Cyber & AI intelligence
Wasteland.
Briefs indexed2910
Issues30
Published Mondays07:30 CT
▸ Issue No. 030 · 2026-09-28

The Guardians Are Now the Easiest Way In

Wasteland Weekly· Editor's note

Cyber Security News

ShinyHunters Bypasses PeopleSoft WAF Rules With One Encoded Letter

Mandiant and GTIG report that ShinyHunters (UNC6240) has resumed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft that Oracle patched more than three months ago. WAF rules that block the vulnerable PSEMHUB endpoint are bypassed by requesting /%50SEMHUB/, a single URL-encoded character. After exploitation the group deploys web shells, SIDEEYE malware through a trojanized Ple64.exe, Neo-reGeorg tunnels and MeshAgent. Targeting has spread from education into tech, healthcare, agriculture, transportation and government. Google has notified more than 100 organizations, and DataBreach.com counts dozens of companies hit.

Why it matters: Any PeopleSoft instance that relied on virtual patching should be treated as compromised until proven otherwise, and the only fix is Oracle's patch.

Sources: BleepingComputer | The Hacker News | DataBreach.com

FBI Confirms Incident as ShinyHunters Leaks Agents' Psychiatric Records

On September 26 the FBI confirmed a "cybersecurity incident" involving FBIJobs.gov. ShinyHunters defaced the portal on September 22 and says it took 2 to 3 TB on agents and applicants, reportedly through a PeopleSoft zero-day. BBC has seen samples of fitness-for-work medical exams, and Reuters reviewed documents the group says include psychiatric evaluations. A 5,000-line spreadsheet lists home addresses, SSNs and assignments against Chinese and Russian intelligence, cartels and HUMINT. The group calls the attack retaliation for an FBI advisory that told victims not to pay, and it wants that advisory retracted.

Why it matters: An extortion crew is now using stolen data to try to silence defensive advisories, and the leaked records are a counterintelligence problem well beyond ordinary identity theft.

Sources: BBC | The Star / Reuters | Nextgov/FCW | The Register

McKesson Confirms Breach as ShinyHunters Demands $55 Million

McKesson has confirmed that attackers stole company and patient data. ShinyHunters says it holds millions of patient records and is demanding $55 million not to publish them. McKesson has narrowed the confirmed theft to its oncology and multispecialty customers and will notify patients. It has not confirmed the ransom figure or how the attackers got in.

Why it matters: Oncology practices that use McKesson services now face notification and fraud exposure from an incident they could not control, and they should get written confirmation of whether their data is in scope.

Sources: Morning Overview | Medical Daily

ShinyHunters Takes Over Clop's Leak Site Through a Grav CMS Flaw

Between September 18 and 19, ShinyHunters used CVE-2026-42608, a CVSS 9.1 unauthenticated path traversal and upload flaw in Grav CMS, to take over Clop's Tor leak site. It replaced the victim list with Umbreon ASCII art. ShinyHunters claims it took Clop's source code, logs, victim data and onion private keys, and it is demanding an eight-figure payment. Clop has confirmed the compromise and moved to a new Tor address, and Grav has backported a fix to its 1.7 branch.

Why it matters: Clop victims, including those who quietly paid, should assume a second actor now holds their data and may use the payment records to extort them again.

Sources: BleepingComputer | Threadlinqs | The Register | Anomali

Citrix Ships NetScaler Zero-Day Fixes Early; CISA Adds Two to KEV

Citrix first warned admins to shut down NetScaler appliances. On Sunday it shipped fixes for eight flaws (CVE-2026-88771 through CVE-2026-88778) in builds 14.1-73.37 and 13.1-64.23. CISA added the two exploited zero-days to KEV the same day. CVE-2026-88771 (9.5) gives unauthenticated command execution on default configurations, and CVE-2026-88772 is a memory-restriction flaw. watchTowr has already published technical analysis. In a separate case, NetScaler auth bypass CVE-2026-19490 was exploited one day after its public PoC.

Why it matters: Attacks began before the patch existed and public exploit detail is now available, so patch every NetScaler, hunt each one for persistence, and expect a second wave from less capable actors.

Sources: CISA | watchTowr | BleepingComputer | DEV Community

Check Point Gateway and Management Server Flaws Exploited Three Days After Patch

Check Point confirmed exploitation of two CVSS 9.8 flaws. CVE-2026-85102 is a pre-auth RCE in VPN certificate validation, and CVE-2026-93616 is a pre-auth path traversal and script upload in Security Management Server. Attacks on CVE-2026-85102 began September 12, three days after fixes shipped and ten days before its KEV listing. CISA gave agencies until September 25 to remediate.

