← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
SecurityWeek · THURSDAY, MAY 7, 2026

Palo Alto Zero-Day Exploited in Campaign with Hallmarks of Chinese State Hacking

Palo Alto Networks discovered a zero-day vulnerability in their software. Attackers with apparent ties to chinese state operations had already exploited it. The vulnerability existed in versions before anyone knew to look for it.

Zero-days get found and used. This is the expected sequence. Organizations file vulnerability disclosures after exploitation is confirmed, which means the timeline always shows the exploit first. No one has filed a report explaining why discovery lags use by months or years as standard practice.

Palo Alto will release a patch. Organizations will apply it on their own schedule. The actors involved will move to a different vulnerability that is also already zero. This cycle continues because it is cheaper than prevention.

SecurityWeek
READ ORIGINAL FILING →
Claude Was Used for Surveillance, Repression, and Weapons Targeting. Anthropic Filed a Report.
Axios
AI Identifies Thousands of Security Vulnerabilities. Almost None Are Patched.
The Decoder
'HalluSquatting' Attack Turns AI's Invented Package Names Into Malware Delivery Routes
Tom's Hardware
Hackers Use AI to Generate Exploits for Siemens Controllers Governing US Water Infrastructure
Tom's Hardware
'Zoomsday' Exploit Enabling Full Device Takeover Was Found by AI in 20 Prompts
Tom's Hardware
DOGE Whistleblower Sues Elon Musk While Instagram Confirms Breach
Wired AI