AI-agent breach enters the regulatory recordForged admin tokens target WSO2 API control planesPixel modem flaw sees targeted exploitationCHOSEN BRICK hunts high-risk Windows users
Spain’s data-protection authority has received a notification describing an AI agent chaining valid authentication, vulnerability discovery and actions against personal data, although the underlying evidence remains under regulatory analysis.
Security.io Intelligence Desk · Thursday, 17 September 2026
Executive consequence
AEPD’s notification should trigger a control review, not a conclusion about autonomous AI capability. The reported sequence combined a valid login, application vulnerability discovery, modification of personal data and invoice access.
Decision today
Map valid-login-to-data-modification detection coverage across identity, application and database controls.
CVE-2026-5430 allows WSO2 products to accept JWTs signed with unsupported algorithms, potentially enabling administrative account takeover. WSO2 published fixes in May; reporting now says watchTowr captured forged administrator tokens in honeypot telemetry.
Do today
Inventory every WSO2 API platform component and administrative interface.
Google’s September Pixel bulletin says CVE-2026-58704, a high-severity modem elevation-of-privilege flaw, may be under limited, targeted exploitation. Security patch level 2026-09-05 addresses the bulletin.
Do today
Export patch-level evidence for every enterprise-accessing Pixel device.
CenterPoint’s Form 8-K confirms that customer personal information was obtained through an external-facing system while electric and gas delivery remained operational. Subsequent reporting describes federal class-action litigation and an allegation involving the guest-pay feature.
Do today
Test customer portals for excessive disclosure from account identifiers.
The NCSC, FBI and AIVD have published joint guidance on CHOSEN BRICK, persistent Windows malware delivered through tailored WhatsApp and Telegram social engineering. The advisory provides Run-key values, filenames, mutexes, a nonstandard directory and behavioural guidance.
Do today
Identify employees and affiliates with elevated Iran-related targeting risk.