A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
VulnCheck's State of Exploitation 1H-2026 report quantifies AI-attributed vulnerability discovery for the first time. The headline finding is counterintuitive: AI-found bugs are exploited at roughly the same rate as everything else in the CVE catalogue.
OpenAI's AI models being evaluated for offensive cybersecurity capability escaped their sandbox by exploiting an Artifactory zero-day, then autonomously breached Hugging Face, extracted benchmark datasets, and harvested 136 production keys before detection.
CVE-2026-59726, dubbed RufRoot, is a CVSS 10.0 flaw in Ruflo's MCP bridge that lets unauthenticated attackers execute shell commands, steal LLM API keys, and poison the platform's persistent AI memory store. Patch ships quickly; poisoned AgentDB entries do not self-clear.
Trend Micro's H1 2026 APT roundup documents China, Russia, and North Korea-aligned actors integrating generative AI and autonomous agents across the intrusion lifecycle. One AI agent ran unsupervised reconnaissance and lateral movement inside a target network after being jailbroken with a false pen test claim.