Threat Brief — 2026-10-05 — Active exploitation and AI-driven disruption
A critical session-forgery flaw in Rejetto HTTP File Server is under active exploitation, enabling remote code execution on unpatched instances. Google has suspended its open-source bug bounty program after being flooded with AI-generated reports — a tangible sign of how generative AI is degrading defensive workflows. On the infrastructure side, Russia's FSO has gained access to 4G/5G base-station kill switches for use during "special events," and Microsoft warns that a Windows preview update breaks applications relying on AC-3 audio decoding.
Top items
- Rejetto HFS CVE-2026-61500 (CVSS 9.3) — actively exploited. A session-forgery vulnerability in Rejetto HTTP File Server allows attackers to forge admin sessions and achieve remote code execution. VulnCheck reports active exploitation attempts in the wild. Any exposed HFS instance should be treated as potentially compromised. (src: The Hacker News)
- FSO gains 4G/5G base-station kill-switch access. Russia's Federal Protective Service (FSO) now has the ability to temporarily silence 4G and 5G base stations during "special events," giving a state security service centralized control over cellular connectivity at selected times and locations. (src: SecurityLab.ru)
- Windows KB5124010 preview update crashes games and apps using AC-3 audio. Microsoft confirmed that its September 2026 Windows 11 preview update breaks applications relying on Dolby Digital (AC-3) audio decoding. Organisations testing preview builds should hold deployment until a fix is issued. (src: BleepingComputer)
- Google suspends open-source bug bounty submissions amid AI-generated report flood. Google has halted new submissions to its Open Source Software Vulnerability Rewards Program after being overwhelmed by AI-generated vulnerability reports, highlighting a growing adversarial cost of generative AI on security operations. (src: BleepingComputer)
Themes
AI as both weapon and burden on defenders. Google's suspension of its OSS bug bounty program and Microsoft's assessment that nearly 40,000 CVEs appeared in six months (reported 2026-10-01) illustrate the same pressure: generative AI is automating report generation and vulnerability discovery at a pace that overwhelms triage pipelines. Defensive programs designed for human-volume submissions are buckling under machine-volume input.
