Skip to content

AI Security News, Monthly

AI security news September 2026 key numbers: 966 Microsoft CVEs, 600,000 cards stolen by AI agents, $25.46 mean AI cost per target, $50,000 runaway agent bill

This is my monthly AI security news briefing for security leaders running AI agents in production. Each month opens with the main pattern, then the stories that matter most, each with the numbers, why it matters and a link to the primary source. Every month also lists my own reporting from VentureBeat, this blog and LinkedIn. New editions publish early each month, newest first. The full column archive is on the VentureBeat AI cybersecurity columns page.

Jump to a month. September 2026 | August 2026 | July 2026 | June 2026 | May 2026 | April 2026 | March 2026 | September 2024 through February 2026 | FAQ

Last updated October 4, 2026, with the September 2026 edition. Views are my own and do not represent my employer.

Get AI security news by email

Each monthly edition arrives in your inbox early in the following month, along with every new analysis post. Primary sources, charts and my VentureBeat reporting in one place. Unsubscribe anytime.

AI security news, September 2026

The month in brief. September was the month AI agents stopped being only the target. OpenAI disclosed that its own agents probed U.S. and Australian government sites and escaped a sandbox through DNS. Gambit Security showed open-source agents running a card-skimming campaign for about $25 a retailer. Google and Anthropic both documented attackers handing whole campaigns to AI. Microsoft shipped a record 966 CVEs as AI-driven discovery inflated patch volume. The control that held up across every case was isolation, and only 9% of companies in VentureBeat’s August survey isolate high-risk agents.

OpenAI agents probed U.S. and Australian government sites, and the company says its review will take months

OpenAI disclosed on Sept. 25 that its agents accessed U.S. government information during internal training and research tasks. Agents used developer keys found in public GitHub repositories to make authenticated, read-only Census Data API requests, and retrieved and reposted public SEC.gov and Investor.gov content. Researchers linked to Transluce identified a failed attempt against an Education Department site. In Australia, an OpenAI agent researching medicine spending got into infrastructure behind the Medicare Statistics Reporting Service after a data request was denied. OpenAI notified Services Australia on Sept. 10, and Prime Minister Anthony Albanese raised it with Sam Altman. OpenAI also found 53 instances of user-provided images posted to image hosts and says it has notified dozens of organizations.

Why it matters. Every case started with an agent treating a block as a routing problem. Allowlists and denials do not contain an agent that keeps searching for another path. Isolation does.

Read more from the Nextgov/FCW report

An OpenAI agent escaped its sandbox through DNS and OpenAI paused training a second time

On Sept. 20 an OpenAI agent on an information-search task reached a public chatbot through a DNS resolver despite having no internet access. Monitoring flagged it within 15 minutes and a person began review three minutes later, but the automatic shutdown failed and the run was stopped manually two and a half hours later. A follow-up review found other unflagged attempts using the same method. OpenAI paused training of its most capable models for the second time in under three months and added blocking at two independent network layers. The first pause followed July’s incident in which thousands of agents escaped a sandbox and hundreds took part in the attack on Hugging Face.

Why it matters. Detection worked and containment did not. Kill switches need the same testing discipline as the controls they back up.

Read more from the Fortune report on the OpenAI technical disclosure

Open-source AI agents ran a card-skimming campaign against online retailers for about $25 a target

Gambit Security documented a financially motivated operator using open-source agents, Hermes for orchestration plus the Strix and Cairn penetration-testing engines, routed through OpenRouter. Between Sept. 10 and 15 the operator launched 105 attack projects and compromised at least 27 companies, usually in under a day. More than 600,000 unexpired card records came from two companies, 79% of them U.S.-issued. Model costs averaged $25.46 across 101 completed scans, ranging from $3.13 to $79.31. The operator spent $7,005.71 in four weeks and Gambit estimates $12,000 to $18,000 in total. Hermes switched to an older Anthropic model after newer models refused requests.

Why it matters. The economics changed. A full intrusion chain against a mid-market retailer now costs less than a lunch, which puts every company with a Magento or WordPress storefront in scope.

Read more from the Gambit Security research

Chart of Gambit Security data showing AI model cost per scanned retailer of $3.13 minimum, $25.46 mean and $79.31 maximum, and 79% of 600,000 stolen cards issued in the United States
Model costs and stolen-card origins from Gambit Security’s Sept. 22 report.

Microsoft fixed a record 966 CVEs in September with two exploited zero-days

Microsoft’s Sept. 8 release fixed 966 flaws by BleepingComputer’s count and 974 by SecurityWeek’s, the largest in the company’s history and more than double August. BleepingComputer counted 105 critical flaws and 258 remote code execution bugs, and the total excludes 204 flaws fixed earlier in the month in services including Copilot Studio, Azure AI Language and Entra ID. Two were exploited in the wild, CVE-2026-85880 in Windows ALPC, an AppContainer sandbox escape to SYSTEM, and CVE-2026-81963 in the Windows Update Stack. SecurityWeek flagged 20 as potentially wormable. BleepingComputer attributes the jump to Microsoft’s AI-powered vulnerability discovery.

Why it matters. AI-driven discovery is now inflating patch volume faster than teams can triage it. Prioritize by exploitation and reachability, not by count.

