The Harm SurfaceAI, cyber, and autonomy

Threads · stories carried across issues

You meet week four knowing weeks one to three.

Most weekly briefs ship a list of disconnected links. A thread is a story carried across issues with an explicit record of what changed and when, so a pattern that takes a month to appear is not lost in four separate Wednesdays.

Open threads 16 live
ST-01 Opened 2026-09-02 Live · 1 development

Two SonicWall SMA1000 zero-days are being chained in attacks

SMA 1000 is a remote access appliance, so the chain lands on the edge of the network with no credentials. Patch it ahead of anything internal this week.

The record

  1. 2026-09-02

    Two SonicWall SMA1000 zero-days are being chained in attacks

ST-02 Opened 2026-09-01 Live · 1 development

Attackers are stealing OpenAI keys through a Langflow flaw

Langflow is the third AI development platform in three weeks to be exploited, after Ray and MLflow. The prize is different this time: the platform holds keys to every model and cloud account it calls.

The record

  1. 2026-09-01

    Attackers are stealing OpenAI keys through a Langflow flaw

ST-03 Opened 2026-08-31 Live · 1 development

CISA Adds Two Known Exploited Vulnerabilities to Catalog

The record

  1. 2026-08-31

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

ST-04 Opened 2026-08-31 Live · 1 development

Both PaperCut flaws are now confirmed as actively exploited

PaperCut runs on a server that every workstation talks to and that usually holds domain credentials. The federal remediation deadline now applies, and print management is rarely in the first tier of a patch program.

The record

  1. 2026-08-31

    Both PaperCut flaws are now confirmed as actively exploited

ST-05 Opened 2026-08-31 Live · 1 development

Fire Ant moved from hypervisors to routers and TACACS

Router and TACACS compromise puts the actor inside the systems that authenticate and log everything else. Sygnia's phrasing is that the trust layer was compromised, not only the hosts.

The record

  1. 2026-08-31

    Fire Ant moved from hypervisors to routers and TACACS

ST-06 Opened 2026-08-29 Live · 1 development

TerminalFix moves ClickFix from the Run box to the terminal

The move off the Run dialog is the point: Terminal accepts longer and more complex commands without looking wrong. Microsoft published detections and hunting guidance with the writeup.

The record

  1. 2026-08-29

    TerminalFix moves ClickFix from the Run box to the terminal

ST-07 Opened 2026-08-27 Live · 1 development

VulnCheck found two more factory implants in ZBT routers

VulnCheck's researchers read these as domestic Chinese surveillance technology built for the Chinese market rather than as an export campaign. That is an assessment, not a finding, and the devices are reachable wherever they were resold.

The record

  1. 2026-08-27

    VulnCheck found two more factory implants in ZBT routers

ST-08 Opened 2026-08-24 Live · 1 development

A WordPress single sign-on plugin is being bypassed in the wild

Single sign-on is the control that makes one credential safe to hold. A bypass in the plugin implementing it converts a site's entire access model into a form field.

The record

  1. 2026-08-24

    A WordPress single sign-on plugin is being bypassed in the wild

ST-09 Opened 2026-08-21 Live · 1 development

Malware reached a car's head unit through its own update channel

A modern head unit is an Android device with a permanent mobile connection and no patch cycle a fleet owner controls. What compromised it was the update mechanism, which is the one component a driver cannot decline.

The record

  1. 2026-08-21

    Malware reached a car's head unit through its own update channel

ST-10 Opened 2026-08-20 Live · 1 development

Three Rust crates ran their payload at compile time

A build-time payload runs on whatever compiles the code, which is a developer laptop or a CI runner holding more credentials than production does. Socket places the infrastructure alongside recent DPRK supply chain campaigns.

The record

  1. 2026-08-20

    Three Rust crates ran their payload at compile time

ST-11 Opened 2026-08-19 Live · 1 development

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilit

The record

  1. 2026-08-19

    CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

ST-12 Opened 2026-08-19 Live · 1 development

MLflow entered the exploited catalogue seven days after Ray

For the second week running the catalogue includes a platform whose job is running machine learning work. Ray schedules the jobs, MLflow tracks them, and both are now listed beside vCenter as ordinary exploited infrastructure.

The record

  1. 2026-08-19

    MLflow entered the exploited catalogue seven days after Ray

ST-13 Opened 2026-08-19 Live · 1 development

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

The record

  1. 2026-08-19

    Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

ST-14 Opened 2026-08-19 Live · 1 development

Slovakia found a Russian backdoor in its traffic speed cameras

Two of the three sources behind this item are Catalin Cimpanu, who writes the bulletin, so the corroboration count overstates how many independent voices carry it. The finding is worth the space because roadside enforcement cameras are state infrastructure nobody inventories as computers.

The record

  1. 2026-08-19

    Slovakia found a Russian backdoor in its traffic speed cameras

ST-15 Opened 2026-08-12 Live · 1 development

The August Windows zero-day

This is the same identifier Microsoft patched at August's Patch Tuesday and issue 02 carried as one flaw already in use. The attribution arrives a week later and names the targets, so the sectors listed should treat the August update as an incident trigger rather than as routine maintenance.

The record

  1. 2026-08-12

    Lazarus used the August Windows zero-day on defence firms

ST-16 Opened 2026-08-06 Live · 1 development

Agents outside the test boundary

Three labs, three escapes, one month. The pattern is no longer about any single lab's controls. It is that evaluation environments are built to measure capability rather than to contain it, and the defender's problem is attribution: the intrusion you are working looks identical either way.

The record

  1. 2026-08-06

    A Meta model breached a third party during a safety evaluation

How a thread ends

A thread closes when nothing has moved for 45 days, and closing is recorded rather than silent. A closed thread stays on the page with its final state, because a pattern that stopped is itself a finding.

Live · moved in the last 45 days Watching · open, nothing new Closed · dated, and kept