Last Week in AI Security — Week of May 11, 2026
Google disrupts first confirmed AI-assisted zero-day attack; Microsoft's MDASH AI system discovers 16 Windows vulnerabilities; Semantic Kernel RCE flaws enable prompt injection to code execution.
Key Highlights
- Google confirms first AI-generated zero-day exploited in the wild, marking new era of AI threat
- Microsoft's multi-model AI scanner MDASH finds 16 Windows vulnerabilities including 4 critical RCEs
- CVE-2026-25592 and CVE-2026-26030 in Semantic Kernel allow prompt injection to escalate to RCE
- PyTorch CVE-2026-24747 enables RCE via malicious checkpoint files with CVSS 9.8
- MITRE ATLAS v5.4.0 adds agentic AI attack techniques including 'Publish Poisoned AI Agent Tool'
Executive Summary
The week of May 11, 2026, marks an inflection point in AI security: the first confirmed case of adversaries using AI models to discover and weaponize a zero-day vulnerability in a planned mass exploitation campaign. Google’s Threat Intelligence Group reported on Monday that it disrupted criminal actors who used an AI model—neither Gemini nor Anthropic’s Mythos—to identify and exploit a two-factor authentication bypass in a popular web administration platform. The Python exploit bore tell-tale signs of machine generation: educational docstrings, hallucinated CVSS scores, and textbook-clean code structure that analysts flagged as AI-generated.
This development arrives alongside a defensive counteroffensive from AI security tooling. Microsoft announced that its multi-model agentic scanning harness (codename MDASH) discovered 16 new vulnerabilities across Windows networking and authentication components—including four Critical-severity remote code execution flaws in tcpip.sys and the IKEEXT service. The system achieved 96% recall on five years of historical Microsoft Security Response Center cases in clfs.sys and 100% recall in tcpip.sys, demonstrating that AI-assisted code analysis can now rediscover bugs that required Patch Tuesday responses and were exploited by real attackers. Palo Alto Networks echoed this finding in its May update, confirming that the majority of vulnerabilities disclosed in its May Patch Wednesday advisories were discovered using frontier AI models including Anthropic’s Mythos and OpenAI’s GPT-5.5-Cyber.
The third major story underscores how AI’s threat model has shifted from content security to execution risk. Microsoft disclosed CVE-2026-25592 and CVE-2026-26030, two Critical vulnerabilities in its Semantic Kernel framework that allow prompt injection attacks to escalate into arbitrary code execution. The flaws enable attackers to manipulate AI agents—specifically those using file upload/download and code execution plugins—by injecting malicious instructions that trigger RCE on the host system. The disclosure includes an interactive CTF challenge demonstrating how prompt injection can smuggle Python AST-traversal payloads through vulnerable eval() sinks to launch calc.exe. Organizations running Semantic Kernel must upgrade to version 1.71.0 or later immediately and recognize that AI agents equipped with tools are no longer just content generators but fully operational execution environments.
Top Stories
Google Confirms First AI-Assisted Zero-Day Discovered and Exploited by Criminals
Google’s Threat Intelligence Group reported Monday that it disrupted what it believes is the first real-world case of criminal threat actors using AI to discover and weaponize a zero-day vulnerability for mass exploitation. The bug, a two-factor authentication bypass in a popular open source web-based administration platform, was reportedly developed by criminals working together on a large-scale intrusion operation.
GTIG said that the attackers appear to have used an AI model to both identify the flaw and help turn it into a usable exploit. Google worked with the unnamed vendor to quietly patch the issue before the campaign could properly kick off, which it believes may have disrupted the operation before it gained traction.
The company insists that neither Gemini nor Anthropic’s Mythos was involved, but said that the exploit itself looked suspiciously machine-made. According to the report, the Python script included what Google described as “educational docstrings,” a hallucinated CVSS score, and a polished textbook coding structure that looked heavily influenced by LLM training data. Google said that the issue stemmed from developers hard-coding a trust exception into the authentication flow, creating a hole that attackers could exploit to sidestep 2FA checks.
John Hultquist, chief analyst at Google’s threat intelligence arm, told reporters: “It’s here. The era of AI-driven vulnerability and exploitation is already here.”
Google did not reveal which AI model was used or which criminal group was involved, but stated there was no evidence of nation-state involvement, though groups tied to China and North Korea have been exploring similar techniques. The findings underscore how hackers are using available AI tools like OpenClaw to exploit software flaws in ways that can be particularly damaging to companies, government agencies and other organizations even as cybersecurity firms pump billions of dollars into bolstering their defenses.
The timing is significant. In April, Anthropic delayed the rollout of its Mythos model, citing worries that criminals and adversaries could use the tool to identify and prey on decades-old software vulnerabilities. That model is now available to a select group of organizations through Project Glasswing, and OpenAI launched its competing Daybreak initiative last week, offering GPT-5.5-Cyber to vetted security teams.
Microsoft’s AI Scanner Discovers 16 New Windows Vulnerabilities Including Four Critical RCEs
Microsoft announced on May 12 that its new multi-model agentic scanning harness (codename MDASH) helped researchers discover 16 new vulnerabilities across Windows networking and authentication components, including four Critical-severity remote code execution flaws.
Today Microsoft is announcing a major step forward in AI-powered cyber defense: a new multi-model agentic scanning harness (codenamed MDASH). The system identified two particularly severe vulnerabilities patched in April Patch Tuesday:
CVE-2026-33827 (patched April 2026): The vulnerability lived in the IKEEXT service, the Windows component responsible for IKE and AuthIP keying for IPsec, and was reachable by a remote, unauthenticated attacker over UDP/500 on any host configured as an IKEv2 responder (RRAS VPN, DirectAccess, Always-On VPN infrastructure, or any machine with an inbound connection security rule). By sending a crafted IKE_SA_INIT carrying Microsoft’s “IPsec Security Realm Id” vendor-ID payload, followed by a single IKEv2 fragment (RFC 7383 SKF) that reassembles immediately, an attacker could trigger a deterministic double-free of a 16-byte heap allocation inside the service. Because IKEEXT runs as LocalSystem inside svchost.exe, this represents a pre-authentication remote code execution path into one of the highest-privilege contexts on the system.
CVE-2026-33824 (patched April 2026): A second critical RCE vulnerability in Windows networking components.
The MDASH system demonstrated remarkable retrospective accuracy. We re-ran codename MDASH against pre-patch snapshots of two heavily reviewed Windows components and measured whether the historical MSRC-confirmed bugs would have been (re-)discovered: clfs.sys: 96% recall on 28 MSRC cases spanning five years. tcpip.sys: 100% recall on 7 MSRC cases spanning five years.
These are the strongest internal numbers we publish, and they are meaningful for a specific reason: the MSRC case database is the ground truth for what real attackers exploited, what required a Patch Tuesday, and what defenders had to react to. A system that recovers 96% of a five-year MSRC backlog in a heavily reviewed kernel component is not finding theoretical weaknesses; it is finding the bugs that mattered.
Palo Alto Networks released its own update on May 13, confirming that This is the first time where the majority of findings were the result of frontier AI models scanning our code. The company has been testing Anthropic’s Mythos and Claude Opus 4.7, as well as OpenAI’s GPT-5.5-Cyber. Regardless of the current restricted access, we believe these capabilities will flow more broadly to other models. We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm.
Prompt Injection Becomes Remote Code Execution: Critical Semantic Kernel Vulnerabilities
Microsoft disclosed on May 7 two Critical vulnerabilities in Semantic Kernel, its open-source framework for building AI agents, demonstrating how prompt injection can escalate from content manipulation to arbitrary code execution.
This scenario is the real security story behind modern AI agents. Once an AI model is wired to tools, prompt injection draws a thin line between being just a content security problem and becoming a code execution primitive. In this post in our research series on AI agent framework security, we show how two vulnerabilities in Semantic Kernel could allow attackers to cross that line, and what customers should do to assess exposure, patch affected agents, and investigate whether exploitation may already have occurred.
CVE-2026-25592 and CVE-2026-26030 allow attackers to leverage prompt injection to achieve remote code execution. The vulnerabilities exist in Semantic Kernel’s file handling and code execution plugins. AI agents have fundamentally changed the threat model of AI model-based applications. By equipping these models with plugins (also called tools), your agents no longer just generate text; they now read files, search connected databases, run scripts, and perform other tasks to actively operate on your network. Because of this, vulnerabilities in the AI layer are no longer just a content issue and are an execution risk. If an attacker can control the parameters passed into these plugins via prompt injection, the agent may be driven to perform actions beyond its intended use.
