Routers on Trial, AI Found More Bugs – PSW #947
In the security news this week:
- BPFDoor
- OpenSSH compresses a little too much
- AI can find bugs. Who gets them fixed?
- TP-Link and the courts
- Cisco NX-API
- ClingSTUN
- LineageOS, Android TV, and a Raspberry PI
- Dell’s updater has a privilege problem
- SonicWall SSRF
- U-Boot’s LogoFAIL like
- Exploit-DB isn’t dead
- MFA passes. The attacker still gets in.
- LakeShark and cool gadgets
- Kasa cameras and an exposed debug interface
- SharePoint hardening is back on the checklist
- Google pauses open-source bug bounty submissions
- NetScaler’s latest vulnerability needs a closer look
- Kiteworks tells customers to shut it down
- Exchange gets an unexpected security update
- Do LLMs actually reason?
- disagree on AI risk?
- Anthropic, AI consciousness and the Vatican
- Grok gets involved in foreign policy
- WordPress malware that survives cleanup
- Can spyware vendors stop their own tools?
- When an AI chatbot conversation reaches the police
- Open-weight AI models enter the cyber debate
- AI agents take their attacks shopping
If your threat model still says "hackers break in," you're about five years behind.
They're logging in with stolen creds, abusing cloud identities, automating recon, and turning AI into a force multiplier. Meanwhile, you've got a vulnerability backlog that's older than some interns.
If you're defending financial infrastructure, this one's worth your time.
Join us October 14 for the FinSec Virtual Summit to hear how practitioners are prioritizing the threats that actually matter and defending modern financial environments without chasing every shiny new security product.
Register for free at https://securityweekly.com/finsec using the discount code CSS26-SW!
InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Paul Asadoorian
- SMTP is the key: BPFDoor and AVERAT hitting the network edge
Summary: Rapid7 details BPFDoor, Rekoobe, and AVERAT malware targeting telecom and network-edge systems in South Korea and Taiwan. The implants blend into appliance software and use BPF-filtered traffic or SMTP over TCP port 25 for covert command and control. Some stage binaries, run them, then delete them, while compromised NAS devices and DVRs provide relay infrastructure.
Paul's take: If a mail gateway is expected to make outbound SMTP connections, port 25 alone tells you very little, and file scanning can miss payloads that have been deleted while still running. I’d look for the behavior around it: unexpected raw packet sockets or BPF filters, non-mail processes opening SMTP connections, and Linux processes whose
/proc/<pid>/exepath ends in(deleted). Then ask whether those capabilities make sense for that specific device (a DVR probably should not be relaying mail). - OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
Summary: OpenSSH 10.6 disables its shared LZ77 compression dictionary to address a side-channel attack that can expose plaintext across multiplexed SSH channels. The release also includes fixes for SFTP path handling, authentication state, forwarding restrictions, and other issues. Some "light" background reading: Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels (https://arxiv.org/abs/2609.07709)
Paul's take: The headline sounds like SSH encryption is broken, but this is a compression side channel. An attacker needs to influence input on one channel while secrets pass through another channel sharing the compression state. I’d update OpenSSH, especially on systems using connection multiplexing, and avoid enabling compression where trusted and untrusted traffic share a connection.
- 3 lessons from frontier AI vulnerability research
Summary: Microsoft says its FORGE Lab helped discover Windows vulnerabilities assigned 140 CVEs and submitted 155 internally validated reports across 23 open-source projects; 93 had documented maintainer acknowledgement or acceptance. The post argues that AI vulnerability research needs to scale validation and remediation alongside discovery. For Linux kernel crash proof-of-concept generation, Microsoft reports an average model cost of $3.61 and 21.5 minutes per successful case, excluding failed candidates, initial screening, human investigation, and patch preparation.
Paul's take: This is the best quote from the article: Discovery creates security value only when validation and remediation can keep pace. I like that Microsoft is measuring progress in validated findings and fixes, not just bugs discovered. But those cost numbers are for successful cases and leave out much of the work needed to ship a fix. And 93 acknowledged or accepted reports are not the same as 93 fixes in production. The real test is whether these systems give maintainers reproducible evidence and reduce the time from finding a bug to releasing a patch.