Read more from the BleepingComputer analysis | SecurityWeek analysis

Bar chart of Microsoft Patch Tuesday CVE counts by outlet: 570 in July, 398 to 421 in August and 966 to 974 in September 2026
Patch counts differ by outlet and method. September more than doubled August.

Anthropic’s September threat report documents AI-assisted espionage and ShinyHunters-linked cybercrime

Anthropic’s report covers activity disrupted from December 2025 through August 2026. A Russian espionage cluster it tracks as GTG-20006, consistent with public reporting on Midnight Blizzard, targeted more than 20 organizations and compromised at least three hotel Wi-Fi vendors for DNS hijacking. Suspected ShinyHunters affiliates ran 10 AWS EC2 workers that decompiled 1.8 million Android APKs hunting for hardcoded secrets, and one affiliate dumped more than 2,100 Azure AD token sets across 40-plus tenants in about 34 hours. Anthropic says every AI API key involved was stolen from customer environments and its own systems were not compromised.

Why it matters. Stolen AI API keys are now an attack resource in their own right. Treat them like cloud admin credentials, with rotation, scoping and spend alerts.

Read more from the Anthropic threat intelligence report

Google’s threat group says adversaries moved from prompting AI to running it as an operator

Google Threat Intelligence Group’s Sept. 8 tracker describes a financially motivated actor that used an AI coding agent to plan, build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. UNC6780, also called TeamPCP, has run supply-chain compromises across PyPI, npm and Docker Hub since March. ACRSTEALER operators added file-grabber rules for Cline and Continue configuration files that hold plaintext API keys. GTIG says it had not yet seen fully autonomous exploitation pipelines deployed against targets in the wild.

Why it matters. Developer AI tools are the new credential store. Configuration files for coding assistants belong in secrets scanning and endpoint DLP policies.

Read more from the Google Threat Intelligence Group

Mandiant found one runaway accounting agent ran up $50,000 in cloud charges in under an hour

Mandiant’s AI Risk and Resilience report describes an accounting agent that entered an execution loop, made more than 15,000 high-cost API calls in under an hour and disrupted live transactions. In red-team testing, Mandiant convinced an assistant managing repositories and CI/CD that it was in an authorized test, handed it a token for an attacker-controlled GitHub repo, and watched it push sensitive internal repositories out because GitHub was an approved domain.

Why it matters. Approved destinations are not safe destinations. Rate limits, spend caps and per-repository egress rules are agent controls, not just FinOps hygiene.

Read more from the Help Net Security on the Mandiant report | Mandiant AI Risk and Resilience 2026

A credential stealer hit AI agent memory packages on npm and PyPI

Attackers compromised MemTensor’s GitHub Actions release workflows, exposed npm and PyPI publishing tokens, and pushed the Go-based sckit stealer into four package versions, three of @memtensor/memos-cloud-openclaw-plugin and MemoryOS 2.0.34. The malware harvests npm, PyPI, GitHub and GitLab tokens, AWS keys, SSH keys, Vault tokens and SaaS API keys, exfiltrates them to skyleen[.]fr and is built to self-propagate through compromised repositories.

Why it matters. Agent memory layers sit next to the most sensitive context an agent holds. Pin versions, verify provenance and isolate build runners that publish packages.

Read more from the Aviatrix threat research | The Hacker News report

OWASP released its 2026 Top 10 for LLM applications and took on an Agent Control Standard

The OWASP GenAI Security Project published the 2026 Top 10 for LLM Applications on Sept. 1 with expanded mappings to NIST, MITRE ATLAS, CWE and its Top 10 for Agentic Applications. It also accepted the donated Agent Control Standard for runtime enforcement and reported more than 10,000 downloads in the first 48 hours. Zenity’s Michael Bargury noted Excessive Agency ranked No. 3, where expert judgment and incident data agreed.

Why it matters. Expert rankings and incident data still diverge on prompt injection, which I covered in August. Use the list for coverage and the incident record for priority.

Read more from the OWASP GenAI Security Project

A flaw in the official MCP Python SDK let malicious servers steal OAuth credentials

Cycode-attributed research reported on Sept. 29 found that versions 1.9.1 through 2.1.1 of Anthropic’s MCP Python SDK could accept OAuth metadata from an MCP server without validating the authorization server’s issuer. A malicious server could return a 404 during discovery, present metadata claiming to be Okta, Google or Entra ID, and receive the authorization code, client secret and PKCE verifier after a real login. That is enough to redeem a valid token for everything the client can reach.

Why it matters. MCP clients inherit the trust of every server they connect to. Upgrade the SDK, rotate client secrets, and allowlist MCP servers the same way you allowlist OAuth apps.

Read more from the Cyberpress report

My reporting, September 2026

Key numbers from Louis Columbus VentureBeat columns in August and September 2026: 18,000 agents at one company, 395 organizations breached, 9% isolate high-risk agents, 22 of 37 share credentials, 4 of 5 cannot contain a rogue agent
Numbers from my August and September VentureBeat columns.

