SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

2026-07-15T13:24:11Zbee0b4b1375256c088abfc048ad6b31fd9070d3feb0b7ecad1bec7d7878dffe4
AI memory poisoningCVE-2026-15409CVE-2026-44747Cursor code executionForg365Grok BuildLabubaRATLegacyHiveMemGhostOAuth client ID spoofingRabbitMQ access-controlSAPSecure Boot bypassSonicWallUEFI shimWindows PoCbotnetgit repo exfiltrationmacOS CrashStealernpm DDoSnpm compromisephishing-as-a-servicesupply-chainxAIzero-day

What happened

Multiple high-impact vulnerabilities and active threats across cloud, endpoint, supply-chain, and AI ecosystems. Highlights include active exploitation of two SonicWall SMA 1000 zero-days (one tracked as CVE-2026-15409, CVSS 10.0), a critical SAP NetWeaver ABAP out-of-bounds write (CVE-2026-44747, CVSS 9.9), a new Windows User Profile Service PoC (LegacyHive) for local privilege elevation, and Microsoft's record Patch Tuesday covering 622 flaws including two actively exploited zero-days. Supply-chain and developer tooling risks are prominent: compromised @asyncapi npm packages distributing a 2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
bee0b4b1375256c088abfc048ad6b31fd9070d3feb0b7ecad1bec7d7878dffe4
Enrichment time
2026-07-15T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.