First reported forescout.com
Lead dispatch
First reported · updated · 2 reports bleepingcomputer.com
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab patched CVE-2026-90970, a critical (CVSS 9.9) flaw in its self-hosted AI Gateway service powering GitLab Duo features. An authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway. Fixes shipped in versions 19.2.4, 19.3.2, and 19.4.1; GitLab-hosted instances are already protected.sandbox-escape · remote-code-execution · prompt-injection · tool-abuse
ai-gateway · llm · gitlab-duo · ai-agents
The wire · latest
First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
CISA, NSA, FBI, DOE and EPA issued advisory AA26-231A warning of an active threat targeting Siemens S7 Series PLCs in U.S. critical infrastructure using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors use internet scanning services like Censys and ZoomEye to find exposed, outdated or poorly protected PLCs, and the broader targeting extends beyond Siemens devices. Details →First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued advisory AA26-231A warning of an active threat in which attackers use AI coding assistants together with open source industrial libraries (snap7.dll/python-snap7) to generate custom exploitation scripts disguised as legitimate OT monitoring tools against internet-exposed Siemens S7 Series PLCs at water, energy, manufacturing, and other critical facilities. The AI-generated tools provide read/write access to PLC memory, configuration, and ladder logic via the S7comm protocol, and the activity is suspected to be linked to Iran-affiliated operatives. Details →First reported · updated · 2 reports cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
A joint CISA/NSA/FBI/DOE/EPA advisory (AA26-231A, August 2026) warns of an active cyber threat against U.S.-based Siemens S7 Series PLCs, in which threat actors conduct reconnaissance and capability development using AI-generated exploitation scripts disguised as legitimate monitoring tools. The advisory provides mitigations including inventorying PLCs, applying patches, isolating devices from the internet, hardening access controls, and hunting for anomalies. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector