A single security scan this week found over 16,000 publicly exposed databases built with AI coding tools — a wake-up call that the rush to build fast with AI is quietly creating a breach crisis for businesses of every size, not just tech giants.
Two fresh warnings, a SANS-flagged wave of attacks abusing legitimate remote-support software and a newly exploited Citrix NetScaler zero-day with a federal patch deadline this week, both target the exact remote-access tools SMBs and their IT providers rely on every day.
198 Hits
A fix for a critical Zimbra email server flaw was available for more than three weeks before the public was told about it, and attackers used that time. Microsoft Threat Intelligence reports that threat actors exploited CVE-2026-73570 (CVSS 8.9), an unauthenticated operating system command injection vulnerability in the Zimbra Collaboration Suite, for weeks before it was disclosed. The Shadowserver Foundation counted 274 compromised Zimbra servers in a single recent week.
233 Hits
Cisco has confirmed that attackers are actively exploiting a critical vulnerability in the software many businesses use to connect their offices together. The flaw, tracked as CVE-2026-76504 and rated 9.8 out of 10 on the CVSS severity scale, affects Cisco Catalyst SD-WAN Manager. It lets a remote attacker slip past a login check and gain administrator-level access to a protected management API. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already added it to its Known Exploited Vulnerabilities (KEV) catalog and gave federal agencies until October 3, 2026 to fix it.
334 Hits
AI agents are quickly moving from experiment to everyday business tool, and a new lawsuit is a timely reminder that when an AI agent causes harm, someone is still responsible. On September 29, 2026, the nonprofit Legal Advocates for Safe Science and Technology (LASST) sued OpenAI in California, seeking to hold the company accountable for the actions of its AI agents, including their role in the July 2026 breach of Hugging Face. At the center of the case is a California law that took effect this year and says, in effect, that "the AI did it" is not a legal defense.
353 Hits
