SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
2026-07-15T13:24:11Z•bee0b4b1375256c088abfc048ad6b31fd9070d3feb0b7ecad1bec7d7878dffe4
AI memory poisoningCVE-2026-15409CVE-2026-44747Cursor code executionForg365Grok BuildLabubaRATLegacyHiveMemGhostOAuth client ID spoofingRabbitMQ access-controlSAPSecure Boot bypassSonicWallUEFI shimWindows PoCbotnetgit repo exfiltrationmacOS CrashStealernpm DDoSnpm compromisephishing-as-a-servicesupply-chainxAIzero-day
What happened
Multiple high-impact vulnerabilities and active threats across cloud, endpoint, supply-chain, and AI ecosystems. Highlights include active exploitation of two SonicWall SMA 1000 zero-days (one tracked as CVE-2026-15409, CVSS 10.0), a critical SAP NetWeaver ABAP out-of-bounds write (CVE-2026-44747, CVSS 9.9), a new Windows User Profile Service PoC (LegacyHive) for local privilege elevation, and Microsoft's record Patch Tuesday covering 622 flaws including two actively exploited zero-days. Supply-chain and developer tooling risks are prominent: compromised @asyncapi npm packages distributing a 2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- bee0b4b1375256c088abfc048ad6b31fd9070d3feb0b7ecad1bec7d7878dffe4
- Enrichment time
- 2026-07-15T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.