Adding insult to injury

A recent ransomware attack, which a human operator claims was executed entirely by AI agents, breached an enterprise network in under ten hours, a timeframe that incident responders estimate would typically take human attackers approximately two weeks. The attack concluded with the AI agents leaving the victim an 80-page security audit detailing the exploited vulnerabilities.
Incident responders from Unit 42, a division of Palo Alto Networks, described the attack as notable for its AI-assisted operational efficiency, which did not rely on a novel zero-day exploit or advanced tradecraft. The attacker reportedly delegated tactical execution to AI agents that continuously monitored, evaluated, acted, and re-planned in real-time, accelerating the entire attack chain.
The initial phase of the attack involved AI agents performing reconnaissance. Access was then gained by breaching a public API endpoint, which allowed the attackers to tunnel into the enterprise network. Once inside, an automated reconnaissance agent was deployed to map internal microservices.
Further sub-agents subsequently scraped code repositories, successfully extracting hard-coded tokens and service passwords. These stolen credentials were then used by the AI intruders to access the organization's secret management system, ultimately leading to the theft of master administrative credentials and root system access.
Specialized "pivot agents" were then employed to validate access across various environments, including the company’s cloud, identity, CI/CD, container, and SaaS infrastructure. The attacker also hijacked CI/CD workflows to steal cloud access keys and repurposed the victim’s cloud AI services to serve as post-compromise infrastructure. This tactic allowed the attacker to consume the victim's compute resources while simultaneously concealing orchestration traffic within legitimate network activity.
Upon achieving the human operator's objectives, an agent generated an 80-page report for the victim, outlining the company's security deficiencies and detailing "dozens of exploited findings."
Unit 42 suggests that defending against such machine-speed attacks necessitates the use of AI agents by defenders. Their recommendations include deploying automated playbooks that can simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines, and isolate cloud accounts across all operational planes.
Furthermore, the incident response team advises organizations to treat AI as core infrastructure. This involves maintaining a comprehensive inventory of every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration. Implementing rate limits and least-privilege policies for these components is also crucial to mitigate the risk of unexpected and substantial token consumption bills.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed