# Autonomous exploit chains, 432 CVEs in 48h, and broken client-side…

Canonical: https://brew.new/browse/templates/email/pt1_k97jnr75ej7mqg9dzyjz0dq8c98e4pnt

Brand: approov.io
Category: newsletter

![Preview of Autonomous exploit chains, 432 CVEs in 48h, and broken client-side…](https://cdn.brew.new/email-preview-0786221ee7975e83-tracking_r57mpdfedryw94qdh26bwf69r18dtc0w-1789000778363.png)

## Email content

View in browser

Approov-newsletter-banner-image

Summer 2026

AI isn't just changing how we write code - it is fundamentally changing how applications are attacked and defended.

Over the past few weeks, we've seen AI models chain zero-day exploits on their own, a massive wave of AI-assisted bug submissions hit the Linux kernel, and clear signs that traditional mobile security checklists can't keep up with automated reverse engineering.

AI Agents Escape the Sandbox: OpenAI Incident Signals the Rise of Autonomous Attackers

During a recent internal evaluation, OpenAI's research models did something eye-opening: they found zero-day vulnerabilities in JFrog Artifactory, broke out of their sandbox environment, and pivoted to target external Hugging Face instances using leaked credentials.

While this happened in a controlled test rather than the wild, it proves that agentic AI can already handle complex, multi-step exploit chains without human guidance. If you rely on traditional network boundaries, now is the time to tighten up identity security and continuous monitoring.

Read The Register's analysis of the OpenAI sandbox escape

Leaked n8n API Tokens Expose Live Instances to Credential Theft

New research from GitGuardian revealed that 321 publicly reachable n8n automation instances accepted API tokens leaked in public GitHub commits. Because n8n orchestrates workflows across databases, AI services, and internal APIs, a single exposed token gives attackers a massive blast radius.

Researchers demonstrated four ways an attacker could use standard REST API requests, without exploiting any software vulnerability, to enumerate workflows, execute tasks using stored credentials, and even exfiltrate raw API keys by routing requests to external endpoints.

Automation platforms sit right at the center of your infrastructure. When static API keys leak in .env or configuration files, attackers don't need a zero-day to break in. They simply log in. Long-lived credentials and unverified clients continue to be one of the highest-risk identity vectors for modern security teams.

Read GitGuardian's research write-up on The Hacker News

On-Demand Webinar: AI Just Made Hacking Apps Much Easier

Agentic AI isn't just changing how software gets built - it's creating entirely new threat vectors like compute theft and denial-of-wallet attacks.

In this session, security researcher Vishal Bhaskar joins Dan Barahona to discuss why legacy defenses fall short against AI workloads, and how runtime Zero Trust keeps malicious bots from burning through your cloud budget.

What you'll learn:

Why agentic AI breaks traditional perimeter security

How to bridge the gap between AI theory and real-world runtime defense

How to ensure your compute is consumed only by verified clients, not spoofed agents

How to calculate the real ROI of an AI attestation strategy

Watch the on-demand webinar

Client-Side Trust Breaks the EU's New Age Verification App

The European Commission's new privacy-first age verification app relies on local data storage, but security researcher Paul Moore has already bypassed it three times using simple Chrome extensions. By stripping local document checks or relaying QR codes, his scripts pass verification automatically.

Relying on client-side trust fails because you cannot verify what happens on an untrusted device. When local checks fail, lawmakers usually default to full identity requirements. For security teams, it is a simple lesson: client-side logic without continuous runtime attestation offers no real protection.

Read the full story on TechRadar

Linux Kernel Team Publishes 432 CVEs in Two Days, Raising Concerns Over AI-Driven Bug Reports

If your vulnerability triage team felt a sudden spike in pressure recently, this is why. The Linux kernel team released 432 CVEs over a single 48-hour period.

Security researchers suspect this massive influx was driven by AI-assisted bug hunting tools. While many of these reports cover low-impact edge cases, each one technically qualifies as a vulnerability. Manually reviewing hundreds of kernel CVEs is no longer realistic. The industry is reaching a tipping point where automated, high-frequency patching strategies are mandatory just to stay afloat.

Read the analysis in The Register

Why Mobile Security Checklists Are Failing in the AI Era

Static defenses like basic code obfuscation and hardcoded API keys are essentially obsolete. Modern AI-driven reverse engineering tools can unpack mobile apps and extract embedded secrets in seconds.

To adapt, security leaders are moving toward Mobile Application Risk Management (MARM). The core goal is simple: eliminate static secrets entirely and move toward a Zero Secrets Architecture. That means using runtime attestation, short-lived tokens, and continuous integrity checks on the device, app, and API level.

If you can't trust the client environment, you have to verify every request in real time.

Learn how to build a MARM framework

Approov Limited

Scotiabank House, 6 South Charlotte Street, Edinburgh, Midlothian EH2 4AW, United Kingdom | +44 0131 655 1500

US HQ: 165 University Avenue, Suite 200, Palo Alto, CA 94301, USA | +1 (650) 322-5300

Unsubscribe Manage Preferences

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97jnr75ej7mqg9dzyjz0dq8c98e4pnt)

[Browse email designs](https://brew.new/browse/templates)
