AI-generated decoy documents are being used in active espionage campaigns, Microsoft reports hundreds of systems compromised via React2Shell exploitation, and Tenable highlights ongoing gaps in prompt injection and AI data security controls.
React2Shell
AI Security Daily Briefing — December 18, 2025
Cisco warns of active exploitation of an AsyncOS zero-day, a study finds WAFs ineffective against modern React2Shell exploits, and SonicWall patches an exploited SMA1000 zero-day, all of which affect perimeter defenses that protect AI-related services and admin portals.