Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities

2026-04-07T20:51:46Zbc50e0a3b1e186eff93a8f0769eac05f1a868de659a97044bc4d4c121e89c293
AI securityAkiraCVE-2026-35616FBI IC3FortiClient EMSFortinetGrafanaICS/SCADAIranian government threat actorParagonProject Glasswingbudget/CISAcritical infrastructurecybercrime trendsdata exfiltrationhotfixopen sourceprompt injectionransomwarerapid encryptionspywarestalkerwarevulnerability researchzero-day

What happened

This CyberScoop collection highlights multiple high-impact security developments: major tech firms launched Project Glasswing to use AI for discovering critical open-source software vulnerabilities; U.S. agencies warn Iranian state-aligned hackers are conducting disruptive attacks against U.S. energy and water (ICS/SCADA) infrastructure; a Grafana prompt‑injection flaw dubbed “GrafanaGhost” enables stealthy data exfiltration via the product’s AI features; Fortinet FortiClient EMS is being actively exploited via critical zero-day(s) with CVE-2026-35616 noted and only a hotfix available while a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
bc50e0a3b1e186eff93a8f0769eac05f1a868de659a97044bc4d4c121e89c293
Enrichment time
2026-04-07T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.