
Cybersecurity Today Fortinet EMS Zero-Day, Anthropic's AI Finds Thousands of Bugs, Iranian Hackers Target US ICS
7 snips
Apr 9, 2026 An actively exploited FortiClient EMS zero-day and emergency hotfixes make the headlines. A powerful AI model uncovers thousands of high-severity vulnerabilities and advanced exploit techniques. A crafty supply-chain campaign abused social engineering to push malicious packages across ecosystems. Iranian-linked actors are reportedly targeting industrial PLCs in the US.
AI Snips
Chapters
Transcript
Episode notes
Patch Exposed Fortinet EMS Immediately
- Apply emergency hotfixes immediately when Fortinet EMS 7.4.0.5 or 7.4.0.6 are internet-exposed.
- Diffused found an unauthenticated RCE (CVE-2026-35616) and Shadow Server counts ~2,040 exposed EMS instances in the wild.
AI Can Autonomously Discover Complex Zero Days
- Anthropic's Claude Mythos can autonomously find and chain high-severity zero days across major OSes and browsers.
- It built a four-vuln browser exploit, escaped layered sandboxes, and completed simulated attacks faster than skilled humans.
Keep Powerful Vulnerability-Finding AI Restricted
- Use high-capability AI defensively with strict controls and partner access only.
- Anthropic will not publicly release Mythos and is offering $100M usage credits plus $4M to open-source security groups.
