Week in review: Cisco 0-day exploited, Patch Tuesday outlook

▼ Summary
– OWASP released Agent Memory Guard, an open-source runtime defense against memory poisoning in AI agents, as a reference implementation for the OWASP Top 10 for Agentic Applications.
– A new independent assessment found that nearly all of 100 production AI agents carry conditions allowing a single hostile document to take them over, highlighting major security gaps.
– Researchers built a proof-of-concept AI-driven worm that autonomously reasons about how to attack each target it encounters, using a small LLM running on compromised machines.
– Critical vulnerabilities were actively exploited, including a Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) and a Windows Netlogon RCE flaw (CVE-2026-41089).
– A brute-force attack on password manager Dashlane let attackers access some user accounts and copy encrypted vaults, triggering account lockouts.
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
A new open-source project from OWASP, Agent Memory Guard, acts as a runtime defense layer between AI agents and their memory stores. It screens every read and write through a pipeline of detectors and a YAML policy, serving as the reference implementation for ASI06, Memory Poisoning, a key entry in the OWASP Top 10 for Agentic Applications.
Enterprises are often blindsided by data discovery gaps, according to Avani Desai, CEO at Schellman. In an interview, she highlighted how abandoned cloud storage hides shadow data, post-merger duplicated datasets slow integration, and why synthetic data is overmarketed while confidential computing remains undervalued.
Applying zero trust principles to physical security systems like cameras and door controllers requires making trust decisions at the edge. Chuck Davis, VP of Global Information Security at Hikvision, explained how to avoid recreating old perimeter assumptions, why these devices are IT assets, and what the Mirai botnet taught the industry.
A small team of around a dozen analysts in Slovenia handles 6,000 cyber incidents a year at SI-CERT, the national cyber response center. Gorazd Božič, who manages the team at ARNES, noted that incident volume has surged from roughly 300 a decade and a half ago, covering everything from online fraud to ransomware.
An independent assessment of 100 production AI agents found that only 11% pass the security bar. Nearly all carry conditions that could allow a single hostile document to take them over, even as they write code, drive browsers, and manage cloud infrastructure.
Spotless compliance evidence can still hide a broken control, warned Marc Rubbinaccio of Secureframe. He explained how organizations check 110 requirements but miss the 320 assessment objectives beneath them, and how continuous monitoring is changing compliance work for CMMC and FedRAMP 20x.
Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant OAuth access that persists even after publishers vanish. These grants often reach into business systems beyond the listed function, exposing company email, files, calendars, and code repositories.
Keyless car theft can happen in under a minute using just two people, cheap radio amplifiers, and a fob inside a house. Germany’s ADAC runs ongoing tests against relay attacks, which affect models across the global market.
AgentGG is an open-source agentic SAST scanner that uses AI agents to read code, follow imports, walk the call graph, and confirm findings before reporting them, cutting down on manual triage.
Hackers are exploiting a Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) in limited attempts. The company has observed no successful lateral movement from the targeted devices.
A US federal watchdog has outlined how NIST fumbled management of the National Vulnerability Database (NVD), failing to effectively manage the growing backlog of unprocessed vulnerabilities.
A critical Windows Netlogon RCE flaw (CVE-2026-41089) is now actively exploited, the Centre for Cybersecurity Belgium (CCB) warned. The stack-based buffer overflow allows remote code execution in Windows domain environments.
Google has fixed an actively exploited Android vulnerability (CVE-2025-48595) in the June 2026 security updates, addressing a high-severity flaw in the Android Framework.
Researchers have built a proof-of-concept autonomous AI-driven worm that reasons its way through corporate networks. It analyzes each target, creates a strategy on the fly, and uses a small free LLM running on compromised machines.
A Cisco SD-WAN 0-day (CVE-2026-20245) privilege escalation vulnerability is being exploited with no patch available from Cisco.
The June 2026 Patch Tuesday forecast was only partly right. After the Anthropic Mythos announcements, Microsoft’s updates were standard fare, with 65 CVEs in Windows 11 and 58 in Windows 10.
Businesses can learn a lot about risk management from this year’s mega events, like the Winter Olympics and the FIFA World Cup. The scale of these events highlights the challenge of managing risk successfully.
Cutting vulnerabilities in a live manufacturing environment is rarely simple. A critical CVSS 10 on an industrial asset can’t be patched like a normal IT environment, requiring careful planning.
You need both BAS and autonomous pentesting together, as a new tool may find critical issues initially but then report the same stale issues on subsequent runs, creating noise.
Governing shadow AI without killing innovation is a key challenge, as Alan Snyder of NowSecure explained. Companies must adopt AI fast to stay competitive, but they also need to do it safely.
