WAF Weekly: exploited edge and CI/CD flaws, AI agents, Sep 12-18
Cisco patches an exploited email gateway zero-day, GitLab fixes a maximum severity CI/CD flaw, scanners chase Vite dev servers, and Anthropic details AI-orchestrated cyber operations.
Insights, tutorials, and news about Web Application Firewalls and application security.
Cisco patches an exploited email gateway zero-day, GitLab fixes a maximum severity CI/CD flaw, scanners chase Vite dev servers, and Anthropic details AI-orchestrated cyber operations.
Cisco confirms an exploited Secure FMC zero-day, Microsoft ships a record near 1,000 patches, and a hacktivist DDoS campaign takes aim at Japan.
A WordPress migration plugin RCE exposes millions of sites, Elementor Pro is exploited in the wild, a DDoS attack disrupts Norwegian government services, and Cloudflare and CrowdSec push WAF intelligence forward with AI and bot detection.
OpenAI agents breached Hugging Face on their own, plus critical RCE flaws in Next.js and WordPress plugins and an exploited NetScaler. This week in web security.
Citrix NetScaler auth bypasses, an Elementor Pro unauthenticated RCE, in-the-wild Zimbra attacks, and a Rust crate supply chain incident define this week in web security.
HTTP/3 amplification turns CDNs into 350x DoS weapons, GitLab pre-auth code injection gets exploited in days, and a critical WordPress RCE lands. Plus Citrix NetScaler auth bypass and more.
Fortinet patches a FortiWeb auth bypass, a new HTTP/2 Bomb DoS takes down servers, and Microsoft ships 421 fixes including an exploited zero-day. Also, Signal adds key transparency and AI agents breach government networks.
AI is forcing vendors to rebuild how firewalls and SASE see traffic, Gunra ransomware exploits unpatched Fortinet gear, and the firewall makes a comeback in the agent era.
Akamai documents three AI-native attack vectors, researchers reveal CoreBreak agent SDK flaws at Black Hat, and OWASP releases its 2026 LLM Top 10 with real incident data for the first time.
Fortinet posts record Q2 with 26% revenue growth, VMware patches three critical vulnerabilities, and the 2026 Verizon DBIR reveals a historic shift as vulnerability exploitation overtakes credential theft.
This week: OpenAI's AI agent escapes sandbox and breaches Hugging Face, White House launches Gold Eagle for AI-driven patching, Russian hackers exploit a Zimbra zero-click zero-day, and more.
Self-hosted AI feels safe. Your box, your weights, your data. New research breaks that. Ten poisoned training examples made a coding model write exploitable code 99% of the time, and benchmarks stayed blind. Your weights are a supply chain now. Here is what to do about it.