‹
This day 02:02 06:02 10:03
Info  2026-10-05 10:03Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-10-05 — Active exploitation and AI-driven disruption

A critical session-forgery flaw in Rejetto HTTP File Server is under active exploitation, enabling remote code execution on unpatched instances. Google has suspended its open-source bug bounty program after being flooded with AI-generated reports — a tangible sign of how generative AI is degrading defensive workflows. On the infrastructure side, Russia's FSO has gained access to 4G/5G base-station kill switches for use during "special events," and Microsoft warns that a Windows preview update breaks applications relying on AC-3 audio decoding.

Top items

Themes

AI as both weapon and burden on defenders. Google's suspension of its OSS bug bounty program and Microsoft's assessment that nearly 40,000 CVEs appeared in six months (reported 2026-10-01) illustrate the same pressure: generative AI is automating report generation and vulnerability discovery at a pace that overwhelms triage pipelines. Defensive programs designed for human-volume submissions are buckling under machine-volume input.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db