Sep 7 – 9, 2026

6 verified items across three lanes, from the week of Sep 7, 2026. Part of the Jul 1 – Sep 9, 2026 board.
Week of

Capability1 itemsfull lane ↗

New Security firm says AI helped it find a WeChat zero-click flaw and write a working remote-code exploit in about two days

Calif disclosed WeWorm, a zero-click worm that hijacks a WeChat account through an incoming call on both iOS and Android and then calls the victim's contacts, built on a memory-corruption bug in WeChat's VoIP stack. “Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days,” the firm writes, with the worm itself taking roughly another week, adding that “a worm at this scale used to be the kind of thing that took a larger team months” and that “if exploited, actors can compromise over a billion phones (or accounts).” The bug was reported to Tencent on July 24 and patched on August 21 in Android 8.0.77 and iOS 8.0.76, with a server-side mitigation; technical details are withheld pending a conference presentation.

Self-reported, untestedCalif ↗ ·

Defense1 itemsfull lane ↗

New Microsoft ships its largest Patch Tuesday on record, and the analysts counting it say AI discovery is not producing more exploited flaws

September's update was Microsoft's biggest, though trackers count it differently — SecurityWeek reported 974 CVEs, Tenable's own tally 964, of which 104 critical. Two were actively exploited privilege-escalation zero-days: CVE-2026-85880, a heap buffer overflow in Windows Advanced Local Procedure Call, and CVE-2026-81963, a link-following flaw in the Windows Update Stack. Tenable senior staff research engineer Satnam Narang: “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles. It's critical that organizations understand which vulnerabilities actually apply to them.”

Reported by pressSecurityWeek ↗ ·

Attacks4 itemsfull lane ↗

New NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models

The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.

On the recordNSA / CISA / FBI ↗ ·

New Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours

In its September AI Threat Tracker, Mandiant reports a suspected financially motivated actor compromising an organisation's cloud infrastructure to deploy an autonomous, multi-agent attack framework: “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” using preconfigured markdown instruction sets as operational playbooks and compromising thousands of third-party credentials. A separate reconnaissance framework ran a production dashboard managing “over 23,800 harvested secrets in real time, including API keys for cloud and AI services.” Google adds that it “has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild.”

Reported by researchersGoogle Threat Intelligence Group / Mandiant ↗ ·

New Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets

The same report says GTIG observed suspected UNC6508 activity “compromising cloud environments to deploy local LLM infrastructure”: “By using a local, open-weight model deployed in compromised infrastructure, UNC6508 is able to avoid commercial AI API monitoring, while co-opting victim compute resources,” against academic, medical and military research institutions in North America. Mandiant separately investigated “multiple data theft extortion operations in which threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research,” affecting technology, healthcare and media and entertainment companies in North America and Europe. Google also says it now sees coordinated distillation campaigns against its own models “on a regular basis, some exceeding 100 million prompts.”

Reported by researchersGoogle Threat Intelligence Group / Mandiant ↗ ·

A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components

SecurityWeek reports that the researcher known as Nightmare Eclipse published three zero-days with proof-of-concept code: PrettyPrague, which targets the Avast sandbox to spawn a shell with full system privileges; FalconFlank, a privilege-escalation bug in the Office malicious-macro remediation feature of the CrowdStrike Falcon Sensor; and GreenSection, an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. Gen Digital said it “immediately initiated our security response procedures and have fixed the issue”; CrowdStrike said it was “actively investigating these claims” and advised disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting; Nvidia had not commented at publication.

Reported by pressSecurityWeek ↗ ·

Sources cited this week

  1. NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models — NSA / CISA / FBI, Sep 8, 2026. media.defense.gov ↗
  2. Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours — Google Threat Intelligence Group / Mandiant, Sep 8, 2026. cloud.google.com ↗
  3. Security firm says AI helped it find a WeChat zero-click flaw and write a working remote-code exploit in about two days — Calif, Sep 8, 2026. calif.io ↗
  4. Microsoft ships its largest Patch Tuesday on record, and the analysts counting it say AI discovery is not producing more exploited flaws — SecurityWeek, Sep 8, 2026. securityweek.com ↗
  5. A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components — SecurityWeek, Sep 7, 2026. securityweek.com ↗