Rosetta Daily · May 20, 2026
Auto-generated · 29 sources configured (WebSearch mode) · 14 items selected
Window: past 7 days (manual first run with widened window)
In-the-Wild / New CISA KEV
-
🔴🔥 CVE-2026-20182 — Cisco Catalyst SD-WAN auth bypass (CVSS 10.0)
Unauthenticated remote attacker can bypass auth and gain admin on the SD-WAN Controller/Manager. Added to CISA KEV; FCEB agencies must patch by 5/17. Cisco attributes active exploitation with high confidence to UAT-8616 (the same cluster that weaponized CVE-2026-20127).
CISA Alert · Tenable -
🔴⚠️ CVE-2026-42897 — Microsoft Exchange Server 0-day (CVSS 8.1, disclosed 5/14)
Spoofing + XSS in Exchange Subscription Edition / 2016 / 2019. Microsoft confirmed in-the-wild exploitation. Anyone running on-prem Exchange needs to look immediately.
SecurityWeek · Security Affairs
Critical Vulnerabilities
-
CVE-2026-44578 — Next.js WebSocket SSRF (CVSS 8.6, 5/11)
Affects all self-hosted Next.js >= 13.4.13. Unauthenticated attacker can make the Next.js process issue an internal HTTP GET to any reachable host on port 80 and read the response. Patch to 15.5.16 / 16.2.5.
Hadrian writeup -
CVE-2026-42595 — Gotenberg SSRF (CVSS 8.6, 5/14)
Chromium URL-to-PDF endpoint missing default SSRF protection; built-in deny-list regex was insufficient. Upgrade to 8.32.0.
TheHackerWire -
CVE-2026-0073 — Android System RCE (Critical)
Adjacent-attacker RCE in Android System component disclosed in Google's May Android Security Bulletin. No privileges, no user interaction.
Vendor Advisories
- Microsoft Patch Tuesday — May 2026(120 fixes)
17 Critical (14 RCE / 2 EoP / 1 Info Disclosure). First Patch Tuesday in nearly two years with no actively-exploited 0-days. Highlight: multiple Office RCEs triggerable via Preview Pane — patch urgency on Word/Excel.
Krebs· Bleeping· Talos
Web Security Research
- PortSwigger Top 10 Web Hacking Techniques of 2025
Side-channels emerged as a core exploitation primitive in 2025. New work on error-based blind SSTI, polyglot detection, and Parser Differentials (interpretation divergences across languages/frameworks) becoming weaponizable.
PortSwigger
AI Security
-
⚠️ Mandiant M-Trends 2026 — two malware families that call LLM APIs at runtime:
- PROMPTFLUX(VBScript dropper first seen 2025/06) calls the Gemini API to rewrite its own source hourly, evading signature-based detection
- PROMPTSTEALattributed to Russian APT28 (FROZENLAKE)
Median initial-access-to-hand-off time collapsed from 8 hours (2022) to 22 seconds(2025).
Google Cloud Blog· Help Net Security
-
⚠️ OWASP Top 10 for Agentic Applications 2026 (Dec 2025)
First formal taxonomy of autonomous-agent risks: goal hijacking, tool misuse, identity abuse, memory poisoning, cascading failures, rogue agents.
OWASP -
⚠️ CVE-2025-53773 — GitHub Copilot Prompt Injection → RCE (CVSS 9.6)
Hidden prompt injection in PR descriptions enables RCE via Copilot — one of the first real-world demos of indirect injection in enterprise dev workflows. -
Lakera memory-injection research: indirect prompt injection via poisoned external sources can corrupt an agent's long-term memory, inducing persistent false beliefs about security policy and vendor relationships.
AI Frontier — Three Labs This Week
OpenAI
- GPT-5.5 Instant (5/5)— Replaces GPT-5.3 Instant as ChatGPT default. 52.5% fewer hallucinated claims than 5.3 Instant on medical/legal/financial prompts. Live in the API as
chat-latest.
OpenAI· TechCrunch - New voice models in API (5/7)— reason / translate / transcribe speech
- Codex in ChatGPT mobile app (5/14)— remote SSH, hooks, access tokens, HIPAA support for enterprise
- Personal Finance feature (5/15)— Pro users in US, connects bank accounts
Anthropic
- Project Glasswing + Claude Mythos Preview— Anthropic committing $100M in model credits for partner vulnerability hunting. Mythos has autonomously found "thousands of high-severity vulnerabilities" across every major OS and browser, with the ability to construct working exploits. Partners: AWS / Apple / Microsoft / Google / CrowdStrike / Palo Alto + ~40 orgs.
Anthropic Glasswing· Platformer - The Anthropic Institute launched (5/7)— four research areas: economic diffusion / threats & resilience / AI in the wild / AI-driven R&D
Agenda - Anthropic Fellows Program— applications open for May and July 2026 cohorts; scalable oversight / adversarial robustness / model organisms / interpretability / AI security / model welfare
Google DeepMind
- Gemini Omni (5/19 at I/O)— multimodal video gen/edit; Omni Flash rolling out to AI Plus/Pro/Ultra and free to YouTube Shorts/Create users
TechTimes - Antigravity + Gemini 3.5 Flash (5/19 at I/O)— for agentic coding and long-horizon tasks. Demo: built a working OS from scratch in 12 hours. Ultra subscription dropped from $250 → $200/month
Cybernews - Big Sleep (Project Zero + DeepMind)— AI agent finding real vulnerabilities autonomously, including one about to be weaponized by threat actors
Google Cloud Blog
🛡 = security-relevant, also archived under
intel/ai-frontier/security/
Key Observations / Threads This Week
- The asymmetric AI-as-weapon vs AI-as-defense race is now overt: Mandiant documenting PROMPTFLUX rewriting itself via Gemini API, while Anthropic's Mythos finds thousands of 0-days. Same root capability, both sides racing.
- Three high-severity SSRFs in May: Next.js, Gotenberg, OpenClaw. For web bounty hunting, SSRF is a high-value direction right now.
- Indirect prompt injection has graduated from PoC to RCE: CVE-2025-53773 (Copilot, 9.6) is one of the earliest empirical demonstrations in dev workflows.
Failed Sources
- This run used WebSearch mode (workspace web_fetch has provenance restrictions). Scheduled Task runs will use WebFetch for fuller coverage.
Sources config: intel/sources.yaml