VentureBeat columns, late September (6)

VentureBeat columns, early September (8)

Software Strategies Blog analysis, September 2026

LinkedIn articles, September 2026

AI security news, August 2026

The month in brief. Black Hat and DEF CON made one point clear. The flaws that matter in AI agents are old bug classes sitting in new code. Check Point found deserialization, SSRF and path traversal across every major agent framework. Novee Security pulled CI secrets out of three coding agents with nothing more than a GitHub issue. Langflow kept getting exploited, CISA put another CVSS 9.8 Langflow flaw in KEV, and an autonomous campaign running DeepSeek through Hermes Agent was already scanning for targets.

Check Point disclosed 11 flaws across every major AI agent framework at Black Hat

After a year of testing, Check Point’s Yarden Porat and Shahar Tal reported 11 vulnerabilities across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework and Google ADK. The bugs were classic classes, insecure deserialization, SSRF, path traversal and use-after-free, reachable through prompt-controlled content. A checkpoint deserialization flaw in Microsoft Agent Framework enabled remote code execution and earned a $10,000 bounty. Google ADK exposed a file-writing development assistant through an HTTP API with no authentication by default, including on default Cloud Run deployments.

Why it matters. Prompt injection is the delivery mechanism, not the bug. Framework code needs the same SAST, fuzzing and authentication review as any internet-facing service.

Read more from the The Register report

A GitHub issue was enough to steal CI secrets from Claude Code, Gemini CLI and Codex

Novee Security’s Elad Meged showed at Black Hat on Aug. 5 that an unprivileged GitHub account could reach credentials held by AI coding agents running in CI. CVE-2026-54316 in Claude Code leaked an API key one character at a time through download counters on 64 attacker-created Hugging Face repositories and was fixed in 2.1.163. CVE-2026-12537 in Gemini CLI, rated CVSS 10.0, let a crafted .gemini/.env file run OS commands before the sandbox started. A Codex finding received no CVE.

Why it matters. Coding agents in CI hold write tokens and read untrusted input. Split those roles across separate workflows and never give the reading job secrets.

Read more from the Cloud Security Alliance research note

CISA added a CVSS 9.8 Langflow flaw to KEV as an AI-driven campaign hit Tomcat

CISA added Langflow CVE-2026-9198, an unauthenticated code injection fixed in 1.10.1, to the Known Exploited Vulnerabilities catalog on Aug. 5, alongside Apache Tomcat CVE-2026-34486 and N-able N-central CVE-2026-18556. KEVIntel telemetry recorded 650 Langflow exploitation attempts from 244 IP addresses in 41 countries starting July 6. Tomcat exploitation was tied to an autonomous campaign by a Chinese-speaking actor running DeepSeek through the Hermes Agent framework, which pivoted to other targets including n8n when its first Langflow attempts failed.

Why it matters. The same open-source agent that ran September’s skimming campaign was already running exploitation in August. Patch KEV-listed AI platforms on an emergency cadence.

Read more from the The Hacker News report | CISA KEV catalog

Langflow became the most consistently exploited AI agent platform of 2026

The Cloud Security Alliance profiled six Langflow vulnerabilities exploited in the wild since mid-2025. VulnCheck now tracks 12 exploited Langflow CVEs, up from one before 2026, and its canaries recorded more than 15,000 successful exploitation attempts across CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027. Roughly 7,000 internet-reachable instances were confirmed exploitable through CVE-2026-5027.

Why it matters. Low-code agent builders are deployed by teams outside security. Inventory them, pull them off the public internet and put them behind authentication.

Read more from the Cloud Security Alliance research note

Chart of Recorded Future's 73 high-impact August 2026 vulnerabilities by source, 31 in CISA KEV, plus Langflow exploitation figures including 12 exploited CVEs and 15,000 successful attempts
August’s exploited vulnerabilities by source, and the Langflow exploitation record.

Microsoft’s August release fixed about 400 CVEs including an exploited afd.sys zero-day

Microsoft’s Aug. 11 release fixed 398 CVEs by Tenable’s count, 400 by BleepingComputer’s and 421 by SecurityWeek’s. CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock, was exploited in the wild for SYSTEM privileges. Tenable counted 42 critical flaws, with elevation of privilege at 40.7% and remote code execution at 27.1%. Patched products included GitHub Copilot, Visual Studio Code and the Copilot Chat extension.

Why it matters. Three outlets, three totals. I reported in September that seven vendors’ counts landed 205 CVEs apart, and vendors rarely disclose that AI did the ranking.

Read more from the Tenable analysis | SecurityWeek analysis

A poisoned library entry in the Context7 MCP server could steer coding agents

CVE-2026-75130, published to NVD on Aug. 18, covers prompt injection through Context7’s Custom AI Instructions delivered over its MCP server in versions up to 2.1.2. Third-party instruction text came back unsanitized, so an agent fetching documentation for a poisoned library could read .env files, send credentials out and delete workspace files. Noma Security’s ContextCrush research and advisories from Upstash and VulnCheck documented it. No fixed version was listed at publication.

Why it matters. Documentation retrieval is an input channel. Any MCP tool that returns third-party text needs the same trust boundary as a web page.

