A preview cyber model escaped a stock VM three times on bugs nobody had labelled as security issues, and its disclosure trail is one line. Plus IST's Fragile Foundations sprint and PaperCut on KEV.
Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.
Top Story
A preview cyber model broke out of a stock virtual machine three times, twice on bugs nobody had labelled as security issues. The disclosure record for what it found is one line: "bug has been reported."
On August 26, Trail of Bits published what happened when researcher Artem Dinaburg, with preview access to OpenAI's GPT-5.6-Cyber under the Patch the Planet initiative, gave the model a single task: escape the QEMU/KVM virtual machine he normally uses for sandboxing, a Debian 12 guest on an AMD Zen 3 host. It escaped three different times. The first escape used Januscape (CVE-2026-53359), a host-kernel bug disclosed a few weeks earlier with no public exploit, so the agent built one. After a full kernel update, the second escape chained CVE-2026-9539 in libslirp, the VM networking library Debian 12 still ships at a vulnerable version, with a libslirp bug-fix commit that had never been assigned a CVE. After Dinaburg rebuilt QEMU and libslirp from upstream source, the third escape ran on three zero-days across QEMU, KVM and libslirp plus one upstream-patched KVM bug that never reached the distribution kernel because it was not recognized as a security issue. The agent worked autonomously for roughly 12 hours; Dinaburg's stated job was rebooting the host when it hardlocked. (Trail of Bits)
The post's verdict: "you can no longer assume a mere VM will contain a sufficiently advanced AI agent." Against Firecracker, the agent hardlocked the machine with kernel flaws but could not escape. And the disclosure status of the new bugs, as printed in the post's own results table, reads "No; bug has been reported" for the QEMU and libslirp zero-days, with the KVM details "pending stable kernel patches." No timeline, no identifier plan, and no statement of who the finder of record is when the finder is a model running under a vendor's preview program.
The same day, Anthropic's Project Glasswing coordinated-disclosure dashboard updated its running totals: 2,300 vulnerabilities disclosed across 392 open source projects, 462 identifiers issued (177 CVE records and 285 GitHub Security Advisories, with some findings carrying both), and 421 known to be patched. Anthropic states that the disclosed count is "a subset" of what its models have found, "since the process of independent human triage and review is the rate limiting step." (Anthropic) Read as ratios: at most one in five disclosed findings has a public identifier, and 18% have a known patch.
Why it matters for VDP: finding rate stopped being the constraint this summer; identifier assignment, maintainer capacity and provenance are. A QEMU maintainer receiving one of these reports cannot tell from the report whether a clock started, whether anyone else holds the same bug, or who to negotiate an embargo with. Any program that triages on "does this have a CVE" will miss four out of five Glasswing findings by construction. And for anyone running agentic tooling inside a plain VM, which describes most AI-assisted research rigs, the isolation boundary just moved to the host.
📎 Throwback: In Issue #28 we covered the CVE Program's Frontier AI Researcher CNAs pilot, which lets Anthropic and OpenAI assign CVE IDs for what their models find. The dashboard above is the first public measure of how far that pipe is from keeping up.
Upcoming Deadlines & Events
| Date | Agency | Event/Deadline | Action Required | Link |
|---|---|---|---|---|
| Sep 3, 2026 | ||||
| IST | Fragile Foundations Sprint kickoff call, 11:00 AM ET | Register for the webinar; volunteer for a working group (see Friends section) | ||
Sep 7, 2026NIST CSRC** Sep 8, 2026**NIST CSRC** Sep 11, 2026**CRA ReadinessSep 14, 2026KEV catalog,CISA alertSep 25, 2026NIST CSRC** Sep 28, 2026**Copyright.gov** Sep 30, 2026**Inside PrivacyOct 1, 2026pwn2own@trendmicro.comZDI RulesOct 5, 2026NIST CSRC** Oct 13, 2026**Federal RegisterOct 15, 2026SP 1353,SP 800-213APrioritized by date, nearest first.
