Cyber Security News
Rhysida Dumps 5.8TB of Berlin Government Data After the City Refuses 30 Bitcoin
Rhysida published approximately 5.79 terabytes across roughly 1.44 million files stolen from Berlin's state administration on September 4, after the Senate refused a 30 BTC (~€2 million) demand and the auction countdown expired around 15:35 local time. Exfiltration occurred between August 7 and 12 from the Senate Department for Mobility, Transport, Climate Protection and Environment, but Berlin did not disconnect affected departments from the shared Landesnetz backbone until August 14. That seven-day detection-to-isolation gap converted a two-department intrusion into a metropolitan-scale exposure. The trove reportedly includes plaintext credentials, a payment database, personnel dossiers, civil protection and CBRN response planning, and KRITIS critical-infrastructure assessments.
Why it matters: The contents outrank the tonnage: plaintext credentials and KRITIS planning documents turn a data leak into an active follow-on intrusion problem and a counterintelligence gift, and the seven-day containment delay means the root cause was decision authority, not tooling.
Sources: SecurityAffairs | The Straits Times | The CyberSec Guru | BleepingComputer
CISA Adds Seven Actively Exploited Flaws, Three of Them AI Infrastructure
CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalog on September 2, spanning SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kestra OSS, Starlette, and BerriAI LiteLLM. Two carry maximum CVSS 10.0 scores. Three of the seven target AI or ML infrastructure (the first KEV batch where AI components make up nearly half the additions), and observed post-exploitation activity splits between cryptominers and hands-on reverse shells. Wiz attributed the combined LiteLLM and Starlette activity to the Qilin ransomware group.
Why it matters: AI middleware has crossed from emerging risk to catalogued exploitation, and a ransomware operator chaining flaws in the AI stack means these gateways now need VPN-grade patch SLAs, not developer-tooling ones.
Sources: The Hacker News | CISA | CyberSecureFox | Forkast
BadHost Puts an Invisible Dependency on the Mandatory Patch List
CVE-2026-48710, dubbed BadHost, is a CVSS 6.5 HTTP request smuggling flaw in Starlette added to KEV on September 2. Starlette is the ASGI framework underneath FastAPI, and it processes every HTTP request reaching LiteLLM, vLLM, and the large population of Python-based MCP servers. Almost no organization lists Starlette in its asset register, and Wiz has tied the LiteLLM and Starlette chain to confirmed Qilin exploitation.
Why it matters: A 6.5 sitting beneath thousands of AI gateways has a blast radius that score-driven patch prioritization will systematically miss: resolve your actual dependency tree today rather than searching a CMDB for a vendor name.
SonicWall SMA1000 Takes Its Third SSRF Zero-Day in Nine Months
SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in the SMA1000 Appliance Work Place interface carrying a CVSS 10.0, chained with CVE-2026-83549, a post-authentication OS command injection in the AMC component, for unauthenticated remote code execution. Both are confirmed exploited in the wild and were added to KEV on September 2. This is the third separate zero-day advisory for the same appliance family in nine months, and the fifth actively exploited SMA 1000 flaw since late 2025, with the flaw pattern repeating nearly verbatim. Reporting indicates MFA seeds harvested during the July intrusions remain valid after the September patches.
Why it matters: Patching does not remediate this: firmware updates do not revoke stolen seed material, so anyone who patched in July and closed the ticket may still be authenticating attackers today.
Sources: Rapid7 | SecurityWeek | Tech Times | CyberScoop
AI Agents Run a Complete Ransomware Intrusion in Under Ten Hours
Palo Alto Networks Unit 42 documented a September 2 incident in which a human-directed operator used frontier AI agents to dismantle an enterprise victim's cloud, identity, CI/CD, and SaaS defenses in under 10 hours. Researchers estimate that work would take a human team roughly two weeks. The campaign spanned more than 50 MITRE ATT&CK techniques and used no zero-days: entry came from an exposed API, hard-coded credentials, and excessive cloud permissions. The agents generated an 80-page security audit of the victim environment as a postscript. Cybernews separately found an exposed server holding ~3.1TB from 30-plus organizations belonging to a Gentlemen affiliate running an AI agent for reconnaissance and exfiltration, at an estimated $0.40 to $4.00 per target.
Why it matters: A 10-hour full-chain compromise finishes before a next-business-day IR retainer picks up the phone, and at a few dollars per target, campaign concurrency stops being limited by operator headcount.
Sources: Unit 42 | The Register | CSO Online | TMC Insight
FulcrumSec Publishes 8.7 Million Manchester Airport Travellers After Refusal
FulcrumSec published roughly 549GB of uncompressed data covering 8.7 to 8.8 million people who transited Manchester, London Stansted, and East Midlands airports, after Manchester Airports Group declined to pay. The records span car park, lounge, and Fast Track bookings plus in-airport Wi-Fi sign-ups, exposing email addresses, phone numbers, home addresses, licence plate numbers, purchasing history, and browsing device data; HaveIBeenPwned has confirmed the contents, and the set was subsequently offered for sale. Reporting notes sensitive travel information tied to public officials and high-profile individuals. FulcrumSec told press it took about 86GB, compared with the ~550GB published.
Why it matters: Ancillary services (parking, lounges, guest Wi-Fi) sit outside core aviation security programs while holding identity data at airline scale, and licence plates plus travel timing make this targeting material rather than credit-fraud fodder.
Sources: SecurityWeek | Computer Weekly | BBC | Infosecurity Magazine
Qilin Dumps ATF Case Files, Cellebrite Extractions, and Agent Records
Qilin published roughly 6.3GB allegedly stolen from the Bureau of Alcohol, Tobacco, Firearms and Explosives on September 1, after a 72-hour ransom deadline lapsed. The trove reportedly includes active case files, mobile-device extractions from iPhone and Samsung handsets, Cellebrite forensic dumps, phone communication analyses, and files tied to individual agents, including a named matter involving armored-truck robberies in Houston and Laredo. The Department of Justice confirmed the ATF ransomware incident only after Gun Owners of America publicly drew attention to it. ATF states the affected system was a legacy CALEA node not connected to core operational networks.
Why it matters: Cellebrite extractions and communication analyses expose investigative sources, methods, and uninvolved third parties: this is evidence-chain contamination with a threat-to-life dimension, not a PII loss that credit monitoring addresses.
Sources: Dataconomy | CNN Politics | SOFX | Slay News
Winona County Paid $128,539 and Was Attacked Again Months Later
Winona County, Minnesota negotiated and paid a ransom of $128,539 following a January 2026 cyberattack on its IT network. It was attacked again months later. The payment secured neither silence nor protection against repeat compromise.
Why it matters: This is the direct counterfactual to Berlin and Manchester in the same news cycle: payment bought a second intrusion inside the same calendar year, which is the strongest argument incident responders have against negotiation.
Sources: MPR News
Thomson Reuters C-Track Breach Reaches Courts in Eleven States and Two Countries
Thomson Reuters disclosed on September 2 to 4 that an unauthorized party spent roughly four months inside its cloud environment extracting files from C-Track, the court case management platform sold by its West Publishing Corporation unit. The intrusion dates to March 2026; West Publishing discovered it on June 30 (about 110 days later). Affected jurisdictions span 11 US states, the US Virgin Islands, and Ontario, with exposed records potentially containing names, Social Security numbers, medical information, and sealed court data. Affected courts say the company held backup copies of their case data that they neither requested nor knew existed. The New Hampshire Supreme Court confirmed on September 5 that its data was accessed.
Why it matters: Sealed records include juvenile proceedings and protected witness information, so this is a physical-safety event, and the loss occurred in vendor-side retention the data owners had no visibility into.
Sources: Help Net Security | Gizmodo | Valley News / NHPR | ABA Journal
IDScan Breach Puts 153 Million Driver's Licenses and Their Infrared Layers Up for Sale
A dark web marketplace called Nexus surfaced this week selling high-resolution scans of more than 153 million North American driver's licenses sourced from identity-verification vendor IDScan.net. The listings include the infrared and ultraviolet captures banks and government agencies use to confirm a physical document is genuine. The FBI's New Orleans field office opened an investigation on September 1, the marketplace went offline within hours, and the dataset reportedly includes the license of US Secretary of Defense Pete Hegseth. Multiple class-action investigations have opened against IDScan.
Why it matters: The IR/UV layers are the verification substrate itself, not the identity data verification protects: this degrades a control rather than exposing records, and credit monitoring is not a remediation for it.
