Policy Pulse - Issue #30 | Week of August 23, 2026 Mandiant published the architecture and early results of its Agentic Vulnerability Discovery Harness on August 18, reporting that the system found more than 100 true-positive critical vulnerabilities in two days during one incident-response engagement. Over ten months, the harness processed tens of millions of lines of code, generated tens of thousands of findings, and produced 12 assigned CVEs, with another dozen findings in active disclosure. The system includes explicit human validation gates, and Mandiant says program operators need comparable receiving systems to handle AI-scale vulnerability intake. Policy Pulse - Issue 30 | Week of August 23, 2026 Mandiant found more than 100 critical flaws in two days with an agentic review harness. NIST opened two new comment windows, and CISA added nine actively exploited vulnerabilities. Policy Pulse - Issue 30 | Week of August 23, 2026 Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. Top Story Mandiant just made AI-scale vulnerability disclosure measurable On August 18, Mandiant published the architecture and early results of its Agentic Vulnerability Discovery Harness. In one incident-response engagement, the system found more than 100 true-positive critical vulnerabilities in two days. Across ten months of use, Mandiant says the harness has processed tens of millions of lines of code, run thousands of analysis pipelines, generated tens of thousands of findings, produced 12 assigned CVEs, and left another dozen findings in active disclosure. Mandiant https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review?ref=blog.disclose.io The useful bit is not just the volume. Mandiant built explicit gates around it: agents create a threat model, discover entry points, trace control and data flow, generate hypotheses, and attack those hypotheses with multiple validators. Human consultants then reproduce exploitation, write proof-of-concept code, discard false positives, deduplicate the survivors, and prepare formal disclosures. That is closer to a disclosure production line than a faster scanner. Why it matters for VDP: AI-scale intake is no longer a hypothetical future problem. A single team has demonstrated more than 100 critical findings in 48 hours while keeping a human validation gate. Program operators now need a comparable receiving system: machine-readable evidence requirements, aggressive duplicate clustering, support for chained findings, clear CNA routing, and enough coordination capacity to keep validated reports from becoming a new backlog. Upcoming Deadlines & Events | Date | Agency | Event/Deadline | Action Required | Link | |---|---|---|---|---| Aug 24, 2026 | US Copyright Office | DMCA Section 1201 renewal and new-exemption petitions due | File a renewal or new/expanded-exemption petition | | Aug 24, 2026 NIST CSRC https://csrc.nist.gov/pubs/sp/800/213/r1/ipd?ref=blog.disclose.io Aug 28, 2026 TAP portal https://tapportals.mk.gov.lv/public participation/aad3f00b-a797-4097-9469-9851f65949b5?ref=blog.disclose.io Sep 8, 2026 NIST CSRC https://csrc.nist.gov/News/2026/security-guidelines-storage-infrastructure-draft?ref=blog.disclose.io Sep 25, 2026 NIST CSRC https://csrc.nist.gov/News/2026/ai-data-center-security-analysis-draft-sp-800-239?ref=blog.disclose.io Oct 5, 2026 NIST CSRC https://csrc.nist.gov/pubs/ir/8613/ipd?ref=blog.disclose.io Oct 15, 2026 NIST CSRC https://csrc.nist.gov/pubs/sp/1353/ipd?ref=blog.disclose.io This Week in Policy AI & Emerging Tech Security - Copilot helped researchers find a one-click Copilot exploit. Varonis published CoSnitch on August 18, a chain built from automatic prompt execution, connector-assisted data exfiltration, and persistent memory poisoning. The researchers found the undocumented autorun behavior by repeatedly questioning Copilot about its own architecture. Microsoft assigned CVE-2026-24301 , shipped server-side patches on August 18, and Varonis found no evidence of exploitation. Varonis https://www.varonis.com/blog/cosnitch?ref=blog.disclose.io Why it matters for VDP: AI-product intake needs a route for behavioral and trust-boundary failures, not just conventional code defects. Reproducing this class means capturing prompts, connector grants, model state, memory changes, and server-side behavior that a normal vulnerability form rarely asks for. Federal Strategy & Regulation - NIST asks how practitioners should use AI to produce CSF 2.0 artifacts. Draft SP 1353, published August 19, provides structured prompts and three use cases: governance review, a current-state profile, and a target-state profile. NIST