The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

2026-09-12T08:51:38Z67160e677c05be559789d704e3ee31183a765a57e78bac03127e9f84d1c77258
CVE-2026-20079CVE-2026-75650CVE-2026-87491AI securityAI supply chainActive DirectoryCISA KEVChrome zero-dayCisco Secure Firewall Management CenterGoogle V8QilinSonicWallactive exploitationauthentication bypasscredential theftexploit kitsexposed AI endpointsnation-state actorsransomware

What happened

The feed highlights active exploitation of critical enterprise vulnerabilities, including Cisco Secure Firewall Management Center authentication bypass flaws used to deploy Qilin ransomware, mass exploitation of a SonicWall flaw linked to credential and Active Directory theft, and multiple vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog. It also reports actively exploited Chrome V8 zero-days, nation-state adoption of exploit kits, exposed AI infrastructure and endpoints, AI model extraction campaigns, and risks from insufficiently isolated AI agents and sandboxes.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
67160e677c05be559789d704e3ee31183a765a57e78bac03127e9f84d1c77258
Enrichment time
2026-09-12T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet · Baitaphish