Security & Threat Intelligence

The Watch

The Signal

Cisco Catalyst SD-WAN has a CVSS 10.0 authentication bypass (CVE-2026-20127)

Simultaneously, vendor data confirms attacker breakout-to-exfiltration has collapsed to 6 minutes. If your patching cadence is monthly, you're already compromised.

In Play

  1. Critical Vulnerability Avalanche: Cisco 10.0, ICS 10.0, and 80+ CVSS 9.0+ CVEs

    Four CISA KEV additions, CVSS 10.0 in both Cisco SD-WAN and ICS/SCADA systems (Copeland XWEB Pro), critical RCE in developer tools (Rollup, OpenSSL, n8n, Langflow), and 40+ Firefox CVEs create a simultaneous multi-layer exposure event requiring emergency triage across network, OT, browser, mobile, and supply chain surfaces.

    Ask Clarity
  2. Attacker Breakout Collapse: 6-Minute Exfil and AI-Accelerated Kill Chains

    CrowdStrike reports 30-minute average lateral movement (down 70% in 4 years), ReliaQuest records first data theft at 6 minutes, and Chatty Spider achieves exfil to Google Drive in 4 minutes — while CyberStrikeAI's open-source release on GitHub combines MCP-based AI orchestration with 100+ offensive tools, compressing attack decision loops to machine speed.

    Ask Clarity
  3. OT/ICS Weaponization: Pre-Positioned Access Becoming Operational Weapons

    Dragos confirms state-affiliated groups are transitioning multi-year ICS footholds from reconnaissance to active weaponization while three CISA ICS advisories this week (Copeland CVSS 10.0, Johnson Controls CVSS 9.8 with hardcoded credentials, InSAT MasterSCADA CVSS 9.8) demonstrate that OT vendors continue shipping products with fundamental authentication failures.

    Ask Clarity
  4. Non-Human Identity Crisis: AI Agents as Unmanaged Enterprise Principals

    Google Workspace CLI launched with 100+ agent skills and 8,800+ GitHub stars on day one, Cloudflare reports 94% of login attempts are bots, MCP adoption is creating 'identity dark matter' — ungoverned non-human entities with production data access — and Snyk claims organizations tracking only AI models miss 67% of their actual AI attack surface.

    Ask Clarity
  5. Law Enforcement Wins and Displacement Effects

    Tycoon 2FA (62% of Microsoft-blocked phishing, 500K+ orgs targeted, $350/month), LeakBase (142K members, 14-country takedown), The Com/Project Compass (30 arrests, Lapsus$/Scattered Spider pipeline), and Intellexa (8+ year prison sentences) represent a coordinated law enforcement offensive — but AitM techniques are commoditized and credential displacement to alternative channels is inevitable within weeks.

    Ask Clarity

Deep Dives

Patch Everything: Cisco CVSS 10.0 Leads the Densest Critical-Vulnerability Week of 2026

The Vulnerability Avalanche

This week delivered a concentration of critical vulnerabilities across every layer of the enterprise stack that demands emergency triage. The headline: CVE-2026-20127, a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller/Manager, has been in CISA KEV since February 25 — meaning exploitation has been active for at least 8 days. A second flaw (CVE-2026-20129, CVSS 9.8) grants netadmin privileges. Together, they give attackers full control of your WAN fabric — every branch, every tunnel, every policy.

But Cisco is just the tip. Three additional CISA KEV entries landed this week: VMware Aria Operations (CVE-2026-22719, CVSS 8.1, unauthenticated command injection during migration workflows) and Qualcomm chipsets (CVE-2026-21385, Android). VMware's flaw is particularly insidious — it's exploitable during support-assisted product migration, precisely when post-Broadcom organizations have relaxed controls.


ICS/SCADA: Three CVSS 10.0 Advisories

Industrial control systems received devastating disclosures this week:

SystemCVE(s)CVSSVulnerability
Copeland XWEB ProCVE-2026-21718/2466310.0Auth bypass + OS command injection
Johnson Controls Frick Controls6 CVEs9.8OS command injection + hardcoded email credentials
InSAT MasterSCADA BUK-TSCVE-2026-214109.8SQL + OS command injection

Developer Toolchain Under Fire

A cluster of CVSS 9.8-9.9 RCEs hit developer tools simultaneously: Rollup JS bundler (CVE-2026-27606, path traversal to RCE), Kubernetes PersistentVolumes (CVE-2025-62878, CVSS 9.9), n8n workflow automation (CVE-2026-27495, CVSS 9.9), Langflow AI tool (CVE-2026-27966, prompt injection to Python REPL RCE), and OpenSSL (CVE-2025-15467, buffer overflow across v3.0-3.6). The Cloudflare CIRCL crypto library (CVE-2026-1229, CVSS 9.8) silently produces incorrect P-384 elliptic curve values — signatures may verify when they shouldn't.

Browser and Mobile Fleet

Mozilla released five security advisories covering 40+ CVEs at CVSS 9.8-10.0 across Firefox and Thunderbird. Android's March 2026 bulletin includes CVE-2026-0006 (CVSS 9.8), a zero-click RCE requiring no user interaction. Every unpatched browser and Android device is a multi-vector target.

Authentication bypass is the dominant vulnerability class this week — appearing in Cisco SD-WAN, CrushFTP, Copeland, WordPress, and more. This isn't bad luck; it's an industry-wide failure in security engineering fundamentals.

What to do

  1. Patch Cisco Catalyst SD-WAN Controller/Manager for CVE-2026-20127 and CVE-2026-20129 immediately; if delayed, isolate management interfaces and audit logs since February 25

  2. Patch VMware Aria Operations for CVE-2026-22719; disable migration endpoints not actively in use

  3. Push Firefox/Thunderbird updates and Android March 2026 security update via MDM by end of week

  4. Run emergency SCA scan for Rollup (≥4.59.0), n8n (≥2.10.1), OpenSSL (3.0-3.6 branches), and Cloudflare CIRCL (≥1.6.3) across all codebases and CI/CD pipelines

  5. Apply CISA ICS advisories for Copeland, Johnson Controls, and InSAT MasterSCADA; verify OT/IT network segmentation enforcement

Your SOC Has 6 Minutes: Attacker Breakout Times Have Collapsed and AI Is Accelerating Both Sides

The Data Is In — And It's Worse Than Expected

Multiple vendor threat reports independently converge on a single alarming conclusion: attacker breakout-to-exfiltration timelines have collapsed from hours to minutes. This isn't a single vendor's marketing claim — it's a cross-industry trend confirmed by at least four major research teams.

Metric202120242025/2026Source
Average lateral movement time~100 min48 min30 minCrowdStrike
Fastest observed data exfiltration4 hours6 minutesReliaQuest
Chatty Spider: access → exfil to Google Drive4 minutesCrowdStrike

Chatty Spider is particularly concerning for professional services: they target law firms, achieving data exfiltration to personal Google Drive within 4 minutes of workstation access. Total intrusion duration: under one hour. If your DLP doesn't distinguish corporate from personal cloud tenants, this actor operates entirely within your blind spots.


AI Is Compressing Both Sides of the Kill Chain

The release of CyberStrikeAI as open-source on GitHub marks a threshold event. This isn't another script kiddie toolkit — it combines MCP-based AI orchestration with 100+ offensive tools, enabling autonomous multi-stage attacks. The MCP integration means an AI agent can select, configure, and chain tools based on real-time reconnaissance results, collapsing human decision loops to machine speed.

On the social engineering front, Trend Micro prototyped an automated LinkedIn-scraping-to-spear-phishing pipeline in a single day. OpenAI's threat report reveals scammers using ChatGPT to craft culturally authentic personas targeting specific demographics like "American men in their 40s in the medical field who talk about golf online." The cost of tailored social engineering is approaching zero.

Attackers now exfiltrate your data in 6 minutes while your SOC takes 30 to triage the alert. If you haven't automated containment for high-confidence detections, AI-accelerated adversaries have already won the race.

The Ransomware Economy Shows Strain

Despite ransomware claims increasing 50% in 2025, total payments remained flat at ~$900M per Chainalysis. This divergence suggests organizational resilience investments are working — but attackers are compensating with volume and speed. The 6-minute exfil window means your only real defense is automated containment, not human investigation.

What to do

  1. Benchmark your mean-time-to-contain against a 30-minute lateral movement threshold this week; if automated endpoint isolation isn't triggering within 5 minutes of high-confidence detections, escalate SOAR playbook tuning as P1

  2. Block or monitor personal cloud storage (Google Drive, Dropbox, OneDrive personal tenants) as exfiltration channels from corporate endpoints by end of sprint

  3. Task detection engineering team to clone CyberStrikeAI from GitHub, analyze MCP orchestration patterns, and develop behavioral detection signatures within 2 weeks

  4. Run a tabletop exercise this quarter simulating a 6-minute exfil scenario to test automated containment triggers end-to-end

OT/ICS: State Actors Are Done Collecting — They're Building Weapons With Your Infrastructure

From Access to Weaponization

Dragos's latest research makes a distinction defenders must internalize: the threat is not that state-affiliated actors are gaining access to OT environments — it's that they already have access and are transitioning to active weaponization. This maps to a progression from MITRE ATT&CK for ICS initial access and persistence toward Impair Process Control (TA0106) and Inhibit Response Function (TA0107). Multiple intelligence sources independently confirmed this assessment.

The detection gap is stark. Most OT security monitoring — where it exists at all — is calibrated for anomalous network connections and known malware signatures. Weaponization-phase activity looks different: unauthorized engineering logic changes, subtle process variable manipulation, firmware modifications to PLCs, and staging of destructive payloads on engineering workstations. These are the signals your SOC should be hunting for now.


This Week's ICS Advisories Prove the Point

Three CISA ICS advisories landed simultaneously, demonstrating that OT vendors continue shipping products with authentication as an afterthought:

  • Copeland XWEB Pro: CVSS 10.0 — authentication bypass combined with OS command injection. A perfect score.
  • Johnson Controls Frick Controls Quantum HD: 6 CVEs including OS command injection, code injection, and hardcoded email credentials (CVSS 9.8)
  • InSAT MasterSCADA BUK-TS: SQL injection + OS command injection (CVSS 9.8)

Hardcoded credentials in industrial control equipment in 2026 is not a zero-day — it's a design philosophy failure that state actors are built to exploit.

