Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Howdy 👋🏽
I hope you’re having an excellent week! It’s been a very, very long one for me as I’m currently refreshing the AI Tooling Visibility book and getting it ready for Amazon storefront. More on that soon!
Quick reminder for my NYC folks: I’m speaking at BSides NYC on October 17 about AI tooling logs and what we can actually detect with them. Tickets are pay what you can. We’re also throwing a Gatsby-themed party in Midtown the night before. Looking forward to seeing some of you there!
We’ve got plenty to cover this week. Let’s get to it.
🗞️ TL;DR
🏆 Pwn2Own hits AI infrastructure: Day one brought 32 zero-days, with wins against Codex, LiteLLM, and Oracle’s AI database.
💰 Armadin adds another round: The company announced a $255.5M Series B at a valuation above $2.5B.
📬 Google pauses part of its open-source bounty: New product-vulnerability submissions stopped after a flood of mostly invalid automated reports.
🛠️ NetScaler needs another patch: Attackers are exploiting another flaw in NetScaler systems configured for SAML authentication.
🧾 Attackers test stolen AWS keys: Datadog shows how attackers check whether stolen credentials let them use AI models through Amazon Bedrock.
We also hit on LLM safety bypasses, detection-rule performance, and private networking for people and AI agents.
Your AI Agents Are Deployed. Are They Trusted?

Agents don't wait for permission; they simply act. Varonis Atlas' latest expansion is Agent Intent-Based Access Control (IBAC), a new layer that compares what an agent was asked to do to what it actually does. Agent IBAC blocks, alerts, and quarantines in real time when agents drift off course. Stop guessing what your agents can reach and start controlling what they do.
⚒️ Picks of the Week
Researchers exploit Codex, LiteLLM, and Oracle at Pwn2Own

Pwn2Own Ireland’s opening day produced 32 zero-days and $388,500 in awards across the day’s targets, BleepingComputer reports. The competition, run by Zero Day Initiative, pays researchers to demonstrate working exploits against real products in a controlled setting.
AI tooling featured heavily. Ikotas Labs earned $40,000 for an argument-injection exploit against OpenAI Codex. Taisic Yun of Xint earned another $40,000 by chaining input-validation and code-injection flaws in LiteLLM to obtain a reverse shell, giving the researcher remote command access.
A second LiteLLM exploit used four bugs, two of them previously known, and earned Out of Bounds $15,000. VinSOC also combined five bugs against Oracle Autonomous AI Database for a $40,000 win.
Google pauses part of its open-source bug bounty

Google stopped accepting new product-vulnerability submissions to its Open Source Software Vulnerability Reward Program after a surge in automated reports, most of them invalid. Supply-chain submissions and pending reports are unaffected. An update is promised for Q1 2027, without a reopening date.
Other programs have changed their rules, too. curl ended cash bounties earlier this year after a flood of low-quality AI reports. GitHub tightened public submissions using researchers’ report-quality scores, with limited initial submissions for newcomers. Both still accept vulnerability reports.
A separate Google Threat Intelligence Group report found that monthly vuln disclosures climbed from 5,045 in January to 10,740 in August. Observed exploitation also increased, with attackers continuing to target network appliances and internet-facing enterprise services.
CrowdStrike bypasses LLM safety checks by splitting up requests

CrowdStrike tested roughly 515 techniques against a frontier LLM’s safety classifier, which checks requests before they reach the main model. None of the direct attacks got through. The researchers then tried asking for smaller pieces of code separately.
Each request looked like ordinary software work and passed the safety check. The researchers gave the responses to a smaller model without that classifier, which combined them into working offensive code. One example was a program that injects code into another Windows process.
The method worked in nine of 10 tested ATT&CK-aligned categories. Attempts to disable security hooks used to monitor running programs were still blocked. The classifier screened each request separately and never saw the completed attack code. Microsoft’s separate capability-laundering study describes a related pattern.
DIVD details its Zammad breach
The Dutch Institute for Vulnerability Disclosure confirmed that volunteer email addresses were stolen in last month’s breach of Zammad, an open-source helpdesk that organizes support requests and conversations into tickets.
The attacker combined one flaw that allowed remote code execution with another that granted higher privileges. DIVD believes an autonomous AI agent carried out the attack, based on the scripts and behavior it observed. It has not identified the operator or model.
Zammad’s advisory says the remote flaw is exploitable on unsupported 6.5-and-earlier releases, while 7.0+ is not affected in practice. Version 7.2 adds hardening. A fix for the separate privilege-escalation issue is still in progress.
🔬 Threats & Research
NetScaler needs another patch
Attackers are exploiting CVE-2026-88779 in customer-managed NetScaler ADC and Gateway systems configured as a SAML service provider or identity provider. The memory-overflow flaw can crash the service. Remote code execution has not been confirmed.
Last week’s patches don’t cover it. The new bulletin lists the updated builds.
FortiMail’s encryption interface is under attack
Fortinet says attackers are exploiting CVE-2026-104286, a CVSS 9.8 flaw in FortiMail’s Identity Based Encryption interface. It lets an attacker write files to the system without signing in, potentially leading to code execution.
The current advisory provides affected-build information and the latest patch and mitigation status.
Cisco patches another SD-WAN authentication bypass
Cisco confirms exploitation of CVE-2026-76504, which lets unauthenticated attackers reach administrative SD-WAN Manager APIs through crafted requests.
Fixed releases are available. The temporary Live Protect mitigation covers some attack paths and does not replace the update.
GitLab patches an AI Gateway sandbox escape
GitLab fixed CVE-2026-90970 in its AI Gateway. A signed-in user with Duo Agent Platform access could use a custom-flow prompt template to break out of its sandbox and execute code on a self-hosted gateway.
Versions 19.2.4, 19.3.2, and 19.4.1 contain the fix; GitLab-hosted gateways were already patched.
Attackers test stolen AWS keys for access to AI models
Datadog analyzed scripts that check whether exposed AWS keys can access models through Amazon Bedrock, AWS’s managed AI service. They list available models across regions and send small test requests to check whether the credentials work. One sends “ping” and limits the response to four tokens.
Researchers saw similar malicious activity at 12 organizations over 30 days, but could not link those incidents to the specific scripts they analyzed. The report lists the API calls involved and links to detection rules.
📦 Security Products & AI
Wiz launches AI code scanning with cloud context