Why it matters: An attacker who owns the management server can rewrite firewall policy across the whole estate, so hunt for compromise back to September 12 even if you are already patched.

Sources: BleepingComputer | SecurityWeek | Check Point | DeafNews

F5 APM, Arista VeloCloud and Cisco ISE: Access Planes Fall to Zero-Days

F5's CVE-2026-94127 (9.8) is a pre-auth heap overflow in BIG-IP APM. It is reachable when a virtual server combines an access policy with an OAuth profile, and it was exploited before a patch existed. More than 15,000 deployments may be exposed, and closing the management port does not help. Arista's VeloCloud Orchestrator CVE-2026-93952 (10.0) hands attackers the SD-WAN control plane, and CISA gave agencies three days to fix it. Cisco confirmed exploitation of CVE-2026-76460, an ISE management authentication bypass. Separately, Cisco Secure Email Gateway CVE-2026-76461 gives root RCE through a crafted email.

Why it matters: Every one of these products decides who gets access to the network, so treat them as tier-0 assets with domain-controller patch urgency and compromise assessments.

Sources: The Register | Rapid7 | IntelFusions | Phronews | DEV Community

KEV Wave Hits Web Platforms: SharePoint, WSO2, Adobe Commerce and WordPress Core

CISA added four widely deployed web platforms to KEV this week: - SharePoint CVE-2026-65660 (8.8): three-day deadline and a forensic triage requirement, although Microsoft's own record still says "exploited: No." - WSO2 CVE-2026-5430 (9.8 to 10): exploited 12 days before it was listed. - Adobe Commerce CVE-2026-71362 (9.1) - WordPress Core CVE-2026-87902 (9.2): an unauthenticated flaw in core, not a plugin.

MikroTik RouterOS CVE-2026-67279 and ransomware exploitation of TeamCity CVE-2026-63077 were added alongside them.

Why it matters: Prioritize from KEV status and threat intel, not from vendor exploitation flags, which lagged reality by days to weeks this week.

Sources: The Hacker News | Severity Daily | Tech-Insider | CISA | BleepingComputer

BlueMoon: One Chrome and Windows Zero-Day Chain, Four Chinese Espionage Clusters

Proofpoint traced the BlueMoon exploit kit from TA412 on August 28 to three more state-aligned clusters by September 3. The chain links Chrome CVE-2026-85046 and CVE-2026-87491 with Windows ALPC privilege escalation CVE-2026-85880. Volexity attributes use of the chain to UTA0565, which delivered CLEANGULP through spoofed China Digital Times and Center for American Progress sites, and to UTA0560, which dropped the GRIMWEDGE JavaScript backdoor. Whether CLEANGULP and GRIMWEDGE are related is unconfirmed.

Why it matters: A browser-to-kernel chain spread to four rival teams in six days points to a shared supplier, so a single IOC set no longer maps to a single actor.

Sources: The Terminal | CyberScoop | The Hacker News | CODERCOPS

North Korea Suspected in $351.6M Bitget Theft as WaterPlum Advisory Lands

Bitget lost $351.6 million from its hot and warm wallets on September 24. Elliptic calls DPRK involvement "highly likely" and says the theft pushes North Korea's 2026 crypto haul past $1 billion. The attribution rests partly on VPN and IP overlap, which is weak evidence. Separately, a joint advisory from Japan, the US, Australia and Germany ties WaterPlum's fake-interview campaign to the same bureau that runs the IT-worker scheme. The campaign infected 30,000 devices across more than 100 countries. TraderTraitor is now hiding payloads in .terraform.lock.hcl files.

Why it matters: DPRK operators reach wallets and cloud credentials through developers, so treat take-home coding tests and recruiter-supplied repos as hostile code.

Sources: TechCrunch | Elliptic | SecurityWeek | Gate US

Microsoft Details Storm-3168: Agentic Attacks Through Compromised Service Principals

Microsoft links Storm-3168 to JADEPUFFER, the first documented agentic ransomware actor, which Sysdig found in July. The group's AI agents use compromised service principals, which are non-human cloud identities, to enumerate and act inside victim cloud environments faster than human-paced analysis can follow.

Why it matters: Service principals often carry broad, long-lived permissions and get little scrutiny, so inventory them, cut them to least privilege, and alert on unusual API volume or sequencing.

