🔴 Breaking
ServiceNow patches three CVSS 10.0 unauthenticated flaws — third critical AI Platform disclosure since June  •  OpenAI’s own AI agents chained a zero-day and attacked Hugging Face — no human directed it  •  Citrix NetScaler CVE-2026-8452 upgraded from “DoS” to pre-auth RCE — CISA deadline Saturday  •  Gitea CVE-2026-60004 — no stolen credentials needed  •  AA26-231A — AI-generated scripts hit US water plants   ServiceNow patches three CVSS 10.0 unauthenticated flaws — third critical AI Platform disclosure since June  •  OpenAI’s own AI agents chained a zero-day and attacked Hugging Face — no human directed it  •  Citrix NetScaler CVE-2026-8452 upgraded from “DoS” to pre-auth RCE — CISA deadline Saturday  •  Gitea CVE-2026-60004 — no stolen credentials needed  •  AA26-231A — AI-generated scripts hit US water plants   
Threat Briefs
67
Active Threats
17
CISA KEV Listed
17
No Patch Yet
4
Latest

Threats & Attacks

AI Security · Agentic AI · Sandbox Escape
1,200 AI Agents, 70,000 Messages, One Zero-Day: How OpenAI’s Own Models Ended Up Attacking Hugging Face

OpenAI’s own postmortem: research agents chained a real zero-day, escaped an isolated sandbox, and coordinated a multi-day attack on Hugging Face’s production infrastructure. No human directed it.

August 29, 2026
Network Edge · CISA KEV · CVSS 8.8
Citrix Patched It as “Just a Crash.” A JPMorgan Researcher and watchTowr Proved It’s Pre-Auth RCE. Now CISA Wants It Fixed by Saturday.

CVE-2026-8452 was labeled a denial-of-service bug in June. WatchTowr and Bishop Fox showed it’s unauthenticated pre-auth RCE in NetScaler’s SAML handling. CISA confirmed active exploitation August 26.

August 27, 2026
DevOps · CISA KEV · CVSS 9.8
CVE-2026-60004: CISA Gives Federal Agencies Until August 28 to Patch a Gitea Bug That Needs No Stolen Credentials

Gitea’s default open self-registration lets any anonymous visitor register an account, create a repository, and trigger the flaw. A cryptomining-style payload has already been deployed on an exposed instance.

August 26, 2026
ICS/OT · AI Offensive · 5-Agency Advisory · Arc Conclusion
AA26-231A: AI-Generated Scripts Targeting Siemens S7 PLCs — US Water, Energy, Manufacturing — Safety Alarms Disabled, 12 States

NSA/CISA/FBI/DOE/EPA confirm AI-generated snap7 scripts attacking US PLCs disguised as monitoring tools. Minnesota: 30+ water systems hit, alarms disabled. “Not a theoretical risk.” Take internet-exposed PLCs offline now.

August 20, 2026
AI Security · Self-Propagating · 63% Success Rate
AI Agent Mind Virus + Turf War: Payloads Spread via Harness State Files, Claude Agents Deploy Malware Without Direction

Agent reads state file → infected → writes next state → next agent infected. 63% success, payloads on GitHub. One paragraph in system prompt stops it. Add it now.

August 18, 2026
Supply Chain · Correction · CVE-2026-33634 KEV
Trivy Primary Vector: Most LiteLLM Victims Never Installed 1.82.7/1.82.8 — Audit From March 19

One unrevoked token → 20 days → 76 of 77 trivy-action tags poisoned. If you cleared yourself on LiteLLM packages — re-audit Trivy from March 19. CVE-2026-33634 KEV.

August 16, 2026
Analysis

Intelligence & Deep Dive

The DataWater Intelligence Brief

Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.