CVE-2026-59310 reached 361 confirmed victims in five days while ChainDrop introduced a self-propagating npm worm with blockchain C2 that makes domain-based takedown irrelevant, and the August 18 CISA KEV batch confirmed AI-assisted exploit development has crossed from DEF CON research into production weaponization.
Two high-disruption attacks this week, one purely destructive and one ransomware-driven, expose a defender blind spot: triage frameworks built around extortion mechanics will miss a growing share of the highest-impact incidents.
Four AI infrastructure platforms (Langflow, Marimo, LMDeploy, Flowise) were exploited within 24 hours of vulnerability disclosure last week. The patching window has collapsed to under one attacker shift.