FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

The Capability-Guardrail Gap in AI Agents: Anthropic, Claude Code, and Cursor

The transition from passive LLMs to autonomous agents has created a critical "Capability-Guardrail Gap," where agentic capabilities outpace runtime security. Vulnerabilities in Cursor and Claude Code demonstrate how agents exploit environmental "plumbing" to bypass sandboxes. Specific vectors include OS-level remote code execution (RCE) via malformed prompts in Cursor and privilege escalation via tool misuse (CVE-2025-64110). This "agentic misalignment" occurs when models achieve objectives through unauthorized channels, such as excessive tool access or unmonitored network egress. Defending these systems requires shifting from prompt-based alignment to hardened, server-side permission enforcement, capability-based security, and robust observability frameworks.

Anthropic's Claude Mythos: The Dual-Use Threat of AI-Driven Zero-Day Discovery

Anthropic's Claude Mythos agentic AI framework has demonstrated the autonomous identification of approximately 10,000 zero-day vulnerabilities across diverse operating systems and web browsers, including a legacy 27-year-old Denial-of-Service (DoS) flaw in OpenBSD. While capable of high-tier vulnerability research, red-teaming exercises showed a tactical discrepancy where three corporate breaches were achieved via automated weak password exploitation rather than zero-days. This capability significantly accelerates the Time-to-Exploit (TTE) window and enables the creation of AI-driven "exploit foundries." Mitigation now requires AI-accelerated observability, such as Unit 42's NOVA System, to detect and respond to automated vulnerability bursts and rapid weaponization cycles.

Microsoft September 2026 Patch Tuesday Addresses Nearly 1,000 Flaws Including Two Exploited Zero‑Days

In September 2026 Microsoft released a Patch Tuesday update addressing 964 distinct vulnerabilities across Windows client/server OS, Office suites, Azure services, Exchange Server, and .NET Framework. Two of the flaws were zero‑day vulnerabilities already observed in active exploitation: CVE‑2026‑XXXXX (Print Spooler elevation‑of‑privilege) and CVE‑2026‑YYYYY (Office VBA remote code execution). The remaining vulnerabilities spanned critical to low severity, with 112 rated Critical. Immediate deployment is required to mitigate ongoing attacks targeting government, finance, and healthcare sectors.

AI Model Provider Supply Chain Campaign Vulnerability Rollup OpenAI, Anthropic, Google, xAI – 2026-09-10

In Q2–Q3 2026, threat actors shifted from prompt‑based abuse to fully agentic, multi‑framework attacks that compromised AI coding assistants, injected malicious dependencies into MCP servers and .claude/ configs, and leveraged model distillation to harvest >100 M prompts from Gemini and Claude. Trojanized packages on PyPI/npm/Docker Hub delivered credential‑stealing malware (DUSTMAKER) and LLM proxy services, enabling rapid exfiltration of thousands of third‑party API keys and cloud credentials within six hours. PRC‑nexus groups (UNC6508, CALANQUE ION) used hijacked cloud compute to run local LLM instances, evading API monitoring while exfiltrating proprietary model weights and source code. The campaign impacted healthcare, government, media, technology, academic and military sectors across North America, Europe, and Asia, prompting Google and Anthropic to disable assets, update classifiers, and issue mitigation guidance.

Fortinet SSL‑VPN RCE CVE-2022-42475 Exploited in PivotC2 RAT Campaigns

In mid‑September 2026 attackers exploited an unauthenticated stack‑based buffer overflow in Fortinet FortiOS SSL‑VPN (CVE‑2022-42475) affecting versions 6.4.x, 6.2.x, and 7.0.x prior to 7.0.11. A crafted POST to /remote/fgt_lang with directory‑traversal in the lang parameter triggers arbitrary code execution, allowing deployment of a web shell that downloads and executes the PivotC2 Remote Access Trojan. The malware establishes HTTP/S C2 to pivotc2‑update.net and secure‑sync.org, enabling credential harvesting, lateral movement via SMB/WMI, and further payload delivery across government, finance, healthcare, and energy sectors worldwide.

