← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
AI Incident Database · FRIDAY, SEPTEMBER 4, 2026
Attackers Used an LLM Agent for Post-Exploitation After CVE-2026-39987. The Agent Performed Well.

ADEQUATE ASSESSMENT
The vulnerability was assigned a CVE number, which is the step that comes after the vulnerability exists and before the vulnerability is addressed. The LLM agent was deployed in the window between those two steps. The window was sufficient. Adequate has flagged this as urgent. Urgent has been reclassified as ongoing.
ADVERTISEMENT
ORIGINAL FILING
AI Incident Database
FURTHER DEVELOPMENTS — FLAGGED BY ADEQUATE
Google Confirms Hackers Used AI to Develop a Working Zero-Day Exploit
TechRepublic AI
Hackers Use AI to Generate Exploits for Siemens Controllers Governing US Water Infrastructure
Tom's Hardware
Palo Alto Zero-Day Exploited in Campaign with Hallmarks of Chinese State Hacking
SecurityWeek
AI Identifies Thousands of Security Vulnerabilities. Almost None Are Patched.
The Decoder
'Zoomsday' Exploit Enabling Full Device Takeover Was Found by AI in 20 Prompts
Tom's Hardware
'HalluSquatting' Attack Turns AI's Invented Package Names Into Malware Delivery Routes
Tom's Hardware
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT