Cybersecurity & Privacy — 2026-03-17

First CVE Identified by AI Agent Recognized in Microsoft Patch Tuesday

CVE-2026-21536, a critical remote code execution bug in Microsoft Devices Pricing Program, is the first vulnerability identified by an AI agent and officially assigned a CVE. The milestone marks a new era in automated vulnerability discovery. Separately, Krebs reported in detail on the Stryker wiper attack, revealing attackers used Microsoft Intune to remotely wipe all connected devices, disrupting surgical supply ordering at major hospital systems.

View in full brief →

UNCLASSIFIED // OPEN SOURCE