Policy Pulse - Week of September 1, 2026 | Issue #32

Policy Pulse #32 is up. Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.

Top story: a preview cyber model broke out of a stock VM three times, and the disclosure record is one line

On August 26 Trail of Bits published what happened when GPT-5.6-Cyber, under OpenAI’s Patch the Planet preview, was given one task: escape the QEMU/KVM virtual machine used for sandboxing. It escaped three times. The first used a recently disclosed host-kernel bug with no public exploit, so the agent wrote one. The second chained a known libslirp CVE with a bug-fix commit that had never been assigned a CVE. The third, after QEMU and libslirp were rebuilt from upstream source, ran on three zero-days plus an upstream-patched KVM bug that never reached the distribution kernel because nobody had recognized it as a security issue.

The post’s own results table records the disclosure status of the new bugs as “No; bug has been reported.” No timeline, no identifier plan, and no statement of who the finder of record is when the finder is a model running under a vendor’s preview program.

The same day Anthropic’s Project Glasswing dashboard updated its totals: 2,300 vulnerabilities disclosed across 392 open source projects, 462 identifiers issued, 421 known to be patched. Read as ratios, at most one in five disclosed findings has a public identifier. Finding rate stopped being the constraint this summer. Identifier assignment, maintainer capacity, and provenance are.

Friends of disclose.io: the IST Fragile Foundations Sprint

The Institute for Security and Technology launched a 100-day sprint on AI-powered cyber threats to the cyber-poor operators of life safety critical functions: small and rural water, healthcare, and emergency services. Developed by Josh Corman, led by Jen Ellis and David Batz, five working groups with named co-leads. Kickoff call is September 3, 2026 at 11:00 AM ET (register), and volunteers can sign up for a working group via the registration form. If you have ever tried to report a finding to a utility and found no path, this is the place to fix that.

Also in this issue: ONCD’s Project Watershed 250 water-sector pilot in Texas, CISA’s Gold Eagle now feeding VINCE, PaperCut’s two zero-days landing in KEV after a bypassed emergency patch, the DOJ seizure of the QScan/QTRouter domains, a federal judge voiding the Pentagon’s “supply chain risk” label on Anthropic, and Wyden and Casar asking GAO for an unclassified accounting of federal law-enforcement hacking.

Upcoming deadlines worth your calendar: IST kickoff Sep 3. CRA Article 14 reporting obligations begin Sep 11. PaperCut KEV remediation due Sep 14. NIST IR 8613 comments close Oct 5, and SP 800-213A comments close Oct 15.

Read the full issue: Policy Pulse - Issue #32 | Week of September 1, 2026