Your agent is vulnerable to CVE-2026-25592 if it uses a Semantic Kernel .NET SDK version older than 1.71.0. The fix removes the AI model’s autonomous ability to invoke dangerous file system and code execution functions. The AI agent can no longer invoke it, and prompt injection can no longer reach it: This single change breaks the entire attack chain. The AI can now only be called directly by the developer’s intentional code.
Microsoft released an interactive CTF challenge that demonstrates the attack. This CTF challenge lets you step into the shoes of an attacker and try to exploit the CVE-2026-26030 vulnerability in a controlled environment. You need to craft a prompt injection that not only bypasses the agent’s natural language defenses but also smuggle a Python AST-traversal payload through the vulnerable eval() sink.
Organizations must upgrade Semantic Kernel to version 1.71.0 or later immediately. The disclosure signals a broader shift: AI agents with tool access are not chatbots; they are privileged execution environments where natural language becomes a command shell.
Framework & Standards Updates
NIST Releases AI RMF Profile for Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. The profile will guide critical infrastructure operators towards specific risk management practices to consider when engaging AI-enabled capabilities. The profile focuses on sector-specific risk considerations for energy, healthcare, transportation, and other critical sectors, emphasizing safety, resilience, and system reliability.
Recent NIST AI Risk Management Framework updates from 2025 to 2026 reflect a shift from foundational guidance to more operational, sector-specific, and implementation-ready resources. The framework continues to align with NIST Cybersecurity Framework 2.0, ISO 42001, and other emerging standards.
MITRE ATLAS v5.4.0 Adds Agentic AI Attack Techniques
The February 2026 v5.4.0 update added further agent-focused techniques including “Publish Poisoned AI Agent Tool” and “Escape to Host.” MITRE ATLAS catalogs 16 tactics, 84 techniques, and 56 sub-techniques specifically targeting AI and machine learning systems, up from 15 tactics and 66 techniques as of October 2025. The November 2025 framework update (v5.1.0) expanded to 16 tactics, 84 techniques, 32 mitigations, and 42 case studies, with continued updates through February 2026 adding agentic AI techniques.
The expansion reflects growing recognition of agentic AI as a distinct attack surface. MITRE ATLAS maps 14 tactics and 66 techniques to defend AI systems from threats like data poisoning and model theft. The framework helps security teams identify AI vulnerabilities through real-world case studies and adversarial testing. ATLAS added 14 new techniques in 2025 for AI agents, covering risks like prompt injection and memory manipulation attacks.
OWASP Updates Reflect Agentic AI Risks
Key frameworks include the OWASP Top 10 for LLM Applications 2025 and the OWASP Top 10 for Agentic Applications 2026 for risk taxonomy, signaling formal recognition of autonomous AI systems as a distinct security domain requiring specialized controls beyond traditional LLM application security.
Vulnerability Watch
CVE-2026-24747: PyTorch Checkpoint RCE (CVSS 9.8)
A critical vulnerability in PyTorch’s checkpoint loading mechanism has been discovered, allowing attackers to execute arbitrary code through malicious model files. The flaw exists in the weights_only unpickler, which fails to properly validate pickle opcodes and storage metadata when processing checkpoint files. Researchers have assigned this vulnerability CVE-2026-24747 with a CVSS v3 score of 9.8, indicating severe risk across confidentiality, integrity, and availability.
The vulnerability stems from inadequate validation in PyTorch’s weights_only feature, which was designed to safely load model checkpoints by restricting pickle operations. However, attackers can bypass these restrictions by crafting malicious checkpoint files (.pth) that exploit the unpickler’s weaknesses. When a user loads such a file using torch.load() with weights_only=True, the malicious payload executes with the same privileges as the victim’s process.
Affected versions: PyTorch up to and including 2.9.1
Patched version: PyTorch 2.10.0 and later
Mitigation: Upgrade immediately to 2.10.0+; never load checkpoint files from untrusted sources; implement file integrity verification.
CVE-2026-25592 & CVE-2026-26030: Microsoft Semantic Kernel RCE (Critical)
As detailed in Top Stories, these vulnerabilities in Semantic Kernel .NET SDK versions prior to 1.71.0 allow prompt injection to escalate to remote code execution through file system and Python execution plugins.
Affected versions: Semantic Kernel .NET SDK < 1.71.0
Patched version: 1.71.0 and later
Mitigation: Upgrade immediately; plugins are now only invokable programmatically, not by AI models directly.
