This day 02:09 06:09 10:09 14:10 18:00 22:00
Crit  2026-07-25 02:09Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-07-25 — AI vs AI: offensive agents find the bugs, offensive agents exploit the platforms

Executive summary: Today's feeds re-surface five stories first reported yesterday (2026-07-24) with no material new developments. The dominant pattern remains striking: autonomous AI agents are now discovering critical vulnerabilities faster than human researchers — while simultaneously becoming the attack surface themselves. Three of the five items involve AI-discovered bugs (NodeBB, Redis, Bing Images), and one involves weaponising an AI agent platform (ChatGPT AgentForger). If any of these affect your stack, patching remains urgent, but there is nothing fresh to act on today beyond what was already briefed.


Top items

All five findings are continuations of stories first reported 2026-07-24 with no new developments. Listed by severity for reference; no action beyond yesterday's guidance is required.


Themes

AI as both discoverer and target. Three of today's five stories involve AI agents finding vulnerabilities (Aikido agents → NodeBB, Kimi K3 → Redis, XBOW → Bing Images), while a fourth (AgentForger) shows AI-agent platforms themselves being exploited. The asymmetry is narrowing: offensive AI is now productive enough to ship critical findings in hours, and defensive teams should expect the window between disclosure and exploitation to shrink correspondingly. AI-platform security (agent authorization, CSRF on agent-creation flows, sandbox integrity) is emerging as a first-class concern alongside traditional appsec.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db