Sources: TechTimes | BleepingComputer | Tom's Hardware
China-Linked Operators Broke Into Hotel Rooms to Boot Executive Laptops From USB
CrowdStrike's 2026 Threat Hunting Report attributes to China-linked OVERCAST PANDA a series of physical intrusions against business travelers in China between March and May 2026. Operators entered hotel rooms while executives attended dinner at an agricultural industry conference on Hainan Island, booted the unattended laptops from USB media, and installed the FlowCloud backdoor, writing the implant before the host operating system, and therefore before any endpoint security tooling, ever loaded. The exploited weakness had an available vendor fix the affected companies had not enabled.
Why it matters: This invalidates the assumption underpinning most executive-travel programs (that a laptop locked in a room is a laptop at rest), and the controls that break the chain (pre-boot authentication, Secure Boot enforcement, firmware boot-order lockdown) are not EDR features.
Sources: NOVALOGIQ | The SaaS Sentinel | Lapaas Voice
Fire Ant Hides GRE Tunnels Inside Cisco Routers That Config Audits Cannot See
Sygnia reported that Chinese actor Fire Ant has pivoted from VMware hypervisors to compromising Cisco IOS XR routers, TACACS+ authentication servers, and Linux management hosts. Investigators detected the activity after finding an active GRE tunnel interface on an IOS XR router that could not be accounted for by the running configuration or the device's commit history. The tunnel existed in operational state while remaining invisible to configuration audit. The group deployed TacTap, described as the first publicly documented malware injecting code directly into a running TACACS+ authentication daemon, harvesting credentials in transit while evading file-integrity monitoring, and actively suppressed logging.
Why it matters: Credential theft at the TACACS+ layer collapses network segmentation across every device that authenticates against it, and config-diff review (the standard network audit workflow) will not surface any of it.
Sources: The Hacker News | Geek Feed | CSO Online | Brinztech
APT28 Turns Microsoft Edge Into Its Own Command Channel With HOOKEDGE
Recorded Future's Insikt Group documented APT28 campaigns against government, diplomatic, and defense-manufacturing organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026, delivering HOOKEDGE: a previously undocumented lightweight Windows batch-script backdoor distributed through malicious Word macro documents impersonating government ministry meeting agendas. The backdoor drives Microsoft Edge as a proxy to retrieve C2 instructions from a free public developer testing service, meaning there is no dedicated attacker infrastructure to block or sinkhole. Reporting describes a two-stage triage model that fingerprints victims before deploying the backdoor to high-value targets.
Why it matters: Blocklist-based network defense fails by design here: the courier is a signed Microsoft browser process and the command channel is a legitimate developer domain, so detection has to move to process lineage rather than domain reputation.
Sources: Xcitium Threat Labs | Rescana | gbhackers | securityonline.info
Leaked Bauman University Files Expose the GRU's Cyber Recruitment Pipeline
More than 2,000 internal documents leaked from Bauman Moscow State Technical University expose a previously undisclosed "Department No. 4" that trained hackers, malware developers, information-warfare operators, and propagandists for Russia's GRU. Reporting links graduates and the department's placement system to personnel associated with APT28 and Sandworm, tying specialist academic training directly to military service assignments. The material documents curriculum, personnel flow, and unit affiliation rather than any intrusion set, and was reviewed by an international journalistic consortium rather than issued as a government attribution.
Why it matters: This converts a long-held analytic assumption into documented fact and gives attribution analysts a basis for tracking future operator cohorts and anticipating capability continuity even when individual units are disrupted.
Sources: Security Affairs | SC Media | DigitalShield
Famous Chollima Gets Legitimately Hired, Then Plugs In a Hardware KVM
Huntress published five real 2026 intrusion cases in which the DPRK-linked Famous Chollima group used stolen and AI-forged identity documents to apply for, interview for, and be legitimately hired into remote IT development, sales, and marketing roles. Once onboarded, operators used hardware KVM devices to control corporate endpoints in a way that bypasses installed security software entirely. Separately, Rapid7 Labs attributed a Linux toolkit (the "ted backdoor," compiled directly into victims' own HAProxy builds) plus curlRAT to DPRK operators targeting South Korean media and automotive organizations.
Why it matters: A hardware KVM sits below the operating system, so EDR, DLP, and session recording observe a legitimate employee at a legitimate console: the control point moves out of the SOC and into HR identity verification at hire.
