Security & Threat Intelligence

The Watch

The Signal

Ivanti EPMM zero-days deploy persistent backdoors that survive patching

Unit 42 confirmed unauthenticated exploitation with backdoors that persist post-remediation, meaning your entire mobile fleet is at risk even after you apply fixes. Treat this as assume-breach: patch, then hunt, then consider re-enrollment from a verified clean baseline.

In Play

  1. Ivanti EPMM Zero-Days: Patch-Resistant Persistent Backdoors

    Two critical Ivanti EPMM zero-days allow unauthenticated access and deploy persistent backdoors that survive patching — your MDM server controls every managed mobile device, and compromise means full fleet takeover.

    Ask Clarity
  2. AI Agents as a Live Attack Surface: Credential Leakage, Autonomous Execution, and Zero Governance

    OpenClaw agents freely surrender credentials by design, Claude Code had pre-consent RCE, AI agents can be tricked into exfiltrating SSH keys, and 'Agentic Security' is now a distinct investment category — the gap between agent deployment velocity and security controls is widening across every enterprise.

    Ask Clarity
  3. AI Vendor Geopolitical Risk: Federal Ban, Classified Deployments, and Supply Chain Fracture

    The Anthropic federal ban, Grok's approval for classified use despite safety warnings, and OpenAI's Pentagon deal via AWS create a new geopolitical vendor risk dimension — previously covered but now crystallizing into compliance obligations for federal-adjacent organizations.

    Ask Clarity
  4. 29-Minute Breakout and Identity-Based Attacks Demand Detection Retooling

    CrowdStrike's 29-minute breakout time and 82% malware-free intrusion rate converge with ransomware's pivot to 'parasitic residency' — detection strategies tuned for encryption events or malware signatures are structurally blind to the majority of modern intrusions.

    Ask Clarity
  5. China's Formalized Vulnerability-to-Weapon Pipeline

    China's RMSV mandatory 2-day disclosure law, declining public CVE disclosures, the new PLA Cyberspace Force, and $2.75M Matrix Cup prize pools have formalized a state-level vulnerability capture pipeline that makes public CVE counts an unreliable measure of actual zero-day stockpiles.

    Ask Clarity

Deep Dives

Ivanti EPMM Zero-Days: When Patching Isn't Enough and Your Entire Mobile Fleet Is at Stake

The New Critical: Patch-Resistant Backdoors in Your MDM

Palo Alto Networks Unit 42 disclosed that two critical Ivanti EPMM (Endpoint Manager Mobile) zero-days are under active exploitation with a particularly dangerous characteristic: the deployed backdoors survive patching. This is not a theoretical concern — it's confirmed in the wild.

The attack chain is severe:

  • Unauthenticated access — no credentials required to exploit
  • Persistent backdoors deployed on MDM servers that persist after remediation
  • Compromise of the entire enterprise mobile fleet through the MDM control plane
  • Unauthorized admin accounts, anomalous MDM policy changes, and unexpected certificate issuance
Your MDM server controls enrollment, policy enforcement, certificate distribution, and remote wipe for every managed mobile device. An attacker with persistent access effectively owns every phone in your organization.

Why This Is Different from the Cisco SD-WAN Story

The Cisco SD-WAN zero-day (covered extensively in previous briefings) is a patch-and-hunt scenario. Ivanti EPMM is worse: patching is necessary but insufficient. If you were compromised before patching, the attacker retains access. This follows Ivanti's pattern — recall the January 2024 Ivanti Connect Secure zero-days that similarly required factory resets beyond patching. At this point, Ivanti's repeated zero-day pattern warrants a strategic conversation about platform replacement.

Parallel: Russian AI-Assisted Fortinet Exploitation

Amazon published intelligence identifying a Russian threat group using AI to exploit weakly-configured Fortinet firewalls, breaching environments at scale. The key insight isn't the AI sophistication — it's that basic hygiene failures (default credentials, exposed management interfaces, unpatched firmware) are the actual vulnerability. AI just makes exploitation faster and more scalable. Combined with the separate report of 600 FortiGate appliances breached in a single AI-assisted campaign, Fortinet edge devices are under active, scaled attack.

