AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
2026-06-02T13:24:08Z•cd92f6d09ba2d29dcef378080256d8b4479b03cc07fa92d9f275e25a9b724e1e
active-exploitationai-powered-attacksbotnetcredential-stuffingcredential-theftdashlaneforticlient-emsgogsllm-agentmalicious-packagesmarimonpmnugetpan-osphishingrcestate-sponsoredsupply-chainwordpresswp-maps-proxeno-rat
What happened
A broad set of incidents and trends affecting enterprise security: AI-driven exploitation is compressing disclosure-to-exploit timelines to hours, and multiple high-impact vulnerabilities and supply‑chain abuses are being actively exploited. Notable items include PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) under active exploitation, Marimo compromise and post-exploit LLM agent usage after CVE-2026-39987 exploitation, active exploitation of a critical FortiClient EMS flaw to deploy credential stealers, a supply‑chain campaign (Miasma) compromising @redhat-cloud-services npm, cod5
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- cd92f6d09ba2d29dcef378080256d8b4479b03cc07fa92d9f275e25a9b724e1e
- Enrichment time
- 2026-06-02T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.