Security & Threat Intelligence

The Watch

The Signal

A DigitalMint ransomware negotiator allegedly ran ALPHV/BlackCat attacks against

Three employees at the same IR firm were operating ransomware simultaneously. If you haven't audited your incident response vendor for conflict-of-interest provisions and employee criminal background checks, your trusted defender may be your most dangerous adversary.

In Play

  1. Your Incident Responder Was the Attacker: $75.25M DigitalMint Insider Scheme

    A ransomware negotiator at DigitalMint allegedly attacked victims with ALPHV/BlackCat then served as their 'trusted advisor,' extracting $75.25M. Two colleagues already pled guilty. This is systemic third-party IR vendor compromise — not a rogue actor.

    Ask Clarity
  2. Critical Infrastructure Vulns: HPE Aruba CX Admin Takeover + n8n CISA KEV

    HPE Aruba CX switches have a near-CVSS-10 unauth password reset enabling full admin takeover. Simultaneously, CISA added n8n to KEV with 24,700 instances still exposed, and SAP is patching a 7-year-old critical RCE. March Patch Tuesday adds 12 more.

    Ask Clarity
  3. Iranian Multi-Front Cyber Escalation: Stryker Wiped, 10 ISACs Warn, Targets Named

    Pro-Iran hacktivist Handala wiped devices across medical giant Stryker's global network. 10 ISACs issued a joint 'highly volatile' threat warning. Iran publicly named Google, Microsoft, Palantir, IBM, and Nvidia as targets. First confirmed cyberattack on a US firm has landed.

    Ask Clarity
  4. Internal AI Platforms Failing OWASP Basics at Scale

    McKinsey's AI platform Lilli fell to unauthenticated SQLi in 2 hours, exposing 46.5M chat messages and 728K files. An autonomous AI agent found and exploited it. Separately, CodeWall's agent chained 4 low-severity bugs to gain admin. AI offensive tooling is outpacing AI platform security.

    Ask Clarity
  5. Cyber Insurance Now Prices Your AI Posture

    Insurers are creating two-tier pricing: defensive AI use (threat detection, automated response) lowers premiums, while ungoverned AI deployments raise them. This creates a direct financial feedback loop that CISOs can leverage to justify AI security investment with the CFO.

    Ask Clarity

Deep Dives

When Your Ransomware Negotiator IS the Ransomware Operator: The DigitalMint Betrayal

The Scheme That Should Rewrite Your IR Vendor Contracts

Angelo John Martino III, a 41-year-old ransomware negotiator at DigitalMint, stands accused of conducting at least 10 ALPHV/BlackCat ransomware attacks while simultaneously serving as the trusted intermediary companies hired to negotiate their way out. Federal authorities allege he extorted $75.25 million, with individual payments reaching $26.8 million and $25.7 million — numbers that only make sense when the attacker has perfect intelligence on the victim's insurance limits, backup status, and pain threshold.

This wasn't a lone wolf. Two other DigitalMint employees — Kevin Tyler Martin and Ryan Clifford Goldberg — already pleaded guilty in December 2025 to similar attacks. They face sentencing April 30. Three employees at the same firm, all running ransomware operations while being paid to stop them.


How the Dual-Role Attack Model Worked

Map this to your incident response workflow and the picture is devastating:

  1. Initial compromise: Martino allegedly deployed ALPHV/BlackCat via standard affiliate vectors (compromised VPNs, phishing, credential abuse)
  2. Victim engages DigitalMint: At least 5 confirmed companies hired Martino's own employer to negotiate on their behalf
  3. Intelligence harvesting: Through the negotiation process, Martino allegedly accessed financial details, backup status, insurance coverage, and business continuity timelines
  4. Calibrated extortion: Armed with insider knowledge, demands were tuned for maximum extraction — far above the ransomware average
The ultimate social engineering: the attacker is positioned as the defender, and the victim voluntarily shares their most sensitive recovery information.

Why Your Current Vendor Controls Likely Failed

Most IR retainer agreements focus on response time SLAs, scope of services, and hourly rates. They rarely address:

  • Conflict-of-interest provisions and information barriers between offensive/intelligence teams and negotiation teams
  • Employee criminal background check requirements, including ongoing monitoring
  • Data compartmentalization — what information the vendor can access and how it's segregated
  • Attestation that no employees have active cybercrime investigations

Martino was released on $500K bond and banned from cybersecurity work. $9.2M in cryptocurrency and $2M+ in real estate and vehicles were seized. He faces up to 20 years. But the damage to the IR vendor trust model is already done.

The Broader Pattern

This cycle also surfaced the confirmed SSA data exfiltration via thumb drive by a DOGE engineer, proving removable media controls fail even in federal environments handling the most sensitive PII in government. The common thread across both incidents: privileged insiders with trusted access exploiting the trust itself. Your vendor is only as trustworthy as their least-vetted employee.

What to do

  1. Audit all IR retainer and ransomware negotiation vendor agreements for conflict-of-interest provisions, information barriers, and employee background check requirements by end of this sprint

  2. Compartmentalize information shared with negotiation firms — never provide a single vendor with simultaneous visibility into insurance limits, recovery timeline, and financial position

  3. Add conflict-of-interest certification to all cybersecurity vendor contracts requiring vendors to attest no employees have active criminal investigations related to cybercrime

  4. Brief board or senior leadership on the DigitalMint case as a concrete third-party risk scenario to justify enhanced vendor due diligence budget

Emergency Patch Sprint: HPE Aruba CX Admin Takeover, n8n on CISA KEV, and a 7-Year-Old SAP Bomb

Three Critical Vulnerabilities Demand Parallel Action

This cycle delivers a multi-front active exploitation scenario hitting network infrastructure, workflow automation, and enterprise ERP simultaneously. Any one of these warrants an emergency change window.

HPE Aruba CX Switches: Unauthenticated Admin Takeover (~CVSS 10.0)

An unauthenticated password reset flaw in HPE Aruba CX enterprise switches lets any network-reachable attacker seize admin control without credentials. No user interaction required. Aruba CX switches are widely deployed across campus, data center, and spine-leaf architectures. A compromised core switch enables traffic interception, VLAN hopping, ARP poisoning, and lateral movement that bypasses every application-layer control you've deployed. Your EDR, WAF, and CASB are irrelevant here — this is network-layer compromise. Four independent intelligence streams confirm this vulnerability and its severity.

n8n Workflow Automation: RCE + Credential Theft (CISA KEV)

Two critical n8n flaws enabling arbitrary command execution and stored credential exposure are now on CISA's Known Exploited Vulnerabilities catalog — confirming active exploitation in the wild. There are 24,700 instances still internet-facing. n8n workflows typically store OAuth tokens, API keys, and database credentials. A single compromised instance cascades across your entire integration fabric. Shadow IT risk is acute — developers self-host n8n without security team visibility.

SAP CVE-2019-17571: Seven Years and Still Critical

SAP released critical patches including for a vulnerability originally disclosed in 2019. The fact this CVE is still receiving critical patches in 2026 means SAP knows it persists in production environments. This is technical debt as active exploitation risk, with direct SOX compliance implications if SAP handles financial reporting.

March 2026 Patch Tuesday: 3 Office + 9 Azure, Zero Zero-Days

The silver lining: zero zero-days this cycle. But three high-severity Office vulnerabilities are prime candidates for weaponized phishing documents within days. Nine Azure patches often slip through because cloud teams don't follow traditional Patch Tuesday cadences.

VulnerabilitySeverityStatusPatch Target
HPE Aruba CX unauth reset~CVSS 10.0Disclosed, imminent exploitationEmergency (48 hours)
n8n RCE + credential theftCriticalActive (CISA KEV)Immediate
SAP CVE-2019-17571CriticalPatch available7 days
MS Office (3 vulns)HighNo zero-days72 hours
MS Azure (9 vulns)VariableNo zero-days14 days

What to do

  1. Query CMDB for all HPE Aruba CX switches and apply vendor patches or restrict management interfaces to MFA-protected jump hosts via ACLs within 48 hours

  2. Run external attack surface scan for n8n instances (default port 5678), patch all instances, and rotate every credential stored in n8n workflows immediately

  3. Deploy March Patch Tuesday Office updates across all endpoints within 72 hours, prioritizing the 3 high-severity vulnerabilities

  4. Schedule SAP emergency patching for CVE-2019-17571 within 7 days; if blocked by change management, deploy WAF rules and segment SAP systems as compensating controls

Iranian Cyber Escalation Goes Kinetic-to-Digital: Stryker Wiped, 10 ISACs Warn, Tech Giants Named

Three Simultaneous Escalation Signals

The Iranian cyber threat crossed from geopolitical posturing to operational impact this cycle. Three developments, from four independent intelligence streams, form a coherent escalation pattern that demands heightened monitoring.

1. Handala Wipes Stryker's Global Fleet

Pro-Iran hacktivist group Handala claimed a destructive cyberattack against Stryker, one of the world's largest medical device manufacturers ($18B+ revenue). Employee reports describe wiped devices and defaced login screens across Stryker's global network. This wasn't ransomware or data theft — it was destruction for geopolitical messaging (MITRE T1485 Data Destruction, T1491 Defacement). The healthcare implications are critical: Stryker manufactures surgical equipment, implants, and connected devices. A compromised update pipeline could affect device integrity downstream — this is a patient safety concern, not just an IT event.

2. Ten ISACs Issue Joint Warning

Ten information-sharing groups including the Water ISAC issued a joint advisory describing a "highly volatile" threat environment with expected escalation from Iranian state-sponsored actors, hacktivists, and cybercriminals following U.S. and Israeli military strikes on Iran. This level of cross-sector coordination is unusual and signals shared intelligence that isn't fully public yet.

3. Iran Names Specific US Companies

Iran has publicly identified Google, Microsoft, Palantir, IBM, and Nvidia as potential targets. CNN confirmed the conflict's first major cyberattack against a US firm has already occurred. Declared intent backed by demonstrated capability — the blast radius extends to the entire customer and partner ecosystems of these five companies.

When kinetic conflict escalates in the Gulf, cyber operations follow within weeks — and this time, the cyber arrived before the shooting stopped.

