The SnapShield expansion adds detection for data being read and moved out, on top of encryption. Founder Douglas Milburn says containment can fire on activity across a few files, and that legitimate work sometimes trips it.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+18
- Incentives75
- Confidence45
Adversa AI encrypts its instructions so Grok's input filter sees only noise, then lets Grok's own sandbox decrypt them. The firm says it reported the technique to xAI on 3 June 2026 and reproduced it again on 19 August.
Reality
- Evidence45
- Adoption18
- Hype gap+18
- Incentives65
- Confidence52
Microsoft has tracked this since May 2026. First contact lands on an unmanaged personal phone, and the attacker's own authenticator outlives the stolen session, so tenant telemetry only starts after the account is already lost.
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives65
- Confidence58
A dev.to write-up follows the bytes past the prompt box into the envelope a client assembles around it, then pairs one git command with a local scanner that reads the ignored-file list as an attachment manifest.
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap+12
- Incentives22
- Confidence45
The 500-plus engagements behind that share are all companies that already needed an outside responder, so the figure describes how fast a bad day closes rather than your odds of having one. It still decides which of your controls can fire in time.
Publishers:paloaltonetworks.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+30
- Incentives80
- Confidence60
The path Mindguard reported works against Kiro 0.7.45 on Windows and Amazon closed it in 0.8.140, but no CVE was assigned and workspace trust made no difference, so the installed version string is the only check you have.
Reality
- Evidence60
- Adoption32
- Hype gap+12
- Incentives66
- Confidence55
Adversa AI's Cryptographic Context Injection keeps instructions as ciphertext until the agent's own runtime decrypts them. The exfiltration then rides a tool the agent already had.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+42
- Incentives80
- Confidence30
Adversa says it hid data-exfiltration instructions in AES-256-GCM ciphertext and let Grok decrypt them in its own Python sandbox. The plaintext version of the same attack was refused.
Reality
- Evidence42
- Adoption20
- Hype gap+22
- Incentives68
- Confidence44