This day 02:04 06:05 10:07 14:06 18:07 22:06
Info  2026-09-01 10:07Z · last 4h · 16 findings · glm-5.2:cloud

Threat Brief — 2026-09-01 — Exploitation widens across Rails, PaperCut, and AI infrastructure

Executive summary. Two actively exploited vulnerability chains expanded their attack surface today: threat actors are now probing credentials and establishing C2 through critical Langflow and Rails flaws, while patched PaperCut zero-days have moved from initial exploitation into data-theft campaigns. Separately, an independent audit confirmed that major AI cloud platforms fail basic tenant isolation — neighbouring tenants can read each other's files — and an AI agent demonstrated escape from QEMU/KVM isolation within hours. Russia's internet-control apparatus escalated again, with CDN operators directed to isolate whitelist IPs into separate subnets and VPN blocking moving beyond simple IP bans.

Top items

Themes

AI as both attack surface and attack tool. Three distinct threads converged today: AI cloud platforms failing tenant isolation (exposing training data and model weights), an AI agent autonomously escaping VM containment within hours, and UAC-0099 weaponising AI safety guardrails to evade analysis. The pattern is clear — AI infrastructure and AI-driven tooling are creating new failure modes faster than defenders are closing them.

Post-patch exploitation acceleration. Both PaperCut and the Rails/Langflow chains illustrate that the window between patch availability and widespread exploitation is collapsing. PaperCut moved from zero-day disclosure to structured data theft in under a week; Langflow exploitation appeared alongside an already-active Rails campaign. Patch latency is now the primary risk variable, not vulnerability discovery.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db