CISOs should focus on post-quantum migration in the next 24 months, as a Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organizations about two and a half years to prepare.
AI agent governance gets harder when agents outnumber your people, warned Amit Gautam of Abluva, explaining the security risks autonomous AI agents bring to enterprise environments.
EU organizations are buckling under rising compliance pressure from frameworks like NIS2 and DORA, while AI raises new questions for security teams, according to Antonija Vojnović of Span.
DNS-AID lets AI agents find and verify each other through the Domain Name System, using it as a global, vendor-neutral directory for publishing and discovering one another.
A brute-force attack triggered Dashlane account lockouts, with the company confirming the incident after users reported account suspension emails and login problems.
Meta is trying to get ahead of scammers before the FIFA World Cup, as the FBI warned of spoofed websites selling fake tickets and fraudulent hospitality packages.
Spanish police arrested a man in Granada for allegedly leaking sensitive government personnel data belonging to members of state institutions.
A breach of the GTA V cheat service Atlas Menu exposed 64,000 accounts, including email addresses, usernames, IP addresses, and hashed passwords.
Anthropic is expanding Project Glasswing to 150 organizations in more than 15 countries, its cybersecurity initiative built around the Claude Mythos Preview model.
A malware campaign targeting Minecraft users has infected over 116,000 systems through a Malware-as-a-Service operation named WeedHack.
Microsoft has responded to security challenges facing code, AI agents, and models with a series of new tools, including a multi-agent vulnerability discovery system and new controls for managing AI agents.
AI is helping low-skill hackers pull off advanced cyberattacks, according to an Anthropic analysis of 832 accounts banned for malicious cyber activity between March 2025 and March 2026.
Attackers obtained encrypted password vaults from some Dashlane user accounts, the company disclosed, though it found no evidence of internal system compromise.
145 AI laws were passed in 2025 by state legislatures, with more than 1,000 additional bills introduced, according to DataGrail’s Privacy and AI Trends Report 2026.
NVIDIA has gone open source with a big batch of physical AI agent tools, designed to break the messy work behind robots and self-driving cars into tasks that AI agents can run themselves.
Microsoft Defender Vulnerability Management’s updated exposure score adds vulnerability risk signals and asset context to help teams understand where risk is concentrated.
A new AI model backdoor attack called BadBone stays hidden until you customize the model, planting a backdoor inside a backbone model that inherits the flaw in downstream tasks.
OpenAI has brought frontier AI to existing AWS environments, making frontier models and Codex available on Amazon Bedrock with AWS-native security and governance controls.
KDE Linux has cut kernel modules and unused packages after a security audit of its components, following the discovery of multiple security issues in the upstream Linux kernel.
Codex knowledge work is expanding into research, reports, and spreadsheets, as office workers lose hours to email triage and searching for files. McKinsey research puts the average knowledge worker at 28 percent of the week on email.
Meta has added stricter guardrails for teen feeds globally on Instagram, Facebook, and Messenger, with new content settings and a Limited Content feature for parents.
Known vulnerabilities are behind most application security incidents, with eight in ten organizations taking a hit tied to a flaw their team had already cataloged, according to a Cloud Security Alliance survey.
Agent Threat Rules (ATR) is an open detection format for AI agent security threats, targeting prompt injection, tool poisoning, and credential theft.
Microsoft Scout agent opens a new category of always-on Autopilots, designed to keep operating in the background inside Office applications once a person stops paying attention.
A new Android feature promises to spot deepfake scam calls with fake call detection, flagging suspected spoofed calls when both parties use Phone by Google on Android 12 or later.
ETSI has set security requirements for AI data centers and cloud platforms with TS 104 033, establishing a framework for protecting AI models, datasets, and training processes.
Trend Micro Mobile Security detects scams in messages, QR codes, and websites, protecting iOS and Android devices from harmful websites, ads, and unsafe Wi-Fi networks.
Most pros have seen AI hallucinations in IT operations, as autonomous AI takes action inside enterprise environments, with frequent reports of AI output errors carrying operational impact.
Let’s Encrypt is working toward post-quantum certificates at web scale through Merkle Tree Certificates (MTCs), targeting a staging environment in late 2026 and production readiness in 2027.
Photos from Infosecurity Europe 2026 show the cybersecurity event that took place from June 2 to 4 in London.
Attackers already know the secrets are on your developers’ machines, with a GitGuardian analysis finding an average of 150 secrets per endpoint, including private keys and cloud credentials.
CIS SecureSuite Platform simplifies security management with tools and resources for implementing CIS Benchmarks, making it easier to harden systems.
Cybersecurity jobs available right now include a selection of roles spanning various skill levels, as of June 2, 2026.
New infosec products of the week feature releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma.
(Source: Help Net Security)