CVE-2026-20182: Cisco Catalyst SD-WAN Controller Auth Bypass (CVSS 10.0) — Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It’s rated 10.0 on the CVSS scoring system, indicating maximum severity. “Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system,” CISA said.
In a separate advisory, Cisco attributed the active exploitation of CVE-2026-20182 with high confidence to UAT-8616, the same cluster behind the weaponization of CVE-2026-20127 to gain unauthorized access to SD-WAN systems.
Exploitation: Confirmed in the wild
CISA deadline: May 17, 2026
Action required: Apply Cisco patches immediately; assume breach if exposed internet-facing instances exist.
CVE-2026-42945: NGINX Heap Buffer Overflow (CVSS 9.2) — Active Exploitation
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the vulnerability was introduced in 2008. Successful exploitation of the flaw can permit an unauthenticated attacker to crash worker processes or execute remote code with crafted HTTP requests.
However, it bears noting that code execution is possible only on devices where Address Space Layout Randomization (ASLR), a safeguard against memory-based attacks, is turned off.
Affected versions: NGINX 0.6.27 through 1.30.0
Exploitation: Active in the wild
Mitigation: Upgrade NGINX immediately; ensure ASLR is enabled on all systems.
CVE-2026-32207: Azure Machine Learning XSS (CVSS 8.8)
Improper neutralization of input during web page generation (‘cross-site scripting’) in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. Notebook spoofing via web scripting can enable attackers to trick users into running actions, leaking sensitive notebook/session data, or performing unauthorised workflows through the UI. In ML environments, compromised notebooks can quickly translate into data exposure and integrity loss across projects and teams, impacting both security and operational continuity.
CVSS Score: 8.8
Risk: High for organizations exposing Azure ML notebooks to untrusted users
Patched: May 7, 2026
CVE-2026-42897: Microsoft Exchange Server Spoofing — Active Exploitation
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. Microsoft has released mitigations but no permanent patch is yet available for all affected versions.
CVSS Score: 8.1
Exploitation: Active in the wild
Action required: Apply Microsoft’s mitigation guidance immediately.
Industry Radar
OpenAI Launches Daybreak Cybersecurity Initiative
OpenAI announced on May 12 the launch of Daybreak, a cybersecurity initiative combining frontier AI model capabilities with Codex Security to help organizations identify and patch vulnerabilities before attackers exploit them. “Daybreak combines the intelligence of OpenAI models, the extensibility of Codex as an agentic harness, and our partners across the security flywheel to help make the world safer for everyone,” the AI upstart said. “Defenders can bring secure code review, threat modeling, patch validation, dependency risk analysis, detection, and remediation guidance into the everyday development loop so software becomes more resilient from the start.”
Like Anthropic’s Mythos, the idea is to leverage AI to tilt the balance in favor of defenders and help detect and address security issues before they are found by bad actors. Access remains tightly controlled with OpenAI vetting organizations before granting access to GPT-5.5-Cyber.
Akamai Acquires LayerX for AI Usage Control
Akamai announced on May 14 that it entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser technology, for approximately $205 million. “Our customers are adopting AI at record speed, and they’re telling us the same thing: Their existing controls cannot see how employees are interacting with AI tools and sharing with large language models,” said Mani Sundaram, Executive Vice President and General Manager, Security Technology Group, Akamai. “The acquisition of LayerX helps close that gap, providing Akamai with a control layer that governs AI at the point of use so enterprises can move at AI speed without compromising safety and compliance.”
The acquisition is expected to close in Q3 2026.
Google Cloud and Wiz Expand AI Security Portfolio
At Google Cloud Next, Wiz announced new capabilities designed to secure the AI-native development lifecycle, including integration with vibe-coded applications and inline AI security hooks. Wiz is announcing a new integration, generally available in May, that runs Wiz security scanning directly inside the Lovable platform so vulnerabilities, secrets, and misconfigurations caught by Wiz surface in Lovable’s built-in security view, right where teams are already building. Wiz removes risks from AI-generated code the moment it is created. Inline AI security hooks integrate directly into IDEs and agent workflows to evaluate prompts and scan AI-generated output instantly, injecting security guardrails before the code is ever committed. Agent-based remediation: Wiz Skills equip coding agents and AI-native IDEs with full code-to-cloud context and validated attack surface findings from the Wiz Security Graph.