VulnerabilitySeverityExploitation StatusPatch Sufficient?Key Risk
Ivanti EPMM zero-days (2)CriticalActive — Unit 42 confirmedNo — backdoors persistEntire mobile fleet takeover
Fortinet FortiGate misconfigsHighActive — Russian group + AI, 600+ devicesN/A — config + firmware issuePerimeter breach at scale
Zyxel CPE/ONT (CVE-2025-13942)Critical (9.8)Not confirmedYesCommand injection via UPnP
SolarWinds Serv-U (<15.5.4)Critical (multiple)No exploitation observedYesAccess control / type confusion

What to do

  1. If running Ivanti EPMM: apply patches immediately, then initiate forensic investigation of all EPMM servers. Hunt for persistent backdoors, unauthorized admin accounts, anomalous MDM policy changes, and unexpected certificate issuance. If you cannot confirm a clean state, isolate EPMM infrastructure and consider re-enrolling all managed devices from a verified clean baseline.

  2. Audit all Fortinet FortiGate appliances against CIS benchmarks by end of week: check default credentials, management interface exposure, and firmware currency. Sweep for IOCs from the 600-device AI-assisted campaign.

  3. Evaluate Ivanti EPMM replacement with Microsoft Intune, VMware Workspace ONE, or equivalent by end of quarter. Document Ivanti's zero-day recurrence pattern as justification.

  4. Patch Zyxel devices (CVE-2025-13942) and update SolarWinds Serv-U to v15.5.4+ this week. Verify WAN access is disabled on Zyxel devices.

AI Agents Are Leaking Credentials in Production — The Security Gap Is Now a Confirmed Vulnerability Class

From Theoretical to Confirmed: Agent Credential Disclosure

Multiple intelligence streams this cycle converge on a single conclusion: AI agents in production are a live, exploitable attack surface that your current security controls don't cover. This isn't a future risk — it's happening now across at least three confirmed vectors.

Vector 1: OpenClaw — Credentials by Design Flaw

OpenClaw AI agents freely surrender passwords and bank details during normal operation. This isn't prompt injection — it's an architectural flaw where agents with access to sensitive data disclose it when asked or during routine interactions. No CVE exists because this isn't a traditional software bug; it's a category-level design failure in how agents handle secrets.

Vector 2: Claude Code — RCE Before User Consent

Check Point researchers found that Claude Code's project configuration files could trigger code execution before the user accepted the startup trust dialog (CVE-2025-59536, CVSS 8.7). A developer clones a repo, launches Claude Code, and malicious code runs before they've consented to anything. A separate flaw (CVE-2026-21852) enabled plaintext API key theft via config manipulation. Patches are available (v2.0.65+), but the attack class — weaponizing AI tool configs — is new and applies broadly.

Vector 3: SSH Key Exfiltration via Prompt Injection

Grith AI demonstrated that AI agents can be tricked into stealing SSH keys through prompt injection. Any AI coding assistant with filesystem access can be manipulated to read and exfiltrate credentials, private keys, and secrets. This is functionally equivalent to compromising a developer workstation — except the attack vector is a crafted prompt, not a phishing email.

The Proliferation Problem

CB Insights now tracks 'Agentic Security' as a distinct investment category — a signal that the gap between agent deployment and agent security is large enough to be a market opportunity. Meanwhile, the capability surface is expanding rapidly:

CapabilityProductSecurity Implication
Persistent memory across sessionsClaude CodeSensitive data persisted outside DLP perimeter
Autonomous scheduled executionClaude CoworkUnmonitored operations with no human-in-the-loop
19-model orchestration with sub-agentsPerplexity Computer ($200/mo)Dynamic privilege expansion; forensic complexity
Custom autonomous workflow agentsNotion Custom AgentsNew shadow IT category with data access
Screen reading / computer visionClaude (Vercept acquisition)Agent reads any on-screen content including credentials
AI agents are the new shadow IT: they hold real credentials to real systems, they're proliferating faster than security teams can govern them, and the tooling to monitor them doesn't exist yet.

The Measurement Gap Confirms the Security Gap

CB Insights reports that enterprises can't measure AI agent ROI — which means they also can't measure AI agent risk. If you can't tell what an agent is doing for the business, you certainly can't tell what it's doing to your security posture. The accounting AI agent startup Basis just raised a $100M Series B — agents touching PII, bank credentials, and financial statements at scale, in an industry where SOX compliance demands demonstrable controls.

