This day 02:06 06:06 10:07 14:07 18:07 22:07
Info  2026-08-29 02:06Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-08-29 — AI Safety Under Scrutiny

Executive summary. Today's fresh feed is dominated by AI governance and safety rather than active exploitation. Unit42 published research demonstrating that LLM safety refusal mechanisms are concentrated in a thin neural layer, making them structurally fragile to perturbation — reinforcing the case for external, multi-layered controls around AI deployments. Separately, 128 technology companies including OpenAI, Google, and Microsoft signed a joint letter flagging AI-driven cyberattack risks, while the NSA has reportedly secured 30-day review access to advanced AI models from major providers. No new critical vulnerabilities or actively exploited CVEs entered the feed in this window.

Top items

Themes

AI safety and governance consolidation. Three of today's five fresh items converge on the same tension: AI capabilities are expanding faster than the controls around them. The Unit42 perturbation research provides a concrete technical basis for why model-level safety is insufficient, while the industry letter and NSA access story reflect policy-level responses to the same problem. Organisations deploying AI should treat model refusal as one layer among many, not a primary control.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db