A newly disclosed zero-click RCE vulnerability affects multiple widely used AI coding agents that install plugins from marketplaces. Researchers warn this is the first supply-chain vulnerability across the AI agent ecosystem: if an attacker can influence a plugin, they may gain the same reach as the employee running the agent. Some affected agents reportedly remain unpatched, raising urgency for inventorying agent use and controlling plugin sources.
Source: Help Net Security
Check Point fixes critical root code execution flaw (CVE-2026-91843) in Security Management and Log Servers
Check Point addressed CVE-2026-91843, a critical vulnerability that could allow attackers to execute code as root on Security Management and Log Servers without login. The reported CVSS score (9.8) and “no authentication” aspect make this especially high-risk for organizations that expose management planes or have weak internal segmentation. Teams should prioritize patching, review access paths to management components, and validate hardening controls immediately.
Source: Security Affairs
Orkes Conductor: critical unauthenticated pre-auth RCE (CVE-2026-58138) exploited in real attacks
A critical Orkes Conductor vulnerability (CVE-2026-58138) is being actively exploited, including via inline workflow definitions. Because it is pre-auth/unauthenticated, attackers may be able to compromise systems before defenders even detect exposure. Organizations using Orkes Conductor should confirm version status, apply fixes/mitigations, and hunt for suspicious workflow or execution attempts.
Source: Security Week
Brevo supply-chain attack: malware injected into 100,000+ websites via compromised Cloudflare access
Attackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts into websites associated with Brevo customers. Reports indicate the campaign potentially affected over 100,000 sites, illustrating how third-party platform compromise can rapidly translate into wide web compromise. Defenders should review content integrity, monitor for malicious script injection patterns, and validate any dependencies on Brevo-delivered assets.
Source: Security Week
Android: RatHat trojan uses AI navigation, accessibility abuse, and debugging tricks to steal banking credentials and PINs
Security researchers report a new Android malware strain (RatHat) that can manipulate infected phones to steal bank logins, authentication codes, and screen-lock PINs. The technique reportedly combines AI-driven screen control with misuse of Android accessibility and debugging capabilities, making it harder for users and some defenses to detect or remove. Mobile teams should review app exposure, tighten device-level permissions, and strengthen detection for unusual accessibility/debug behavior.
Source: Security Affairs
US CISA upgrades disclosure infrastructure: new VINCE-NT system streamlines coordinated vulnerability handling
CISA revealed a new VINCE-NT platform intended to support faster, more streamlined coordinated vulnerability disclosure. The update is positioned as more secure and operationally efficient—key for reducing time from vulnerability discovery to actionable guidance for defenders. Organizations participating in disclosure ecosystems should watch for changes in processes, timelines, and submission workflows.
Source: SCMagazine
AI security shifts from “sandboxing” to runtime governance and audit trails
Multiple reports emphasize that AI agents are moving into production workflows, driving demand for controls that can observe, enforce, and prove what an agent did. New offerings focus on agent runtime security—visibility into which agents run, the actions they take, and audit evidence for governance and compliance. The takeaway for security teams: treat AI agent execution like any other privileged workflow, with logging, policy enforcement, and verification.
Source: Help Net Security
You May Also Be Interested In...
AI-Built exploit and sign-in flaw opened path to internal OpenAI code
23 million user records compromised in Gyazo data breach
Bots with good manners are better at fooling people on social media