Subscribe to Running With Scissors

Hacking, policy, advocacy, and the sharp end of security research. Delivered to your inbox.

Free. No spam. Unsubscribe anytime.

Check your inbox

A confirmation link has been sent to your email.

Policy Pulse - Issue #30 | Week of August 23, 2026

Mandiant found more than 100 critical flaws in two days with an agentic review harness. NIST opened two new comment windows, and CISA added nine actively exploited vulnerabilities.

Policy Pulse - Issue #30 | Week of August 23, 2026

Policy Pulse - Issue #30 | Week of August 23, 2026

Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.


Top Story

Mandiant just made AI-scale vulnerability disclosure measurable

On August 18, Mandiant published the architecture and early results of its Agentic Vulnerability Discovery Harness. In one incident-response engagement, the system found more than 100 true-positive critical vulnerabilities in two days. Across ten months of use, Mandiant says the harness has processed tens of millions of lines of code, run thousands of analysis pipelines, generated tens of thousands of findings, produced 12 assigned CVEs, and left another dozen findings in active disclosure. (Mandiant)

The useful bit is not just the volume. Mandiant built explicit gates around it: agents create a threat model, discover entry points, trace control and data flow, generate hypotheses, and attack those hypotheses with multiple validators. Human consultants then reproduce exploitation, write proof-of-concept code, discard false positives, deduplicate the survivors, and prepare formal disclosures. That is closer to a disclosure production line than a faster scanner.

Why it matters for VDP: AI-scale intake is no longer a hypothetical future problem. A single team has demonstrated more than 100 critical findings in 48 hours while keeping a human validation gate. Program operators now need a comparable receiving system: machine-readable evidence requirements, aggressive duplicate clustering, support for chained findings, clear CNA routing, and enough coordination capacity to keep validated reports from becoming a new backlog.


Upcoming Deadlines & Events

Date Agency Event/Deadline Action Required Link
Aug 24, 2026 US Copyright Office DMCA Section 1201 renewal and new-exemption petitions due File a renewal or new/expanded-exemption petition copyright.gov
Aug 24, 2026 NIST Comments close on SP 800-213 Rev. 1, IoT Product Cybersecurity Guidelines Submit comments on federal IoT product security requirements NIST CSRC
Aug 28, 2026 Latvia Ministry of Defence Consultation closes on researcher safe-harbor amendment 26-TA-1830 Comment on the proposed legal conditions for good-faith research TAP portal
Sep 8, 2026 NIST Comments close on SP 800-209 Rev. 1, storage infrastructure security Submit comments NIST CSRC
Sep 25, 2026 NIST Comments close on SP 800-239, AI data center security analysis Submit comments NIST CSRC
Oct 5, 2026 NIST Comments close on IR 8613, Multi-Cloud Architecture Challenges Submit operational evidence on cross-cloud security gaps NIST CSRC
Oct 15, 2026 NIST Comments close on SP 1353, AI for CSF 2.0 analysis and reporting Review the prompts and submit comments NIST CSRC

This Week in Policy

AI & Emerging Tech Security

  • Copilot helped researchers find a one-click Copilot exploit. Varonis published CoSnitch on August 18, a chain built from automatic prompt execution, connector-assisted data exfiltration, and persistent memory poisoning. The researchers found the undocumented autorun behavior by repeatedly questioning Copilot about its own architecture. Microsoft assigned CVE-2026-24301, shipped server-side patches on August 18, and Varonis found no evidence of exploitation. (Varonis)

    Why it matters for VDP: AI-product intake needs a route for behavioral and trust-boundary failures, not just conventional code defects. Reproducing this class means capturing prompts, connector grants, model state, memory changes, and server-side behavior that a normal vulnerability form rarely asks for.

Federal Strategy & Regulation

  • NIST asks how practitioners should use AI to produce CSF 2.0 artifacts. Draft SP 1353, published August 19, provides structured prompts and three use cases: governance review, a current-state profile, and a target-state profile. NIST stresses that the examples are not assessment or assurance methodologies. Comments close October 15. (NIST)

    Why it matters for VDP: Disclosure teams can test whether the guide maps policies, interview notes, triage records, and remediation evidence to CSF outcomes without turning a generated profile into fake assurance. NIST is asking for comments on the guide and prompts now.

  • NIST maps 23 security and compliance challenges unique to multi-cloud systems. Draft IR 8613, published August 21, says the hardest gaps cluster around identity and access management, telemetry and logging, configuration and change management, data protection, and authorization. Comments close October 5. (NIST)

    Why it matters for VDP: Multi-cloud reports fail at the seams: nobody owns the whole path, logs live in different systems, and a finding that reproduces in one provider can disappear in another. Program operators should test cross-provider evidence retention and escalation, then send that experience to NIST.

CVE & Vulnerability Programs

  • CISA added nine vulnerabilities to the KEV catalog in five days. The August 17-21 additions cover Ray (CVE-2025-62593), MLflow (CVE-2026-64849), SharePoint (CVE-2026-55040), VMware vCenter (CVE-2026-59310), macOS (CVE-2026-65400), Microsoft IKE (CVE-2026-33824), two TrueConf Server flaws (CVE-2026-72529 and CVE-2026-72530), and Zimbra (CVE-2026-73570). (CISA KEV catalog)

    Why it matters for VDP: Ray and MLflow put AI and data infrastructure in the same exploited-vulnerability queue as collaboration and identity-critical enterprise software. Intake routing, asset ownership, and remediation escalation need to work across all of them, with CISA's risk-based deadlines now ranging from days to weeks rather than one uniform clock.

  • The DMCA security-research exemption reaches its renewal gate tomorrow. The Copyright Office's tenth Section 1201 rulemaking accepts renewal petitions for current exemptions and petitions for new or expanded exemptions until August 24. Comments supporting or opposing renewal petitions are due September 28. (US Copyright Office, 2024 final rule)

    Why it matters for VDP: The good-faith security research exemption is temporary. Renewal preserves the current anti-circumvention protection for the 2027-2030 cycle; any expansion or change in regulatory language requires a new petition now.

International Developments

  • The EU e-Evidence Regulation became applicable on August 18. Regulation (EU) 2023/1543 lets judicial authorities issue European Production and Preservation Orders directly across borders to covered service providers, backed by designated establishments or legal representatives. (EUR-Lex, European Commission)

    Why it matters for VDP: A cross-border vulnerability or incident report can become evidence in a criminal matter. VDP and CSIRT teams should preserve provenance and chain of custody when escalation starts, and keep voluntary researcher communications distinct from compulsory legal orders. The regulation standardizes evidence access; it does not create researcher safe harbor.


Worth Reading


Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.

Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!