Security Monitor 2026-10-01
Informational security guidance. Not certification. Not a substitute for scoped human review.
Executive Summary
Yesterday's DIVD breach is now the most concrete public proof yet that the agentic-attacker thread is real. DIVD identified the exact vector: two previously unknown Zammad zero-days (CVE-2026-102489 and CVE-2026-102490) chained by an AI agent to go from initial access to root and data exfiltration in seconds. DIVD is urging anyone running any version of Zammad to update to version 7 or take the box offline.
The exploited-flaw pipeline kept running on the edge layer. Cisco disclosed that an unauthenticated admin-API bypass in Catalyst SD-WAN Manager (CVE-2026-76504, CVSS 9.8) is under active exploitation and is already in CISA KEV with a federal due date of October 3. The Citrix NetScaler zero-day campaign (CVE-2026-88772) is now confirmed to have hit government and finance organizations in weeks-long attacks.
On the endpoint side, the first public proof-of-concept for the Apple CoreGraphics zero-day (CVE-2026-86950) appeared, with a WhatsApp PDF delivery path being checked. Google's GTIG data now shows AI-discovered vulnerabilities are nearly twice as likely to enable RCE as the rest.
The operational imperative is threefold. If you run Zammad, treat it as compromised until you're on version 7 or the box is offline. If you run Cisco SD-WAN Manager or Citrix NetScaler, the unpatched appliance is a confirmed target, so patch and hunt for access now. If you run Apple endpoints, the CoreGraphics PoC plus the WhatsApp vector means the October 2 KEV deadline is no longer theoretical.
For NetScaler specifically, the CISA KEV due date was September 30 and is now overdue as of October 1.
Headline Developments
1. DIVD identifies the two Zammad zero-days its AI-agent attacker chained to root in seconds HIGH
Source: Security Affairs - AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds (Sept 30). DIVD and Merlon details are reported by Security Affairs secondary.
- DIVD, working with Merlon Security, identified the two previously unknown vulnerabilities that enabled the breach: CVE-2026-102489 (a session-hijack flaw enabling unauthenticated remote code execution as the Zammad user) and CVE-2026-102490 (a local privilege escalation from the Zammad user to root).
- Chained together, the two flaws let the attacker hijack sessions, run code remotely, and escalate from the Zammad user to root "in seconds, due to the agentic part of this hack." The AI agent made each decision and carried out the next step without waiting for a human operator.
- After gaining root, the attacker reached other services, read and exfiltrated data, and only network segmentation plus a fast response from DIVD's IT and incident-response teams stopped further movement. Some data theft had already occurred before the attack was stopped.
- The affected surface is broad: Zammad is an open-source helpdesk platform with more than 2,000 customers and roughly 55,000 users.
- DIVD is urging anyone running any version of Zammad to update to version 7 or take the system offline as soon as possible. A further public update was expected October 1, with notification of other possible victims of the same underlying vulnerability.
Why this matters: This converts the "agent as attacker" thread from a confirmed breach (09-29/09-30) into a confirmed, named, patchable flaw with CVEs. The 09-30 brief flagged the breach as MEDIUM because there was no CVE to patch and no named product. That ceiling is now wrong in the defender's favor: there are two CVEs, the exploit path is public, and the victim is telling the whole industry to update. For any organization that runs Zammad, the defensive action is now specific and immediate: upgrade to version 7 or take the box offline. For everyone else, it's the clearest public demonstration that an autonomous agent can chain a session hijack into a root shell faster than a human SOC can react, which is exactly the failure mode the defensive tooling (Nvidia's safety platform, 09-28; Anthropic's compliance API, 09-30) is being built to detect.
Pattern callout: Extends the "the vendor is now the case study" pattern (09-16 through 10-01) and the "the agent's supply chain is the supply chain" pattern (09-13 through 10-01), but this is the first time the "agent as attacker" thread (DIVD breach, 09-29/09-30) has the underlying CVEs published. The prior iteration described the agent's behavior; this one names the two flaws the agent chained, which means the defensive question shifts from "detect the agent" to "patch the product the agent is chaining, before the next agent gets to it."
2. Cisco warns of active exploitation of an unauthenticated admin-API bypass in Catalyst SD-WAN Manager HIGH
Source: The Hacker News - Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager (Sept 30). Incident framing is reported by THN; the CISA KEV entry was verified separately on the CISA catalog.
- Cisco warned on September 30 that attackers are actively exploiting a critical authentication bypass in Catalyst SD-WAN Manager, tracked as CVE-2026-76504 (CVSS 9.8).
- The flaw lets a remote attacker with no login access use the Manager's API as the admin user, giving unauthenticated administrative control over the SD-WAN fabric.
- Catalyst SD-WAN Manager is the control dashboard that administrators use to monitor and configure as many as 6,000 branch devices per site, so a single compromised Manager is a large blast radius across the WAN.
- Cisco pushed emergency guidance with the disclosure; the flaw is a zero-day that was exploited before a fix was widely known.
- CISA KEV (verified 2026-10-01): CVE-2026-76504 was added 2026-09-30 with federal remediation due date 2026-10-03. Active exploitation was reported publicly; the CISA KEV listing (due October 3) is confirmed separately on the catalog.
- The report also noted Cisco's earlier SD-WAN history, including an information-disclosure flaw (CVE-2026-20127) patched in February and a maximum-severity Catalyst SD-WAN Controller auth bypass (CVE-2026-20182) tagged as actively exploited.
Why this matters: This is a confirmed exploited zero-day in a widely deployed WAN control plane, with a public CVE, active exploitation, and a CISA KEV entry with an October 3 deadline, which puts it firmly in the HIGH band. The defensive implication is the same one that has recurred all month: the management/control API is the boundary, and it's unauthenticated or weakly authenticated in practice. For any organization running Catalyst SD-WAN Manager, the action is to apply the fix immediately, restrict the Manager API to trusted networks, and hunt for unauthorized admin-API calls in the logs. It also reinforces the broader point that SD-WAN and edge management are a primary target class, not a niche one.
Pattern callout: Extends the "the edge appliance is the boundary, and the boundary is failing" pattern (09-17 through 10-01). The prior iterations were Citrix NetScaler (09-27/09-28/09-30), SharePoint (09-25), MikroTik RouterOS (09-25), WSO2 API Manager (09-25), and the PeopleSoft PSEMHUB WAF bypass (09-27/09-28). This iteration adds another WAN control-plane API to the same list, which means the failure isn't one vendor or one product: it's the category of management APIs that sit in front of the fabric.
3. NetScaler zero-day campaign confirmed against government and finance organizations HIGH
Source: SecurityWeek - Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks (Oct 1). Campaign details are reported by SecurityWeek, summarizing Mandiant/GTIG; Rapid7's "Observed Exploitation" is corroboration, not a new primary CVE.
- Mandiant and Google Threat Intelligence Group identified weeks-long attacks exploiting CVE-2026-88772 against government and finance organizations, with the activity first spotted in late September.
- The report focuses on the exploitation of the NetScaler ADC and Gateway zero-day (CVE-2026-88772), which the 09-30 brief already covered as a pre-auth RCE with a now-public exploit path.
- Rapid7's tracking of the same CVE added an "Observed Exploitation" section on September 30 with cases its SOC team flagged, corroborating that exploitation is occurring in customer environments, not just in theory.
- CISA KEV due date for CVE-2026-88771 and CVE-2026-88772 is 2026-09-30 (verified on the CISA catalog). That deadline has passed as of October 1 and is treated as overdue.
Why this matters: This is the new material for a story the 09-27 through 09-30 briefs already carried: the victims are now confirmed to include government and finance organizations, and the timeframe is weeks, not a one-day scan. That is a confirmed exploitation pattern with a high likelihood of lateral movement in exactly the kind of environment where a NetScaler sits at the perimeter, which is the HIGH definition. The defensive implication is unchanged but sharpened: if you run NetScaler ADC or Gateway and haven't applied the patch, treat the appliance as already exposed, because the campaign is ongoing and the federal deadline has already passed. The WAF and segmentation aren't substitutes for the patch, and the exploit is public.
Pattern callout: Extends the "exploited flaws move to KEV and stay exploited" pattern (09-17 through 10-01) and the "the edge appliance is the boundary, and the boundary is failing" pattern (09-17 through 10-01). The 09-30 iteration was the public exploit path for CVE-2026-88772; this one is the confirmed victim set (government and finance) and the duration (weeks). Together they close the loop on the NetScaler story: the flaw is real, the exploit is public, the victims are confirmed, and the KEV deadline has passed.
4. Apple CoreGraphics PoC published, with a WhatsApp PDF delivery path under review HIGH
Source: The Hacker News - Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path (Sept 30, reported Oct 1). PoC analysis is reported by THN, summarizing Calif researchers.
- Researchers at Calif published the first public proof-of-concept for CVE-2026-86950, the Apple CoreGraphics flaw Apple said may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
- The trigger is a malicious PDF with a crafted embedded TrueType font. The overflow is in the glyph bounding-box calculation: before the patch, one rasterizer function saturated an out-of-range glyph coordinate and another truncated it, so the calculated bounding box came out too narrow and CoreGraphics allocated a working buffer that was too small and wrote past it.
- The analysis was started from a binary comparison of iOS 26.7 and 26.7.1, where CoreGraphics was the only library changed and the same fix was applied more than 20 times across eight rasterizer functions.
- The published code demonstrates a crash, not yet a working code-execution exploit; turning the memory corruption into reliable execution is separate work the analysis doesn't demonstrate.
- The headline flags a possible delivery path: WhatsApp PDF checks. Apple hasn't described a workaround for systems that can't update, and iOS 27 / macOS 27 aren't listed as affected in the September 28 advisories.
Why this matters: The 09-30 brief covered the KEV addition and the patch; this is the new material, the first public PoC plus a candidate zero-click-adjacent delivery channel. The combination is what raises the stakes: a public crash PoC in a rendering path (PDFs) plus a plausible messaging delivery vector is the same shape as the WeChat and iMessage zero-click incidents that have recurred this quarter. The defensive action is still the patch (iOS 26.7.1 / iPadOS 26.7.1 / macOS 26.7.1 / Sequoia 15.8.1), and the CISA federal deadline is October 2. The PoC doesn't change the patch requirement, but it does confirm the flaw is triggerable and lowers the cost for an attacker to build a working exploit, which shortens the window in which the unpatched device is safe.
Pattern callout: Extends the "exploited flaws move to KEV and stay exploited" pattern (09-17 through 10-01) at the endpoint layer, and extends the broader recurring theme this quarter of messaging-app PDF/document zero-click attack surfaces. The 09-30 iteration was the KEV entry and the Apple advisory language; this one is the public PoC plus a candidate delivery channel, which moves the story from "Apple says it was used" to "here is a public crash, and here is a plausible way to send it."
5. Google GTIG: AI-discovered vulnerabilities are nearly twice as likely to enable RCE CONTEXT
Source: Infosecurity Magazine - AI-Found Vulnerabilities More Likely to Enable RCE, Google Says (Sept 30). GTIG research figures are reported by Infosecurity Magazine secondary.
- In research published September 30, Google Threat Intelligence Group found that 50% of vulnerabilities it identified as likely AI-discovered resulted in remote code execution, against 26% of other CVEs.
- Vulnerability disclosures roughly doubled from 5,045 in January 2026 to 10,477 in July and 10,740 in August. Exploited vulnerabilities rose from an average of 10.5 per month in 2025 to 18 per month so far in 2026.
- Zero-day exploitation rose only marginally (eight to 11 per month, jumping to 22 in August). GTIG suggested most of the growth came from the rapid weaponization of n-days, possibly aided by AI tools that analyze patches and proof-of-concept code.
- GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782, and inference/serving infrastructure for 212, nearly a quarter of which involved unauthenticated APIs or server-side request forgery.
- The report cited CVE-2026-1731, an unauthenticated command-injection flaw in BeyondTrust Privileged Remote Access and Remote Support discovered autonomously by Hacktron AI, as a confirmed exploitation case: one threat cluster exploited it within four days of disclosure and five more within seven days.
Why this matters: This is the data backbone for the agent thread that has run through every brief since 09-13. The number that matters for a CISO is the RCE ratio: if AI-assisted discovery is finding flaws that are nearly twice as likely to be RCE, then the patching backlog isn't just getting bigger, it's getting more dangerous per entry. The defensive implication is that the "patch slow, triage by CVSS" heuristic is under pressure, because the class of flaws that AI agents are both finding and exploiting skews toward remote code execution. The ceiling is CONTEXT: this is research and trend data, not an exploited CVE to patch today, and there's no single defensive action to deploy. It's the strongest quantitative confirmation yet that the "agent's supply chain is the supply chain" pattern isn't a narrative but a measured trend.
Pattern callout: Extends the "the agent's supply chain is the supply chain" pattern (09-13 through 10-01, 19 days running) with its first hard quantitative anchor. The prior iterations were individual incidents (LiteLLM, Orkes Conductor, FakeGit, Next.js/Satori, ServiceNow, SalesBleed, the DIVD breach). This one is the aggregate: AI-discovered flaws are disproportionately RCE, and the volume is doubling. It also gives the "agent as attacker" thread (DIVD, 09-29/09-30/10-01) a statistical frame, which is why the two stories should be read together.
Pattern Analysis
| # | Pattern | Description |
|---|---|---|
| 1 | KEV stay exploited | Today's NetScaler victim confirmation (government and finance, weeks-long, Story 3) and the Apple CoreGraphics PoC (Story 4) both land in the KEV window and reinforce the same point: the KEV pipeline is the new baseline, and the patching backlog is growing with it. Cisco Catalyst SD-WAN Manager CVE-2026-76504 joined KEV on 09-30 with a 10-03 deadline; NetScaler CVE-2026-88771/88772 is overdue past 09-30. Cross-brief history (09-17 through 10-01, 15 days running): Cisco ISE and SEG (09-20/09-21), the two Microsoft EoP zero-days (09-20), Zyxel GS1900 CVE-2026-7273 (09-21, deadline 09-24), WSO2 API Manager CVE-2026-5430 (09-24, deadline 09-27), SharePoint CVE-2026-65660 and MikroTik CVE-2026-67279 (09-25, deadlines 09-27/09-28), Citrix NetScaler (09-27), Apple CoreGraphics CVE-2026-86950 (09-30, deadline 10-02), and Cisco SD-WAN Manager (09-30). |
| 2 | Edge boundary failing | Today's Cisco Catalyst SD-WAN Manager unauthenticated admin-API bypass (CVE-2026-76504, Story 2) adds another WAN control-plane API to the same category: the edge and control plane (load balancer, reverse proxy, API gateway, WAN manager) is the attack surface. The recurring failure mode is a management or control API that is unauthenticated or weakly authenticated in practice. WAF-based mitigations aren't a substitute for patching, and the management API, not the data path, is the thing being defeated. Cross-brief history (09-17 through 10-01, 15 days running): NetScaler zero-days (09-27/09-28/09-30), SharePoint RCE (09-25/09-28), MikroTik RouterOS admin takeover (09-25/09-28), WSO2 API Manager auth bypass (09-25/09-28), and the PeopleSoft PSEMHUB WAF bypass (09-27/09-28). |
| 3 | Vendor as case study | Today's DIVD Zammad zero-day disclosure (Story 1) is the sharpest case yet: the victim is a security-research nonprofit, and it's now publishing the exact CVEs its agent-attacker chained. The warning window for defenders is bounded not just by the vendor advisory but by the attacker's agent deployment cycle and the speed at which a two-flaw chain can go from initial access to root. Cross-brief history (09-16 through 10-01, 16 days running): OpenAI U.S. government website disclosure (09-26), OpenAI/Hugging Face agent chain detail (09-26/09-27), OpenAI self-replicating prompt injection (09-25/09-27), Nvidia Open Agent Safety Platform (09-28), and the Claude Compliance API (09-30). |
| 4 | Agent supply chain | Today's Google GTIG AI-discovered RCE ratio (Story 5) is the first quantitative anchor for the pattern: AI-discovered flaws are disproportionately RCE, and the volume is doubling. The DIVD Zammad zero-day CVEs (Story 1) convert the agent-as-attacker thread into named, patchable product flaws. The architectural assumption they share is that the tool interface and API layer are trusted boundaries. They aren't. Cross-brief history (09-13 through 10-01, 19 days running): LiteLLM CVE-2026-59822 (09-17), Orkes Conductor RCE CVE-2026-58138 (09-18), Plugin4Shell (09-19), MaxKB CVE-2026-77521 (09-21/09-22), FakeGit (09-23), Next.js/Satori CVE-2026-94545 (09-23/09-24), ServiceNow AI Platform unauthenticated flaws (09-24/09-25), SalesBleed in Salesforce Agentforce (09-25), Wallarm 2026 API ThreatStats (09-26/09-27), OpenCode RCE (09-28), and the DIVD autonomous-agent breach (09-29/09-30). |
| 5 | Regulatory posture tightens | Today's DIVD Zammad disclosure (Story 1) adds a new actor: a non-U.S. security nonprofit publishing CVEs it discovered as a victim, with an explicit industry-wide call to update. CISA KEV clocks keep ticking for Apple (deadline 10-02) and Cisco SD-WAN Manager (deadline 10-03); NetScaler is already overdue. The cost of treating agent and infrastructure security as an engineering problem instead of a compliance program is rising, and the disclosure path is becoming a legal and operational requirement. Cross-brief history (09-14 through 10-01, 18 days running): AEPD first AI-agent-attributed breach notification (09-16), CISA Zyxel deadline (09-21), Australia government investigation and vendor-notification rebuke (09-24), NIST SP 800-82 Rev 4 draft (09-24), CISA/FBI ICS integrator fact sheet (09-24), OpenAI U.S. government website disclosure (09-26), CISA KEV additions for NetScaler (09-27), Apple (09-30), and Cisco SD-WAN Manager (09-30), NCSC-NL pre-disclosure warning (09-27), and the FBI's internal "cyber security incident" declaration (09-28). |
Recommended Actions
Immediate (this week):
-
If you run any version of Zammad, update to version 7 or take the box offline today. DIVD (Story 1) confirmed that two chained zero-days (CVE-2026-102489 and CVE-2026-102490) let an AI agent go from initial access to root and data exfiltration in seconds. The exploit path is public, the affected versions span the current release line, and the victim is explicitly urging the industry to act. If you can't reach version 7 immediately, isolate the instance behind a strict WAF and hunt for indicators: session-hijack anomalies, unexpected local privilege escalation, and unauthorized access to other services.
-
If you run Citrix NetScaler ADC or Gateway, apply the CVE-2026-88771/CVE-2026-88772 patch immediately and treat any unpatched box as compromised. The CISA KEV deadline was September 30 and is now overdue (Story 3), the exploit path is public and pre-auth (09-30), and the campaign is confirmed against government and finance organizations over weeks. If you can't patch immediately, take the appliance out of production or isolate it behind a strict WAF rule that blocks DTLS handshake reassembly. Hunt for indicators of compromise: unexpected process execution on the appliance, unusual outbound connections, and modifications to the NSPPE binary.
-
If you run Cisco Catalyst SD-WAN Manager, patch CVE-2026-76504 immediately and restrict the Manager API to trusted networks. The flaw (Story 2) is an unauthenticated admin-API bypass under active exploitation and in CISA KEV with a federal due date of October 3. Apply the fix, limit the management API to a dedicated management network, and review the Manager logs for unauthorized admin-API calls. If you can't patch immediately, take the Manager out of the internet-facing path.
-
If you run Apple endpoints (iOS, iPadOS, macOS), push the 26.7.1 / 15.8.1 updates to every device in the fleet before October 2. The CoreGraphics zero-day (CVE-2026-86950) is in KEV, the deadline is tomorrow, and the first public PoC plus a candidate WhatsApp PDF delivery path have now been published (Story 4). If you can't update immediately, restrict PDF and file handling on affected devices and monitor for unexpected process launches triggered by document open events.
This month:
-
Build SOC detection for the specific agentic post-exploitation behavior DIVD described (Story 1). The agent's signature is a rapid, self-sequencing chain: session hijack, remote code execution as a low-privilege user, privilege escalation to root, and lateral movement to other services, all in seconds. That is a distinct pattern from human-driven post-exploitation, and it's detectable if you have the telemetry. If you run Claude or an equivalent, the Claude Compliance API (09-30) is the cheapest way to get the session and tool-call telemetry into your SIEM.
