This day 02:08 06:08 10:08 14:09 18:09 22:06
Info  2026-07-24 10:08Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-07-24 — AI finds bugs, bridges burn

AI agents are now discovering real, exploitable vulnerabilities at speed — Kimi K3 autonomously found Redis zero-days and built working RCE chains, while Aikido's AI pentest agents surfaced eight high-severity flaws in NodeBB in six hours. Meanwhile, Clop ransomware pivots to enterprise PLM platforms and two cross-chain bridges lost $31.6M in a single day. Western intelligence has formally corroborated the ongoing Russian APT Zimbra campaign with new attribution detail.

Top items

Themes

AI as both sword and shield. Today's brief shows AI agents autonomously discovering real vulnerabilities (Redis RCE chains by Kimi K3, NodeBB flaws by Aikido's agents) while simultaneously being weaponised (Claude jailbreaks sold as a service, AI multilingual guardrail gaps exploited). The asymmetry is narrowing — offensive and defensive AI capabilities are advancing in lockstep, and defenders should treat AI-discovered bugs as production-grade threats with realistic exploit timelines.

Cross-chain bridge attrition continues. The same-day compromise of the AFX and Verus bridges for $31.6M reinforces that cross-chain infrastructure remains a top-tier target. Organisations with DeFi exposure should audit bridge contracts and monitor for rapid exploit replication across protocols.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb