CYBER
THE WANG REPORT · Friday, September 4, 2026 · HONG KONG
Cyber Intel | INDEX 62 ELEVATED | KEV 7D 7 | CRIT/HIGH 86% | APAC-FSI 23% | EPSS HEAT 47 | NVD + CISA KEV · 250 CVEs


From the desk · Daily take
KT
AI Agents Ran A Ten-Hour Breach Across Cloud, Identity, CI/CD

The incident researchers disclosed on September 2 ran a multi-agent frontier AI system against a single enterprise target and moved from initial access to full compromise of cloud infrastructure, identity systems, and the CI/CD pipeline in under ten hours, chaining more than 50 MITRE ATT&CK techniques along the way. Dark Reading's writeup calls the comparison point a "two-week attack," the kind of timeline a human red team or intrusion crew needs to do equivalent reconnaissance, lateral movement, and privilege escalation by hand. The AI system produced an 80-page audit trail of its own actions. That log is the artifact worth reading before the vendor summary: it names which of the 50-plus techniques chained into privilege escalation on identity infrastructure, and identity is the layer that turns a single compromised account into control of everything downstream.

No named CISA advisory or CVE accompanies this one yet, which is itself the finding. A technique count and a ten-hour clock are not the same as a patchable flaw, and a security team briefing its board on September 4 cannot point to a single control that would have stopped this the way MFA stops a credential-stuffing run. The closest available lever is detection speed: an environment tuned to flag CI/CD pipeline changes and identity privilege escalations within minutes, not the hours a ten-hour compressed attack still needs to complete each stage, is the only control category that scales to machine-speed intrusion. Boards asking "are we exposed to this" this week should be asking their SOC how fast that specific alert fires, not whether they have a patch to apply.

Permalink → All takes →
FROM THE CYBER DESK · WEEKLY COLUMN
KT
ATF Let A Ransomware Crew Set The Clock
ATF confirmed a cyber incident only after Qilin's ransomware crew posted the claim publicly, ceding its own disclosure timeline to the group that broke in.
The Watch-ListFull wire →
FBI, DOJ Seize China Linked Hacking Platform Used On Critical Infrastructurebing newsSep 4 CrowdStrike Zero Day Grants Full SYSTEM Control On WindowsBleepingComputerSep 4 Cyber Attack Cripples Cardiac Device Giant Boston Scientificbing newsSep 3 Google Warns Chrome Zero Day Under Active AttackBleepingComputerSep 4 Hackers Ran Live Feed Into Every ID Verification Scan For A YearHackerNewsSep 4 OpenAI Puts $1 Billion Into Cyber Defense After Zero Day Finding AIbing newsSep 4 Critical Cisco Nexus Flaw Lets Attackers Run Code As RootThe Hacker NewsSep 3 GPT 6 Astra Scores 100% On Exploit Benchmark, OpenAI Blocks PoC RequestsThe Hacker NewsSep 4 AI At Machine Speed Cuts Two Week Attack Down To 10 HoursDark ReadingSep 3 Brazilian Hacking Group Breeze Comet Tears Into Financial SystemsDark ReadingSep 3 OpenAI Agents Hijacked German Website In Undisclosed AI Breakoutqwant newsSep 4 Fake Merger Scams Target Large Enterprises In Detailed ConsDark ReadingSep 4
CVE SpotlightFull feed →
CRIT 9.8
Gitea Code Injection
CVE-2026-60004 · KEV listed Aug 25 · EPSS 87%
CRIT 10.0
Metabase SQL injection via password reset endpoint
CVE-2026-72898 · KEV listed Aug 11 · EPSS 82%
CRIT 9.3
TrueConf Server Missing Authentication
CVE-2026-72529 · KEV listed Aug 20 · EPSS 2% · OT
Ranked by CISA KEV status, APAC financial-services and OT relevance, CVSS, and EPSS exploit probability. Source: NVD + CISA KEV, updated Sep 4. Updated daily.
Vendor WatchAll 16 vendors →
Okta Okta Lifts Full Year Outlook as AI Agents Drive Demand Sep 4 CrowdStrike CrowdStrike Guides for 24.6% ARR Growth Through FY28 at Fal.Con Sep 4 AI Security Tools HiddenLayer Raises $100M Series B to Scale AI Agent Security Sep 2 Zscaler Zscaler Posts 25% ARR Growth, Cuts 3% of Workforce Amid AI Push Sep 3
On the Record
OPEN
ATF will issue a follow-up disclosure specifying which systems (NFA registry, eTrace, or case files) were affected by the Qilin intrusion.
Kai Tanner · made Aug 30 · In print →
OPEN
Qilin will publish a data sample from the ATF breach on its leak site to substantiate its claim.
Kai Tanner · made Aug 30 · In print →
OPEN
A future Entra ID vulnerability will score a perfect 10.0 CVSS again, following CVE-2026-69836 and September 2025's CVE-2025-55241.
Kai Tanner · made Aug 23 · In print →
OPEN
HKMA's Cyber Resilience Testing Framework pilot will reach selected institutions by late 2026.
Kai Tanner · made Aug 23 · horizon late 2026 · In print →
OPEN
HKMA's AI-Driven Cyber Risks task force will not publish guidance that regulates agentic AI toolkits and their operators directly, as opposed to the vendor-escalation channel, within 2026.
Kai Tanner · made Aug 16 · horizon 2026-12-31 · In print →
OPEN
Hong Kong's HKMA/SFC will not name specific institutions or attach deliverable dates to their AI cyber risk guidance before Singapore's ACT taskforce publishes its guidance
Kai Tanner · made Aug 2 · In print →
OPEN
MAS's Third-Party Risk Management and AI Risk Management guidelines will close consultation and one or both will become binding rules
Kai Tanner · made Aug 2 · In print →
OPEN
Large SFC-licensed internet brokerages will be required to comply with Circular 26EC35's OTP ban 'as soon as practicable,' effectively immediately, while smaller brokers and newer virtual asset platforms get a 12-month window from July 9, 2026.
Kai Tanner · made Jul 13 · horizon 2027-07-09 · In print →
Calls this desk has made in print, against a named horizon. Each is owned, confirmed, or eaten in print when the horizon arrives.
Cyber Scorecard | CVE Feed | Vendor Watch | Column Archive
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.