Historical Pattern and Expected TTPs

Iranian APT groups (APT33/Elfin, APT34/OilRig, CyberAv3ngers) have established playbooks during prior escalations: spear-phishing with credential harvesting, VPN and edge-device exploitation, OAuth token abuse targeting cloud tenants, and destructive wiper deployment (ZeroCleare, Shamoon lineage). CyberAv3ngers have previously demonstrated capability against Unitronics PLCs in water utilities.

New York Regulatory Response

New York enacted first-in-nation cybersecurity regulations for water/wastewater requiring complete OT/IT separation, MFA, incident reporting, and vulnerability management — with a $2.5M SECURE grant program. This sets the template other states will adopt. Full OT/IT air-gapping for a mid-size utility will cost multiples of the $100K implementation grants offered.

What to do

  1. Conduct supply chain impact assessment for Stryker products within 48 hours — identify any Stryker devices, software, or services in your environment and assess firmware update integrity

  2. Update SOC watchlists with Iranian APT IOCs (APT33, APT34, CyberAv3ngers) and TTPs — prioritize detection of OAuth token abuse, VPN exploitation, and wiper indicators

  3. Map organizational dependencies on Google, Microsoft, Palantir, IBM, and Nvidia and document in BCP — identify which services create exposure if these vendors experience destructive attacks

  4. If operating OT/ICS environments (water, energy, manufacturing): map all OT/IT network pathways and begin planning for unidirectional gateway architecture, using NY regulation as template

McKinsey Lilli Breach Proves Your Internal AI Platforms Are Your Most Unaudited Attack Surface

A $500M Consulting Firm's AI Platform Fell to a 1998-Era Vulnerability

CodeWall's autonomous AI security agent exploited an unauthenticated SQL injection in McKinsey's internal AI platform Lilli, achieving full read/write database access within two hours. The blast radius: 46.5 million chat messages, 728,000 sensitive files, and McKinsey's entire proprietary RAG knowledge base. This wasn't a sophisticated zero-day chain — it was OWASP A03:2021 (Injection), the vulnerability class we've been fighting since 1998.

The attack chain was devastatingly simple:

  1. Unauthenticated API endpoint — no login required
  2. Classic SQL injection — arbitrary database queries
  3. Flat data architecture — all sensitive data in one database
  4. Full compromise in under 120 minutes by an automated agent, not a human
McKinsey is not a small shop with no security budget. If their AI platform shipped with zero authentication on a SQL-injectable endpoint, what does your internal AI platform look like?

AI Offensive Tools Are Now Production-Grade

Three data points converge into a single pattern this cycle:

Tool/IncidentWhat HappenedTime to Compromise
CodeWall vs. McKinsey LilliAutonomous SQLi discovery and exploitation2 hours
CodeWall vs. hiring platformChained 4 low-severity bugs to admin accessAutonomous
Researcher vs. Perplexity CometAI browser tricked into executing phishing4 minutes

The implication is direct: severity-only vulnerability triage is now demonstrably insufficient. Your backlog of risk-accepted low/medium findings may contain exploitable chains that an AI-equipped attacker will find. And AI platforms themselves — the ones your data science team built in Q3 that ingest documents across the organization into a single RAG datastore — are likely running with the same basic security gaps McKinsey's did.

The Broader AI Security Gap

OpenAI this cycle formally acknowledged that prompt injection against AI agents is functionally equivalent to social engineering — and recommended shifting defenses from input filtering to blast-radius limitation. Simultaneously, Cursor added 30+ marketplace plugins with read/write access to developer tools, Replit Agent 4 runs parallel agents with database access, and Perplexity launched a local-machine AI orchestrator. Each creates data flow paths and credential access patterns your existing controls don't cover.

The uncomfortable truth: AI platform security is being left to data science teams who optimize for capability, not to security teams who optimize for control.

What to do

  1. Conduct emergency security assessment of all internal AI/LLM/RAG platforms for OWASP Top 10 vulnerabilities within 14 days — starting with authentication gaps and injection flaws

  2. Classify and segment AI platform datastores — ensure RAG knowledge bases and chat logs don't aggregate data across classification levels into single flat repositories

  3. Reassess vulnerability management methodology to account for AI-driven chaining of low-severity bugs into critical exploit paths

  4. Draft organizational policy on agentic AI browser tools (Perplexity Comet, Auto-GPT with browsing) — restrict to sandboxed environments, prohibit corporate credential use

The bottom line

A ransomware negotiator at DigitalMint allegedly attacked his own clients then served as their 'trusted advisor' to extract $75.25M — while a near-CVSS-10 unauthenticated admin takeover in HPE Aruba CX switches and 24,700 exposed n8n instances on CISA's KEV demand emergency patching, Iran-linked Handala wiped Stryker's global network prompting a 10-ISAC joint threat warning, and McKinsey's internal AI platform fell to basic SQL injection in two hours exposing 46.5 million messages — the through-line is that your IR vendors, your network switches, your nation-state adversaries, and your AI platforms all need the same thing today: zero trust applied to the entities you assumed you could trust.