-
Adopt the GTIG RCE-ratio data (Story 5) as a triage input for your patching backlog. If AI-discovered flaws are nearly twice as likely to be RCE, then the "patch slow, triage by CVSS" heuristic is under pressure. Re-rank your open CVE queue to weight RCE-class flaws higher, and prioritize the agent-orchestration and inference-infrastructure categories GTIG identified as the largest concentrations of AI-related flaws.
-
Review your agent inventory and confirm that every AI agent running in your environment is accounted for, scoped, and monitored. The DIVD breach (Story 1) is a confirmed public case of an autonomous agent performing real post-exploitation in a real organization, and it's now tied to named CVEs. The defensive implication is that your SOC needs a detection rule for agentic behavior and a tested disclosure path for AI-caused incidents, not just a patch process.
Ongoing:
-
Maintain a KEV patching backlog that covers infrastructure, endpoints, and management APIs. The Apple CoreGraphics addition (09-30, Story 4) extended the KEV pipeline to consumer/enterprise endpoints, and the Cisco SD-WAN Manager flaw (Story 2) added a WAN control plane with an October 3 deadline. The defensive implication is that the patching scope now includes every Apple device, every edge appliance, and every management API in the fleet, not just the data path.
-
Track the DIVD investigation for the full victim list and any additional CVEs. The investigation is ongoing and DIVD said it's identifying other possible victims of the same underlying vulnerability (Story 1). The defensive implication is that when the next update drops, you'll know exactly what else was in the chain, and you can hunt for the same tooling and the same flaw family in your own environment.
-
Treat the management/control API as a first-class attack surface in your threat model. The recurring pattern across NetScaler (Story 3), Cisco SD-WAN Manager (Story 2), WSO2 API Manager (09-25), and PeopleSoft PSEMHUB (09-27/09-28) is the same: the API that sits in front of the system is the thing being defeated. The defensive implication is that authentication, egress control, and audit logging on management APIs deserve the same rigor as on the data path, and that a WAF isn't a substitute for a patched, authenticated, and monitored management API.
Relevant Risk Summary
| Risk | Severity | Recommended Actions |
|---|---|---|
| DIVD Zammad zero-days CVE-2026-102489 + CVE-2026-102490, AI-agent chained to root and data theft (10-01) | HIGH | Update any Zammad instance to v7 or take offline; hunt for session-hijack and privesc IoCs |
| Cisco Catalyst SD-WAN Manager CVE-2026-76504 unauthenticated admin-API bypass, actively exploited, KEV due 10-03 (09-30/10-01) | HIGH | Patch immediately; restrict Manager API to trusted networks; review logs for unauthorized admin calls |
| Citrix NetScaler CVE-2026-88772 zero-day campaign, confirmed against government and finance (10-01; KEV deadline 09-30 overdue) | HIGH | Patch NetScaler ADC/Gateway now; isolate if unpatched; hunt for IoCs |
| Apple CoreGraphics CVE-2026-86950, first public PoC + candidate WhatsApp PDF delivery (09-30/10-01, deadline 10-02) | HIGH | Push iOS 26.7.1 / iPadOS 26.7.1 / macOS 26.7.1 / 15.8.1 to all endpoints before October 2 |
| Google GTIG: AI-discovered vulnerabilities nearly twice as likely to be RCE (09-30) | CONTEXT | Re-rank CVE queue to weight RCE higher; prioritize agent-orchestration and inference-infra categories |
| FBI PeopleSoft breach (CVE-2026-35273, ongoing) | HIGH | Confirm patch and PSEMHUB disabled; hunt for x.jsp, u.jsp, Ple64.exe, tunnel.jsp artifacts |
| OpenCode RCE GHSA-632h-h47v-g4x4 (09-28, ongoing) | MEDIUM | Upgrade all OpenCode instances to 1.18.22; restrict browser interface exposure |
Sources
- Security Affairs - AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
- The Hacker News - Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- SecurityWeek - Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
- The Hacker News - Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- Infosecurity Magazine - AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Generated: 2026-10-01 07:30 EDT | Window: past 24h | Sources: Security Affairs, The Hacker News, SecurityWeek, Infosecurity Magazine