Commerce Department Signs AI Model Testing Agreements
The U.S. Department of Commerce announced on May 5 that Google, Microsoft, and xAI agreed to provide the Center for AI Standards and Innovation (CAISI) early access to their AI models for national security testing. Under the new agreement, the US government will be allowed to evaluate the models before deployment and conduct research to assess their capabilities and security risks. The agreement fulfils a pledge the administration of US President Donald Trump made in July to partner with technology companies to vet their AI models for “national security risks”.
CAISI, which serves as the government’s main hub for AI model testing, said it had already completed more than 40 evaluations, including on cutting-edge models not yet available to the public.
Policy Corner
U.S. Government Seeks Greater Role in AI Model Oversight
Multiple reports indicate the Trump administration is considering expanded government oversight of frontier AI models through a new AI working group and potential executive orders. The discussions follow the release of Anthropic’s Mythos model last month, which demonstrated unprecedented capability in discovering and exploiting software vulnerabilities.
It was the latest example of jumbled signals from the Trump administration in the month since Anthropic announced a new model it called Mythos that it said was so “strikingly capable” at hacking and cybersecurity work that it could only release it to a small group of trusted organizations. Anthropic created an initiative called Project Glasswing bringing together tech giants including Amazon, Apple, Google and Microsoft, along with other companies like JPMorgan Chase, in hopes of securing the world’s critical software from “severe” fallout that the new model could pose to public safety, national security and the economy.
Trump administration officials and allies are sending mixed signals about whether voluntary commitments or formal regulatory frameworks should govern frontier AI development, particularly for models with cybersecurity implications.
OpenAI Provides EU Access to GPT-5.5-Cyber; Anthropic Withholds Mythos
OpenAI announced on May 12 that it would grant the European Union access to GPT-5.5-Cyber, while Anthropic has yet to provide the EU Commission with access to Mythos despite its release a month earlier. European partners including businesses, governments, cyber authorities and EU institutions such as the EU AI office, would be granted access to OpenAI’s GPT-5.5-Cyber, a variation of its latest AI model, the company said. OpenAI announced it was rolling out the model in limited preview capacity to vetted cybersecurity teams.
Though Mythos was released a month ago, Anthropic has yet to grant the EU preview access to review it. The EU is discussing access with Anthropic, Regnier said, but added that the discussions are at a “different stage” than they were with OpenAI. While the Commission had had “four or five” meetings with Anthropic, Regnier said that discussions with the company were “not yet at the same stage as the solution we have on the table from OpenAI.”
No major U.S. federal AI legislation advanced this week, though CISA continues to emphasize AI-related risks in its threat assessments for critical infrastructure operators.
Research Spotlight
Academic research publication was relatively light this week, though several notable preprints emerged:
Red Teaming the Mind of the Machine: A Systematic Evaluation of Prompt Injection and Jailbreak Vulnerabilities in LLMs
A May 2025 preprint (published to arXiv) presents a systematic investigation of jailbreak strategies against GPT-4, Claude 2, Mistral 7B, and Vicuna. This paper provides a systematic investigation of jailbreak strategies against various state-of-the-art LLMs. We categorize over 1,400 adversarial prompts, analyze their success against GPT-4, Claude 2, Mistral 7B, and Vicuna, and examine their generalizability and construction logic.
Among the tested models, GPT-4 demonstrated the highest vulnerability with an ASR of 87.2%, confirming its powerful but permissive instruction-following nature. Prompt injections exploiting roleplay dynamics (e.g., impersonation of fictional characters or hypothetical scenarios) achieved the highest ASR (89.6%). These prompts often bypass filters by deflecting responsibility away from the model (e.g., “as an AI in a movie script…”). Logic trap attacks (ASR: 81.4%) exploit conditional structures and moral dilemmas to elicit disallowed content. Encoding tricks (e.g., base64 or zero-width characters) achieved 76.2% ASR by evading keyword-based filtering mechanisms.