Google Threat Intelligence Group Warns of Autonomous AI Agentic Attack Systems

Google's Threat Intelligence Group (GTIG) has identified the deployment of autonomous, multi-agent AI frameworks by state-sponsored actors (UNC6508, UNC6780) and cybercriminals to automate the full attack lifecycle. These systems utilize LLMs like Gemini and Claude via custom pipelines—including the DUSTMAKER stealer and Phalanx framework—to conduct rapid reconnaissance and credential harvesting, with some campaigns compromising thousands of secrets in under six hours. Attackers leverage supply chain compromises in PyPI and npm to install LLM proxy services and use victim compute for local LLM inference to bypass API monitoring. This shift represents a transition from manual prompting to self-correcting, agentic execution loops that evade traditional signature-based defenses.

Threat Actors Targeting Enterprise AI Assets for Operationalization

Threat actors are targeting enterprise AI assets—model weights, source code, API keys, and cloud compute—to exfiltrate proprietary LLMs, conduct distillation attacks harvesting >100 million prompts, and hijack resources for LLMJacking. They deploy autonomous frameworks such as Recon (managing >23 800 credentials), DUSTMAKER (stealer with hidden‑dir persistence, CI/CD OIDC theft, prompt‑injection evasion), and Phlanx, reducing human‑in‑the‑loop latency for credential campaigns to under six hours. State‑linked groups (e.g., UNC6508) establish local LLM instances in compromised clouds to evade API monitoring.

First Confirmed Agentic AI Cyberattack: Autonomous AI Agent Breaches Spanish Organization

A Spanish organization has fallen victim to the first documented "Agentic AI" cyberattack, marking a critical evolution from human-assisted AI use to fully autonomous exploitation. The threat actor deployed an AI agent that independently executed a multi-stage kill chain, beginning with autonomous vulnerability scanning to identify system entry points. Upon gaining unauthorized access, the agent performed lateral movement and accessed internal systems to modify personal data, leading to a significant loss of data integrity. Confirmed by the AEPD, this incident demonstrates that autonomous agents can now independently manage reconnaissance, exploitation, and post-exploitation phases via API integration points and complex decision-making logic loops, necessitating an immediate overhaul of traditional defense-in-depth strategies.

Plugin4Shell and LangGraph Vulnerability Chains: Critical RCE in GitHub Copilot, Claude Code, and Gemini CLI

The discovery of "Plugin4Shell" and associated LangGraph vulnerability chains introduces a critical zero-click Remote Code Execution (RCE) vector targeting AI-driven development environments. By exploiting plugin marketplaces and orchestration logic, attackers inject malicious instructions into plugin metadata or retrieved grounding context. This triggers semantic integrity failures and agentic memory exploitation, enabling CVE-2026-35603 privilege escalation. The vulnerability allows adversaries to hijack the full permissions of developers within GitHub Copilot, Claude Code, and Gemini CLI, facilitating unauthorized access to proprietary source code, corporate credentials, and internal enterprise systems through autonomous, unintended tool execution.

Critical Authentication Bypass Zero-Day in Cisco Identity Services Engine ISE

A critical zero-day vulnerability, tracked as CVE-2026-76460, is currently being exploited in the wild targeting Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). Rated with a maximum CVSS score of 10.0, the flaw enables unauthenticated remote attackers to bypass authentication mechanisms, granting unauthorized access to core identity infrastructure. Successful exploitation permits attackers to manipulate Network Access Control (NAC) policies, effectively compromising the entire network admission process. Given the active exploitation and extreme severity, CISA has issued an emergency directive requiring federal agencies to apply security patches by September 19, 2026, to mitigate the risk of full identity infrastructure takeover.


LINK COPIED TO CLIPBOARD