AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties

2026-04-08T20:51:40Zbc8a4965b4754556959debfa2593f0e1fb7a84266bd862166ddd75e17d65a832
AI-securityCVE-2026-35616FortiClientGrafanaIranian-actorsLatin-America-fraudMaaSMedusaOT/ICSPLC-exploitationReact2ShellStorm-1175TeamPCPVenom-Stealerbug-bountycredential-harvestinggithub-targetingnpm-compromiseover-privilegeprompt-injectionransomwareremediation-crisissupply-chain-attackvertex-aizero-day

What happened

A Dark Reading roundup highlighting rising threats and security trends: AI-driven automation is shifting the bottleneck from discovery to remediation (prompting HackerOne to pause some bounties); multiple supply-chain and package attacks (Axios NPM compromise, AI-assisted GitHub targeting); high-velocity ransomware campaigns (Storm-1175 deploying Medusa) and automated credential-exfiltration campaigns (exploiting React2Shell in Next.js apps); an actively exploited FortiClient authentication bypass (Fortinet emergency patch CVE-2026-35616); OT/ICS disruption via Internet-facing PLCs attributed/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
bc8a4965b4754556959debfa2593f0e1fb7a84266bd862166ddd75e17d65a832
Enrichment time
2026-04-08T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.