Cybersecurity Today

Fortinet EMS Zero-Day, Anthropic's AI Finds Thousands of Bugs, Iranian Hackers Target US ICS

7 snips
Apr 9, 2026
An actively exploited FortiClient EMS zero-day and emergency hotfixes make the headlines. A powerful AI model uncovers thousands of high-severity vulnerabilities and advanced exploit techniques. A crafty supply-chain campaign abused social engineering to push malicious packages across ecosystems. Iranian-linked actors are reportedly targeting industrial PLCs in the US.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Patch Exposed Fortinet EMS Immediately

  • Apply emergency hotfixes immediately when Fortinet EMS 7.4.0.5 or 7.4.0.6 are internet-exposed.
  • Diffused found an unauthenticated RCE (CVE-2026-35616) and Shadow Server counts ~2,040 exposed EMS instances in the wild.
INSIGHT

AI Can Autonomously Discover Complex Zero Days

  • Anthropic's Claude Mythos can autonomously find and chain high-severity zero days across major OSes and browsers.
  • It built a four-vuln browser exploit, escaped layered sandboxes, and completed simulated attacks faster than skilled humans.
ADVICE

Keep Powerful Vulnerability-Finding AI Restricted

  • Use high-capability AI defensively with strict controls and partner access only.
  • Anthropic will not publicly release Mythos and is offering $100M usage credits plus $4M to open-source security groups.
Get the Snipd Podcast app to discover more snips from this episode
Get the app