Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

Cyber Security

Vulnerabilities, threats and incidents, security advisories from CERT-EU, ENISA, CISA and NCSC, AI security and regulation (NIS2, CRA).

“RCE” — 3 articles ✕

Cyber Security· Important· 🧪 Worth Testing

GitHub's open-source AI agent found 24 Android app vulnerabilities

GitHub Security Lab built an open-source 'Taskflow Agent' that uses custom AI prompt workflows to audit code for vulnerabilities, and used it to find and report over 24 vulnerabilities in Android applications. Two detailed examples show the agent finding a location-tracking flaw in the OsmAnd navigation app and an account-takeover chain in the Wikipedia Android app via a deeplink parsing bug. The team notes LLMs are strong at finding complex logic vulnerabilities and understand API behavior well, but struggle to correctly judge severity and often produce false positives, so findings still require human review. The taskflows are open source and can be run on any GitHub repository via a Copilot-powered codespace script, though running them consumes premium model requests and can take hours.

GitHub Security
Cyber Security· Important

Cisco Talos exposes China-nexus group UAT-11587 using new 'Antino' backdoor against Asian governments

Cisco Talos disclosed a China-nexus threat cluster, tracked as UAT-11587, that has targeted government, defense, diplomatic and policy organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria since September 2025. The group delivers a previously undocumented Rust-compiled Windows backdoor called Antino via spear-phishing with spoofed senders and fake Gmail attachment widgets. Antino communicates covertly through Microsoft 365 (Outlook/OneDrive via Microsoft Graph) instead of a traditional C2 server, and the group heavily relies on Cloudflare infrastructure for delivery and staging. Talos found roughly 350 compromised endpoints across eight countries, with the largest wave hitting around 57 Indian endpoints in a single two-day period.

Cisco Talos

CERT-EU warns of actively exploited critical SharePoint RCE flaws

CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.

CERT-EU