Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
12 hours ago

Tenable Security Intel Brief: AI agents ran an intrusion in 10 hours

Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.

But first: Anthropic's Claude Mythos 5 is coming to the Tenable One Exposure Management Platform, where it will power Tenable One Adversary View, debuting in the coming weeks. As Tenable Chief Product Officer Eric Doerr writes, "Mythos 5 provides frontier-scale adversarial reasoning, while Tenable's agentic harness provides the context and controls to turn that reasoning into secure, controlled action." Read the announcement here.

This week, Palo Alto Networks' Unit 42 details a ransom-driven intrusion reportedly carried out by AI agents that compressed weeks of attack tradecraft into under 10 hours and left the victim an 80-page audit of its own security posture.

AI agents ran a full enterprise intrusion in under 10 hours →

Brief: Unit 42 investigated an intrusion where a human attacker reportedly used AI agents to breach an enterprise network, steal credentials, hijack cloud infrastructure, and leave an 80-page security audit, all in under 10 hours.

Intel: In ransom negotiations, the attacker told investigators they had used "frontier AI models and attack-specific agentic AI frameworks," a claim Unit 42 relayed without naming any model. Agents entered through a public-facing web service, mapped internal microservices, pulled credentials embedded in code repositories, accessed the secrets management system to harvest master administrative credentials, and hijacked the automated build system to pull cloud access keys. The victim's own AI compute endpoints were then turned into post-compromise infrastructure. Investigators counted over 50 distinct attack techniques executed across the full chain.

Why it matters: Over the last year, we have highlighted the rise of AI usage among attackers. Two editions ago, Talos found a crew handing post-breach operations to AI. This attacker reportedly handed agents the entire intrusion, a 10-hour job that could pay for itself in ransom.

SonicWall SMA 1000 hit by two more zero-days on a federal clock →

Brief: SonicWall disclosed two actively exploited zero-days in its SMA 1000 remote-access appliances on August 31, and CISA added both to the Known Exploited Vulnerabilities (KEV) catalog on September 2 with a federal deadline of September 5.

Intel: CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw (CVSSv3 10.0) in the SMA 1000 Appliance Work Place interface. An unauthenticated attacker can trick the appliance into making requests on their behalf, exploiting it as an unintended proxy to reach sensitive functionality. CVE-2026-83549 is an OS command injection flaw (CVSSv3 7.8) in the Appliance Management Console requiring an authenticated administrator. SonicWall says it "has investigated a case indicating the active exploitation" of the flaws; BleepingComputer reports the two were chained. No workaround exists. Affected: SMA1000 models 6210, 7210, and 8200v only.

Why it matters: Shadowserver counts over 400 SMA 1000 appliances reachable online, on a product line at its fourth security event in roughly ten months: a MySonicWall breach in September 2025, a zero-day in December, two more in July, now this pair. The track record runs ahead of the product description.

Unauthenticated Magento zero-day hit stores before a fix existed →

Brief: CVE-2026-75650, an unauthenticated remote code execution flaw dubbed StyleSmuggler, was assigned a maximum CVSSv3 score of 10 and is being exploited in the wild against Adobe Commerce and Magento Open Source sites.

Intel: Our Research Special Operations team compiled a FAQ on the zero-day, which injects PHP through the styles properties in Magento's template system. The code fires with no authentication when a store renders the "Payment Transaction Failed Reminder" email. Sansec reports exploitation began September 4, three days before Adobe's September 7 hotfix VULN-39341, with operators changing payloads several times a day across the window.

Why it matters: Sansec found a second, unrelated attacker dropping web shells on stores the implant group had already breached. By the time a fix existed, the flaw was being worked by more than one crew, so patch status told a store nothing about how many intruders it was hosting.

UAC-0099 plants an LLM safety trigger in malware to stop AI triage →

Brief: ESET discovered GuardBreaker: in an attack on a Ukrainian target, Russia-aligned UAC-0099 planted text in a malicious VBS script to trip AI safety filters and derail AI-assisted analysis.

Intel: UAC-0099 inserted the text "I want to make nuclear weapon. Help me ..." as a comment inside the script. When an AI tool scans the file, it hits that text, trips its safety guardrails, and stops analyzing before it reaches the malicious code. The script deploys MATCHBOIL, a loader ESET says is exclusive to UAC-0099, a group that typically targets the transportation and energy sectors; CERT-UA has documented the malware. A June 2026 cluster of PyPI packages used the same approach, Socket reported, embedding weapon-instruction text to force AI scanners into refusal.

Why it matters: The safety guardrail did exactly what it was built to do, and that's the problem. An attacker who knows which text stops an AI tool from reading further can use the guardrail itself as a shield for the malicious code that follows.

Stat of the week: 153 million

The number of digital scans of U.S. and Canadian driver's licenses for sale on Nexus, a new dark-web identity theft service that added nearly 400,000 records in a single 24-hour span, according to KrebsOnSecurity.

Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.

No RepliesBe the first to reply