
The door into SonicWall.
SonicWall issues emergency patches. European wind and solar sites are exposed online. South Korea warns of AI-powered attacks on banks. Maria Varmazis unpacks the EU’s new Space Threat Response Architecture. Google patches dozens of high-severity Chrome flaws. Researchers uncover an SSRF vulnerability in Harbor. AI reshapes vulnerability management. Wikimedia says OpenAI agents repeatedly broke its rules. Pwn2Own kicks off in Ireland. Our guest is Derek Holt, CEO of Digital.ai, who says AI has killed the cybersecurity response window. VIN there, done that.
Today is Wednesday October 7th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
SonicWall issues emergency patches.
SonicWall has released hotfixes for a maximum-severity server-side request forgery vulnerability affecting SMA1000 secure access appliances. CVE-2026-102255 affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models. An unauthenticated remote attacker could exploit the flaw to make requests through the appliance, potentially reaching internal functions and performing unauthorized operations. SonicWall says there’s currently no evidence the vulnerability is being exploited, but it’s urging customers to install the fixes. Shadowserver is tracking more than 400 Internet-exposed SMA1000 appliances. The warning follows a string of attacks against the product line: threat actors exploited several SMA1000 zero-days earlier this year, including flaws used to deploy malware and vulnerabilities CISA linked to ransomware gangs.
Dutch researchers flag vulnerable wind and solar sites.
Dutch researchers have identified more than 8,500 internet-facing administrative systems tied to wind and solar sites across 35 European countries, warning that some could potentially give attackers operational control. Most were login or administrative pages, but researchers believe roughly 181 sites may have allowed full control. One exposed turbine interface displayed live data alongside “Start, Stop and Reset” controls, and some systems managed multiple turbines or entire farms. Spain had the most exposed solar systems, while Germany led in exposed wind systems. Researchers urged operators to remove administrative interfaces from the public internet. The findings come amid heightened concern over attacks on European critical infrastructure, including a December 2025 cyberattack affecting 30 wind and solar sites in Poland.
South Korea’s President calls for vigilance against AI powered attacks on banks.
South Korean President Lee Jae Myung says there are signs AI models were used in recent cyberattacks against the country’s banks, prompting him to call for cybersecurity defenses designed for the AI era. South Korean police have launched a broad investigation after several commercial banks, including Shinhan and KB Kookmin, reported attacks involving breaches of customer information. Authorities haven’t disclosed what AI tools may have been used or the full extent of the breaches. Financial regulators have shared information on 28 unique IP addresses associated with recent hacking attempts and urged the sector to maintain heightened vigilance. Lee called for officials to quickly establish what happened, limit the damage, and concentrate personnel and resources on responding to the attacks.
Space-Cyber Story
The European Union has strengthened its ability to respond to threats against space systems by adopting the enhanced Space Threat Response Architecture, or STRA. The framework, first created in 2023, is an information-sharing initiative to inform collective response to space-related incidents, and it helps the EU to monitor, assess, and respond to threats that could affect European security, critical services, and the operation of EU space programs.
Crucially the updates to the EU's Space Threat Response architecture expands the scope of the threat environment, as the previous iteration had too narrowly defined threats to the space domain to remain effective.
According to an official EU fact sheet about this update, the nature of threats against space assets now not only include "anti-satellite strikes and interference with satellite signals," but they also include "cyber-attacks against space infrastructure and other forms of hostile or irresponsible behaviour."
The updated framework also establishes operational procedures for monitoring threats, issuing alerts, and quickly coordinating responses through the EU's Common Foreign and Security Policy tools. Under the new guidance, the EU's High Representative can now authorize a provisional urgent response to an ongoing threat when immediate action is needed.
Google patches over fifty high severity Chrome bugs.
Google has released Chrome 155 with fixes for 247 vulnerabilities, including four critical use-after-free flaws affecting several browser components. The update also patches 53 high-severity bugs and 190 medium- and low-severity issues. External researchers reported 62 of the vulnerabilities, with researcher Xinyang Ge finding several using AI-assisted techniques. Google has paid about $33,000 in disclosed bug bounties so far. The company says there’s no indication any of the patched vulnerabilities are being exploited in the wild.