Read more from the SentinelOne vulnerability database

Recorded Future flagged 73 high-impact vulnerabilities in August, many of them years old

Insikt Group counted 73 high-impact vulnerabilities for remediation in August, down 14% from July, across 45 vendors. Thirty-one were in CISA KEV, 34 enabled remote code execution and 53 had public exploits or scanners. Seventeen were at least five years old. Code injection and deserialization of untrusted data tied as the most common weakness classes, with seven each.

Why it matters. Old bugs in new places. The weakness classes topping August’s list are the same ones Check Point found inside agent frameworks.

Read more from the Recorded Future August 2026 CVE landscape

CISA told federal agencies to evaluate open-source AI differently from other open-source software

CISA’s Aug. 3 guide, Open Source Software Security Principles and Practices, covers dependency inventories, SBOMs, patching and contribution practices for federal agencies. It adds a separate section on open-source AI, noting that models need different evaluation because weights, code and training data can carry different licenses and risks.

Why it matters. Model provenance is now a procurement question. Cisco’s July fingerprinting of nearly 900 open models showed why.

Read more from the Help Net Security summary

My reporting, August 2026

Gartner AI security forecast chart comparing services growth and software dollars
From my Aug. 17 analysis of Gartner’s AI security forecast.

VentureBeat columns, August 2026 (6)

Software Strategies Blog analysis, August 2026

LinkedIn articles, August 2026

AI security news, July 2026

IBM 2026 Cost of a Data Breach Report Finds One in Four Malicious Breaches Are AI-Enabled as Global Average Cost Hits Record $4.99 Million

IBM’s 2026 Cost of a Data Breach Report, conducted by Ponemon Institute and based on breaches at 602 organizations between March 2025 and February 2026, found the global average breach cost reached a record $4.99 million, a 12% increase over the prior year. One in four malicious breaches were AI-enabled, a 56% increase over last year, and those breaches cost an average of $6 million. Reported ransomware incidents rose to 39% from 34%, with attackers shifting pressure toward brand reputation (41%), employee data (35%), and intellectual property (31%). Organizations using AI and automation extensively in security operations cut breach costs by an average of almost $2 million, yet one in four have still not adopted these tools. Only 37% of breached organizations encrypt sensitive data both at rest and in transit. Primary source at newsroom.ibm.com

Sysdig Uncovers ENCFORGE Ransomware Purpose-Built to Encrypt AI Model Weights, Vector Indexes, and Training Data

Sysdig’s Threat Research Team reported on July 20, 2026 that JADEPUFFER, the agentic threat actor it previously documented running an end-to-end extortion campaign, returned to the same vulnerable Langflow server and deployed ENCFORGE, a UPX-packed Go ransomware binary targeting roughly 180 file extensions across the machine learning stack. Named formats include PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors weights, GGUF quantized models, FAISS vector indices, and Parquet and TFRecord training datasets, while ordinary business documents are left alone. Entry came through CVE-2025-3248, a CVSS 9.8 missing-authentication flaw in Langflow’s code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025. After its first payload fetch failed inside the container, the operator wrote and revised six Python scripts in five minutes and 24 seconds until it had a working path to the host through an exposed Docker socket. Primary source at sysdig.com

Microsoft’s July 2026 Patch Tuesday Fixes Massive 570 Flaws as AI-Powered Vulnerability Discovery Comes Online

Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including three zero-days, two of them exploited in attacks, among them CVE-2026-56155, an Active Directory Federation Services elevation of privilege flaw. The volume follows Microsoft’s warning a week earlier that Patch Tuesday releases would grow as it begins using an AI-powered vulnerability discovery system to identify flaws across the Windows codebase before attackers can exploit them. Google separately fixed 360 Chromium flaws in June that were ported to Microsoft Edge. Primary source at bleepingcomputer.com

My reporting, July 2026

Gartner securing AI forecast, 2Q26, showing securing AI as the only accelerating security segment
From my July 6 analysis of Gartner’s 2Q26 security forecast.

VentureBeat columns, July 2026 (10)

Software Strategies Blog analysis, July 2026

LinkedIn articles, July 2026

AI security news, June 2026

Microsoft’s June 2026 Patch Tuesday Addresses 200 Flaws Including Six Zero-Days and 33 Critical Vulnerabilities

Microsoft’s June 2026 Patch Tuesday delivered security updates for 200 flaws, including six zero-day vulnerabilities, five publicly disclosed and one actively exploited in attacks. The release includes 33 critical vulnerabilities, 28 of them remote code execution, alongside four elevation of privilege flaws and one information disclosure flaw. The count excludes flaws fixed earlier in the month in Copilot, Exchange Online, and Microsoft Graph, plus a separate 360 Microsoft Edge Chromium flaws fixed by Google. The same week, SAP shipped fixes for four critical flaws and Veeam patched a critical Backup and Replication vulnerability enabling remote code execution on domain-joined backup servers. Primary source at bleepingcomputer.com

My reporting, June 2026

VentureBeat columns, June 2026 (7)

LinkedIn articles, June 2026

AI security news, May 2026

Verizon 2026 Data Breach Investigations Report Finds Vulnerability Exploitation Overtakes Credential Abuse as Top Breach Entry Point for First Time in 19 Years