Wiz AI SAST is in public preview for Wiz Code customers. The scanner uses AI to find business-logic flaws, including missing ownership checks that let one user read another’s data. The Wiz Security Graph links findings to the affected cloud resources and their permissions.
Wiz also rechecks earlier findings and merges reports about the same underlying bug, even when the AI describes it differently on the next scan. Teams can track one issue through to a fix instead of reviewing it as a new finding each time.
AWS reports an 89% score on a benchmark for finding and fixing bugs

AWS says Continuum for code vulnerabilities completed 819 of 920 CyberGym-E2E tasks (89%) within 90 minutes each. To pass, it had to find a bug, demonstrate it, and produce a patch that kept the project’s tests passing.
The benchmark tests memory-safety flaws in C/C++ projects. Each task has a known target vulnerability, but the 89% score also counts successful fixes to other valid bugs the agent finds. Continuum fixed the designated target in 37.8% of tasks. The product remains in gated preview.
Apple plans tighter Full Disk Access controls
Apple announced additional macOS controls that will require more explicit user action before granting Full Disk Access.
The announcement gives no release date, macOS version, or implementation details.
Google and Mistral expand access for cyber defenders
Google began rolling out Gemini 4 Argon to trusted defenders through Fairwind, promising access without cyber guardrails for those partners and its internal teams. Broader availability is still ahead.
Mistral’s Large 4 is now in public API preview, with separate reduced-moderation testing for vetted cyber partners. Open weights are planned for later this month.
Legit adds automated fixes for vulnerable dependencies
Legit Security expanded its remediation agent to vulnerable dependencies.
The agent updates dependency versions and lockfiles, then rescans to check that the vulnerability is fixed before opening a pull request. For upgrades that may break the application, it also proposes code changes. Those code changes are assessed by AI; the dependency rescan does not verify that the application still works.
🤝 Funding & M&A
Armadin raises $255.5M
Armadin announced a $255.5M Series B, co-led by Andreessen Horowitz and Accel, for its autonomous security platform.
The company puts its valuation above $2.5B. Its AI agents continuously test systems for weaknesses and attempt to exploit them.
Hadrian adds $40M for offensive security
Hadrian raised $40M in a round co-led by Forgepoint Capital International and SmartFin.
The company finds internet-facing assets and tests whether their weaknesses can be exploited. The funding will support platform development and international expansion.
doxx.net raises $38M and opens its private networking beta
doxx.net launched its open beta alongside a $38M Series A led by a16z.
It lets people and AI agents connect devices in private networks, make encrypted calls, and transfer files directly between peers. Agents can set up connections and firewall rules through its API and MCP support. DNS filtering helps block connections to malicious sites.
Founder Barrett Lyon previously built Prolexic, an early DDoS-protection company acquired by Akamai. He also founded BitGravity, acquired by Tata Communications, and Defense.net, acquired by F5. His launch post recalls working with the FBI in 2003 as an online casino faced DDoS extortion demands. He’s spent more than two decades building and defending networks.
Collibra acquires trail ML
Collibra announced its acquisition of trail ML. The software helps companies turn AI policies into checks, collect evidence, and assess whether their AI systems meet those requirements.
Collibra says trail ML also helps enforce rules on AI agents. Financial terms were not disclosed.
Osavul raises €8.5M for hybrid-threat intelligence
Osavul raised an €8.5M Series A led by 33N Ventures.
Its intelligence platform covers information operations, cyber threats, and physical threats. The funding supports expansion into enterprises and critical infrastructure.
Other funding: Netsec raised more than $10M for combined IT and security operations, while Fleuret AI raised €4M in pre-seed funding for agentic pentesting.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.


