Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities
2026-04-07T20:51:46Z•bc50e0a3b1e186eff93a8f0769eac05f1a868de659a97044bc4d4c121e89c293
AI securityAkiraCVE-2026-35616FBI IC3FortiClient EMSFortinetGrafanaICS/SCADAIranian government threat actorParagonProject Glasswingbudget/CISAcritical infrastructurecybercrime trendsdata exfiltrationhotfixopen sourceprompt injectionransomwarerapid encryptionspywarestalkerwarevulnerability researchzero-day
What happened
This CyberScoop collection highlights multiple high-impact security developments: major tech firms launched Project Glasswing to use AI for discovering critical open-source software vulnerabilities; U.S. agencies warn Iranian state-aligned hackers are conducting disruptive attacks against U.S. energy and water (ICS/SCADA) infrastructure; a Grafana prompt‑injection flaw dubbed “GrafanaGhost” enables stealthy data exfiltration via the product’s AI features; Fortinet FortiClient EMS is being actively exploited via critical zero-day(s) with CVE-2026-35616 noted and only a hotfix available while a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- bc50e0a3b1e186eff93a8f0769eac05f1a868de659a97044bc4d4c121e89c293
- Enrichment time
- 2026-04-07T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.