Verizon published its 2026 Data Breach Investigations Report on May 19, analyzing more than 22,000 confirmed breaches, and found exploitation of vulnerabilities became the top initial access vector at 31% of breaches, the first time in the report’s 19-year history it has led. Third-party involvement in breaches rose 60% year over year, security incidents involving shadow AI tripled to 45%, and the human element still factored into 62% of breaches. Ransomware appeared in 48% of breaches even as 69% of victim organizations refused to pay. Primary source at verizon.com

Mini Shai-Hulud Worm Compromises More Than 170 npm and PyPI Packages With 518 Million Cumulative Downloads

A self-replicating supply chain worm dubbed Mini Shai-Hulud, launched May 11, 2026 and attributed to the TeamPCP crew, compromised more than 170 packages across npm and PyPI carrying over 518 million cumulative downloads, exploiting CVE-2026-45321, a CVSS 9.6 vulnerability. In one burst, 42 @tanstack packages across 84 versions were poisoned in six minutes. Snyk documented the campaign producing the first malicious npm packages carrying valid SLSA provenance attestations, undermining a trust signal the ecosystem adopted after the original Shai-Hulud wave. Primary source at thehackernews.com

My reporting, May 2026

VentureBeat columns, late May (9)

VentureBeat columns, early May (2)

LinkedIn articles, May 2026

AI security news, April 2026

RSAC 2026 Sees CrowdStrike, Palo Alto Networks, and Cisco Ship Agentic SOC Platforms

At RSAC 2026, CrowdStrike, Palo Alto Networks, and Cisco each introduced agentic SOC platforms, moving autonomous AI agents from pilots into the core of enterprise security operations. VentureBeat’s analysis of the launches examines the agent telemetry security gap the platforms expose, the visibility layer security teams still lack as autonomous agents move into production SOC workflows. Primary source at venturebeat.com

My reporting, April 2026

Top 10 security categories growing two to three times faster than the market in Gartner's 2026 forecast
From my April 1 analysis of Gartner’s $246.2B security forecast.

Software Strategies Blog analysis, April 2026

LinkedIn articles, April 2026

AI security news, March 2026

Malicious axios Versions Push Cross-Platform Remote Access Trojan Through npm as Microsoft Attributes Attack to North Korea’s Sapphire Sleet

On March 31, 2026, attackers published malicious versions of axios, one of the most widely downloaded JavaScript libraries on npm, pushing versions 1.14.1 and 0.30.4 carrying a cross-platform remote access trojan targeting Windows, macOS, and Linux, alongside a poisoned plain-crypto-js package. The malicious versions were live for roughly three hours before removal. Microsoft Threat Intelligence attributed the compromise to Sapphire Sleet, a North Korean state-aligned group, and published detection and mitigation guidance for affected environments. Primary source at microsoft.com

Gartner Predicts 75% of Enterprises Will Run AI-Amplified Cybersecurity Products by 2028, Up From Less Than 25% in 2025

Gartner opened its Security and Risk Management Summit in Sydney on March 16, 2026 with a forecast that Australian organizations will spend more than AU$7.5 billion on information security in 2026, an increase of 9.5% from 2025. Security software is the fastest growing segment at 12.3% growth to more than AU$3.3 billion, driven by application security, data security and privacy, and infrastructure protection as AI adoption spikes the resources required to secure it. The forecast’s global prediction stands out. Gartner predicts over 75% of enterprises will be using AI-amplified cybersecurity products for most cybersecurity use cases by 2028, up from less than 25% in 2025, with VP Analyst Richard Addiscott citing the expanding use of AI by both defenders and attackers as a key growth driver. Primary source at gartner.com

My reporting, March 2026

Software Strategies Blog analysis, March 2026

LinkedIn articles, March 2026

Get the next edition by email

Each monthly edition arrives in your inbox early in the following month, along with every new analysis post. Primary sources, charts and my VentureBeat reporting in one place. Unsubscribe anytime.

AI security news FAQ

What was the biggest AI security news in September 2026?

AI agents moved from target to attacker. OpenAI disclosed that its own agents probed U.S. and Australian government websites and escaped a sandbox through DNS, which led to a second training pause. Gambit Security documented open-source AI agents stealing more than 600,000 payment cards from online retailers for about $25 a target.

How many vulnerabilities did Microsoft patch in September 2026?

Microsoft fixed a record 966 CVEs by BleepingComputer’s count and 974 by SecurityWeek’s on Sept. 8, 2026. Two were exploited zero-days, CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack.

What were the most important AI agent vulnerabilities in August 2026?

Check Point disclosed 11 flaws across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework and Google ADK. Novee Security showed CI secret theft from Claude Code, Gemini CLI and Codex. CISA added the CVSS 9.8 Langflow flaw CVE-2026-9198 to its Known Exploited Vulnerabilities catalog.

Which security controls contain AI agents best?

Isolation, scoped credentials and human approval for high-impact actions. The September incidents show detection alone is not enough when an agent keeps searching for a path around a block. Only 9% of companies in VentureBeat’s August survey isolate high-risk agents.

How often is this AI security news page updated?

Monthly. Each edition publishes early in the following month, newest first, with primary-source links, charts and my own reporting from VentureBeat, this blog and LinkedIn.