- US states sue popular kitmaker TP-Link over China risks
Summary: Attorneys general in Florida, Iowa, Montana, and Nebraska are suing TP-Link, alleging deceptive security claims and undisclosed China ties in its supply chain. The complaint cites vulnerabilities in TP-Link routers and their use in state-backed campaigns; TP-Link denies the allegations and says a foreign government does not control its US business or products.
Paul's take: I want to see this argued with evidence about product security, not just country of origin. A router being exploited in an intrusion campaign is not proof it was built as a backdoor, and these allegations have not been tested in court. But claims like “100 percent safeguard” deserve scrutiny. Router security should be judged by measurable practices, including vulnerability handling and how long devices receive fixes.
- Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
So much attack surface, why does this carrier-grade gear need an API? Also, it has an API, which means it needs to be super locked down and secure. A 9.8 CVE is concerning...
- ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
Summary: Fortinet describes ClingSTUN, a Linux backdoor spread by exploiting known vulnerabilities in internet-facing routers and IoT devices. It uses public STUN servers to discover external addresses and maintain NAT bindings, then turns compromised devices into proxy nodes with persistence, process-hiding, and remote-command features. Fortinet notes that how operators deliver control traffic through NAT remains unverified.
Paul's take: The STUN detail is interesting, but STUN traffic by itself is not an indicator of compromise; legitimate VoIP and WebRTC use it too. I’d look for it alongside the malware’s other behavior, such as unexpected persistence changes, process tampering, and repeated UDP keepalives. The report also leaves an important gap: it documents the NAT-traversal setup but doesn’t establish exactly how the operator reaches the backdoor through it.
- Using LineageOS For Phones And DIY Smart TVs Is Pretty Nifty
Summary: A Hackaday writer installed LineageOS on a 2016 Xiaomi Mi 5, bringing it from Android 8 to Android 15, and tried LineageOS Android TV on a Raspberry Pi 4. The phone required bootloader unlocking and some driver troubleshooting, while the Pi setup was as simple as writing an image to an SD card. The author notes that streaming apps requiring DRM may limit the DIY TV’s usefulness.
Paul's take: Phones are the boring part of the story, while cool, there are many Android phones that can do cool stuff. LineageOS also gives people more control over what runs on their devices, although unlocking and flashing a phone still takes enough work to scare off most people. The Pi TV setup sounds amazing and easier, but DRM restrictions are a real tradeoff if you want it to replace a commercial streaming box. Still, I love that you can run Lineage OS on a RasPI and use it as your Android TV box.
- Engineer sentenced for locking over 3,000 devices on employer network
I love that he had to lookup how to use the command line to change passwords and such, and not only that, left the evidenec behind which did not help his case.
- New Dell System Update flaw lets hackers gain root privileges
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SSRF is great, but we should clearly differentiate between authenticated and unauthenticated SSRF. That makes a huge difference when we are talking about appliances. An authenticated SSRF could just give you the same level of access you already have inside the web interface once you authenticate. Unauthenticated SSRF lets you bypass more controls, perhaps interacting with the application without authentication, which makes it more like an authentication bypass than SSRF. For example, if I can use SSRF to interact with the web app without credentials, perhaps I can use that access to add an account for myself.
This is not new, see this article from 2023: https://www.synack.com/exploits-explained/exploits-explained-escalating-privileges-with-ssrf/ - Also, this speaks to type of attack I was discussing above: " So, it allowed a remote unauthenticated attacker to obtain valid authorization tokens for different services. All an attacker has to do is tell the server about the service they want to interact with and a URL to send the authenticated access token. The server will send the credentials without asking for anything. It’s that simple—and pretty scary!"
We need to understand the details of the vulnerability when we assess, and its easy to just lump all SSRF vulnerabilities into one buckets, but treat them accordingly. The SMA1000 has had a string of vulns, and unauthenticated SSRF is just the latest.
- The Lucifer: How to Spot a Compromised MikroTik Router
- U-Boot – Out-of-Bounds Write in the BMP RLE8 Decoder
This is basically LogoFAIL for U-Boot.
- Exploit-DB is DEAD !!!
Summary: The author introduces Exploit-Index, a free, daily updated project that combines CVE data with PoCs, Nuclei templates, Metasploit modules, CISA KEV, and EPSS. It adds a documented risk score and a command-line interface, aiming to reduce the manual work of checking multiple sources.
Paul's take: Exploit-DB isn’t dead, and the article admits that. Bringing scattered sources together could save analysts time, but an index or composite score can’t tell you whether an exploit applies to your exact product version and configuration. I’d use it to prioritize what to investigate, then verify the source and test any PoC in an isolated lab. Using AI, one can build this pretty easily, ask me how I know :) There are many sources for "exploit available", however "Exploited in the wild" takes a bit more work to go beyond just the public KEV lists, ala VunCheck (who does a great job at this).
- WordPress libheif RCE
- Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
- MFA Passed. The Attacker Still Got In.
Summary: Carlos Perez is BACK BLOGGING! He argues that “MFA” covers methods with very different protections: SMS, OTP codes, and push approvals can be relayed through phishing proxies, while passkeys, Windows Hello for Business, and multifactor certificates are designed to resist phishing. He also notes that passkeys do not prevent every attack, including device-code phishing and token theft after sign-in, and recommends measuring what users have registered, what policies allow, and what they actually use.
Paul's take: This is why “MFA enabled” is a weak security metric. Number matching helps with push bombing, but it does not stop an attacker-in-the-middle from relaying a sign-in. I’d start with privileged accounts, measure phishing-resistant sign-ins, and treat device-code flow, account recovery, and stolen sessions as separate problems. A passkey is a meaningful upgrade, not the end of the identity security work.
- SAMS0N1TE/LakeShark: Handheld T Display P4 & ESP32-P4 SDR scanners – RTL-SDR spectrum, P25 Phase 1, FM/AM, ADS-B and POCSAG, plus onboard LoRa/MeshCore, GPS and Flipper .sub capture. No PC.
Summary: LakeShark is an open-source handheld radio workbench for the LilyGO T-Display P4, combining software-defined radio features with LoRa mesh, GPS, offline maps, and Flipper
.subtools. Depending on the board and radio hardware, it can handle P25 Phase I, ADS-B, FM/AM, and POCSAG; the project marks features such as P25 Phase II as experimental.Paul's take: I love projects that turn a small embedded board into a useful field tool without needing a PC. The interesting part is how much is integrated here, from radio reception and offline mapping to notes and mesh messaging. Just check the exact board variant and the experimental labels before expecting every feature to work with your hardware. The LilyGO T-Display P4 ($119 at the time of this writing, without shipping/taxes/tarifs) looks HOT.
- Security Advisory: Physical UART Access Leading to an Unauthenticated Root Shell in Kasa EC70 and EC71 (CVE-2026-102370)
Summary: TP-Link disclosed that Kasa EC70 v4 and EC71 v4 cameras can expose an unauthenticated root shell through their UART debug interface. Exploitation requires physical access, device disassembly, reconnecting severed debug traces, and manipulating the boot process. TP-Link rates the issue Medium, CVSS 4.0 5.4, and lists firmware 2.4.3 Build 20260902 rel.4511 or later as fixed.
Paul's take: This is a concrete device-security issue, but the prerequisites matter. It requires hands-on physical access and hardware work, so it is not evidence of remote access or of the supply-chain claims in the lawsuits. I appreciate that the advisory names the affected hardware revisions, exploit conditions, and fixed firmware. Update affected devices, and keep this specific finding separate from broader geopolitical allegations.
Lee Neely
- CISA Urges SharePoint Hardening After New Exploitations
Summary: Researchers at the Symantec Threat Hunter Team say that Warlock ransomware is being used in attacks against critical infrastructure organizations in Portuguese- and Spanish-speaking countries. The threat actors are exploiting known vulnerabilities in Microsoft SharePoint. In late August 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) published an alert warning that threat actors were exploiting six SharePoint vulnerabilities; the document urges users to harden their SharePoint instances.
Lee's Take: Before you breathe easy that Warlock is targeting SharePoint sites someplace else, make sure that you've applied the updates from Microsoft as well as the hardening guidance from CISA.
- Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
Summary: Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) in response to a "significant rise" in AI submissions. In announcements on the program's website and on X, Google says the program is halted as of October 1, 2026; the company will provide "an update" in the first few months of 2027. According to Tom's Hardware, "Google engineers and open-source maintainers were reportedly being overwhelmed by thousands of these poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations." Google urges researchers to submit reports through the company's other VRP programs or through the Patch Rewards Program.
Lee's Take: We've talked about AI Slop before, if you are submitting bug reports, make sure that you've reviewed the submission, that it's truly accurate and verifiable. If you're accepting submissions, make sure that your policy clearly states that badly written and bogus reports will be discarded, then use logic to filter these out, if possible, summarizing the reported issue, to mitigate risks of ignoring a legitimate flaw. Human governance of AI created content is critical, both for credibility and to ensure that you first do no harm.
- Mississippi mayor says ransomware incident led city to shut down systems
Summary: A ransomware attack has shut down the computer systems of Vicksburg, Mississippi, the city’s mayor told residents on Thursday evening. Mayor Willis Thompson published a statement in the local newspaper saying the city is investigating a ransomware attack that has not impacted emergency services but has affected payments for utilities.
Lee's Take: Before you breathe easy that Warlock is targeting SharePoint sites someplace else, make sure that you've applied the updates from Microsoft as well as the hardening guidance from CISA. The city of Vicksburg is doing a great job of letting the news media know what's going on, however; looking at their website, it appears to be business as usual, no mention of the incident and impacts on services. Make sure that you're putting notices on your regular web sites; don't assume all your users will catch the news. If you're interacting with the city, be kind, they are probably overwhelmed from all sides and need all the support they can get.
- Citrix NetScaler FAQ: CVE-2026-88779
Summary: Citrix published a security bulletin addressing a high severity memory overflow vulnerability leading to denial-service vulnerability (CVE-2026-88779, CVSS score 8.7) in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). According to a blog post published by NetScaler Cyber Threat Intelligence, "Citrix has observed targeted attacks [exploiting the vulnerability] on unmitigated NetScaler deployments." The post also notes, "exposure depends on how the NetScaler deployment is configured." Citric has published signatures that can be used with the Global Deny List feature as a mitigation until organizations are able to update to a foxed version.
Lee's Take: At this point, if you're a NetScaler shop, and you wish to stay with NetScaler, it'd be a good idea to see if their cloud managed service would be a less risky option for you. While you launch folks at running that to ground, have another team make sure that you're on the latest ADC/Gateway release, regardless of whether you're in a vulnerable configuration. Prioritize updating deployments using SAML authentication for Gateway or AAA virtual servers, and don't stop until everything is updated. The watchTowr FAQ includes both information you can leverage when explaining to others and steps to take. Don't overlook running down IOCs, remember you want at check at least 30 days of logs.
- CISA Sends Final CIRCIA Rule to White House for Review
Summary: The US Cybersecurity and Infrastructure Security Agency (CISA) has sent a final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) to the Office of Management and Budget (OMB) for review. The terms of CIRCIA, which was enacted in 2022, require CISA to establish and oversee rules for critical infrastructure entities regarding the reporting of cybersecurity incidents and ransomware payments. The final rule was developed with input from Sector Risk Management Agencies of 16 critical infrastructure sectors, the Justice Department, and other government agencies. The covered agencies will be required to report "substantial" cyber incidents to CISA within 72 hours of discovery; if a ransom is paid, that must be disclosed to CISA within 24 hours of payment. The reporting thresholds depend on the size and annual revenue of the critical infrastructure organizations; each sector has its own set of thresholds. The entities will also be required to submit follow-up reports and to retain two years of incident data.