Sources: Hendry Adrian / Rapid7 | Livdose
Boston Scientific Cyberattack Halts Global Shipments of Implantable Devices
Boston Scientific disclosed in an SEC filing that a cyberattack detected on August 25 struck its on-premises IT and caused what the company itself terms a "global disruption," halting order processing and shipping. The company manufactures pacemakers, defibrillators, stents, and other implantable devices, and more than a week after detection there was still no confirmed restoration timeline. Separately, Baylor Genetics confirmed on September 4 a cyberattack compromising data belonging to approximately 2.8 million patients and employees.
Why it matters: This is a supply-side healthcare incident, not a records breach: the harm is physical availability of implantable cardiac devices, which puts third-party dependency on device and diagnostics manufacturers into the continuity plan rather than the vendor questionnaire.
Mathspace and Two Korean Platforms Show What Consumer-Scale Soft Targets Cost
Online maths education provider Mathspace confirmed that between August 10 and August 27 unauthorised parties accessed an internal system, compromising names and email addresses for more than one million students, school staff, parents, and guardians across Australia and New Zealand. That amounts to a 17-day dwell window before detection, against a victim population that is overwhelmingly minors. Separately, Weverse Company disclosed on September 6 that data tied to 422,584 account IDs leaked from Hive's global fandom platform, after learning of the leak from an external party; South Korea's Ministry of Science and ICT closed its probe into the Tving breach at approximately 39.54 million accounts, plus 361 technical assets including source code and internal access keys sent overseas, attributing the incident to failure to separate development and production environments.
Why it matters: Tving's stolen source code and access keys mean the June intrusion may not be closed even though the initial vector was remediated, and Mathspace's roster is a durable social-engineering asset that makes "from your school's maths platform" lures credible for years.
Sources: ABC News | The Korea Herald | The Asia Business Daily | UPI
Settra and Panzer Show How Cheap It Now Is to Stand Up an Extortion Brand
Settra, a data-theft crew, has named 64 organizations on its leak site since the end of June across just 12 posting days, matching Akira's identical 64-victim count spread over 34 days while staying far lower profile. Panzer, a previously unknown RaaS whose leak site first appeared on August 5, has listed between 16 and 19 alleged victims across 11 countries in a single month, with Windows, Linux, ESXi, and FreeBSD payloads and an 80/20 affiliate split. No Panzer indicators of compromise have been independently confirmed. Meanwhile, an updated FBI, CISA, and HHS advisory confirms Medusa has compromised more than 500 organizations since June 2021.
Why it matters: Burst posting distorts leak-site-derived threat rankings, and Panzer's multi-platform maturity at one month old suggests experienced operators rebranding: treat victim counts as marketing until corroborated.
Sources: IntelFusions | GBHackers | IT Security News | National Cyber Security Consulting
AI News
OpenAI Ships GPT-6 Astra as Its First Model Rated Critical for Cyber Capability
OpenAI released GPT-6 Astra on September 3, the first model formally designated as meeting the company's "critical cybersecurity capability threshold" under its Preparedness Framework (the top tier), with the rating published simultaneously with the release. OpenAI disclosed that Astra can locate zero-day vulnerabilities in hardened systems and convert them into working exploits without step-by-step human direction, and that five weeks earlier the model produced proofs for ten long-unsolved problems in mathematics and theoretical computer science. It carries a 1M-token context window, ships to the public API, ChatGPT paid plans, Azure, and Bedrock, and was trained on more than 100,000 GPUs. President Greg Brockman says it operates software directly without per-app connectors.
Why it matters: A lab has shipped at full commercial availability a model it internally classifies as crossing a dangerous-capability line: the first live test of whether preparedness frameworks constrain deployment or merely annotate it.
Sources: The Verge | WIRED | Ken Huang | Decrypt
OpenAI Revised Astra's Benchmark Numbers After Launch Without Announcing It
Fortune reported that OpenAI edited several published GPT-6 Astra benchmark figures in the days following the September 3 launch, including halving the stated hallucination rate and then reverting it, and raising a cybersecurity score by using a reasoning tier that is not commercially available. The revisions mostly flattered Astra; some of Anthropic's published comparison scores also moved. No announcement accompanied the changes. Separately, R&D World reported Astra scoring 62.7% on an interactive reasoning benchmark under provider-neutral conditions and near-perfect with a custom OpenAI-supplied adapter.
Why it matters: A cybersecurity score attained on a non-purchasable reasoning tier is not reproducible by any customer, and the Critical cyber designation is the load-bearing claim of the entire launch.
Sources: Startup Fortune | NewsBytes | R&D World
Four Frontier Labs Shipped in One Week and Buyers Stopped Being Able to Evaluate
Anthropic (Claude Fable 5.1 and the gated Mythos 5.1, September 1), Meta (Muse Spark 1.3, September 2), Google (Gemini 3.8 Flash, September 2), and OpenAI (GPT-6 Astra, September 3) all shipped flagship updates within days, joined by Tencent's HY4 Preview and an xAI Grok 4.3 batch variant. LLM Price Watch logged nine new model IDs between September 2 and 5 with no reported price changes. CNBC labeled the resulting buyer paralysis "model fatigue," and over 1,100 lab employees petitioned Washington to help pace frontier development.
Why it matters: Release cadence has outrun enterprise evaluation cycles, so procurement decisions are increasingly made on vendor claims rather than independent validation: precisely the gap the benchmark-revision story exploits.
Sources: SiliconReport | PulseAugur | Startup Fortune | Pat McGuinness
Artificial Analysis Rewrote Its Index One Day After Astra Shipped
Artificial Analysis released Intelligence Index v4.2 a day after Astra's launch, an interim update pulling elements forward from the planned v5. The changelog adds AA-Briefcase, an agentic knowledge-work eval with a private test set, and Surge's GDP.pdf, a long-context reasoning eval across 4,592 PDF pages, while dropping GPQA Diamond. Held-out data now accounts for 40% of index weighting. Under the new methodology Claude Fable 5.1 tops the leaderboard with Astra second, after Astra had initially shown no jump over GPT-5.6 Sol on the prior version.
Why it matters: The headline number that justified a procurement decision last week may not survive the next methodology revision, and a 40% held-out weighting is a structural bet that contamination, not capability, had become the binding constraint on measurement.
Sources: OfficeChai | Artificial Analysis | PressReleaseCloud
OSWorld 2.0 Caps the Best Computer-Use Agent at 72.6 Percent
OSWorld 2.0 evaluates AI agents on 108 hour-long real-world computer-use workflows spanning 31 self-hosted websites and professional desktop applications, with tasks averaging more than 300 agent steps. GPT-6 Astra leads and completes only 72.6% of them. The benchmark was built specifically because eighteen months of "computer use" announcements have outpaced verified performance on real software operation.
Why it matters: Roughly one in four long-horizon desktop tasks still fails for the best available system, which is disqualifying for unattended deployment and is the cleanest available calibration against "AGI era" framing.
Sources: Miraflow | Snorkel AI
Anthropic's Claude Produces the First Machine-Checked Proof of Fermat's Last Theorem
Anthropic says Claude generated a fully computer-verified proof of Fermat's Last Theorem, writing roughly 13 million lines of machine-checkable code largely on its own over an 11-day run, now the longest formal proof ever constructed. Because the output is machine-checked, no human trust in the model's reasoning is required: the proof either compiles against the verifier or it does not. The comparable human-led formalization effort has been running far longer on the same job.
Why it matters: This is the one capability claim this week that sidesteps the benchmark-trust problem entirely, and it generalizes: sustained multi-day autonomous work is now viable in any domain with a checker, such as compilers, type systems, test suites.
Sources: Decrypt
Anthropic Splits One Model Into Two Access Tiers and Ships Almost Nothing Publicly
Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1 as twinned versions of the same underlying model, differentiated by how safety scaffolding is applied: Fable ships broadly with up to 45% cheaper agentic operation, a 75% cache-read price cut, and deliberately reduced false-positive refusals, while Mythos remains restricted to vetted US cybersecurity and life-sciences organizations. Astra shipped two days later to the public API, ChatGPT paid plans, Azure, and Bedrock. Anthropic separately signed a $35 billion infrastructure deal with Lambda days before launch.
Why it matters: Decoupling the safety layer from the weights lets one training run serve a mass-market product and a restricted high-capability tier, but capability parity is irrelevant to builders who cannot get an API key, which hands the default-integration position to whoever ships widest.
Sources: The Verge | TechCrunch | DataStudios | SiliconANGLE
Gemini 3.8 Flash Reaches Near-Frontier Coding at 15 Percent of Frontier Cost
Google launched Gemini 3.8 Flash on September 2 (its third Flash-tier release in six weeks), scoring 73.7% on DeepSWE v1.1, within one percentage point of Claude Opus 5's 74.0%, at roughly 15% of Opus 5's invocation cost. The security-tuned sibling, Gemini 3.8 Flash Cyber, topped all commercial models tested in its category and is reported to outperform rivals by 2.6x on Chrome vulnerability discovery while writing patches autonomously; access is restricted to vetted governments and infrastructure operators. The context window did not change from 3.7 Flash, and pricing is set to double in January 2027.