This Week in Policy
Federal Strategy & Regulation
**CISA's vulnerability chief says BOD 26-04 is about "correcting some mistakes we made with previous BODs," and Gold Eagle now feeds VINCE.**Jay Gazlay, CISA's acting associate director for vulnerability management, told an August 27 CISA-hosted LinkedIn event that under earlier directives "we were telling them to do things that were really inefficient"; the highest-risk KEV entries now carry a three-day federal clock. The same report notes that Treasury's Gold Eagle AI vulnerability clearinghouse is augmenting CISA's VINCE coordination platform, which CISA's own fact sheet describes as "a powerful additional source of vulnerability reporting at scale." (Federal News Network,CISA)Why it matters for VDP: Gold Eagle plugging into VINCE is the federal government routing AI-discovered findings into the same coordinated-disclosure pipe human researchers use, at the exact moment (see Top Story) that pipe is the bottleneck.ONCD launches Project Watershed 250, a six-month water-sector cyber pilot in Texas. National Cyber Director Sean Cairncross and Governor Greg Abbott launched the program in San Antonio on August 31. It pairs utilities with private-sector vulnerability finding and remediation at no cost, with EPA and CISA as federal partners and Microsoft, Palo Alto Networks, Dragos and Reflection AI among the participating firms; Cairncross said the government "has admired the problem of cybersecurity in water systems" for too long. (Nextgov,CyberScoop)Why it matters for VDP: federally sponsored vulnerability hunting on third-party utilities raises the authorization and intake questions that most small water systems, which have no disclosure program at all, have never had to answer. It is also exactly the "cyber-poor" population this week's Friends section is about.NIST asks whether its IoT security catalog should cover "products," not just "devices." On August 31 NIST opened a pre-draft call for comments on SP 800-213A Rev. 1, the federal IoT device cybersecurity requirement catalog, to align it with CSF 2.0 and SP 800-53 Rev. 5.2.0 and to decide how to reconcile a device-scoped catalog with the product-scoped SP 800-213 Rev. 1. Comments close October 15. (NIST CSRC)Why it matters for VDP: the device-versus-product question is the one the EU CRA answered with "product," and it decides whether the cloud backends and companion apps that most IoT reports actually target sit inside the catalog or outside it.
CVE & Vulnerability Programs
PaperCut zero-days hit KEV after the first emergency patch was hardened within a day. PaperCut published an urgent bulletin on August 27 for two flaws in its NG/MF print-management servers, shipped an emergency patch on August 28, then shipped a second, hardened "Release 2" the same day after work with Huntress and watchTowr. The flaws, an authentication bypass (CVE-2026-81578) and unsafe dynamic class in the database connector (CVE-2026-82078), chain to unauthenticated remote code execution. CISA added both to KEV on August 31 with a September 14 federal due date. (PaperCut,SecurityWeek,CISA)Why it matters for VDP: the operational lesson is patch validation under pressure. The fix that shipped first was not the fix that held, and the difference was outside researchers testing the patch, not the vendor's own QA. Programs that close a report on "patch released" rather than "patch verified" will keep learning this the hard way.DOJ and FBI seize the domains behind a PRC scanning-and-proxy service. On August 26 the Justice Department announced court-authorized seizures that rendered QScan (which "scans and automatically infects thousands of" IoT devices worldwide) and QTRouter (a proxy network of those compromised devices, commercial proxies and leased servers) inoperable, attributing both to a PRC state-sponsored group operating through Nanjing Xinjiuwei Network Technology Company. Targets named in the court documents include NASA, the Federal Reserve and the US Senate. (DOJ)Why it matters for VDP: the seizure stops the operators, not the vulnerabilities. Every device QScan infected is still an unpatched device, and most of them belong to owners who will never receive a disclosure.
