This day 02:02 06:02 10:02 14:03 18:03 22:04
⚠ exploit status: CVE-2026-85880 · KEV
Info  2026-09-17 02:02Z · last 4h · 3 findings · glm-5.2:cloud

Threat Brief — 2026-09-17 — AI Reaches Into Your Bank Account

Executive summary. Anthropic is piloting "Claude Money," a feature that lets users connect bank accounts directly to Claude for financial analysis — a meaningful expansion of the data-exposure surface for consumer AI assistants. On the vulnerability front, CVE-2026-85880KEV (Windows ALPC Elevation of Privilege) remains listed in CISA's Known Exploited Vulnerabilities catalog, though today's update is purely an informational CVSS vector correction with no new exploit activity. Industry reporting indicates AI security spending is accelerating faster than demonstrated outcomes, with CISOs investing on anticipation rather than proven value.

Top items

Themes

AI data surface keeps expanding. The Claude Money pilot extends a pattern visible across recent weeks — AI assistants are being positioned as intermediaries for increasingly sensitive personal data (financial records, chat histories, coding sessions). Each new integration category expands the blast radius if an assistant's infrastructure, session handling, or agent framework is compromised. Combined with recent reports of AI-powered data breaches and browser-extension hijacking of AI assistants, the trend underscores that the attack surface is growing faster than the controls around it.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db