Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

All News

TENESYS AI NEWS tracks the most important AI news and explains what changed, why it matters and whether a technology is worth testing.

“RCE” — 11 articles ✕

Cyber Security· Important· 🧪 Worth Testing

GitHub's open-source AI agent found 24 Android app vulnerabilities

GitHub Security Lab built an open-source 'Taskflow Agent' that uses custom AI prompt workflows to audit code for vulnerabilities, and used it to find and report over 24 vulnerabilities in Android applications. Two detailed examples show the agent finding a location-tracking flaw in the OsmAnd navigation app and an account-takeover chain in the Wikipedia Android app via a deeplink parsing bug. The team notes LLMs are strong at finding complex logic vulnerabilities and understand API behavior well, but struggle to correctly judge severity and often produce false positives, so findings still require human review. The taskflows are open source and can be run on any GitHub repository via a Copilot-powered codespace script, though running them consumes premium model requests and can take hours.

GitHub Security
Cyber Security· Important

Cisco Talos exposes China-nexus group UAT-11587 using new 'Antino' backdoor against Asian governments

Cisco Talos disclosed a China-nexus threat cluster, tracked as UAT-11587, that has targeted government, defense, diplomatic and policy organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria since September 2025. The group delivers a previously undocumented Rust-compiled Windows backdoor called Antino via spear-phishing with spoofed senders and fake Gmail attachment widgets. Antino communicates covertly through Microsoft 365 (Outlook/OneDrive via Microsoft Graph) instead of a traditional C2 server, and the group heavily relies on Cloudflare infrastructure for delivery and staging. Talos found roughly 350 compromised endpoints across eight countries, with the largest wave hitting around 57 Indian endpoints in a single two-day period.

Cisco Talos

CERT-EU warns of actively exploited critical SharePoint RCE flaws

CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.

CERT-EU

Microsoft tracks active exploitation of unauthenticated Zimbra mail server vulnerability (CVE-2026-73570)

Microsoft Threat Intelligence documented exploitation of CVE-2026-73570, an unauthenticated OS command-injection flaw in the Zimbra Collaboration Suite's SNMP notification path. Attackers triggered it via specially crafted emails against internet-facing servers running the optional zimbra-snmp package with SNMP notifications enabled, requiring no authentication or user interaction. Post-exploitation activity included JSP webshell deployment, privilege escalation to root, persistent access, credential and mailbox theft, lateral movement across Zimbra clusters, and custom remote-access malware. Zimbra fixed the issue in version 10.1.20 (released July 20, 2026); the CVE was publicly disclosed August 13, 2026, and Microsoft observed scanning and exploitation activity during the gap between patch availability and disclosure, as well as after.

Microsoft Security

Critical RCE Vulnerabilities Found in Check Point VPN Gateways

On 9 September 2026, Check Point released emergency hotfixes for two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103), both with CVSS 9.8, affecting Security Gateway, Security Management Server, and Spark Firewall deployments using Remote Access VPN or Site-to-Site VPN. Both flaws allow unauthenticated remote attackers to execute arbitrary code on affected appliances. CERT-EU urges immediate patching, prioritising internet-facing and perimeter devices.

CERT-EU

Critical Citrix NetScaler Vulnerabilities Actively Exploited

Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.

CERT-EU

Ai2 Open-Sources AstaBrief, a Fast 8B Model for Scientific Report Generation

Allen Institute for AI (Ai2) has open-sourced AstaBrief 8B, a model built on Qwen3-8B that turns research questions and retrieved literature excerpts into cited scientific reports. It's now live in Ai2's Asta platform as a 'Fast mode' alongside a Claude-powered 'Thinking mode', generating reports in about 51.1 seconds on average compared to 178.5 seconds for the Claude pipeline — roughly 3.5x faster. Ai2 trained the model using supervised fine-tuning on 47K examples (from 90K filtered real research queries) followed by DPO on about 6K preference pairs, and found that filtering training data for citation density was the single most effective lever for improving grounding quality.

Hugging Face

Google's TPU Team Reproduces Ai2's Olmo 3 7B Training Run in MaxText

A Google Cloud TPU engineering team worked with Ai2 to rebuild Olmo 3 7B's pre-training from scratch using MaxText, Google's JAX/XLA training framework, running on TPUs instead of Ai2's original PyTorch/GPU setup. They matched Ai2's published results not just on the training loss curve but on four independent held-out evaluation surfaces across the full ~5.93-trillion-token, 1.41-million-step stage-1 run plus the stage-2 annealing phase. Along the way they ported Olmo 3's unusual architecture (reordered-norm blocks, QK-norm, 3:1 sliding/global attention ratio) into MaxText and caught a data-loader bug that had been quietly inflating apparent performance through memorization rather than genuine learning.

Google Developers

Google DeepMind Introduces SynthID Bio to Watermark AI-Generated Proteins

Google DeepMind unveiled SynthID Bio, a watermarking technology that embeds an imperceptible, verifiable signature into AI-designed proteins and 3D structures without compromising their biological function. The system was tested on protein binders (VEGF-A, SARS-CoV-2 spike RBD, PD-L1) using AlphaProteo and a modified ProteinMPNN, and also fine-tuned into AlphaFold 3's diffusion network for watermarking predicted 3D structures. DeepMind is also collaborating with Stanford's Hie lab and Arc Institute to apply the approach to Evo 2, a genomic model, to watermark designed bacteriophage genomes. The goal is to strengthen biosecurity by helping DNA synthesis screening providers and public databases verify the provenance of AI-generated biological designs.

Google DeepMind
Agents· Important· 🧪 Worth Testing

Google Cloud Launches Remote MCP Server for gcloud and BigQuery CLI Access

Google Cloud introduced, in public preview, a remote MCP server that exposes the gcloud and bq command-line tools to AI agents via two tools: run_gcloud_command and run_bq_command. The server runs in an isolated, network-restricted sandbox on Google Cloud infrastructure, removing the need for agents to install or maintain local CLI binaries. It uses Agent Identity, OAuth 2.0, and IAM for authentication, integrates with Model Armor to screen for prompt injection, and supports Cloud Audit Logging for full visibility into tool calls.

Google Cloud AI
Agents· Important· 🧪 Worth Testing

Google's Antigravity SDK Adds Local Offline Model Support with Gemma 4 26B

Google announced that its Antigravity SDK now supports running agentic workflows locally and offline, with initial support for Gemma 4 26B A4B running via Google AI Edge's LiteRT. Developers can build agents that run entirely on-device, without cloud API costs or internet dependency. Google also demonstrated a hybrid 'Architect-Builder' pattern where a cloud model (Gemini 3.8 Flash) plans tasks and a local swarm of Gemma 4 26B instances does the heavy execution, keeping source code off the cloud.

Google Developers