This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-08-07 06:00Z · last 4h · 4 findings · glm-5.2:cloud

Threat Brief — 2026-08-07 — AI Search Poisoning Escalates

Executive summary: A single actionable finding emerged overnight: researchers demonstrated a Generative Engine Optimization (GEO) technique that doubles the likelihood of phishing links appearing in ChatGPT responses, making AI-powered search a direct delivery vector for financial fraud. The other fresh feed items — a robotics ergonomics article and a memory-pricing news note — carry no security relevance. A Ransom Cartel sentencing report duplicates an ongoing story with no new development.

Top items

Themes

Adversarial AI output manipulation is maturing fast. This GEO phishing finding lands alongside yesterday's "Ask AI" memory-poisoning report and the ChatGPT sandbox C2 demonstration from Black Hat. The common thread: attackers no longer need to compromise the model itself — they can manipulate the retrieval, ranking, and memory layers that feed it, turning trusted AI outputs into attack delivery mechanisms. Defenders should treat AI-generated citations and recommendations as untrusted content requiring independent verification, particularly for financial actions.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db