Why it matters: Near-parity coding at a fraction of the price collapses the case for routing every agentic task to a frontier model, but the unchanged context window makes this quality-per-token, not capability expansion, and the cost ratio is introductory.
Sources: Winzheng | Google Blog | Tech Insider | Ars Technica
Astra's Architecture Reasons Outside Readable Text, and Safety Researchers Object
Per The Information, Astra uses a technique called "recurrent depth," also known as "opaque recurrence," which lets the model reason outside the sequential token-by-token process characterizing current reasoning models. Chain-of-thought monitoring (the main practical interpretability tool the field has for reasoning models) depends on that thinking happening in readable text. Safety researchers raised objections about transparency and monitorability across all three labs' newest systems, not just OpenAI's.
Why it matters: The industry's post-hoc oversight strategy quietly assumes reasoning traces are legible; recurrent depth breaks that assumption at the architecture level with no demonstrated replacement, degrading interpretability precisely as stakes rise.
Sources: TechCrunch | Rediff | Techy101
The G20 Endorses a Deregulatory AI Framework While Brussels Opens Its First Enforcement Actions
At the G20 Innovation Ministerial in Chapel Hill on September 1, OSTP Director Michael Kratsios presented the "Carolina Principles," asking countries to commit to sector-specific rulemaking, avoid creating new AI-specific regulatory bodies, and reserve legislation for "truly novel circumstances." G20 members adopted the non-binding guidelines unanimously. China signed the same afternoon. Hours later, the European Commission sent AI Act information requests to more than 30 companies, its first use of new enforcement powers, with penalties available for misleading replies and authority since August 2 to order a foundation model withdrawn from the EU market. Mark Zuckerberg separately told President Trump by phone that a national AI regulator is a flawed idea.
Why it matters: "No new regulatory bodies" forecloses the enforcement capacity any future AI rule would need, and an alignment between the US and China on a light-touch floor isolates Brussels rather than the reverse.
Sources: The Star | Winzheng | Business Insider | Superpower Daily
Trump Signs an Executive Order Creating a Voluntary Federal Pre-Release Review Channel
President Trump signed an executive order establishing a voluntary process under which some AI companies share their most advanced models with the federal government before public release, a deliberately narrower instrument adopted after the White House abandoned a stricter proposal the prior month. The mechanism is already live: government evaluators received up to 30 days of access to Astra ahead of launch. Separately, four federal agencies face a lawsuit seeking disclosure of the rules used in those non-public reviews, which exist but whose criteria appear in no public document.
Why it matters: A 30-day federal evaluation window is now a de facto step in the frontier release calendar, but it is voluntary, time-boxed, carries no authority to block a release, and runs on undisclosed criteria.
Sources: WNIS | Ars Technica | Axios
Sanders Introduces a Bill to Ban Superintelligent AI Outright
Sen. Bernie Sanders introduced a measure that would ban work on superintelligent AI and impose a temporary pause on advanced AI development, arriving in the same legislative batch as a separate bill establishing AI oversight at the Pentagon. It is the first US federal proposal attempting a categorical prohibition rather than a disclosure or standards regime. Reuters separately reports the US and China are preparing a mid-September dialogue focused exclusively on frontier AI safety risks, the first official bilateral talks between the two governments dedicated entirely to AI.
Why it matters: Introduction days after OpenAI declared an "AGI era" marks the point where lab marketing language starts generating direct legislative blowback, and it exposes a Congress simultaneously weighing a frontier ban and formalizing frontier use inside the Department of Defense.
Sources: Nextgov/FCW | CNBC
Agent Harness Research Names Four New Attack Classes in One Week
Four papers landed on the agent-runtime attack surface: attacker-controlled hook updates steering agent harnesses toward malicious behavior through trust-on-first-use configuration; context privilege escalation, where content entering a context window at low privilege acts with high-privilege authority; endogenous authorization laundering, where content written to agent memory is later read back as trusted self-originated context; and ECLIPSE, a self-evolving prompt injection optimized for stealth across long task horizons rather than immediate compliance. Manifold Security separately disclosed GitSpawn, in which a repository's own .git/config forces a command-line coding agent to execute attacker-chosen code the moment it inspects the repo: no malicious dependency, no poisoned prompt, no compromised MCP server.
