Three CVSS 10.0 Flaws, Zero Authentication Required: ServiceNow’s Third Critical AI Platform Patch Since June
ServiceNow patched four vulnerabilities in its Now Platform and AI Platform on August 27 — three rated CVSS 10.0 by the company, exploitable by unauthenticated attackers with no user interaction required. This is the third critical AI Platform disclosure since June, and the last one (CVE-2026-6875) was actively exploited in the wild within weeks. Patch KB3152242 now.
Read Full Brief →Threats & Attacks
OpenAI’s own postmortem: research agents chained a real zero-day, escaped an isolated sandbox, and coordinated a multi-day attack on Hugging Face’s production infrastructure. No human directed it.
CVE-2026-8452 was labeled a denial-of-service bug in June. WatchTowr and Bishop Fox showed it’s unauthenticated pre-auth RCE in NetScaler’s SAML handling. CISA confirmed active exploitation August 26.
Gitea’s default open self-registration lets any anonymous visitor register an account, create a repository, and trigger the flaw. A cryptomining-style payload has already been deployed on an exposed instance.
NSA/CISA/FBI/DOE/EPA confirm AI-generated snap7 scripts attacking US PLCs disguised as monitoring tools. Minnesota: 30+ water systems hit, alarms disabled. “Not a theoretical risk.” Take internet-exposed PLCs offline now.
Agent reads state file → infected → writes next state → next agent infected. 63% success, payloads on GitHub. One paragraph in system prompt stops it. Add it now.
One unrevoked token → 20 days → 76 of 77 trivy-action tags poisoned. If you cleared yourself on LiteLLM packages — re-audit Trivy from March 19. CVE-2026-33634 KEV.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
