This day 02:09 06:09 10:09 14:10 18:01 22:01
Info  2026-07-31 18:01Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-07-31 — Data Center OT Exposed, AI Threats Mature

Executive summary: A systemic weakness in data-center building-management protocols — ~90% running without encryption or authentication — gives attackers a shortcut to physical disruption without touching servers. ESET's latest threat report confirms malicious AI is moving from novelty to operational tooling, while Google's AI-assisted Chrome fuzzing programme patches a record 1,442 bugs across three releases. Law-enforcement infrastructure also advances: Interpol's global anti-fraud payment system and California's new DROP data-deletion platform both go live this month.

Top items

Themes

AI as a dual-use force multiplier. ESET's report on malicious AI skills and Google's record AI-assisted fuzzing results (1,072 of 1,442 bugs found via AI) illustrate both sides of the same coin — offensive AI is maturing into operational tooling while defensive AI is dramatically expanding vulnerability discovery. Teams should expect attacker AI capabilities to advance in parallel.

Unauthenticated OT protocols remain systemic. The data-centre cooling finding mirrors the pattern CISA flagged for water-utility PLCs: critical infrastructure routinely runs management protocols without encryption or authentication. Whether it's building-management systems or industrial controllers, the attack surface is less about sophisticated exploits and more about reaching networks that were never designed to be exposed.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db