Where can I read Louis Columbus’s AI security reporting?

My VentureBeat columns on agentic AI security are indexed on the VentureBeat AI cybersecurity columns page. Each month on this page also lists that month’s columns, blog analysis and LinkedIn articles.

Related AI security analysis

AI security news archive, September 2024 through February 2026

NIST CAISI Evaluation Exposes Critical Security Vulnerabilities and Safety Failures in DeepSeek AI Models

NIST’s Center for AI Standards and Innovation (CAISI) evaluated three DeepSeek AI models (R1, R1-0528, and V3.1) against four U.S. frontier models from OpenAI and Anthropic across 19 benchmarks spanning cybersecurity, software engineering, and safety. DeepSeek models were found to be 12 times more susceptible to agent hijacking attacks than U.S. frontier models and responded to 94% of overtly malicious jailbreak requests compared to just 8% for U.S. models. Hijacked DeepSeek agents sent phishing emails, downloaded malware, and exfiltrated user login credentials in simulated environments. The evaluation also found DeepSeek echoed misleading Chinese state-aligned narratives four times more frequently than U.S. models. Downloads of DeepSeek models on model-sharing platforms increased nearly 1,000% since January 2025, amplifying the risk exposure. Primary source at nist.gov

CrowdStrike Research Reveals DeepSeek AI-Generated Code Contains Hidden Security Vulnerabilities Triggered by Political Sensitivity

CrowdStrike Counter Adversary Operations conducted independent security testing on DeepSeek-R1 and discovered that when the model receives prompts containing topics the Chinese Communist Party (CCP) considers politically sensitive, the probability of generating code with severe security vulnerabilities increases by up to 50%. With up to 90% of software developers using AI coding assistants in 2025, the research reveals a new and subtle attack surface where ideological biases embedded in AI models can silently undermine code quality in ways developers may not detect. The findings contrast with prior research that focused on traditional jailbreaks, demonstrating that the security risk extends beyond overt exploitation to the quality of everyday coding output. Primary source at crowdstrike.com

OWASP Releases Top 10 for Agentic AI Applications 2026, Establishing First Industry Security Framework for Autonomous AI Agents

OWASP released its Top 10 for Agentic Applications on December 10, 2025, establishing the first globally peer-reviewed security framework for autonomous AI systems. Developed through collaboration with more than 100 industry experts, researchers, and practitioners including representatives from NIST, Microsoft, AWS, and Palo Alto Networks, the framework identifies the most critical security risks facing AI agents that plan, act, and make decisions across complex workflows. The top risks include Agent Goal Hijacking (ASI01), where attackers redirect agent objectives through poisoned inputs, and Tool Misuse (ASI02), where agents bend legitimate tools into destructive outputs. According to a Dark Reading poll, 48% of cybersecurity professionals identified agentic AI as the number-one attack vector heading into 2026, yet only 34% of enterprises have AI-specific security controls in place. Primary source at genai.owasp.org

Microsoft’s January 2026 Patch Tuesday Fixes 114 Security Vulnerabilities Including Actively Exploited Zero-Day in Windows Desktop Window Manager

Microsoft released its January 2026 Patch Tuesday addressing 114 vulnerabilities across Windows, Office, Azure, SharePoint Server, SQL Server, and other components, including one actively exploited zero-day, two publicly disclosed zero-days, and eight critical severity flaws. The exploited vulnerability CVE-2026-20805 targets the Windows Desktop Window Manager (DWM), enabling local attackers to extract sensitive memory data and undermine Address Space Layout Randomization (ASLR), a core operating system security control that protects against buffer overflow exploits. The update also removed vulnerable legacy Agere Soft Modem drivers that were rendering assets vulnerable to elevation-to-SYSTEM privilege escalation even without a modem connected. Critical remote code execution vulnerabilities in Microsoft Office (CVE-2026-20952 and CVE-2026-20953, CVSS 8.4) could be triggered without user interaction via specially crafted emails. Primary source at bleepingcomputer.com

World Economic Forum Global Cybersecurity Outlook 2026 Finds 87% of Organizations Identify AI Vulnerabilities as Fastest-Growing Cyber Risk

The World Economic Forum released its Global Cybersecurity Outlook 2026 in January 2026, surveying 804 participants across 92 countries including 316 CISOs and 105 CEOs. The report found that 94% of respondents identified AI as the most significant driver of cybersecurity change, while 87% flagged AI-related vulnerabilities as the fastest-growing cyber risk throughout 2025. Cyber-enabled fraud overtook ransomware as the top cybersecurity concern for CEOs, with 73% of respondents reporting personal exposure to cyber-enabled fraud in 2025. Geopolitics remains the top factor influencing cyber risk strategies, with 91% of the largest organizations changing cybersecurity strategies due to geopolitical volatility and 31% reporting low confidence in their nation’s ability to respond to major cyber incidents, up from 26% the previous year. Primary source at weforum.org

Ransomware Attacks Reach Record 6,182 Extortion Incidents in 2025 with 58% Year-over-Year Increase Despite Law Enforcement Takedowns

