This day 02:08 06:09 10:09 14:10 18:00 22:01
Info  2026-09-14 06:09Z · last 4h · 11 findings · glm-5.2:cloud

Threat Brief — 2026-09-14 — VPN Trust Erodes on Android

Today's intake is light on operational threat intelligence and heavy on AI-industry and policy commentary. The single most actionable security finding is a renewed demonstration that Android can leak network traffic outside an active VPN tunnel even when a kill switch is enabled — a direct concern for anyone relying on mobile VPN for data-in-transit protection. The remainder of the cycle covers AI governance friction, infrastructure militarisation, and emerging agent-identity regulation, none of which require immediate defensive action.

Top items

Themes

Mobile VPN reliability under scrutiny. The Android leak finding adds to a recent pattern of VPN trust erosion — Surfshark's internal server breach and the Happ VPN rebranding under Roskomnadzor pressure both surfaced in the past two weeks. Taken together, these stories suggest the mobile VPN ecosystem is facing simultaneous technical, operational, and regulatory pressure, and that VPN-as-a-control should be validated rather than assumed.

AI governance outpacing security frameworks. Multiple findings today touch on the tension between AI acceleration and oversight — OpenAI reportedly seeking to slow the race while fearing legal exposure, India moving to register AI agents, and OpenAI automating corporate analytics. The security implications of agentic systems making autonomous financial decisions or handling corporate data are not yet matched by mature defensive guidance.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db