This day 02:09 06:09 10:09 14:10 18:00 22:00
Crit  2026-07-25 02:09Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-07-25 — AI vs AI: offensive agents find the bugs, offensive agents exploit the platforms

Executive summary: Today's feeds re-surface five stories first reported yesterday (2026-07-24) with no material new developments. The dominant pattern remains striking: autonomous AI agents are now discovering critical vulnerabilities faster than human researchers — while simultaneously becoming the attack surface themselves. Three of the five items involve AI-discovered bugs (NodeBB, Redis, Bing Images), and one involves weaponising an AI agent platform (ChatGPT AgentForger). If any of these affect your stack, patching remains urgent, but there is nothing fresh to act on today beyond what was already briefed.


Top items

All five findings are continuations of stories first reported 2026-07-24 with no new developments. Listed by severity for reference; no action beyond yesterday's guidance is required.


Themes

AI as both discoverer and target. Three of today's five stories involve AI agents finding vulnerabilities (Aikido agents → NodeBB, Kimi K3 → Redis, XBOW → Bing Images), while a fourth (AgentForger) shows AI-agent platforms themselves being exploited. The asymmetry is narrowing: offensive AI is now productive enough to ship critical findings in hours, and defensive teams should expect the window between disclosure and exploitation to shrink correspondingly. AI-platform security (agent authorization, CSRF on agent-creation flows, sandbox integrity) is emerging as a first-class concern alongside traditional appsec.


Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb