LIVE FEED
Agentic AI Pentesting Closes Gap as Exploit Speed Hits 5 Days

Agentic AI Pentesting Closes Gap as Exploit Speed Hits 5 Days

ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 6.5 The Hacker News

A new guide for CISOs highlights the growing role of autonomous AI agents in continuous web pentesting, citing industry data showing attackers exploit vulnerabilities in ~5 days while defenders take 43 days to patch. The piece references proven autonomous pentesting capability — including an AI system topping HackerOne's leaderboard in 2025 — and warns that AI/LLM applications carry critical findings at 2.7x the rate of traditional apps. Security leaders are urged to demand provable coverage, blast-radius guardrails, and audit trails before deploying agentic pentesting tools against production environments.

Google Chrome Shifts to Two-Week Release Cycle for Faster Security Patches

Google Chrome Shifts to Two-Week Release Cycle for Faster Security Patches

FIRST LOOK ATLAS OWASP LOW Limited impact · Standard review ▲ 5.5 TechCrunch AI

Google has accelerated Chrome's release cadence from four weeks to two weeks, beginning with Chrome 153, explicitly citing AI-driven increases in vulnerability discovery and threat velocity as the rationale. For defenders, this halves the N-day patch gap — the window between a known vulnerability and a patched browser reaching end users — a meaningful reduction in exposure time for one of the world's most widely deployed attack surfaces. Residual gaps remain around enterprise patch governance, the challenge of validating rapid updates at scale, and whether two-week cycles are sufficient against AI-accelerated zero-day exploitation timelines.

Microsoft MDASH Brings AI-Powered Windows Vulnerability Discovery

Microsoft MDASH Brings AI-Powered Windows Vulnerability Discovery

FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 BleepingComputer

Microsoft has deployed MDASH (Multi-model Agentic Scanning Harness), an AI-powered agentic system that autonomously scans Windows binaries for vulnerabilities and validates findings through multiple AI models before human engineer review. The accelerated discovery pipeline means defenders will see a higher volume of Patch Tuesday fixes, compressing patch deployment windows and increasing pressure on enterprise patch management processes. Simultaneously, the same AI-accelerated vulnerability discovery capability is available to adversaries, raising the risk that threat actors identify and weaponise flaws faster than Microsoft's pipeline can remediate them.

CVE-2026-43715: Apple WebKit Memory Corruption Flaw

CVE-2026-43715: Apple WebKit Memory Corruption Flaw

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 The Hacker News

Apple patched over 30 vulnerabilities across iOS, macOS, and Safari, with four WebKit flaws credited to AI-assisted discovery by OpenAI Codex Security and Anthropic researchers using Claude. The disclosure marks a notable shift in AI's role in offensive and defensive security research, with Apple explicitly citing AI-accelerated exploit development as the reason for expediting its patch release timeline. This represents a concrete, documented instance of AI tooling being used to find memory corruption and use-after-free vulnerabilities in a major browser engine.

CVE-2026-5194: Anthropic Claude Discovers 10,000+ Flaws

CVE-2026-5194: Anthropic Claude Discovers 10,000+ Flaws

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 The Hacker News

Anthropic's Project Glasswing has deployed Claude Mythos Preview — a frontier AI model — to autonomously discover over 10,000 high- and critical-severity vulnerabilities across widely used open-source software, with 1,094 confirmed as valid high/critical flaws. The initiative highlights a growing asymmetry: AI is accelerating vulnerability discovery far faster than the security community can remediate, compressing patch windows and raising the stakes for defenders. Anthropic is now urging shorter patch cycles and hardened defaults, warning that comparable offensive capabilities could soon be broadly accessible to threat actors.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.