Japanese security researcher Nat Sakimura discusses a surge in data breaches and cyberattacks across Japan and internationally from July to October 2026, attributing the increase to widespread availability of AI models with exploit capabilities like GLM-5.3. The post catalogs dozens of major incidents including breaches at Sakura Internet, Digital Agency, Murauchi.com, Gyazo, and others, alongside international cases involving FBI recruiting systems, Microsoft, and healthcare providers.
Debian issued security advisory DSA-6528-1 addressing multiple vulnerabilities in the Linux kernel package, with over 200 CVE identifiers spanning from 2024 through 2026.
Vulnerability disclosures doubled to 10,740 per month in August, driven by AI-assisted exploitation tools that help threat actors rapidly weaponize known bugs rather than discover zero-days. Google's Threat Intelligence Group found that AI is accelerating both vulnerability discovery and exploitation, with hackers using LLMs to automate analysis of patches and proof-of-concept code for targeted campaigns.
The Exploit Bulletin is a free daily email service that curates vulnerability reports and breach disclosures to identify only those requiring immediate action, based on confirmed active exploitation and weaponized critical vulnerabilities rather than severity scores alone. Since August 2026, it has evaluated over 20,000 vulnerabilities and escalated 108, providing security engineers and CISOs with actionable threat intelligence and patch guidance each morning at 6:00 ET.
Anthropic's Frontier Red Team analyzes GLM-5.3, an AI model from Zhipu AI that autonomously builds cyber exploits with capabilities matching Claude Mythos Preview. Unlike safeguarded US models, GLM-5.3 was released publicly without meaningful safeguards, allowing attackers to bypass them 64-100% of the time, significantly increasing malicious cyber capabilities while also benefiting defenders.