Researchers disclose a server-side request forgery vulnerability in a popular open-source container registry.
OX Research has disclosed a server-side request forgery vulnerability in Harbor, the open-source container registry, that could allow registered users to steal a server’s cloud credentials. The flaw stems from insufficient validation of webhook destinations, allowing a project administrator to point Harbor at internal addresses, including cloud metadata services. Because users automatically become administrators of projects they create, deployments allowing self-registration face additional risk. Researchers found more than 6,000 internet-accessible Harbor instances running vulnerable versions, including 718 cloud-hosted systems where metadata services were directly reachable. The vulnerability could let attackers obtain Harbor’s IAM credentials and potentially access cloud storage, Kubernetes resources, or other internal services beyond their project permissions. Harbor accepted the report in September and has released fixes.
AI forces security teams to rethink traditional vulnerability management.
AI is forcing security teams to rethink traditional vulnerability management as attackers use the technology to discover and exploit weaknesses faster and at greater scale. An article in CSO Online says security leaders argue that annual penetration tests are no longer enough. Instead, organizations increasingly need continuous monitoring, automated pen testing, red teaming, and attack-path validation to determine which vulnerabilities can actually lead to meaningful compromise. AI-powered offensive tools can help prioritize fixes and identify dangerous chains of otherwise minor flaws. But experts caution against removing humans from the equation. Skilled practitioners remain essential for deeper testing, validating automated findings, and understanding how attacks work. There’s also concern that automating entry-level work could weaken the pipeline for future experts. For organizations without established red teams, experts recommend relying on qualified outside partners while focusing internal resources on accelerating remediation.
The Wikimedia Foundation says OpenAI agents repeatedly violated its rules.
The Wikimedia Foundation says OpenAI agents repeatedly violated its rules, attempting unauthorized Wikipedia edits, trying to misuse a citation tool to fetch remote data, and unsuccessfully targeting its Etherpad note-taking service. Wikimedia also attributed millions of automated requests, page crawls, and data queries to OpenAI-operated agents, activity it says may have contributed to a partial service outage in May. The investigation found no evidence the agents stole Wikimedia data or used its services to coordinate with one another. Still, the foundation warned that AI agents are creating significant security and operational burdens, including increased bandwidth consumption and cleanup work. Wikimedia called on AI companies to better monitor their agents and make them easily identifiable so website operators can control how they interact with their services.
Pwn2Own kicks off in Ireland.
Ethical hackers uncovered 32 zero-day vulnerabilities on the first day of Pwn2Own Ireland 2026, earning more than $368,000 in prize money. Researchers targeted smartphones, smart-home devices, printers, and AI products, including OpenAI Codex and LiteLLM. Successful exploits included seven zero-days chained against a Philips Hue Bridge Pro, five used to compromise Oracle’s Autonomous AI Database, and an argument-injection flaw targeting Codex. Pwn2Own’s Zero Day Initiative responsibly discloses the findings to vendors, which receive 90 days to issue fixes before details are published. The competition comes as vulnerability discoveries accelerate, partly driven by AI-assisted research. Google data cited in the report shows monthly vulnerability disclosures more than doubled between January and August, while exploitation of disclosed flaws has also increased.
VIN there, done that.
Your new car may be talking behind your back. Northeastern University researchers tested 21 connected cars and found 19 contacted outside companies over WiFi, while 11 reached advertising, tracking, or analytics domains. Google-owned domains appeared in traffic from 13 cars. The researchers couldn’t inspect most cellular traffic, so they say those numbers are likely an undercount.
The companion apps were chattier still. Seven sent vehicle identification numbers to tracking or analytics companies, sometimes alongside email addresses, phone numbers, or precise location. Four were General Motors apps, notable given GM’s recent settlements over its handling of driver data.
Researchers say a VIN is particularly useful for tracking because, unlike an advertising ID, it can’t be reset. So while your car may promise freedom on the open road, apparently some of its software would prefer you remain very specifically identifiable.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
