Industry News
A running log of the threat intelligence, breaches, and AI-security developments D2 tracks daily — the signal, filtered from the noise.
AI-Generated Browser Ransomware Bridges Theory to a Working Attack
Check Point found malware built with DeepSeek that combined a previously dismissed browser-malware concept with a real Chromium capability into working ransomware on both Windows and Android.
Poisoned MCP Tool Descriptions Can Turn AI Agents Into a Silent Data-Exfiltration Channel
Microsoft found that a malicious server can rewrite a hidden AI tool description to direct an agent to quietly collect and ship out sensitive data — with every step looking routine and no policy ever broken.
Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200)
A CVSS 9.2 memory-corruption bug in libssh2 is statically linked into curl, Git, PHP, backup agents, and countless appliances — and a distro update won't fix most copies.
GPT-5.6 Sol Preview Advances AI's Vulnerability-Research Capability
OpenAI's new GPT-5.6 'Sol' model discovered previously unknown vulnerabilities in widely used software and mobile devices during third-party testing, though it still couldn't complete full attacks against well-defended targets.
Cisco to acquire WideField Security to bring AI-agent identity into Splunk
Cisco's planned acquisition folds non-human and AI-agent identity discovery, exposure mapping, and live session monitoring into Splunk, aimed at the exact failure mode the agentic SOC introduces: authorized entities taking unsafe actions in the wrong context.
FortiBleed campaign escalates against internet-facing Fortinet gear
Attackers are harvesting configuration files from exposed FortiGate devices and cracking the stored credential hashes into working administrator logins, at a scale researchers estimate between roughly 30,000 and 86,000 devices worldwide.
"Cordyceps": a systemic class of exploitable CI/CD weaknesses across the open-source supply chain
Scanning roughly 30,000 high-impact repositories, researchers validated hundreds of full exploit chains and confirmed fixes at Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation.
Four actively exploited flaws in Ubiquiti UniFi OS and Lantronix added to CISA KEV
The worst, CVE-2026-34908, is a CVSS 10.0 improper-access-control bug that lets an unauthenticated attacker on the network reconfigure or pivot through UniFi gear.
FortiBleed: 74k-86k FortiGate devices with compromised credentials
Attackers harvested working administrator and SSL-VPN credentials from internet-facing FortiGate firewalls at scale by cracking weakly hashed secrets pulled from device configs, and CISA has issued a hardening advisory.
Klue OAuth Breach Spreads Across the Security Industry via Salesforce
A single dormant legacy credential at market-intelligence vendor Klue let attackers harvest customer OAuth tokens, breaching Salesforce data at Recorded Future, Tanium, Jamf, Gong, and other security-industry names.