Iranian Threat: The Calm Before the Wiper Storm

The current lull in Iranian cyber operations due to US-Israeli kinetic military pressure is not a reduction in threat — it's displacement. Experts assess that when Iranian groups reconstitute, the operational focus will shift from intelligence collection to destructive wiper attacks, consistent with historical precedent (Shamoon, ZeroCleare, Dustman). Organizations in energy, finance, and government should validate wiper resilience now, not after operations resume.

The attacker doesn't need a zero-day when they already have the keys and understand the process well enough to make a pump overpressure look like a sensor malfunction.

What to do

  1. Conduct a proactive OT/ICS threat hunt this month focused on weaponization indicators: unauthorized logic changes, anomalous engineering workstation activity, new scheduled tasks on HMIs, and lateral movement between IT and OT segments

  2. Apply CISA ICS advisories icsa-26-057-01 and icsa-26-057-10 and verify OT/IT network segmentation enforcement within 2 weeks

  3. Validate offline/immutable backup integrity and test recovery time objectives for wiper-attack scenarios against systems in Iranian targeting scope by end of quarter

  4. Deploy OT-specific network monitoring (Dragos, Claroty, or Nozomi) if not already in place — evaluate within 30 days

The Non-Human Identity Crisis: AI Agents Are Your Newest Unmanaged Attack Surface

Identity Dark Matter Is Already in Production

Eight independent sources this cycle converge on a single uncomfortable truth: AI agents are accumulating enterprise-grade permissions faster than any governance framework can track them. The evidence is overwhelming and specific:

  • Google Workspace CLI launched with 100+ pre-built AI agent skills covering Drive, Gmail, Calendar, Sheets, Docs, Chat, and Admin — installable via a single npm install, earning 8,800+ GitHub stars on day one
  • 94% of login attempts are now bots per Cloudflare's latest threat data — credential-based authentication is fundamentally broken at internet scale
  • 1 in 5 organizations are deploying autonomous agent frameworks or MCP servers in production, per Snyk's AI-BOM telemetry (noting sample bias toward early adopters)
  • Organizations tracking only AI models are blind to ~67% of their actual AI attack surface — embedded agents, MCP servers, and tool integrations constitute 3x the footprint of models alone

Every AI agent connected via MCP to your enterprise data stores is effectively a non-human identity with data access that likely wasn't provisioned through your IAM process, wasn't scoped to least privilege, and has no human sponsor accountable for its permissions.


The Attack Taxonomy Is Crystallizing

The industry is converging on four primary AI agent attack vectors:

VectorMechanismDetection Maturity
Prompt InjectionMalicious instructions override system promptsLow — most orgs lack runtime validation
Agent HijackingTaking control of execution flow or tool-calling chainVery Low — novel attack class
Multimodal AttacksExploiting agents processing images/audio alongside textVery Low — defenses are text-focused
Living off the XaaSC2 embedded in trusted SaaS (Google Calendar, etc.)Low — network detection sees legitimate API calls

A parallel threat compounds this: browser extensions masquerading as VPNs and ad blockers are intercepting verbatim AI chat sessions — prompts and responses containing health data, legal issues, and corporate secrets — and feeding them to data brokers who resell them as searchable datasets. This creates HIPAA, GDPR, and trade secret exposure through a vector most organizations haven't considered.

Observability Toolchain in Flux

Four agent observability startups were acquired in rapid succession — Invariant Labs (by Snyk), Aporia (by Coralogix), HumanLoop (by Anthropic), and Langfuse (by ClickHouse). If you built detection workflows on these tools, your vendor risk profile just changed. Datadog is identified as the next likely consolidator.

Your IAM, SDLC, and detection stack was built for humans — AI agents access the same systems through APIs, CLIs, and MCP servers with different traffic patterns, session behaviors, and audit signatures. If your detection logic is tuned for human access patterns, you have a growing blind spot.

What to do

  1. Inventory all AI agent identities across your environment within 2 weeks: MCP connections, OAuth tokens granted to CLI tools, service accounts for AI agents, and API keys used by coding assistants

  2. Audit Google Workspace OAuth scopes and block unapproved CLI/programmatic access patterns; restrict Admin scope grants to approved principals

  3. Audit and enforce browser extension allowlists across managed endpoints, specifically targeting extensions with blanket URL access claiming VPN or ad-blocking functionality

  4. Establish a non-human identity governance policy this quarter requiring dedicated service accounts, least-privilege scoping, human sponsors, and periodic access reviews for all AI agents

The bottom line

Cisco SD-WAN CVSS 10.0 has been exploited for 8+ days, attacker breakout-to-exfiltration has collapsed to 6 minutes, state actors are converting years of OT access into weapons, and your AI agents are accumulating unmanaged enterprise permissions faster than any governance framework can track them — if your organization can't automatically contain a high-confidence detection within 5 minutes, the data is already gone.