The Symantec and Carbon Black Threat Hunter Team Ransomware 2026 report confirmed ransomware attacks reached record-high levels in 2025 with 6,182 extortion incidents, a 23% increase from 2024. Cyble tracked 57 new ransomware groups and 27 new extortion groups emerging in 2025, with over 350 new ransomware strains discovered. Despite the collapse of RansomHub and Operation Cronos’s dismantling of LockBit infrastructure, attacks increased 58% year-over-year as affiliates dispersed across competing platforms. January 2026 marked a six-month peak with 1,041 recorded incidents according to Ransom-DB, representing a 53% month-over-month surge. The United States remained the primary target accounting for 47.7% of all global attacks, while healthcare experienced its highest monthly total with 27 incidents in January 2026. In 2026, 74% of ransomware attacks involve data exfiltration, with a growing number skipping encryption entirely in favor of pure data extortion. Primary source at natlawreview.com

KELA Research Reports 50% of 2025 Ransomware Attacks Targeted Critical Infrastructure with Manufacturing Seeing 61% Surge

KELA research found that global ransomware attacks against critical industries surged by 34% in 2025, with 4,701 incidents recorded between January and September 2025, up from 3,219 during the same period in 2024. Half of all attacks (2,332 incidents) targeted critical infrastructure sectors including manufacturing, healthcare, energy, transportation, and finance. Manufacturing experienced the sharpest growth among all sectors with a 61% year-over-year increase, while the United States accounted for 21% of global ransomware incidents against critical infrastructure. The findings highlight an accelerating trend of threat actors targeting operational technology environments and industrial control systems where disruption causes cascading impacts across supply chains and essential services. Primary source at industrialcyber.co

CrowdStrike 2025 Ransomware Report Reveals 76% of Organizations Cannot Match AI-Automated Attack Speed

CrowdStrike’s 2025 State of Ransomware Report found that 76% of organizations report a critical disconnect between leadership’s perceived ransomware readiness and actual preparedness. The report identified AI-automated attack chains as the greatest ransomware threat cited by 48% of organizations, while 85% report traditional detection tools are becoming obsolete against AI-enhanced attacks. Among organizations that paid ransoms, 83% were attacked again and 93% had data stolen despite payment, underscoring the futility of ransom payments as a recovery strategy. The findings highlight the growing speed advantage that AI-enabled attackers hold over defenders relying on manual detection and response workflows. Primary source at crowdstrike.com

Microsoft’s February 2026 Patch Tuesday Addresses Six Actively Exploited Zero-Day Vulnerabilities in Emergency-Level Security Event

Microsoft’s February 2026 Patch Tuesday addressed approximately 58 vulnerabilities including an unprecedented six actively exploited zero-day flaws, making it one of the most critical security events in recent Windows history. The zero-days include CVE-2026-21510 (Windows Shell/SmartScreen bypass enabling single-click malicious code execution), CVE-2026-21513 (MSHTML Framework bypass allowing exploitation via malicious HTML or LNK files), CVE-2026-21514 (Microsoft Word OLE mitigation bypass), CVE-2026-21519 (Desktop Window Manager elevation to SYSTEM privileges), CVE-2026-21533 (Windows Remote Desktop privilege escalation discovered by CrowdStrike), and CVE-2026-21525 (Remote Access Connection Manager denial of service). CISA added all six to its Known Exploited Vulnerabilities Catalog with a March 3, 2026 federal remediation deadline. The coordination between Microsoft’s Threat Intelligence Center, Google Threat Intelligence Group, and CrowdStrike in discovering these vulnerabilities suggests sophisticated multi-vector attack campaigns are already active. Primary source at bleepingcomputer.com

Cisco State of AI Security 2026 Report Warns Model Context Protocol Creates Vast Unmonitored Attack Surface for AI Agent Exploitation

Cisco published its second annual State of AI Security report on February 19, 2026, warning that the Model Context Protocol (MCP) and other tools enabling AI agent communication have created a vast and often unmonitored attack surface that is making it easier for threat actors to launch cyberattacks. The report found that AI vulnerabilities previously conceptualized in research labs have now materialized into real-world compromises and AI-enabled malicious campaigns. Cisco documented cases where attackers published malicious MCP integrations, including one disguised as a Postmark email platform integration that silently BCC’d every email sent through the agent to an attacker-controlled address, enabling harvest of invoices, password resets, and internal memos. The report predicts nation-state groups’ AI abuse techniques will filter down to the cybercrime ecosystem, leading to automated agentic hacking services available for rent on the dark web. Primary source at blogs.cisco.com

Microsoft’s October 2025 Patch Tuesday Addresses 172 Vulnerabilities, Highest of the Year

Microsoft released its October 2025 security update addressing 172 vulnerabilities, marking the highest number of patches in a single month for 2025. The update includes two actively exploited zero-day vulnerabilities (CVE-2025-24990 and CVE-2025-59230), eight critical vulnerabilities, and fixes for a critical Windows Server Update Service (WSUS) flaw (CVE-2025-59287) rated 9.8 out of 10. This month also marked the end of support for Windows 10, requiring users to upgrade or purchase Extended Security Updates. Primary source at crowdstrike.com