AI & Emerging Tech Security
A House bill would attach statutory requirements to the government's frontier-lab testing agreements. H.R. 10180, the Self-Improving AI Monitoring Act, introduced August 27 by Rep. George Whitesides (D-CA) with Rep. Pat Harrigan (R-NC), would amend the NIST Act "to authorize certain assessments by the Director of the Institute and impose requirements on certain memorandums of understanding relating to artificial intelligence." Bill text had not been posted as of this writing. (GovInfo)Why it matters for VDP: the pre-deployment testing arrangements between CAISI and the frontier labs are voluntary today. If Congress attaches requirements to them, capability evaluations, including cyber-capability evaluations, acquire a reporting channel with legal shape, and the question of whether model-discovered vulnerabilities must be disclosed gets a vehicle.The gap between what frontier models find and what the ecosystem can absorb is now a first-party number. See the Top Story: Anthropic's own dashboard puts identifiers at 462 against 2,300 disclosed findings, and Trail of Bits' results table lists "bug has been reported" as the entire disclosure status for zero-days a preview model found in QEMU and libslirp.Why it matters for VDP: this is the metric to track weekly. When the identifier share climbs, the plumbing is catching up; when the disclosed count climbs and the identifier share does not, maintainers are drowning.
Legal & Researcher Protections
A federal judge voids the Pentagon's "supply chain risk" label on Anthropic as First Amendment retaliation. On August 27, Judge Rita Lin of the Northern District of California ruled that the Defense Department's designation of Anthropic "constituted unlawful retaliation in violation of the First Amendment" and that the company "was denied the pre-deprivation process required under the Fifth Amendment." (CNN,NPR)Why it matters for VDP: a security-risk designation used to punish a company's public safety positions has the same shape as a legal threat used to punish a researcher's public findings. A ruling that the government cannot do the former without process is a precedent with obvious read-across to the latter.Wyden and Casar ask GAO for an unclassified accounting of federal law-enforcement hacking. On August 21, Sen. Ron Wyden and Rep. Greg Casar asked the Government Accountability Office to review federal law enforcement agencies' hacking of Americans' devices and "publish an unclassified report detailing its findings," noting that "spyware and other hacking tools grant expansive access to personal devices, including webcams, location data, stored files, and encrypted communications." (Wyden)Why it matters for VDP: the letter does not ask how the tools are acquired, but a public GAO report would still be a rare official accounting of the demand side of the vulnerability market, the same bug classes researchers report through VDPs, used by the government instead of fixed.
International Developments
**Australia charges two men under the Criminal Code's possession-and-supply-of-data offences over an alleged open-source supply-chain campaign.**The AFP announced on August 27 that a 21-year-old Cottesloe man and a 23-year-old Mandurah man were charged, in an operation run with the FBI and WA Police, over a syndicate that allegedly inserted malicious code into software on an open-source repository, potentially compromising more than 1,000 organisations and enabling theft of more than 500,000 credentials and at least 300 gigabytes of data. The charges include possessing data with intent to commit a computer offence (section 478.3(1)) and supplying data with intent to commit a computer offence (section 478.4(1)). (AFP)Why it matters for VDP: sections 478.3 and 478.4 are Australia's dual-use tooling offences, the structural cousin of the UK Computer Misuse Act provisions now under a statutory-defence review amendment in the Lords, and Part 10.7 of the Australian Criminal Code has no research defence and no reform vehicle in train. A prosecution that turns on possessing and supplying data is the fact pattern that makes that gap visible.Australia's National Cabinet commits to legislating AI standards in early 2027. On August 26 all nine Australian governments affirmed the Commonwealth's plan to legislate national AI laws and mandatory standards for large data centres, described by Clayton Utz as the first time all governments have committed to a common set of mandatory standards, with legislation intended for early 2027. (Clayton Utz)Why it matters for VDP: the announced content is energy, water and land-use standards for data centres and an as-yet-undefined set of AI conditions. Whether the 2027 legislation says anything about how security flaws in AI systems get reported is entirely open, which makes the next six months the window to put it there.**The UK Cyber Security and Resilience Bill entered Lords Grand Committee on September 1; the fate of the Computer Misuse Act review clause is not yet on the record.**Committee stage on HL Bill 32 began September 1 with further sittings scheduled for September 3, 7 and 9. As of this writing, Hansard had not published the September 1 proceedings, so whether Amendment 164 (the statutory-defence review for good-faith security researchers) was moved, withdrawn or agreed is unknown. (Parliament) 📎Throwback:Issue #31has the text of Amendments 164 and 171.
