AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties
2026-04-08T20:51:40Z•bc8a4965b4754556959debfa2593f0e1fb7a84266bd862166ddd75e17d65a832
AI-securityCVE-2026-35616FortiClientGrafanaIranian-actorsLatin-America-fraudMaaSMedusaOT/ICSPLC-exploitationReact2ShellStorm-1175TeamPCPVenom-Stealerbug-bountycredential-harvestinggithub-targetingnpm-compromiseover-privilegeprompt-injectionransomwareremediation-crisissupply-chain-attackvertex-aizero-day
What happened
A Dark Reading roundup highlighting rising threats and security trends: AI-driven automation is shifting the bottleneck from discovery to remediation (prompting HackerOne to pause some bounties); multiple supply-chain and package attacks (Axios NPM compromise, AI-assisted GitHub targeting); high-velocity ransomware campaigns (Storm-1175 deploying Medusa) and automated credential-exfiltration campaigns (exploiting React2Shell in Next.js apps); an actively exploited FortiClient authentication bypass (Fortinet emergency patch CVE-2026-35616); OT/ICS disruption via Internet-facing PLCs attributed/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- bc8a4965b4754556959debfa2593f0e1fb7a84266bd862166ddd75e17d65a832
- Enrichment time
- 2026-04-08T20:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.