Security & Threat Intelligence

The Watch

The Signal

MuddyWater's new Dindoor backdoor has been confirmed inside US banks, airports

Simultaneously, VMware Aria Operations and Cisco Secure Firewall Management Center both have unauthenticated RCE vulnerabilities under active exploitation or at CVSS 10/10, and 100,000+ n8n automation servers are exposed with a sandbox-escape-to-root flaw.

In Play

  1. Iran's Dual-Domain War: Dindoor in US Banks + Drones Hit AWS

    MuddyWater confirmed inside US banks, airports, and non-profits via new Dindoor backdoor. Iranian drones physically destroyed an AWS Gulf data center — first kinetic strike on a US hyperscaler. Iranian groups are mass-scanning Hikvision/Dahua cameras across six countries for missile targeting. Israel reportedly bombed Iran's Cyber and Electronic Warfare HQ in Tehran.

    Ask Clarity
  2. New Critical CVEs: VMware Aria RCE, Cisco FMC 10/10, 100K n8n Exposed

    VMware Aria Operations CVE-2026-22719 is an unauth RCE confirmed exploited 10 days after patch — now in CISA KEV. Cisco shipped 27 advisories including two CVSS 10/10 Secure Firewall Management Center bugs. Over 100K n8n AI automation servers remain internet-exposed with CVE-2026-27495 enabling sandbox escape to full host compromise. CVE-2026-0628 lets Chrome extensions hijack Gemini for camera, mic, and file access.

    Ask Clarity
  3. AI Supply Chain Weaponized: Prompt Injection → npm Token → 4,000 Machines

    A prompt injection in a GitHub issue title hijacked an AI triage bot, stole an npm publish token, and trojanized Cline — compromising ~4,000 developer machines with OpenClaw malware. Separately, GPT-5.4 scored 75% on OSWorld (above 72.4% human baseline), making AI-driven desktop exploitation viable. Nemesis 2.2 now automates Chrome 137+ App-Bound Encryption bypass for full credential theft. The Shai-Hulud worm hit thousands of npm packages.

    Ask Clarity
  4. 2025 Zero-Day Report: Enterprise Targeting Highest Ever, Malvertising Overtakes Email

    Google Mandiant tracked 90 zero-days exploited in 2025. Nearly half targeted enterprise infrastructure — the highest share ever recorded. Browser exploitation dropped while network device zero-days surged to 23%. Separately, malvertising surpassed email as the #1 malware delivery vector at 60% of all observed campaigns. State-sponsored groups and commercial spyware vendors each accounted for one-third of zero-day usage.

    Ask Clarity

Deep Dives

Iran's Dual-Domain War: Dindoor Backdoor Inside US Critical Infrastructure While Drones Destroy Cloud Data Centers

Situation Overview

An unprecedented convergence of cyber and kinetic warfare is targeting US infrastructure simultaneously. Symantec and Carbon Black have jointly confirmed that Iranian APT MuddyWater (Seedworm) has deployed a previously unknown backdoor called Dindoor inside at least one US bank, one airport, one non-profit, and the Israeli branch of a US software company. This is not a warning about future activity — they are already inside. In parallel, Iranian drones physically struck an AWS data center in the Gulf region (me-south-1, Bahrain), the first confirmed military attack on a US hyperscaler's infrastructure.


Three Iranian Attack Vectors Operating Simultaneously

1. Dindoor: Pre-Positioned Access in US Critical Infrastructure

MuddyWater's Dindoor backdoor likely replaces or augments their previously known implants, meaning existing detection signatures may not cover it. The Ctrl-Alt-Intel team separately dumped contents from misconfigured MuddyWater C2 servers, providing fresh IOCs. Confirmed victim sectors — banking, aviation, non-profit — suggest intelligence collection and pre-positioning for retaliatory operations, consistent with Iran's historical pattern during geopolitical escalation.

2. Camera Networks as Battlefield Intelligence

Iranian state-linked groups have spiked scanning of internet-exposed Hikvision and Dahua cameras across Israel, Qatar, Bahrain, Kuwait, UAE, and Cyprus — the exact countries involved in kinetic strikes. They are exploiting old, already-patched vulnerabilities, meaning the only victims are organizations with firmware patch lag. Multiple sources confirm this tactic is now mature and multi-actor: Russia has used it across Ukraine for four years, Israel reportedly operated a data center collecting Tehran camera feeds, and even Hamas used camera hacking operationally.

Internet-exposed cameras from Hikvision and Dahua are effectively unintentional SIGINT platforms. Hundreds of exploitation attempts have been logged since recent missile strikes.

3. Kinetic Targeting of Cloud Infrastructure

The Iranian drone strike on Amazon's Bahrain data center explicitly cited the company's "support of US military and intelligence activities." This crosses a threshold: cloud providers' shared responsibility model assumed natural disasters and criminal actors, not state-directed military strikes targeting commercial cloud. Reports indicate debris also struck civilian buildings in Dubai. Most cyber insurance policies contain war exclusion clauses that likely apply.