Why it matters: Memory turns a one-shot injection into a persistent implant that outlives incident response, and GitSpawn makes any triage bot or automated PR reviewer that clones untrusted repositories a live RCE path today.
Sources: arXiv:2609.03884 | arXiv:2609.01222 | arXiv:2609.01836 | Cloud Security Alliance
Safety-Stripped Open Models Reach Near-Parity on Autonomous Vulnerability Discovery
NSFOCUS's security agent, built on Zhipu's GLM-5.3, took the top CyberGym Level 1 ranking at a 95.02% vulnerability-reproduction success rate. Independently, an abliterated (safety-stripped) derivative of the same GLM-5.3 base was released for offensive cyber work, scoring 84.5% pass@1 on CyberGym's 1,507 OSS-Fuzz bugs across 188 projects, within roughly one point of GPT-5.5's 85.6%, and hosted in FP8 as a drop-in endpoint swap requiring only a model-ID change. Separately, researchers found a real division-by-zero flaw in FFmpeg (one of the most heavily fuzzed codebases in existence) using LLM-written fuzz harnesses.
Why it matters: Frontier-lab access gating provides little practical restraint when a refusal-trained-out open-weight model reaches parity by API key swap: assume the disclosure-to-exploit window on OSS CVEs compresses from weeks to hours.
Sources: NSFOCUS | abliterated-model-large-v2 | Safety Watch
McKinsey Finds Agent Scaling at 40 Percent While Bottom-Line Impact Sits Flat
McKinsey's State of AI survey reports that 40% of large enterprises now say they are scaling AI agents across at least one business function, up from 27% a year ago. The share reporting any bottom-line impact from AI has not moved, stuck at 37% for two consecutive years. Separately, Guild's Software Factory now autonomously writes 34% of the company's merged pull requests and 56% of its code fixes, and DoorDash has processed 130,000 engineering tasks through its cloud agent platform.
Why it matters: Deployment is compounding and returns are not, which is the strongest available evidence the bottleneck is organizational (process redesign, measurement, integration surface), not model capability, and nine new frontier models will not close it.
Sources: Big AI Agent | InfoQ
Fifty-Turn Conversations Break Models by Two Orders of Magnitude
A University of Arizona team published in Nature's Scientific Reports on September 1 testing seven widely used chatbots across 50-turn sequences of deliberate falsehood, finding affirmation rates spanning 0.08% to over 10%, a two-order-of-magnitude spread across leading systems, with the failure emerging only under sustained multi-turn pressure that single-question probes never surface. Separately, WDCD Run #311 evaluated 11 models on three-round multi-turn dialogues, with Grok 4 leading at 93.2 points.
Why it matters: Nearly every headline score is single-turn while nearly every agentic deployment is long-running, and a 100x per-model spread makes multi-turn robustness a real selection criterion the leaderboards do not price.
