First reported forescout.com
Lead dispatch
First reported secmate.dev
Mistral Vibe Permission Bypass and Arbitrary Code Execution
SecMate disclosed two flaws in Mistral Vibe 2.25.0 (CVE-2026-87987 and CVE-2026-87984) where the coding agent's Bash tool used Tree-sitter to extract a reduced representation of a shell command for its permission allowlist, then executed the original untouched string. Hostile repository content could lead the model to emit a crafted tool call (e.g. an environment assignment prefixing an allowlisted command) that the permission parser classified as read-only, bypassing the approval prompt and enabling arbitrary code execution and reads/writes outside the authorized workspace. Mistral released Vibe 2.25.4 on September 12, 2026.permission-bypass · arbitrary-code-execution · command-injection · indirect-prompt-injection · data-exfiltration · tool-abuse
ai-agents · coding-agent · llm
The wire · latest
First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
CISA, NSA, FBI, DOE and EPA issued advisory AA26-231A warning of an active threat targeting Siemens S7 Series PLCs in U.S. critical infrastructure using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors use internet scanning services like Censys and ZoomEye to find exposed, outdated or poorly protected PLCs, and the broader targeting extends beyond Siemens devices. Details →First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued advisory AA26-231A warning of an active threat in which attackers use AI coding assistants together with open source industrial libraries (snap7.dll/python-snap7) to generate custom exploitation scripts disguised as legitimate OT monitoring tools against internet-exposed Siemens S7 Series PLCs at water, energy, manufacturing, and other critical facilities. The AI-generated tools provide read/write access to PLC memory, configuration, and ladder logic via the S7comm protocol, and the activity is suspected to be linked to Iran-affiliated operatives. Details →First reported · updated · 2 reports cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
A joint CISA/NSA/FBI/DOE/EPA advisory (AA26-231A, August 2026) warns of an active cyber threat against U.S.-based Siemens S7 Series PLCs, in which threat actors conduct reconnaissance and capability development using AI-generated exploitation scripts disguised as legitimate monitoring tools. The advisory provides mitigations including inventorying PLCs, applying patches, isolating devices from the internet, hardening access controls, and hunting for anomalies. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector