Security & Threat Intelligence

The Watch

The Signal

Today's intelligence feed is almost entirely noise — no active CVEs

The one actionable signal buried across multiple sources: a new 15% global tariff is now in effect under Section 122, and based on the 16-month persistence of the previous tariff regime before SCOTUS struck it down, your security hardware procurement costs just went up for the foreseeable future.

In Play

  1. Tariff-Driven Security Budget and Supply Chain Disruption

    Four sources confirm SCOTUS struck down IEEPA tariffs 6-3, but a replacement 15% tariff under Section 122 took effect within hours — average tariff rates only dropped from 16.9% to 15.4%, meaning hardware procurement costs remain elevated with legal uncertainty extending months.

    Ask Clarity
  2. Federal Cybersecurity Authority Erosion via Major Questions Doctrine

    The strengthened Major Questions Doctrine used to strike down tariffs creates a legal template that could be applied to challenge SEC cyber disclosure rules, CISA incident reporting mandates, and FTC data security enforcement — all of which rely on expansive statutory interpretation rather than explicit cybersecurity legislation.

    Ask Clarity
  3. AI Agents Writing Security-Critical Code

    WorkOS shipped an AI agent (powered by Anthropic's Claude) that auto-generates and self-fixes authentication code in production codebases — a new supply chain risk pattern where the 'supplier' is a non-deterministic language model writing the highest-consequence code in your application.

    Ask Clarity
  4. FBI Leadership Instability and Federal Threat Intel Degradation

    FBI Deputy Director Bongino departed, and Director Kash Patel publicly discussed PDB intelligence prioritization on a podcast — signaling politicized intel processes that may degrade FBI cyber division outputs, flash alerts, and InfraGard briefings your organization depends on.

    Ask Clarity

Deep Dives

Your Security Hardware Just Got 15% More Expensive — And It's Staying That Way

What Happened

The Supreme Court struck down Trump's IEEPA-based tariff regime 6-3, ruling that the word 'tariff' does not appear anywhere in the IEEPA statute. The court applied the Major Questions Doctrine — the principle that agencies cannot claim sweeping new powers from ambiguous statutory language. Within hours, the executive imposed a replacement tariff: first 10%, then escalated to 15% by the next morning under Section 122 of the Trade Act of 1974.

Why the Replacement Tariff Matters More Than the Ruling

Four separate intelligence sources covered this story from different angles, and the synthesis is clear: the headline victory is misleading. Average tariff rates only dropped from 16.9% to 15.4%. Treasury Secretary Bessent projects 'virtually unchanged tariff revenue in 2026.' The practical impact on your procurement budget is near-zero relief.

Section 122 is legally capped at 15% for no more than 150 days and requires a 'large and serious' balance-of-payments crisis as justification. The legal basis is widely considered weak. But here's the critical pattern: the previous tariff regime persisted for approximately 16 months before SCOTUS invalidated it. Even legally vulnerable tariffs survive for months during litigation.

Plan for 6-16 months of 15% surcharges on imported security hardware. The legal system moves slower than your procurement cycle.

What's Actually at Risk in Your Stack

Security appliances with international supply chains are directly exposed:

  • Firewalls and network appliances — Palo Alto, Fortinet, and others source components globally
  • Endpoint hardware — sensors, HSMs, and specialized security devices
  • DR site buildouts — servers, storage, and networking gear for redundant infrastructure
  • Cloud and SaaS vendors — contracts with tariff pass-through clauses could trigger automatic price increases

The macroeconomic backdrop compounds the pressure: core PCE inflation at ~3% and GDP growth at only 1.4% signal a stagflationary environment. Your security budget is being eroded from multiple directions simultaneously.

Third-Party Vendor Financial Risk

Smaller security vendors with thin margins and international supply chains may face financial stress from tariff costs they can't pass through. This creates a third-party financial risk that your vendor risk management program should be monitoring — a vendor going under mid-contract is a security event.

What to do

  1. Audit all pending hardware procurement orders for tariff exposure and quantify the 15% impact by end of next week

  2. Review top 10 security vendor contracts for tariff pass-through clauses by March 15

  3. Add tariff contingency line item to 2026 security budget if not already present

  4. Enhance vendor financial health monitoring for smaller security vendors with international supply chains

AI Agents Are Writing Your Auth Code — Your AppSec Process Isn't Ready

The New Supply Chain Risk Pattern

WorkOS launched npx workos — a CLI tool powered by Anthropic's Claude that reads a developer's project, detects the framework, and writes a complete authentication integration directly into the codebase. The agent typechecks, builds, and auto-fixes its own errors in a feedback loop until the code compiles.

