This day 02:07 06:08 10:08 14:08 18:09 22:09
Info  2026-08-26 10:08Z · last 4h · 20 findings · glm-5.2:cloud

Threat Brief — 2026-08-26 — AI attack surface expands

Executive Summary

A new Q2 2026 vulnerability report from Kaspersky's Securelist is the first to aggregate vulnerability data for open-source AI agents and AI frameworks — signalling that AI-agent attack surfaces are now significant enough to warrant dedicated tracking. The cryptographic context injection technique previously demonstrated against Grok has been extended to Gemini, broadening the set of affected platforms. Meanwhile, Russian ministries are pushing to open industrial-control software to third-party AI agents despite only 5% of domestic software currently being AI-compatible — a move that could dramatically expand attack surface in OT environments.

Top items

Themes

AI agents as both target and attack vector. Three of today's four items revolve around AI-agent security — from formal vulnerability tracking (Securelist), to LLM data-theft techniques expanding across providers (Grok → Gemini), to policy decisions that would expose industrial-control systems to AI-agent interaction. The common thread: organisations are rapidly adopting and exposing AI agents without commensurate security maturity, creating a widening gap between deployment and defensive readiness.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db