stresses that the examples are not assessment or assurance methodologies. Comments close October 15. NIST https://csrc.nist.gov/pubs/sp/1353/ipd?ref=blog.disclose.io Why it matters for VDP: Disclosure teams can test whether the guide maps policies, interview notes, triage records, and remediation evidence to CSF outcomes without turning a generated profile into fake assurance. NIST is asking for comments on the guide and prompts now. - NIST maps 23 security and compliance challenges unique to multi-cloud systems. Draft IR 8613, published August 21, says the hardest gaps cluster around identity and access management, telemetry and logging, configuration and change management, data protection, and authorization. Comments close October 5. NIST https://csrc.nist.gov/pubs/ir/8613/ipd?ref=blog.disclose.io Why it matters for VDP: Multi-cloud reports fail at the seams: nobody owns the whole path, logs live in different systems, and a finding that reproduces in one provider can disappear in another. Program operators should test cross-provider evidence retention and escalation, then send that experience to NIST. CVE & Vulnerability Programs - CISA added nine vulnerabilities to the KEV catalog in five days. The August 17-21 additions cover Ray CVE-2025-62593 , MLflow CVE-2026-64849 , SharePoint CVE-2026-55040 , VMware vCenter CVE-2026-59310 , macOS CVE-2026-65400 , Microsoft IKE CVE-2026-33824 , two TrueConf Server flaws CVE-2026-72529 and CVE-2026-72530 , and Zimbra CVE-2026-73570 . CISA KEV catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=blog.disclose.io Why it matters for VDP: Ray and MLflow put AI and data infrastructure in the same exploited-vulnerability queue as collaboration and identity-critical enterprise software. Intake routing, asset ownership, and remediation escalation need to work across all of them, with CISA's risk-based deadlines now ranging from days to weeks rather than one uniform clock. Legal & Researcher Protections - The DMCA security-research exemption reaches its renewal gate tomorrow. The Copyright Office's tenth Section 1201 rulemaking accepts renewal petitions for current exemptions and petitions for new or expanded exemptions until August 24. Comments supporting or opposing renewal petitions are due September 28. US Copyright Office https://www.copyright.gov/1201/2027/?ref=blog.disclose.io , 2024 final rule https://www.govinfo.gov/content/pkg/FR-2024-10-28/pdf/2024-24563.pdf?ref=blog.disclose.io Why it matters for VDP: The good-faith security research exemption is temporary. Renewal preserves the current anti-circumvention protection for the 2027-2030 cycle; any expansion or change in regulatory language requires a new petition now. International Developments - The EU e-Evidence Regulation became applicable on August 18. Regulation EU 2023/1543 lets judicial authorities issue European Production and Preservation Orders directly across borders to covered service providers, backed by designated establishments or legal representatives. EUR-Lex https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1543&ref=blog.disclose.io , European Commission https://commission.europa.eu/law/cross-border-cases/judicial-cooperation/types-judicial-cooperation/e-evidence-cross-border-access-electronic-evidence en?ref=blog.disclose.io Why it matters for VDP: A cross-border vulnerability or incident report can become evidence in a criminal matter. VDP and CSIRT teams should preserve provenance and chain of custody when escalation starts, and keep voluntary researcher communications distinct from compulsory legal orders. The regulation standardizes evidence access; it does not create researcher safe harbor. Worth Reading Mandiant's full architecture, including the validation and human-review gates behind this issue's top story. Staying Ahead of Adversarial AI Through Agentic Source Code Review https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review?ref=blog.disclose.io :A concrete draft practitioners can test against real governance and disclosure artifacts before the October 15 deadline. NIST SP 1353: Using AI for CSF Analysis and Reporting https://csrc.nist.gov/pubs/sp/1353/ipd?ref=blog.disclose.io :The Commission's plain-language guide to the production and preservation order system now in effect. EU e-Evidence: Cross-border access to electronic evidence https://commission.europa.eu/law/cross-border-cases/judicial-cooperation/types-judicial-cooperation/e-evidence-cross-border-access-electronic-evidence en?ref=blog.disclose.io : Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work. Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here