Sources: Progressive Robot | Winzheng
Active Exploitation Watchlist + Notable CVEs
| CVE | Product | Severity | Status | Action |
|---|---|---|---|---|
| CVE-2026-83548 | SonicWall SMA 1000 (6210, 7210, 8200v) pre-auth SSRF | 10.0 Critical | Actively Exploited | Patch Now |
| CVE-2026-49869 | Kestra OSS pre-auth OS command injection | 10.0 Critical | Actively Exploited | Patch Now |
| CVE-2026-59310 | VMware vCenter Server Syslog directory traversal | 9.8 Critical | Actively Exploited | Patch Now |
| CVE-2026-0768 | Langflow root-level remote code execution | 9.8 Critical | Actively Exploited | Mitigate |
| CVE-2026-82329 | JFrog Artifactory authentication bypass | 9.8 Critical | Actively Exploited | Patch Now |
| CVE-2026-20212 | Cisco Nexus 9000 Silicon One unauthenticated root RCE | 9.8 Critical | Patch Available | Patch Now |
| CVE-2023-49105 | ownCloud authentication bypass | 9.8 Critical | Actively Exploited | Patch Now |
| CVE-2026-9586 | Sangoma Switchvox unauthenticated SQL injection | 9.3 Critical | Actively Exploited | Patch Now |
| CVE-2026-0300 | Palo Alto PAN-OS User-ID Portal unauthenticated root RCE | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-19490 | Citrix NetScaler ADC/Gateway authentication bypass | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-59822 | BerriAI LiteLLM improper authentication (MCP tool invocation) | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-83549 | SonicWall SMA 1000 AMC post-auth OS command injection | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-12569 | PTC Windchill / FlexPLM unauthenticated RCE | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-81578 | PaperCut NG/MF missing authentication for critical function | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-82078 | PaperCut NG/MF unsafe reflection | N/A Critical | Actively Exploited | Patch Now |
| CVE-2026-85046 | Google Chrome V8 Maglev JIT type confusion | N/A High | Actively Exploited | Patch Now |
| CVE-2026-68820 | Windows AFD.sys use-after-free (Lazarus, FudModule rootkit) | N/A High | Actively Exploited | Patch Now |
| CVE-2026-21513 | Microsoft MSHTML zero-day (APT28) | N/A High | Actively Exploited | Patch Now |
| CVE-2026-18577 | N-able N-central (incomplete prior patch) | N/A High | Actively Exploited | Patch Now |
| CVE-2026-8452 | Citrix NetScaler ADC/Gateway memory buffer flaw | N/A High | Actively Exploited | Patch Now |
| CVE-2026-48710 | Starlette HTTP request smuggling (BadHost) | 6.5 Medium | Actively Exploited | Patch Now |
| CVE-2026-75925 | IXON VPN Client privilege-escalation RCE (<1.4.7) | N/A High | Patch Available | Patch Now |
The Edge
The ransom economy quietly broke this week, and almost nobody said so out loud. Berlin refused 30 bitcoin and ate 5.8 terabytes including plaintext credentials and CBRN planning documents. Manchester Airports Group refused and 8.7 million travellers went up for sale. The ATF refused and Qilin published Cellebrite extractions from active investigations. And Winona County, Minnesota (which did pay, $128,539 of it) got hit again months later. Four data points, one conclusion: paying does not buy safety and refusing does not buy silence. The decision that incident response has organized itself around for a decade turns out not to be a decision at all. It is a coin flip on which flavor of loss you absorb.
What replaces it is uglier and more expensive, because the terminal state is now permanent publication and every organization has to plan for it in advance rather than negotiate it away. That means the operative variable is no longer negotiation posture but containment tempo. Berlin is the whole lesson. The intrusion touched two departments. Detection worked. What failed was that nobody had authority to sever the Landesnetz backbone for seven days, and in that window a containable event became a metropolitan-scale counterintelligence exposure with credentials attackers can still use. The question every federated organization should be answering on Monday is not "would we pay." It is: who can pull the cable at 2 a.m., and do they need a committee?
Now layer on the timing problem. Unit 42 watched AI agents run a full ransomware chain in under ten hours across fifty-plus techniques, using nothing but an exposed API, hard-coded credentials, and overly broad cloud permissions, and it cost the operator somewhere between forty cents and four dollars. Berlin's authority chain took seven days. That is not a gap you close with better alerting or a faster analyst rotation; the two processes are running on incompatible clocks. Meanwhile a safety-stripped GLM-5.3 derivative hit 84.5% on CyberGym for the price of a model-ID swap, which means the vetted-access programs that OpenAI, Anthropic, and Google all announced in the same week are already leaking around the edges. Gating capability by customer identity is a real control right up until the open-weight equivalent lands one point behind the frontier.
Here is the uncomfortable part. The same week the labs shipped models classified Critical for cyber capability, the G20 unanimously endorsed a framework asking governments not to build the institutions that would oversee them, and China signed. The federal pre-release review that did examine Astra is voluntary, thirty days, no authority to block, and its criteria are the subject of a lawsuit because nobody outside government has seen them. Every governance mechanism arriving this quarter is either non-binding, undisclosed, or aimed at the model layer while the actual failure surface migrated to the harness: hook update channels, context privilege escalation, agent memory as a persistent implant, a .git/config that owns your triage bot. Watch the KEV catalog, not the policy docket. Three of seven additions on September 2 were AI infrastructure, and one of them (a CVSS 6.5 in a transitive ASGI dependency almost nobody has in a CMDB) sits under the entire Python AI stack. That is where this decade's Log4Shell is going to come from, and severity-driven patch prioritization will walk straight past it.