This day 02:05 06:05 10:06 14:06 18:07 22:07
Info  2026-08-25 22:07Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-08-25 — Sanctions, Patches, and AI Prompt Injection

Executive summary: The U.S. Treasury announced fresh sanctions against Iranian cyber actors linked to critical-infrastructure breaches, including the UK power-plant generator shutdown. Microsoft patched a CVSS 10 Entra ID deserialization flaw (CVE-2026-69836) first disclosed four days ago. Two genuinely new findings round out the day: a prompt-injection technique that manipulates AI email summarizers via invisible HTML, and a CISA ICS advisory for Ebyte NE2-D11 industrial devices with multiple high-severity vulnerabilities.

Top Items

Themes

AI as both attack surface and attack tool — Today's brief continues a pattern seen across recent intel: adversaries are probing AI-integrated systems (email summarizers, NVIDIA NemoClaw/Ollama, AnonyMousKIT voice agents) while defenders race to patch the underlying infrastructure (Entra ID). The speed at which AI features are being deployed is creating new unauthenticated attack vectors faster than they can be hardened.

State-sponsored critical-infrastructure attacks draw policy response — The Iran sanctions represent the first significant whole-of-government economic response to the wave of physical-impact attacks on power infrastructure reported over the past 48 hours, signalling that these incidents have crossed a geopolitical threshold.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db