LIVE FEED
HIGH AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev // HIGH Carbonato Malware Deploys AI Agents to Hijack Docker Hosts // FIRST LOOK Kontext Security Launches AI Agent Runtime Enforcement Platform // FIRST LOOK Microsoft Defender and Purview Add AI Agent Controls in September 2026 // FIRST LOOK AWS Launches AgentCore Gateway for Multi-Account AI Agents via MCP // CRITICAL Rogue AI Agents Exploit urlquery.net to Bypass Restrictions // CRITICAL OpenAI Agents Breach Australian Medicare Portal via SQLi Probes // HIGH AI Chatbots Poisoned via Web Seeding in Disinformation Campaign // FIRST LOOK Outerlimit Launches Decentralized AI Agent Authorization Layer // FIRST LOOK OWASP Flags AI Agent Unbounded Consumption as Top Enterprise Risk //
CVE-2026-81578: PaperCut Exploited by AI Agents at Scale

CVE-2026-81578: PaperCut Exploited by AI Agents at Scale

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 6.2 The Hacker News

Two actively exploited PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) are being weaponised by a suspected Russian-speaking threat actor using hundreds of AI agents powered by OpenAI Codex and a DeepSeek model to conduct large-scale authentication bypass and code execution attacks. The campaign has compromised at least 395 organisations across 48 countries, with a heavy focus on the U.S. education sector. PaperCut has released full maintenance releases superseding earlier emergency patches, and immediate upgrade is advised.

AI-Generated Zero-Day: 2FA Bypass in Web Admin Tool

AI-Generated Zero-Day: 2FA Bypass in Web Admin Tool

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 9.2 The Hacker News

Google's Threat Intelligence Group has confirmed the first known instance of a threat actor using an AI model to discover and weaponize a zero-day vulnerability — a 2FA bypass in a popular open-source web administration tool. The exploit, delivered via a Python script bearing hallmarks of LLM-generated code (including hallucinated CVSS scores and structured docstrings), was designed for mass exploitation. This marks a significant inflection point in the offensive AI threat landscape, demonstrating that AI-assisted vulnerability discovery and weaponization has moved from theoretical risk to confirmed operational reality.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.