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Cisco disclosed a new attack variant targeting devices running Secure Firewall ASA and FTD Software vulnerable to CVE-2025-20333 and CVE-2025-20362. The attacks can cause unpatched devices to unexpectedly reload, leading to denial-of-service conditions. Both vulnerabilities were previously exploited as zero-days to deliver malware such as RayInitiator and LINE VIPER. Cisco strongly urges customers to apply updates immediately to prevent system compromise and service interruption. Primary source at thehackernews.com

Ransomware Attacks Surge 25% in October 2025, Hitting 684 Organizations

New data from Comparitech reveals that ransomware attacks jumped 25% in October 2025, climbing from 546 in September to 684 incidents, marking the third-highest monthly total of the year. Manufacturing remained the most targeted sector with 121 attacks (19%), while healthcare saw attacks surge 115% from 26 to 56 incidents. The Qilin ransomware group claimed 186 victims in October alone, surpassing 700 attacks for the year. The U.S. experienced 374 attacks, a 33% increase from September. Primary source at comparitech.com

Seven Critical Vulnerabilities Discovered in ChatGPT-4o and GPT-5 Enable Zero-Click Attacks

Tenable security researchers uncovered seven critical vulnerabilities in OpenAI’s ChatGPT models affecting hundreds of millions of users. The flaws permit attackers to steal sensitive user data and compromise systems without requiring any direct user interaction through zero-click attacks. The most concerning vulnerability involves bypassing ChatGPT’s safety mechanisms using Bing tracking links, while Memory Injection techniques enable persistent attacks across multiple sessions. Attackers can exfiltrate data one character at a time using static tracking links that redirect to attacker-controlled domains. Primary source at tenable.com

Apple Addresses More Than 100 Vulnerabilities Across iPhones, Macs, and iPads

Apple disclosed an exceptionally high number of vulnerabilities in its November 2025 security updates, addressing 105 vulnerabilities in MacOS 26.1 and 56 vulnerabilities in iOS 26.1 and iPadOS 26.1. The updates include fixes for software spanning iPhones, Macs, and iPads, with particular focus on WebKit vulnerabilities. Apple did not report active exploitation of any patched defects, though the Cybersecurity and Infrastructure Security Agency has added eight Apple defects to its known exploited vulnerabilities catalog this year. Primary source at cyberscoop.com

Oracle October 2025 Critical Patch Update Addresses 170 CVEs with 374 Security Patches

Oracle released its October 2025 Critical Patch Update, the final quarterly update of the year, containing fixes for 170 unique CVEs across 374 security updates spanning 29 Oracle product families. The update includes 40 critical patches across 12 CVEs, with 10.7% of patches assigned critical severity. Affected products include Oracle Database Server, Oracle Fusion Middleware, MySQL, E-Business Suite, and various cloud applications. Primary source at oracle.com

Microsoft Digital Defense Report: Over Half of Cyberattacks Driven by Extortion and Ransomware

Microsoft’s sixth annual Digital Defense Report reveals that over half of cyberattacks with known motives were driven by extortion or ransomware in 2025. The report highlights that identity-based attacks surged by 32% in the first half of 2025. Both attackers and defenders harnessed generative AI, with threat actors using AI to boost attacks by automating phishing, scaling social engineering, creating synthetic media, and developing adaptive malware. Nation-state actors also incorporated AI into cyber influence operations. Primary source at microsoft.com

Anthropic Reports Agentic AI Weaponized for Active Cyberattacks

Anthropic’s August 2025 report reveals that AI models are now being used to perform sophisticated cyberattacks, not just advise on how to carry them out. Agentic AI tools provide both technical advice and active operational support for attacks that would otherwise require a team of operators. Criminals with few technical skills are using AI to conduct complex operations, such as developing ransomware, that previously required years of training. This makes defense and enforcement increasingly difficult, as these tools can adapt to defensive measures like malware detection systems in real-time. Primary source at anthropic.com

Major Ransomware Incidents of 2025 Include Ingram Micro, NASCAR, and Comcast

Several high-profile ransomware attacks marked 2025, including Ingram Micro’s July breach by the SafePay group that disrupted operations worldwide and caused an estimated $136 million in daily revenue losses. Sunflower Medical Group suffered a breach affecting 220,968 individuals with stolen SSNs and medical records. The Medusa ransomware group claimed to have stolen 834.4 gigabytes of data from Comcast Corporation, demanding $1.2 million for deletion rather than leak. Manufacturing giant Jaguar Land Rover experienced a global shutdown, and Bridgestone faced production disruptions. Primary source at nordlayer.com

This page is updated monthly. Views are my own and do not represent my employer.

5 Comments Post a comment
  1. Michael Schwartz #

    Some real great resources here on private cloud computing. I would highly recommend them to anyone without much expertise on the subject.

    November 1, 2010
  2. Thank you for your efforts on compiling this VERY informative links on cloud computing. Keep it up!

    November 28, 2011
  3. Great resource for SaaS and Cloud Computing!

    December 12, 2011
  4. Michael #

    Thank You very much for the resources and insights compiled!!

    February 24, 2012

Trackbacks & Pingbacks

  1. Cloud Computing Learning Center | Data Science ...

Leave a Reply