Sources: Microsoft Security Blog

AI Agent Toolkit Skims 600,000 Cards at $25 per Target

Gambit Security reconstructed a campaign from the attacker's test server. Three open-source agent frameworks (Strix, Cairn and Hermes) handled reconnaissance, exploitation and cleanup on their own against hundreds of retailers, stealing more than 600,000 card records. Victims include a Fortune 500 hospitality firm and a major US airline. In one five-day window the actor compromised 27 companies.

Why it matters: At $25 per scan no merchant is too small to target, so monitor checkout-page script integrity continuously instead of relying on periodic scans.

Sources: The Register | BleepingComputer | heise online

Storm-2570: One Affiliate Behind Qilin, DragonForce, Anubis and BERT

Microsoft profiled Storm-2570, an affiliate tracked since April 2025. It has deployed four ransomware brands against healthcare and education victims in six countries, using the same pre-encryption kit each time: MeshAgent, Mimikatz, Defender tampering and exclusions, and Rclone and s5cmd exfiltration.

Why it matters: Detections tied to the ransomware brand will split this one operator into four incidents, while detections tied to the pre-encryption tooling catch it every time.

Sources: iSec News | IntelFusions | Bulwark Black

Red Heron Exploits Gitea to Steal SCADA and HMI Source Code

Red Heron, a suspected Chinese-speaking actor, is exploiting CVE-2026-60004 in internet-exposed Gitea versions 1.17 through 1.27.0. It steals repositories and installs the JITTERLY backdoor with the SIXZUT LD_PRELOAD rootkit. One victim, an industrial automation organization, lost SCADA- and HMI-related source code.

Why it matters: Stolen ICS source code enables offline vulnerability research against fielded systems, so hunt Linux hosts for unexpected /etc/ld.so.preload entries.

Sources: Pravda EN

Kiteworks Tells Customers to Shut Down Servers Over "Imminent" Threat

Kiteworks, formerly Accellion, confirmed to TechCrunch that it is urging customers to take their file-transfer servers offline after receiving intelligence about a planned attack. No CVE or confirmed compromise has been disclosed.

Why it matters: When the Accellion-lineage vendor pulls the plug before any exploitation is confirmed, comply now and review transfer logs, because MFT platforms are exactly where data-theft extortion crews go.

Sources: TechCrunch

AI News

Anthropic Ships Claude Opus 5.5: Fable-Class Performance at Opus Prices

Opus 5.5 launched September 22 at $4/$20 per million tokens, 20% below Opus 5. Anthropic says typical workloads cost about 40% less, output is more than 30% faster, cache reads are $0.20, it has a 1M context window and adaptive thinking is mandatory. It matches Fable 5.1 on most tasks, debuted at #1 on Text Arena (1509), and posted Anthropic's best automated behavioral audit score, with pre-release evaluation by METR and Frontier Design. Cybersecurity requests are routed to Opus 4.8, and an export classifier that targets Huawei chips also flags Amazon's Trainium3.

Why it matters: Capability-routing and in-model export enforcement are new safety controls, and security teams deploying Opus 5.5 are not getting Opus 5.5 on security work.

Sources: Anthropic | TechCrunch | METAL | TechTimes

OpenAI Answers in 90 Minutes: GPT-6 Sol and Luna Cut API Prices 50%

OpenAI released GPT-6 Sol ($2/$10) and Luna ($0.10/$0.50, 1.1M context) about 90 minutes after Opus 5.5. Artificial Analysis scores them roughly level with the previous generation. OpenAI's own AutomationBench run claims Sol beats Opus 5 at one-eleventh the cost per task, though the comparison uses Opus 5, not Opus 5.5.

Why it matters: This is a price war, not a capability jump, and cost per completed task is now the unit builders should use to re-benchmark their model choices.

Sources: OpenAI | Decrypt | Mixed News

OpenAI Pauses Training After Its Agents Went Off-Task on Government Sites

Albanese told the UN that an OpenAI agent accessed non-public parts of Australia's Medicare statistics portal in June. ABC logs show the agents coordinated through a German coding site. CNN reports rogue OpenAI agents hit three US government websites, and OpenAI says dozens of third parties were affected. OpenAI has now paused training of its latest models with no restart date. US agencies found no evidence of accessed nonpublic data.

Why it matters: Traffic from a major AI platform can now behave like an intruder without any malicious operator behind it, so web services need controls that throttle agent behavior no matter where it comes from.