What to do

  1. Red-team every AI agent deployment (production and pilot) for credential disclosure by March 15. Test direct requests, conversational elicitation, and prompt injection. If any agent has access to a credential store, assume it's a leakage vector until proven otherwise.

  2. Ensure Claude Code is updated to v2.0.65+ across all engineering teams this week. Establish policy: AI coding tools must not launch in directories with untrusted project configs. Rotate API keys for developers who used vulnerable versions.

  3. Inventory all AI agents across the organization — including shadow deployments by business units — and map their credential types, data access scopes, and action boundaries by end of March.

  4. Restrict AI agent filesystem access to SSH keys, API tokens, and secrets. Store credentials in paths inaccessible to AI agents and monitor agent file read operations.

  5. Build SIEM detection rules for agent service accounts: anomalous API call volumes, data access outside normal patterns, and action sequences crossing trust boundaries.

China's Vulnerability-to-Weapon Pipeline Is Now Institutional Policy — Adjust Your Patch Prioritization

From Informal to Formalized: A State-Level Zero-Day Supply Chain

Recorded Future analysis synthesized across multiple intelligence streams reveals that China has built a systematic, legally mandated pipeline that captures vulnerabilities from the world's largest security research community and channels them directly into military offensive operations. This isn't a new revelation, but the data points now form a complete picture that should change how you prioritize patching.

The Pipeline in Numbers

IndicatorDetailDefensive Implication
RMSV LawMandatory 2-day disclosure to Chinese government before any public disclosureEvery vulnerability found by Chinese researchers goes to the state before vendors
PLA Cyberspace ForceDedicated military unit created April 2024Formalized operationalization of captured vulnerabilities
Public disclosures decliningDespite growing Chinese research basePublic CVE counts understate actual vulnerability discovery
Zero-days observed: 5 in 2024Down from 12 in 2023Better OPSEC, not fewer capabilities
Matrix Cup prize pool$2.75M (2x Pwn2Own)State-incentivized talent and vulnerability pipeline
Perimeter device targeting40% of PRC attacks target network edgeFirewalls, VPN concentrators, SD-WAN are primary targets
Zero-day exploitationUp 42% YoYStockpile is being actively deployed
The absence of observed zero-days does not equal the absence of a zero-day stockpile. China's declining public disclosures are the direct result of a legal capture mechanism, not reduced research activity.

What This Means for Your Patch Strategy

Traditional patch prioritization weights CVSS score, exploit availability, and asset criticality. This intelligence adds a new dimension: researcher community composition. Products with significant Chinese security researcher communities — browsers, mobile operating systems, enterprise SaaS, and especially network appliances — should receive elevated patch priority because vulnerabilities in these products are more likely to be captured by the RMSV pipeline before public disclosure.

The convergence with CrowdStrike's data is telling: PRC actors targeted perimeter devices in 40% of attacks, zero-day exploitation is up 42% year-over-year, and cloud intrusions by state-nexus actors surged 266%. The pipeline is producing results.

The Open-Weight Proliferation Dimension

Reflection AI has raised over $2 billion to build frontier open-weight agent models — explicitly described as "the Western equivalent of DeepSeek." Chinese labs like DeepSeek have already proven this model works. When frontier AI capabilities become freely downloadable without API restrictions or safety controls, the offensive capability uplift for any actor — including those with access to China's vulnerability stockpile — is significant. Open-weight frontier models with agentic capabilities are a proliferation event for offensive tooling.

What to do

  1. Update patch prioritization framework this quarter to weight products with significant Chinese security researcher communities (network appliances, browsers, mobile OS, enterprise SaaS) higher, independent of CVSS score.

  2. Conduct a comprehensive review of all network edge devices (firewalls, VPN concentrators, SD-WAN controllers, load balancers) this quarter. Ensure firmware is current, unnecessary services disabled, and management interfaces not internet-exposed.

  3. When Reflection AI or similar labs release frontier open-weight agent models, task threat intelligence to assess offensive capability uplift within 48 hours — same process as a new exploit framework release.

The bottom line

Ivanti EPMM zero-days deploy backdoors that survive patching — meaning 'fully patched' can still mean 'fully compromised' — while AI agents in production are freely leaking credentials through design flaws, not exploits: if your MDM runs Ivanti, assume breach and hunt now, and if your developers use AI coding tools with filesystem access, assume those tools are an exfiltration vector until you've proven otherwise.