Analysis of LLMs Against Prompt Injection and Jailbreak Attacks
A February 2026 preprint evaluates prompt-injection and jailbreak vulnerability across multiple open-source LLMs including Phi, Mistral, DeepSeek-R1, Llama 3.2, Qwen, and Gemma variants. This work evaluates prompt-injection and jailbreak vulnerability using a large, manually curated dataset across multiple open-source LLMs, including Phi, Mistral, DeepSeek-R1, Llama 3.2, Qwen, and Gemma variants. We observe significant behavioural variation across models, including refusal responses and complete silent non-responsiveness triggered by internal safety mechanisms. Furthermore, we evaluated several lightweight, inference-time defence mechanisms that operate as filters without any retraining or GPU-intensive fine-tuning. Although these defences mitigate straightforward attacks, they are consistently bypassed by long, reasoning-heavy prompts.
The study found that safety robustness is non-monotonic with model size, suggesting alignment strategy and refusal design matter more than parameter count.
Understanding Adversarial Attacks Against Machine Learning and AI
The UK National Cyber Security Centre released Understanding adversarial attacks against Machine Learning and AI, outlining an evolving set of Adversarial ML (AML) attack classes. Artificial Intelligence (AI) and Machine Learning (ML) systems offer significant advantages, yet also introduce considerable risks. The rapid development cycle, unique architectures, large model sizes, and prevalence of open-source components in AI/ML create new attack surfaces that traditional cybersecurity measures may not adequately address.
What This Means For You
For Security Teams:
-
Immediately patch Semantic Kernel: If you have deployed AI agents using Microsoft Semantic Kernel .NET SDK versions prior to 1.71.0, upgrade now. CVE-2026-25592 and CVE-2026-26030 demonstrate that prompt injection is no longer a content safety issue—it is an RCE vector. Review all deployed agents to identify which plugins are enabled and assess whether file system or code execution capabilities are exposed.
-
Inventory AI-generated code in production: The first AI-discovered zero-day exploited in the wild is now confirmed. Conduct an audit of codebases that include AI-generated contributions (from Copilot, Cursor, or other coding assistants) and prioritize security reviews of authentication flows, cryptographic implementations, and privilege boundaries where AI-generated logic may introduce subtle vulnerabilities.
-
Prioritize CISA KEV deadlines: CVE-2026-20182 (Cisco SD-WAN) and CVE-2026-42897 (Exchange Server) are under active exploitation. If you run these systems, assume breach scenarios and apply patches or mitigations immediately. Both vulnerabilities allow unauthenticated remote access, making them high-value targets for ransomware operators and nation-state actors.
-
Validate PyTorch checkpoint sources: If your organization uses PyTorch models—particularly in training pipelines or inference environments—enforce strict controls around checkpoint file sources. CVE-2026-24747 is trivially exploitable if attackers can supply malicious .pth files. Implement cryptographic signatures for model artifacts and never load checkpoints from untrusted or unverified origins.
For Engineering and DevOps Teams:
-
Update NGINX immediately: CVE-2026-42945 is actively exploited and affects NGINX versions dating back to 2008. Organizations running legacy NGINX configurations are at severe risk. Upgrade to patched versions and ensure ASLR is enabled on all systems. If immediate patching is not possible, implement Web Application Firewall (WAF) rules to filter malformed HTTP requests targeting the rewrite module.
-
Adopt AI security tooling in CI/CD pipelines: Microsoft’s MDASH and similar AI-driven scanners are now demonstrating recall rates above 90% for historical vulnerabilities. Integrate static analysis tools that leverage frontier AI models (where accessible) into your CI/CD pipelines. Tools like Wiz’s inline security hooks and Akamai’s LayerX browser controls can provide real-time defenses against AI-generated attack patterns.
-
Restrict AI agent tool access: If your organization is building or deploying AI agents, implement the principle of least privilege for plugin capabilities. Limit file system access, code execution, and network connectivity to only what is necessary. Microsoft’s fix for Semantic Kernel makes dangerous functions non-invokable by the AI model—apply this design pattern universally across your AI agent architecture.
For Leadership and Risk Management:
-
Reassess AI red-team access: The confirmed use of AI models to discover and weaponize zero-days means adversaries now have parity with defenders in vulnerability research timelines. Organizations must accelerate adoption of AI-assisted security testing and consider partnering with initiatives like OpenAI’s Daybreak or Anthropic’s Project Glasswing to access frontier models for defensive purposes.
-
Plan for the AI exploitation era: Google’s Threat Intelligence Group stated unequivocally: “The era of AI-driven vulnerability and exploitation is already here.” Budget for increased security tooling, expanded red-team exercises, and continuous monitoring. Palo Alto Networks estimates a three-to-five-month window before AI-driven exploits become the