~/greenteam/nerd

Sunday, September 20, 2026

Daily digest

No CMMC-specific news today, but a heavy day for AI-agent security research (Codex sandbox escape, Claude-assisted OpenAI account takeover, BragJack) alongside a high-severity SolarWinds ARM RCE — worth prioritizing patching and reviewing any AI browser-agent usage in the environment.

cybersec The Hacker News

SolarWinds Patches Hard-Coded Key Flaw Enabling Unauthenticated RCE in Access Rights Manager

SolarWinds released updates fixing CVE-2026-28326, a CVSS 8.8 vulnerability in Access Rights Manager caused by a hard-coded key that could allow unauthenticated remote code execution. The flaw affects all ARM versions 2026.2 and prior.

Why it matters: If ARM is used to manage AD permissions in your environment, this is an unauthenticated RCE against a privileged identity tool — patch immediately and treat as a CMMC-relevant vulnerability management action.

cybersec BleepingComputer

North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide

A joint law enforcement advisory states the North Korean group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026, transferring over $10.7 million in stolen cryptocurrency back to North Korea.

cybersec BleepingComputer

ShinyHunters Hacks Clop Ransomware's Leak Site

The ShinyHunters extortion group breached and defaced the Clop ransomware gang's dark web leak site, claiming to have stolen server data and the private keys for its onion service, and is threatening to extort Clop in return.

cybersec Ars Technica Security

Undercover Google Analyst Infiltrated Supply-Chain Hacking Gang

Google's threat intelligence group revealed it placed an analyst undercover inside the inner circle of TeamPCP, a group known for supply-chain hacking operations, to gather intelligence on the gang's methods and members.

cybersec BleepingComputer

Researchers Escape OpenAI Codex Sandbox to Run Commands on Host

Security researchers found two ways to escape OpenAI's Codex sandbox, including one method that achieved command execution on a developer's host machine even from the tool's most locked-down configuration. OpenAI has patched both issues.

Why it matters: If Codex or similar AI coding agents are used anywhere in dev/automation workflows, this shows sandbox isolation assumptions can fail — verify patch status before trusting sandboxed AI tooling with sensitive repos.

cybersec The Hacker News

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Researchers at Hacktron used Anthropic's Claude Opus 5 to chain a bug in OpenAI's public help forum with a weakness in OpenAI's login system, taking over ChatGPT and Codex accounts of several OpenAI employees and reaching an internal code repository. The work was disclosed as authorized security research.

Why it matters: Demonstrates AI models can autonomously chain low-severity bugs into account takeover — a relevant threat model for any self-hosted AI stack or SSO integration you manage.

cybersec BleepingComputer

BragJack Attacks Hijack AI Browser Agents Through Malicious Extensions

A proof-of-concept technique called BragJack, developed by researcher Gal Weizman, uses a single malicious browser extension to hijack AI assistants built into Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome via a method called Prompt Forcing. The research earned over $20,000 in bug bounties and resulted in two CVEs.

Why it matters: If any endpoint policy allows browser AI-assistant extensions on managed Windows 11 devices, this is a reason to restrict or block them via Intune app control until vendors harden these integrations.

infrastructure The Register

Windows Update Delays Balloon After Months of Device Inactivity

The Register details how Windows devices left inactive for extended periods accumulate so many pending updates that the eventual update process can take up to seven hours, despite Microsoft's improvements to update efficiency.

Why it matters: For an Intune-managed fleet, devices that go long stretches without connecting (remote/seasonal users) risk multi-hour lockouts during forced update windows — worth reviewing update ring cadence and compliance deadlines.

infrastructure The Register

Investors Call Agentic AI Security an Unsolved Billion-Dollar Problem

The Register reports that venture investors are describing security for autonomous AI agents as a major unaddressed market gap, arguing the industry has been deferring foundational security work as agentic AI deployment accelerates.