Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: September 4, 2026 - September 4, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Friday, September 4, 2026 -46% vs prior run
[!!] ALERT THRESHOLD BREACHED

AI & Supply Chain

[CRITICAL]

MCP-Design-Vulnerability-2026 — Model Context Protocol (MCP) SDKs - Python, TypeScript, Java, Rust

Systemic design vulnerability in Anthropic's official MCP SDKs affecting 200,000 instances across 150M+ package downloads. 43% of MCP servers vulnerable to command injection, 82% prone to path traversal, 36.7% vulnerable to SSRF. Not a coding error but embedded design default in all official SDKs.

REMEDIATION

Audit all MCP server deployments immediately. Implement least-privilege access controls and authentication for all MCP endpoints. Apply network segmentation to restrict MCP server access. Review and remediate specific CVEs: CVE-2025-6514 (mcp-remote), CVE-2025-49596 (MCP Inspector), CVE-2025-54136 (MCPoison).

Source: OWASP  •  Published: 2026-04-01

[HIGH]

AI-Code-Security-Failure-2026 — AI Code Generation Tools (GitHub Copilot, Cursor, Claude Code)

45% of AI-generated code contains real security vulnerabilities per Veracode 2025/2026 reports, with Java hitting 70%+ failure rates. New CVEs include CamoLeak in Copilot, case-sensitivity bypass in Cursor, RCE via config files in Claude Code, plus IDEsaster with 30+ flaws across tools.

REMEDIATION

Implement mandatory security scanning for all AI-generated code before production deployment. Enable human code review for all AI contributions. Deploy SAST/DAST tools in CI/CD pipelines. Train developers on AI-specific security risks. Review CVE-2025-53773 (GitHub Copilot prompt injection RCE with CVSS 9.6).

Source: Veracode  •  Published: 2026-09-04

Threat Actors & Dark Web

[HIGH]

CVE-2026-45312 — RAGFlow

Microsoft reports adversaries exploiting exposed RAGFlow instances using CVE-2026-45312, CVE-2026-28797, and CVE-2026-24770 to establish persistence and steal large language model (LLM) provider keys and related metadata.

REMEDIATION

Patch RAGFlow instances immediately to address CVE-2026-45312, CVE-2026-28797, and CVE-2026-24770. Remove RAGFlow exposure from public internet. Implement authentication and access controls. Rotate all LLM provider API keys. Review logs for indicators of compromise and unauthorized access to AI infrastructure.

Source: MSRC  •  Published: 2026-09-02

[HIGH]

ShinyHunters-ATC-2026 — American Tower Corporation

ShinyHunters hacking group claims breach of American Tower Corporation exfiltrating over 5.2 million records. Part of broader ShinyHunters campaign including Canvas LMS breach affecting 8,809 universities (275M users, 3.65TB data) and Aura Identity Protection breach (900,000 records).

REMEDIATION

Organizations using Salesforce Experience Cloud must audit guest user permissions immediately. Verify /s/sfsites/aura API endpoint security. Implement API rate limiting and authentication. Review access logs for unauthorized data exfiltration. Notify affected individuals and offer credit monitoring services.

Source: BleepingComputer  •  Published: 2026-09-03

[HIGH]

Thomson-Reuters-Breach-2026 — Thomson Reuters C-Track Court Case Management Platform

Thomson Reuters disclosed unauthorized party obtained files from C-Track court case management platform in March 2026 affecting courts in 11 US states, US Virgin Islands, and Ontario Canada. Breach discovered June 30, 2026 - three month dwell time. Court records may contain names, SSNs, driver's licenses, DOB, medical information, and health insurance data.

REMEDIATION

Organizations must offer affected individuals 12 months of credit monitoring (Experian IdentityWorks). Review all administrative access to C-Track platform. Implement data loss prevention (DLP) controls. Deploy file integrity monitoring. Reduce data retention periods for sensitive PII. Conduct forensic investigation to determine full scope of exfiltration.

Source: BleepingComputer  •  Published: 2026-09-04

[HIGH]

Ransomware-September-2026 — Multiple Organizations (DiaSorin S.p.A., Petrocare Construction)

Active ransomware campaigns in September 2026: Settra group attacked DiaSorin biotech company in Italy (Sept 3), Storm group attacked Petrocare Construction in Canada (Sept 3). ZaWoo data extortion attacks against multiple organizations worldwide. Krybit RaaS represents persistent financially motivated threat.

REMEDIATION

Implement immutable backups with offline/air-gapped copies. Deploy MFA across all access points including VPN, RDP, and administrative interfaces. Implement network segmentation to limit lateral movement. Test backup restoration procedures monthly. Deploy EDR solutions with ransomware behavioral detection. Maintain incident response retainers with forensic firms.

Source: BleepingComputer  •  Published: 2026-09-03

AI & Cybersecurity News

[INFO]

EU-AI-Act-Enforcement-2026 — AI Providers Operating in European Union

EU AI Act entered full enforcement August 2, 2026 with fines up to 3% of global revenue. Article 50 transparency obligations require AI-powered chatbots and voice agents to clearly identify as AI at interaction start. AI-generated content including deepfakes must carry machine-readable labels.

REMEDIATION

Implement Article 50 transparency requirements immediately for all AI systems deployed in EU. Add clear AI disclosure at start of all chatbot and voice agent interactions. Implement machine-readable labeling for AI-generated content. Conduct AI system inventory and risk classification. Prepare documentation for high-risk AI systems ahead of August 2027 deadline. Establish AI governance framework and compliance monitoring.

Source: Web  •  Published: 2026-08-02

Priority Action Matrix

01DO NOWMCP-Design-Vulnerability-2026 (Model Context Protocol (MCP) SDKs - Python, TypeScript, Java, Rust): Audit all MCP server deployments immediately. Implement least-privilege access controls and authentication for all MCP endpoints. Apply network segmentation to restrict MCP server access. Review and r...
02TODAYAI-Code-Security-Failure-2026 (AI Code Generation Tools (GitHub Copilot, Cursor, Claude Code)): Implement mandatory security scanning for all AI-generated code before production deployment. Enable human code review for all AI contributions. Deploy SAST/DAST tools in CI/CD pipelines. Train develo...
03TODAYCVE-2026-45312 (RAGFlow): Patch RAGFlow instances immediately to address CVE-2026-45312, CVE-2026-28797, and CVE-2026-24770. Remove RAGFlow exposure from public internet. Implement authentication and access controls. Rotate al...
04TODAYShinyHunters-ATC-2026 (American Tower Corporation): Organizations using Salesforce Experience Cloud must audit guest user permissions immediately. Verify /s/sfsites/aura API endpoint security. Implement API rate limiting and authentication. Review acce...
05TODAYThomson-Reuters-Breach-2026 (Thomson Reuters C-Track Court Case Management Platform): Organizations must offer affected individuals 12 months of credit monitoring (Experian IdentityWorks). Review all administrative access to C-Track platform. Implement data loss prevention (DLP) contro...
06TODAYRansomware-September-2026 (Multiple Organizations (DiaSorin S.p.A., Petrocare Construction)): Implement immutable backups with offline/air-gapped copies. Deploy MFA across all access points including VPN, RDP, and administrative interfaces. Implement network segmentation to limit lateral movem...

Biggest Risk This Period

BIGGEST RISK

MCP-Design-Vulnerability-2026: Systemic design vulnerability in Anthropic's official MCP SDKs affecting 200,000 instances across 150M+ package downloads. 43% of MCP servers vulnerable to command injection, 82% prone to path traversal, 36.7% vulnerable to SSRF. Not a coding error but embedded design default in all official SDKs.