The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
2026-09-12T08:51:38Z•67160e677c05be559789d704e3ee31183a765a57e78bac03127e9f84d1c77258
CVE-2026-20079CVE-2026-75650CVE-2026-87491AI securityAI supply chainActive DirectoryCISA KEVChrome zero-dayCisco Secure Firewall Management CenterGoogle V8QilinSonicWallactive exploitationauthentication bypasscredential theftexploit kitsexposed AI endpointsnation-state actorsransomware
What happened
The feed highlights active exploitation of critical enterprise vulnerabilities, including Cisco Secure Firewall Management Center authentication bypass flaws used to deploy Qilin ransomware, mass exploitation of a SonicWall flaw linked to credential and Active Directory theft, and multiple vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog. It also reports actively exploited Chrome V8 zero-days, nation-state adoption of exploit kits, exposed AI infrastructure and endpoints, AI model extraction campaigns, and risks from insufficiently isolated AI agents and sandboxes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 67160e677c05be559789d704e3ee31183a765a57e78bac03127e9f84d1c77258
- Enrichment time
- 2026-09-12T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.