Lee's Take: This has taken time as the direction also included cutting overlap with existing regulations. The proposed version of the rule dates from 2024, and initially was hoped to be complete in October of 2025, due diligence, and funding gaps pushed it out to last week, and with luck it'll be finalized by the end of 2026. If you're an affected agency, make sure you have the capability to report in the required interval, to include identifying who is accountable and what is actually involved in making those reports. You really don't want to tell the regulator/auditor you didn't know, those are not fun conversations.
- Kiteworks’ Difficult and Unique Decision to Ensure Customer Data Protection Through Customer-Wide Shutdown Successfully Navigates Credible Threat
Summary: Three days after Kiteworks was warned of an imminent cyberattack — prompting the company on September 25 to urge users to shut down all Kiteworks servers between 2:00 and 8:00 UTC on September 26 (described in NewsBites 28.71) — the company released a follow-up press release noting that the threat window had "passed without incident" and that a critical vulnerability had been remediated. During the shutdown period, investigation by internal teams and federal intelligence authorities revealed "a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," which allowed the company to develop and deploy a fix and an "additional protective layer" before systems were restored.
Lee's Take: Make sure you're on Kiteworks 9.4.1 or higher. Their Email Protection Gateway (EPG) is a component in the Kiteworks Private Content Network (CPN). There were 11 critical authentication bypass, admin account takeover, XSS, improper access control and authentiation flaws in the Kiteworks Core and EPG components. The most critical is tracked as CVE-2026-54154, but there are other flaws which are addressed which don't yet have CVE identifers. Don't wait for that, apply the update, verify your'e following security best practices, and leveraging layered defenses. Attackers are searching for unpatched instances, don't be their success story.
- Released: September 2026 V2 Exchange Server Security Updates
Summary: Over the weekend, Microsoft released unexpected updates for Exchange Server to address a high severity privilege elevation vulnerability (CVE-2026-96940, CVSS scores 8.8 / 7.7) that could be exploited to gain access to other users' mailboxes within an organization; Microsoft notes that "the vulnerability does not allow access across tenant boundaries." Microsoft has also deployed a server-site fix to Exchange Online late last week. The vulnerability was found by internal researchers. While there is presently no indication that it is being actively exploited, the vulnerability has low attack complexity with no user interaction, and Microsoft has assigned it an exploitability assessment of "more likely." Users are urged to ensure they are running the most current version of Exchange Server.
Lee's Take: You know those locally hosted Exchange servers I keep bugging you about? Yeah, get them patched right away. If you're running Exchange Server 2016 or 2019, updates are only available if you're under the Period 2 Extended Security Update (ESU) program. Beyond verifying the ongoing need for hosting this service, make sure that there is a trackable plan to update these to Exchange SE RTM with the latest Security Updates, in this case the 9/2026 V2 update.
- Updates to Full Disk Access in macOS – Latest News – Apple Developer
Summary: Apple is adjusting the controls that manage an app API's use of Full Disk Access, adding measures to ensure that users are aware of the level of permission afforded by this access when choosing whether or not to grant it. Apple contends that it is critical to have "very explicit user action" to allow an app to have the "extraordinary" privileges of Full Disk Access, which bypasses the API's built-in controls that protect users' private data, primarily so backup apps can function properly.
Lee's Take: This is more of a clarification to make it easier to see what access you're granting. Not a whole lot of things need full disk access, but instead only the files they need, if any. Right now, go into your settings and see what applications have full disk access. That should probably only be your EDR, backup and network file sync apps (OneDrive, iCloudDrive, etc.) Most other things only need specific folders. You can usually have more than one folder, so you don't have to give broad access which includes stuff which should not be accessible.
- Data breach at Denmark’s national population register exposes 8.8 million people
Summary: Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register, the government said Monday. The perpetrators exploited an unnamed domestic company’s legitimate access to Denmark’s Central Person Register (CPR) to compromise names, addresses and CPR numbers — roughly comparable to Social Security numbers.