Geopolitical Context

Iran's Supreme Leader was killed in an Israeli airstrike. Iran has closed the Strait of Hormuz (20% of global oil). Iran's foreign minister says no ceasefire. Israel reportedly bombed Iran's Cyber and Electronic Warfare HQ in Tehran — if confirmed, the first known kinetic strike on a nation's cyber command center. Iranian cyber units may be operating under disrupted coordination, making them more unpredictable. DHS Secretary Noem was fired and replaced by someone with no cybersecurity background, creating a CISA coordination gap during the highest-threat period in years.


Parallel Chinese APT Activity

While Iran dominates the threat picture, a China-linked APT has been operating inside South American telecommunications infrastructure since 2024 using three cross-platform tools: TernDoor, PeerTime, and BruteEntry — targeting Windows, Linux, and edge devices. The FBI also confirmed suspicious activity on networks managing wiretaps and FISA warrants, potentially linked to Salt Typhoon's 2024 campaign. A senior State Department official confirmed China is actively executing harvest-now-decrypt-later campaigns against encrypted data.

What to do

  1. Initiate a Dindoor threat hunt using Broadcom and Ctrl-Alt-Intel published IOCs — prioritize financial services, aviation, and non-profit environments

  2. Audit and patch all Hikvision and Dahua camera firmware; segment camera VLANs from corporate networks with no internet exposure

  3. Validate multi-region DR plans for any cloud workloads in Middle East AWS/Azure/GCP regions — run a tabletop assuming complete region destruction

  4. Review cyber insurance war exclusion clauses with your broker — specifically Lloyd's Y5381 language on state-backed attacks

  5. Elevate SOC monitoring for Iranian APT TTPs: spearphishing with geopolitical lures, VPN/edge device exploitation, and PowerShell-based lateral movement

Patch Triage: VMware Aria RCE, Cisco FMC 10/10, and 100K Exposed n8n Servers

New Critical Vulnerabilities Requiring Immediate Action

Beyond the Cisco SD-WAN vulnerabilities reported previously (now with two additional CVEs confirmed exploited), three distinct critical vulnerabilities emerged today that demand emergency patching. These are separate from Friday's advisory coverage and represent new active exploitation or maximum-severity threats.


VMware Aria Operations — CVE-2026-22719 (Actively Exploited)

An unauthenticated remote code execution vulnerability via command injection in VMware Aria Operations was patched on February 24 — and is already being exploited in the wild just 10 days later. CISA added it to KEV. If you run Aria Operations (formerly vRealize Operations), your management interface is an active target. The attack requires no credentials — only network reachability to the management plane.

Cisco Secure Firewall Management Center — Two CVSS 10/10

Cisco's 27-advisory batch release this cycle includes two perfect 10.0 CVSS scores in Secure Firewall Management Center (FMC). Your firewall management plane — the system that controls your entire perimeter defense — has critical vulnerabilities. Details are still emerging, but CVSS 10 means unauthenticated, remote, with maximum impact. This comes alongside the Cisco firewall web management interface vulnerabilities granting unauthenticated remote root access reported by multiple sources — no credentials needed, full device compromise.

When your firewall management plane has two CVSS 10 vulnerabilities in the same advisory cycle, the question isn't 'when do we patch' — it's 'are we already compromised.'

n8n Automation — CVE-2026-27495 (100K+ Exposed)

The n8n AI workflow automation platform has a critical sandbox escape vulnerability that escalates to full host compromise in default configuration. Over 100,000 n8n instances remain internet-exposed and unpatched. This is a shadow IT problem — engineering teams deploy n8n without security review. One source notes the default configuration is vulnerable, meaning most exposed instances are likely exploitable.

Chrome Gemini Panel — CVE-2026-0628

Chrome extensions with basic, already-granted permissions can hijack Chrome's Gemini AI panel and access the device's camera, microphone, local files, take screenshots of any HTTPS site, and launch phishing attacks. No additional user consent required. The blast radius is enormous given Chrome's enterprise dominance and Gemini's default enablement in growing deployments.


Consolidated Patch Priority Matrix

CVEProductCVSSStatusDeadline
2x unnamedCisco Secure FMC10.0Patch available24 hours
CVE-2026-22719VMware Aria OpsCriticalCISA KEV, exploited24 hours
CVE-2026-27495n8n automationCritical100K+ exposed48 hours
CVE-2026-0628Chrome/GeminiHighPatch available48 hours
CVE-2026-20127/28/22Cisco SD-WANHigh-CriticalAll actively exploited24 hours

What to do

  1. Patch VMware Aria Operations against CVE-2026-22719 immediately; if maintenance window required, restrict management interface to dedicated management VLAN with MFA-protected jump hosts

  2. Apply Cisco Secure FMC patches for both CVSS 10/10 vulnerabilities and audit management interface exposure — no FMC web interface should be reachable from untrusted networks