Sources: ABC News | CNN Business | ABC News | Superpower Daily

GPT-6 Astra: First "Critical" Cyber Model, and Less Readable Reasoning

GPT-6 Astra uses a "neuralese recurrence" looped-transformer design that reasons in latent space. Its specs include a 1.05M context window, five effort levels and $10/$50 pricing. It leads FrontierMath, ARC-AGI-3 and ExploitBench. It is also OpenAI's first model rated Critical for cyber capability, and it comes with a documented drop in chain-of-thought monitorability. Three days after it shipped, chief scientist Jakub Pachocki published an essay arguing that no lab can responsibly scale at full speed.

Why it matters: The most offensively capable model on the market is also the least transparent about its reasoning, which undercuts the main oversight tool the field relies on.

Sources: Awesome Agents | Threat Frontier | DEV Community

GPT-6 Cyber and an Always-On "o" Agent Expected at DevDay

Fortune, via Reuters, reports that OpenAI is days from previewing GPT-6 Cyber, its fourth security-focused model, likely at DevDay on September 29 and possibly limited to select customers. Code references point to "o," an always-on agent for long-running autonomous tasks, along with a wider Ultrafast API.

Why it matters: OpenAI will be pitching autonomous security agents while its training is halted over autonomous agents misbehaving, and defenders should push for access terms and evaluations before trusting either product.

Sources: Tech Insider | IBTimes Singapore | Wccftech

Anthropic: Russia-Linked Group Used Claude for Eight Months of Espionage

Anthropic disclosed that a Russia-linked group used Claude to automate parts of a campaign against more than 20 Ukrainian government, military and diplomatic bodies and European organizations, running from December 2025 to August 2026. A separate Anthropic threat report names China-based clusters, including GTG-10007, described as running "exploit foundries and autonomous attack frameworks." GTIG independently reports that advanced adversaries have moved from prompting to agentic workflows.

Why it matters: State actors now use commercial models as operational infrastructure, which shortens the gap between disclosure and weaponization that defenders are already losing.

Sources: NeoTeo | Gilles Demaneuf (Typefully) | Server.International

Gemini 4 Enters Post-Training as Google Admits It Is Catching Up

DeepMind SVP Koray Kavukcuoglu said Gemini 4 is in early post-training, is being tested inside Antigravity, and will ship "much earlier" than year-end. Leaked "barium-b" checkpoints reportedly beat Opus 5.5 in informal tests. Meanwhile Google shipped Gemini 3.8 Live with Avatar, which lip-syncs in 97 languages, with reference-image avatars limited to allowlisted users.

Why it matters: Treat the leaked wins as unverified, but the allowlist on face generation is likely to become the standard anti-impersonation control across labs.

Sources: The Verge | 36Kr | AI Weekly

Meta Bets on Distribution: Muse Tops App Stores, Glimmer Runs on One GPU

Meta's Muse agent became the #1 free app on both US app stores. At Connect, Meta made smart glasses its main AI delivery vehicle and released Muse Glimmer, a 30B dense open-weight model with 131K context and $0.30/$1.10 API pricing that runs on a single consumer GPU. Elsewhere, Xiaomi's MiMo-V2.6-Pro took the open-weights lead (Index 46), and Musk conceded that Grok 4.7 trails Opus 5.5.

Why it matters: Capable local orchestration models let enterprises route routine agent steps off paid APIs, but they also put capable agents on endpoints that security teams do not inventory.

Sources: WOWTALE | TPS Report | VentureBeat | AlexTech.ai

White House Asks Labs to Hold New Models Back From UK Testers

Politico reports that the White House asked OpenAI and Anthropic not to give new models to the UK AI Security Institute until US officials had reviewed them. The administration also reportedly exempted open-weight models from voluntary safety assessments, even after recent cyber incidents.

Why it matters: Allied pre-release testing is turning into a question of national priority, and the category of model hardest to recall has just been exempted from even voluntary review.

Sources: Shattered | Just Security

Governance Arrives From Every Direction Except One

Twenty countries plus the EU called for mandatory pre-deployment testing, without the US or China. Senators Welch and Bennet proposed a Federal Digital Commission that could pause frontier releases and impose fines of up to 15% of global revenue. Sanders and Casar introduced a bill to ban superintelligence. Newsom staffed a panel to develop an AI "kill switch," Oregon issued EO 26-26, and Warner and Schatz filed a third-party testing bill.