Worth Reading
(David Fraser, Canadian Privacy Law Blog): Canada's Bill C-22, the Lawful Access Act, 2026, passed the House on June 18 and now sits with the Senate; it governs "what technological capabilities companies may be required to build" for government access, which is the classic mandated-weakness problem researchers end up finding later.Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fall(NIST, September 1): the report from January's SUSHI@NIST workshop puts provenance, procurement incentives and "provenance-enabled semiconductor ecosystems" into one lifecycle frame, the hardware-side counterpart to this week's software identifier gap.Workshop on Rolling Next-Generation Secure Hardware into Standards (NIST IR 8615)(Council on Foreign Relations, May 18): older, but the right companion to the Friends section below. It argues for CISA and the sector risk management agencies to produce "an inventory of the security assumptions underpinning federal civilian and critical infrastructure systems" within six months, before deciding where AI can be deployed with confidence.The Security Foundations Beneath America's AI Ambitions Are Cracking
Friends of disclose.io
Institute for Security and Technology: the Fragile Foundations Sprint
On August 27, IST launched the Fragile Foundations Sprint, a 100-day effort "to lay the groundwork for pragmatic guidance and future action to strengthen the resilience of critical infrastructure against AI-powered cyber threats." It was developed by Josh Corman, IST's Executive-in-Residence for Public Safety and Resilience, and is led and coordinated by Jen Ellis and David Batz. The focus is deliberately narrow: the "cyber-poor" operators of life safety critical functions, meaning the small-to-medium and rural water, healthcare and emergency-services organisations that IST describes as "lacking in incentives, information, or resources," whose foundational importance "makes them extremely desirable targets for politically-motivated attackers." In Corman's long-standing phrase, it is where "bits and bytes meet flesh and blood."
The sprint runs through five working groups, each with named co-leads: consequences analysis (Mark Montgomery and Éireann Leverett), OT/ICS sector engagement (Alison King and Mike Holcomb), pragmatic guidance for cyber-poor operators (Whitney Bowman-Zatzkin and Samara Moore), novel mitigation analysis (Michael Daniel and Art Manion), and policy and incentives design (Matt Hayden and Megan Samford). IST is explicit that "effective solutions for resilience will often come from non-cyber-oriented approaches," and is recruiting volunteers with AI, cybersecurity, cyber policy and engineering expertise to work alongside the people "literally keeping the lights on." It also wants to hear directly from operators of life safety critical functions.
Why it matters: read this issue top to bottom and the shape is clear. Frontier models are compressing time-to-exploit (Top Story), the federal government is starting to send volunteer red teams at water utilities (Watershed 250), and the operators at the sharp end have no security team, let alone a disclosure program. The novel-mitigation and policy working groups are where a workable answer to "who does a researcher tell, and how" for a rural water system can be designed in from the start rather than bolted on later. If you have ever tried to report a finding to a utility and found no path, this is the place to fix that.
How to take part:
- Kickoff call: September 3, 2026, 11:00 AM ET (
[register](https://us02web.zoom.us/webinar/register/WN_heCRqdBbRYGV471glwKPYQ?ref=blog.disclose.io)) - Volunteer for a working group:
[registration form](https://form.jotform.com/262367406420049?ref=blog.disclose.io) - Duration: 100 days from launch
The Institute for Security and Technology is the nonprofit behind the Ransomware Task Force and UnDisruptable27, its earlier work on the fragility of water infrastructure and emergency healthcare. Josh, Jen and Art are long-time friends of disclose.io and of the disclosure community, and this sprint is the most direct attempt yet to bring the cyber-poor into the conversation the rest of us have been having for a decade.
Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.
Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!