top of page

The Security Brief


CISA's Latest KEV Additions Came With an AI Agent Attached
CISA gave United States federal agencies until today to fix three vulnerabilities under active attack. One of them was being exploited by an AI agent operating with very little human direction. The patch deadline is the smaller half of that story. What Happened On 4 August, CISA added three flaws to its Known Exploited Vulnerabilities catalogue. The most severe is CVE-2026-9198, a code injection bug rated 9.8 in Langflow, IBM's visual framework for building AI agents. It lets
4 days ago4 min read


CVE-2026-16232: Attackers Are Taking Over Check Point Management Servers
Check Point disclosed CVE-2026-16232 on 22 July after discovering it had already been exploited as a zero-day. The flaw lets an unauthenticated attacker log into a Security Management Server with full administrator rights — the machine that writes and pushes policy to every firewall it manages. Rapid7 published a working proof-of-concept on 29 July, which means the window for quiet patching has closed. What Happened Check Point found the bug during a routine internal review a
Jul 313 min read


wp2shell: A Pre-Authentication WordPress Core Flaw Australian Sites Should Patch Now
A single anonymous HTTP request can run code on a vulnerable WordPress site. The flaw, nicknamed wp2shell, sits in WordPress core rather than a plugin, so even a bare installation with nothing added is in range. WordPress shipped emergency fixes on 17 July, and any Australian organisation running an affected version should treat patching as this week's priority. What Happened On 17 July 2026, WordPress released versions 6.9.5 and 7.0.2 to close a pre-authentication remote cod
Jul 303 min read
bottom of page