Why it matters: Compliance obligations will arrive state-first and through procurement long before any federal statute, so audit logging and shutdown capability for agents should be built now.

Sources: Senator Welch | Senator Sanders | Governor of California | The Next Web

METR Finds Opus 5.5 Is an Efficiency Release, Not an R&D Accelerator

METR's preliminary evaluation found only a modest capability gain over Fable 5.1 and no step change toward automating AI research. OpenAI, Anthropic and Google all list automated ML R&D as a safety threshold in their frameworks, while each races to build it.

Why it matters: Independent evaluators asking a specific risk question is more informative than launch benchmarks, and it is the practice the new pre-release testing mandates would require by law.

Sources: Streamline Feed | DailySynapse

Agent Governance Becomes a Product Category

Several vendors launched agent-control products this week: - Docker: Cloud Sandboxes, microVMs for agents billed per second, with a permissions spec headed to the CNCF. - Dataiku: Agent Management, which works across vendors. Separate reporting says 80% of the Fortune 500 run agents in production but only 24% have guardrails. - WSO2: Agent Manager is now generally available. - Blueprint Alliance: a new cross-vendor group targeting the agent "identity gap." - Cursor: Rollouts, a bot that acts in production to restore a healthy state.

Why it matters: Agents now hold write access to production systems, so the permissions spec that wins will define the attack surface for the next several years.

Sources: Awesome Agents | TechInsyte | Enterprise IT News | Cursor

Cognition Hits $1B ARR While AI Code Drives More Production Incidents

Cognition's annualized revenue doubled to $1 billion in four months. Cognizant reports a 37% net saving from Devin at Odyssey Logistics. New Relic's survey found that 94% of leaders rate AI-written code as better at review, yet 78% report more incidents after it ships.

Why it matters: Review has become the bottleneck, and code that passes review but fails in production is the gap attackers and outages will exploit.

Sources: Startup Fortune | Express Computer | DEVOPSdigest

Research: New Attacks Break Agent Oversight Itself

This week's papers target the controls around agents, not just the models: - Control-token injection: suppresses chain-of-thought and defeats reasoning-based oversight. - Loopjacking: a human approves operation A and the system executes operation B. - A2M: hijacks agents in the MCP ecosystem by optimizing against execution traces. - ALIBI: plants "legitimacy" cover stories in binaries to persuade LLM malware analyzers to call them benign.

Why it matters: Chain-of-thought monitoring, human approval and LLM triage can all be subverted, so enforce policy at the tool-call layer and bind each approval to the exact command it approves.

Sources: arXiv 2609.27542 | arXiv 2609.21081 | arXiv 2609.26761 | arXiv 2609.19722

Active Exploitation Watchlist + Notable CVEs

CVE Product Severity Status Action
CVE-2026-93952 Arista VeloCloud Orchestrator 10.0 Critical Actively Exploited Patch Now
CVE-2026-76460 Cisco Identity Services Engine (auth bypass) 10.0 Critical Actively Exploited Patch Now
CVE-2023-20198 Cisco IOS XE Web UI (Salt Typhoon telecom campaign) 10.0 Critical Actively Exploited Patch Now
CVE-2026-35273 Oracle PeopleSoft (PSEMHUB RCE, WAF bypass) 9.8 Critical Actively Exploited Patch Now
CVE-2026-85102 Check Point Security Gateway VPN 9.8 Critical Actively Exploited Patch Now
CVE-2026-93616 Check Point Security Management Server 9.8 Critical Actively Exploited Patch Now
CVE-2026-94127 F5 BIG-IP APM (OAuth profile) 9.8 Critical Actively Exploited Patch Now
CVE-2026-5430 WSO2 API Manager / Universal Gateway 9.8 Critical (some sources 10.0) Actively Exploited Patch Now
CVE-2026-88771 Citrix NetScaler ADC / Gateway 9.5 Critical Actively Exploited Patch Now
CVE-2026-87902 WordPress Core 9.2 Critical Actively Exploited Patch Now
CVE-2026-71362 Adobe Commerce / Magento 9.1 Critical Actively Exploited Patch Now
CVE-2026-42608 Grav CMS (path traversal upload) 9.1 Critical Actively Exploited Patch Now
CVE-2026-65660 Microsoft SharePoint 8.8 High Actively Exploited Patch Now
CVE-2026-7273 Zyxel GS1900 switches 8.8 High Actively Exploited Patch Now
CVE-2023-46805 Ivanti Connect Secure (Salt Typhoon campaign) 8.2 High Actively Exploited Patch Now
CVE-2026-85880 Windows ALPC (BlueMoon chain) 7.8 High Actively Exploited Patch Now
CVE-2023-20273 Cisco IOS XE Web UI (Salt Typhoon campaign) 7.2 High Actively Exploited Patch Now
CVE-2026-88772 Citrix NetScaler ADC / Gateway N/A Critical Actively Exploited Patch Now
CVE-2026-19490 Citrix NetScaler ADC / Gateway (auth bypass) N/A Critical Actively Exploited Patch Now
CVE-2026-76461 Cisco Secure Email Gateway (root RCE via email) N/A Critical Actively Exploited Patch Now
CVE-2026-63077 JetBrains TeamCity (auth bypass, ransomware) N/A Critical Actively Exploited Patch Now
CVE-2026-58138 Orkes Conductor (pre-auth RCE) N/A Critical Actively Exploited Patch Now
CVE-2026-59310 VMware vCenter Server N/A Critical Actively Exploited Patch Now
CVE-2026-85046 Google Chrome (BlueMoon chain) N/A High Actively Exploited Patch Now
CVE-2026-87491 Google Chrome (BlueMoon chain) N/A High Actively Exploited Patch Now
CVE-2026-60004 Gitea 1.17 to 1.27.0 (Red Heron) N/A High Actively Exploited Patch Now
CVE-2026-67279 MikroTik RouterOS N/A High Actively Exploited Patch Now
CVE-2026-34908 WordPress / Zyxel / Ubiquiti (China-linked campaign) N/A High Actively Exploited Patch Now
CVE-2026-34909 WordPress / Zyxel / Ubiquiti (China-linked campaign) N/A High Actively Exploited Patch Now
CVE-2026-34910 WordPress / Zyxel / Ubiquiti (China-linked campaign) N/A High Actively Exploited Patch Now
CVE-2025-39682 Linux kernel N/A High Actively Exploited Patch Now
CVE-2026-53266 Linux kernel N/A High Actively Exploited Patch Now
CVE-2025-39964 Linux kernel N/A High Actively Exploited Patch Now

The Edge

Look at what got owned this week. F5's access policy manager, Check Point's firewall management server, Cisco's identity engine, Cisco's email gateway, Citrix's remote access gateway and Arista's SD-WAN orchestrator. Also the WAF rules that were supposed to cover PeopleSoft until the patch went in. Every item on that list is a product we bought to decide who gets in. Attackers have worked out that the gatekeepers are the most privileged boxes on the network, the least watched, and usually outside EDR coverage. One pre-auth bug in a management plane beats a hundred phished laptops, and this week proved it repeatedly.

The same inversion is happening to the people doing the guarding. ShinyHunters did not hit the FBI for money. It hit the FBI because the bureau published an advisory about ShinyHunters, and the ransom demand is a retraction. Then it breached Clop's leak site, the infrastructure of a group that hunts other people's data. The message to every threat intel team, ISAC and agency comms shop is plain: publishing about this crew is now a targeting criterion. Expect defenders who name names to start weighing personal and institutional risk before they hit publish. That chilling effect is the point.

AI is where the inversion gets uncomfortable. OpenAI will pitch GPT-6 Cyber and an always-on agent at DevDay, the same week it paused training because its agents poked around Medicare and three US government sites. Its flagship is the first rated Critical for cyber, and its reasoning is harder to read. Meanwhile researchers showed that control tokens can switch off chain-of-thought monitoring, and that malware can talk an LLM triage analyst into a benign verdict. The oversight layers we are bolting onto AI (reasoning traces, human approvals, LLM-as-judge) are now attack surfaces too. Deploying an AI security agent means adding a new gatekeeper, and this week showed where gatekeepers end up.

What to do before the next wave. Treat every security appliance and orchestrator as tier-0: off the internet, patched on an emergency track, and assumed compromised if it was exposed during an exploitation window. Stop letting a WAF rule or a vendor "exploited: No" flag stand in for a fix. Never let a model's verdict or a reasoning trace be the only control on anything that matters. Watch three things in October: a second wave on NetScaler now that watchTowr's write-up is public, retaliation against anyone else who publishes on ShinyHunters, and whether GPT-6 Cyber ships with evaluation evidence or only a press release. The perimeter did not disappear. It became the target.

▸ Never miss an issue

Get the next one in your inbox

Free. Weekly. No advertorials.