Lee's Take: Consider that the population of Denmark is just over six million, this is is a pretty comprehensive breach. Called a population scale breach, these were previously seen in Argentina (2021), Turkey (2016), India (2018) and Israel (2026.) Danish 10-digit CPR numbers, used for banking, healthcare and government services, begin with a person's udate of birth and are intended to last a lifetime. In that context, this is as significant as grabbing an entire country's database of SSNs. The breach levearaged a third-parties access to the database and involved brute-forcing to enumerate CPR numbers. We all have interfaces for accessing our data rather than providing the entire data set to a partner or customer. The question is: did we implement monitoring and use detection to catch and stop anomolous behavior? Yes, we still need to watch for low and slow, and a lot of new tools are loud and fast for now. Model and verify normal behavior, then catch the exceptions. Rate and data size limits should be in the conversation.
Sam Bowne
- Don’t be fooled—LLMs don’t reason
AI's that win at Go use two systems: a policy network to guess what move a strong human would play, and search machinery, which looked beyond immediate plausibility and weighed the future consequences of proposed moves. LLMs use only one system, which merely predicts a token from the preceding tokens, over and over. Chain-of-thought systems merely enhance the prompts fed into that same dumb system. They don't add a genuinely separate reasoning mechanism.
- AI ‘godfather’ Yann LeCun has ‘zero concerns’ about human extinction, says Anthropic CEO Dario Amodei is ‘deluded’
He thinks many of those risks are overblown, and that the constant warning about them from executives at some of the leading AI companies is misguided and counter productive. He attributes the incidents to poor human oversight and system design, and says they’re “totally preventable.”
- Anthropic Has Been Aggressively Lobbying the Vatican to Consider AI Consciousness
For months they've been wining and dining religious scholars across the world in secret, NDA-secured meetings to convince them that AI models think and feel, too. It didn't work. The Pope rejected the idea.
- Musk’s AI chatbot Grok reportedly encouraged Trump to capture Venezuela’s president
This is classic Overreliance: trusting an AI with a responsibility it is far too incompetent to perform.
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others.
- Over 543,000 valid credentials exposed in public GitHub repositories
Data pulled from scanning 224 million repositories and more than 58 billion files show that the median time a unique credential remained publicly accessible was 784 days. Github's "Push Protection" safeguards did not prevent this, because some credentials are not blocked, including database connection strings and Google API keys. In a separate scan, the Hugging Face repositories contained 221,303 working credentials.
- The Secrets of a US Spyware King
Paragon Solutions is now American-owned (on paper) and makes the Graphite spyware tool. It was reportedly used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists, in violation of Paragon's policy. But Paragon has limited ability to block misuse--they have no "kill switch", but they claim that blocking tool updates will render the system ineffective in about 12 hours. They were banned from the US during the Biden administration, but that ban was lifted by the Trump administration. Their main competitor, NSO Group, claims to have a kill switch for their Pegasus spyware tool. They were banned in the USA in 2021 for allowing malicious use, but are copying Paragon's move to gain access to the USA market again.
- IQVIA fined $7.8 million for failing to properly anonymize health data
Italian authorities idecided that the company did not provide adequate health-data anonymization warranties. While the company used a unique code instead of patients' names in those records, the data protection agency found they could be used to track and de-anonymize patients over time.
I hope other people can explain what was wrong here, I don't understand it.
- Anthropic reports Florida woman’s Claude ‘diary’ threat to shoot up sheriff’s office, felony charge follows — it’s at least the third such conversation to reach police since August
Anthropic monitors all chats, apparently. Is this acceptable for regulated industries? Is this something companies will be required to do with AI chatbots they provide to employees?
- Anthropic raises alarm over elite hacking ability of Chinese firm Z.ai’s GLM-5.3
The open-weight AI model almost matches Claude Mythos for cyber capabilities, but has far weaker safeguards, Anthropic says. But evading those safeguards makes the model more useful for both defenders and attackers.
In July, the developer platform Hugging Face used GLM-5.2 to help investigate and contain an autonomous intrusion by OpenAI models, after Anthropic’s Claude refused parts of the security work because of its safeguards.
- Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign
Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running.
The operator used three AI harnesses: Strix for vulnerability search, Cairn for autonomous end-to-end exploitation, and Hermes to orchestrate the campaign, launch intrusion jobs, steer the activity and give tactical guidance in the impact and other stages.
