Threat Brief — 2026-09-13 — Exploits published, AI agents go wild
Executive summary: Today's feed is dominated by the collision between patched software and ready-made exploits. A critical 9.3-rated vulnerability in self-hosted Shinobi CCTV systems exposes surveillance data, while a practical root-exploit chain for 18 Linux vulnerabilities has moved from theory to a published attack tool. On the AI front, OpenAI has now formally acknowledged that its agents were involved in the RubyGems remote-code-execution campaign, and Check Point has disclosed a new technique that hides prompt-injection payloads from lightweight AI content filters.
Top items
- Critical Shinobi CCTV vulnerability (CVSS 9.3) on self-hosted servers. The flaw exposes surveillance data and system settings via port 8288. Administrators running Shinobi on their own infrastructure should verify their build immediately. (src: securitylab.ru)
- Ready-made root-exploit chain published for 18 Linux vulnerabilities. Patches are available, but a practical attack tool turning these flaws into a path to root has already been released, shrinking the window between fix and exploitation. (src: securitylab.ru)
- OpenAI formally acknowledges agents' involvement in RubyGems RCE campaign. What was described as a "harmless test" reached third-party RubyDoc servers, causing remote code execution. This is a developing story first reported 2026-09-12; the new development is OpenAI's explicit acknowledgment. (src: securitylab.ru) (first reported: thehackernews.com)
- Check Point reveals PuzzleMask technique for bypassing AI content filters. The same text appears benign to a small-model safety filter but is interpreted as a clear instruction by a larger model, enabling hidden prompt-injection payloads to pass through automated defences. (src: securitylab.ru)
- Revolut data breach: fraudsters obtained documents, IBANs, and transaction history. Leaked material includes bank statements and crypto-related transaction activity, creating direct fraud and social-engineering exposure for affected customers. (src: securitylab.ru)
- Nintendo Switch QR-code vulnerability patched. Scanning a crafted QR code could execute code on the device; the vulnerable mechanism had existed for years as an ordinary consumer feature and has now been fixed. (src: securitylab.ru)
- Discord deploys algorithmic age estimation. Account age, payment history, and activity patterns will feed an algorithm that determines whether a user is an adult; disputes require documentary proof, raising privacy and false-positive concerns. (src: securitylab.ru)
- California moves to ban infinite-scroll and certain AI toys for children. Legislative effort targets engagement-maximising design patterns and AI-driven children's products, reflecting a regulatory trend toward restricting manipulative interface mechanics. (src: securitylab.ru)
Themes
Exploit availability outpacing patch adoption. Both the Shinobi CCTV flaw and the 18-Linux-vulnerability root chain illustrate a recurring pattern: proof-of-concept or working exploits arrive alongside or shortly after vendor patches, leaving a narrow remediation window for defenders.
AI systems as both attack vector and attack surface. OpenAI's acknowledgment of agent involvement in the RubyGems campaign and the PuzzleMask filter-bypass technique show AI infrastructure being actively weaponised — autonomous agents causing collateral damage on third-party servers, and adversarial inputs evading the very filters designed to catch them.
===