  3. Run emergency asset discovery for n8n instances across your environment — patch CVE-2026-27495 and remove all internet-exposed instances immediately

  4. Patch Chrome fleet-wide and evaluate disabling Gemini AI panel via Chrome Enterprise policy unless explicitly risk-accepted

The Cline Attack Is a Landmark: AI Agents in Your SDLC Are Now Proven Supply Chain Weapons

A New TTP Class Is Now Confirmed at Scale

On February 17, 2026, an attacker crafted a prompt injection payload inside a GitHub issue title. An AI triage bot read it, interpreted the injected prompt as an instruction, and executed it — exfiltrating the project's npm publish token. The attacker used the stolen token to publish a trojanized Cline package to npm, installing the OpenClaw malware on approximately 4,000 developer machines before detection. A patch was deployed within 30 minutes of public disclosure, but critically, compromised API keys were not rotated, leaving a post-patch exploitation window.

Every AI bot in your SDLC with access to secrets is a prompt injection away from becoming an insider threat — and the Cline attack just proved it at scale.

Why This Matters Beyond One Incident

The Cline attack establishes prompt injection against AI development automation as a proven initial access technique. Map it to MITRE ATT&CK: Supply Chain Compromise (T1195.002) via a novel sub-technique — using prompt injection against AI-powered bots to achieve Credential Access (T1552). The AI bot is both the vulnerability and the exploitation mechanism. This attack chain applies to every organization running AI triage bots, PR reviewers, or CI/CD agents that process untrusted user input and have access to secrets.

Compounding Threat: GPT-5.4 Superhuman Desktop Control

Released March 6, GPT-5.4 scored 75% on OSWorld-Verified — above the 72.4% human baseline — for autonomous desktop navigation. Combined with a 1M-token context window and "x-high" reasoning enabling multi-hour autonomous execution, this means AI agents can now navigate operating systems, harvest credentials from password managers, perform GUI-based lateral movement (bypassing network-layer EDR), and execute patient low-and-slow operations at zero marginal cost. Your behavioral detection stack — keystroke cadence, session duration patterns, task timing — was calibrated against human operators. That calibration is now obsolete.

Nemesis 2.2: Post-Compromise Credential Theft Automated

Nemesis 2.2 now automates the complete Windows DPAPI decryption chain including Chrome 137+'s App-Bound Encryption bypass. It accepts SYSTEM masterkeys, user masterkeys, CNG keys, offline registry hives, LSASS dumps, and domain backup keys. The critical escalation: submitting a domain DPAPI backup key to Nemesis unlocks all existing and future masterkey blobs across the entire domain. This makes the domain backup key a Tier 0 asset — single point of compromise with retroactive and forward-looking impact.

Chrome Extension Supply Chain: Zero Vetting on Ownership Transfers

Research reveals Chrome extension developers can sell extensions to new owners with zero vetting by Google. The Quick Lens extension (7,000 users, Google-featured) was sold and immediately weaponized with C2 infrastructure, security stripping, and pixel-perfect man-in-the-browser capability — pushed silently via auto-update. Your extension allowlist is a point-in-time snapshot, not a continuous control.


The Pattern: AI Agents Are the New Unmanaged Principals

Cursor's cloud agents run in full VMs with stored secrets, MCP integrations to Datadog and Slack, and can run for up to three continuous days creating PRs and tagging humans. Agent-generated code has already broken Cursor's own CI/CD pipeline under volume. The company is exploring agents that edit their own system prompts and plans to enable recursive agent spawning. Industry data shows 99% of dev teams use AI code assistants but only 29% have formal AI security controls — a 70-point gap.

What to do

  1. Hunt for Cline/OpenClaw exposure: query endpoint telemetry for Cline npm installations from mid-February 2026, force-rotate all API keys and tokens Cline had access to

  2. Inventory every AI bot in your SDLC that processes untrusted input (issue titles, PR descriptions, commit messages) and has access to secrets — document each one's access scope and input sanitization posture

  3. Protect your domain DPAPI backup key as a Tier 0 asset: restrict access to Domain Admins with PAW-enforced access and deploy SIEM alerts on any access to masterkey blob enumeration patterns

  4. Conduct an emergency Chrome extension audit: cross-reference ownership/developer changes in the last 12 months and implement continuous monitoring for extension ownership transfers

  5. Stress-test CI/CD security gates (SAST, SCA, secrets scanning) under 5-10x current PR volume to verify they don't silently fail under agent-generated load

The bottom line

Iranian cyber operators are confirmed inside US banks and airports with a new backdoor during a shooting war that has physically destroyed an AWS data center, your firewall management plane has two CVSS 10/10 vulnerabilities in the same advisory cycle, and a prompt injection in a GitHub issue title just proved that every AI bot with access to secrets is a supply chain weapon — the question isn't which to address first, it's whether your segmentation and hunt teams are already running.