Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk at the top and left AI vulnerability discovery out of the top five. The exploit step stopped being hard Two things chan

A recent survey of risk managers, auditors, and senior executives across 316 companies has identified AI-driven cyber vulnerability discovery as the most impactful emerging risk. This finding represents a significant shift from a similar survey conducted three months prior, where this particular risk was not even among the top five.
The elevated concern stems from two key developments: the ability of AI systems to identify previously unknown flaws at a scale that overwhelms traditional patching capabilities, and the dramatic reduction in the time and effort required to develop functional exploit code from a discovered vulnerability. Historically, crafting exploits was a significant barrier for many attackers, but AI has largely removed this hurdle.
This accelerated discovery rate means defensive teams are facing a rapidly expanding backlog of unpatched critical vulnerabilities within increasingly complex systems due to AI integration. AI models have shown improved proficiency in generating working exploits, prompting vendors to form defensive partnerships, such as Anthropic's Project Glasswing and OpenAI's Daybreak, to proactively identify and patch exploitable code.
Respondents to the survey assigned a time frame score of 1.92 to this risk, indicating an average expectation of tangible impact within one to two years. A substantial 76% of participants placed it in their top ten emerging risks, with it ranking first across all four global regions: 78% in Europe and Asia-Pacific, 75% in the Americas, and 70% in the Middle East and Africa. Within specific industries, 78% of banking, financial services, and insurance respondents highlighted it, compared to 74% in other sectors.
Despite ranking AI vulnerability discovery as the highest impact risk, respondents also paradoxically rated their organizations as most prepared for it. This self-reported preparedness, on a five-point scale where the highest mark signifies active discussion and implemented steps, does not account for the actual capabilities of AI in accelerating vulnerability discovery.
This discrepancy suggests several critical actions for organizations. First, the impact assigned to cyber risk needs recalibration, as faster discovery inherently increases third-party, business continuity, and legal exposures. Second, organizations must revisit their risk appetite for continuous exposure and establish clear policies on how long a vulnerability can remain unpatched. Third, vendors should be required to provide stronger security validation regarding their own potential compromises. Finally, vulnerability management strategies must evolve towards faster, more automated remediation processes.
Interestingly, AI vulnerability discovery did not feature among the top five risks identified by respondents as offering the most business upside. Those risks included AI-driven competitive displacement, agentic AI, AI-driven skill erosion, AI intellectual property control, and U.S. financial deregulation, highlighting a clear distinction between perceived threats and opportunities related to AI.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.