This is not a code suggestion tool. This is an autonomous agent writing security-critical code and self-healing until it passes build checks. The distinction matters enormously:

  • Authentication code is the highest-consequence code in any application — it controls identity, sessions, and access
  • An AI agent that self-heals build errors may produce code that compiles and passes tests but contains subtle logic flaws: improper token validation, missing CSRF protections, overly permissive OAuth scopes
  • Developer trust in 'it builds, so it works' bypasses the adversarial thinking that auth code demands
  • The 'supplier' of this code is a non-deterministic language model — this is supply chain risk where the supply chain is invisible
When your developers let an AI agent write authentication code, they've introduced a supply chain dependency that doesn't show up in any SBOM.

Why This Is Urgent Now

WorkOS is not an outlier — it's the leading edge of a pattern. Every major AI coding tool (GitHub Copilot, Cursor, Amazon CodeWhisperer) is moving toward agentic workflows that write, test, and commit code with decreasing human oversight. Authentication and authorization paths are where this trend becomes a security event.

Most AppSec programs have policies for third-party libraries, open-source dependencies, and even AI-assisted code suggestions. Almost none have policies for AI-agent-authored code in security-critical paths — code that is generated fresh each time, never appears in a dependency manifest, and varies non-deterministically between runs.

What to do

  1. Establish an AppSec policy requiring mandatory security review for any AI-generated code in authentication, authorization, cryptography, or session management paths by March 31

  2. Add AI-agent-generated code as a category in your secure SDLC documentation this quarter

  3. Survey development teams to identify current usage of AI coding agents (WorkOS npx, Cursor, Copilot agent mode) within 30 days

The Major Questions Doctrine Is Quietly Eroding Federal Cybersecurity Mandates

The Legal Pattern You Should Be Tracking

The SCOTUS tariff ruling is a trade policy story on its surface, but the legal mechanism used — the Major Questions Doctrine (MQD) — has direct implications for the regulatory foundations your compliance program may be built on.

MQD holds that federal agencies cannot claim sweeping new regulatory powers from ambiguous statutory language without explicit congressional authorization. SCOTUS has been systematically strengthening this doctrine since 2022, previously using it to strike down Biden's OSHA vaccine mandate and EPA emissions regulations. The tariff ruling is the latest and most aggressive application.

Which Cyber Mandates Are Vulnerable

Several active federal cybersecurity mandates rest on similarly expansive statutory interpretations:

MandateStatutory BasisMQD Vulnerability
SEC Cyber Disclosure RulesSecurities law (not explicit cyber legislation)High — 'material incident' reporting derived from general securities authority
CISA Incident Reporting (CIRCIA)CIRCIA — explicit but implementation stretches textMedium — statute exists but rulemaking details may exceed authority
FTC Data Security EnforcementSection 5 'unfair practices'High — no explicit cybersecurity mandate in statute

None of these have been challenged under MQD yet. But each successful SCOTUS application of the doctrine makes the next challenge more viable and more likely to be filed.

Build your security program on threat reality, not just regulatory obligation — because the legal foundation under those obligations is less stable than it was two years ago.

What This Means Practically

This is not a reason to reduce security investment. It's a reason to reframe how you justify it. If your board-level security narrative is 'we must comply with SEC disclosure rules' rather than 'we must protect our business from material cyber risk,' you're building on sand. The compliance mandate may weaken; the threat landscape won't.

Additionally, upcoming SCOTUS decisions — particularly a case on Federal Reserve independence — could have downstream effects on financial sector cybersecurity regulatory frameworks. If you're in financial services, your legal and compliance teams should be tracking this docket.

What to do

  1. Brief your legal/compliance team on the MQD trajectory and its potential impact on SEC, CISA, and FTC cyber mandates by end of Q1

  2. Reframe board-level security justification from compliance-driven to risk-driven language in your next board presentation

  3. Monitor SCOTUS docket for MQD challenges to cybersecurity-adjacent regulations through 2026

The bottom line

No active cyber threats today, but your security budget is under siege from three directions: a 15% global tariff that will persist for months and hit every hardware refresh, AI agents silently writing authentication code your AppSec process doesn't cover, and a Supreme Court doctrine that's quietly undermining the regulatory mandates you use to justify security spend — reframe your program around threat reality before the compliance floor drops out from under you.