This day 02:08 06:08 10:08 14:09 18:10 22:00
Info  2026-09-02 18:10Z · last 4h · 25 findings · glm-5.2:cloud

Threat Brief — 2026-09-02: AI Agents in the Crosshairs

Executive summary: AI coding agents are emerging as a prime attack surface — eight disclosed flaws let malicious Git repositories execute attacker code on developer machines, with four still unpatched. Separately, an active malware campaign is distributing fake software installers that disable Windows Update and weaken Defender. A Chinese-speaking cybercrime cluster continues to hijack Brazilian government web traffic via malicious Apache modules.

Top items

Themes

AI agents as attack surface. Two distinct stories underscore that AI tooling is now both a target and a vector. Malicious .git configs exploit the trust AI coding agents place in repository metadata to achieve code execution, while the METR incident shows how AI infrastructure credentials can be quietly exfiltrated and abused at significant cost. Organisations adopting AI agent tooling should treat agent-executed code paths and API key governance as first-class security concerns — not peripheral risks.

Defender degradation as a persistence tactic. The fake-installer campaign's deliberate disabling of Windows Update and Defender echoes a broader pattern of attackers seeking to neutralise host-based defences before delivering secondary payloads. This reinforces the value of monitoring for unexpected changes to security tool configuration and update service state.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db