Security & Threat Intelligence

The Watch

The Signal

Ransomware actors have abandoned encryption for pure data theft

If your ransomware defense strategy still centers on backups and recovery, you're protecting against a declining threat model.

In Play

  1. Ransomware Pivots to Data Theft at Machine Speed

    Encryption dropped from 54% to 36% of ransomware cases while exfiltration surged to 77%. HexStrike mass-exploited Citrix in <10 minutes. VMware ESXi targeted in 43% of cases (up from 29%). Edge devices (Fortinet, SonicWall, PAN, Citrix) account for 33% of initial access; stolen creds another 21%.

    Ask Clarity
  2. Critical Vulnerability Convergence: Emergency Patch Week

    CrackArmor exposes 9 AppArmor CVEs enabling container escape and root escalation on every major Linux distro and Kubernetes since 2017. Veeam dropped three CVSS 9.9 backup infrastructure patches. Chrome has one zero-day actively exploited with a second unpatched. Cisco SD-WAN has three under active exploitation with a fourth imminent.

    Ask Clarity
  3. Developer Supply Chain Under Simultaneous Multi-Vector Attack

    81 PhantomRaven npm packages are live right now, abusing Remote Dynamic Dependencies to steal CI/CD tokens at install time. GlassWorm's 72 poisoned VSCode extensions are feeding stolen GitHub creds into ForcedMemo, which has injected crypto-stealers into hundreds of Python repos since March 8. AppsFlyer SDK was compromised to hijack crypto wallet addresses. DPRK uploaded PylangGhost RAT via npm.

    Ask Clarity
  4. Defensive Infrastructure Weaponized: MDM + AI Platforms Breached

    Iranian actors weaponized Stryker's Microsoft Intune to mass-wipe 200K devices across 79 countries — no malware needed, just admin access abuse. Separately, CodeWall's $20 AI agent exploited a trivial SQLi in McKinsey's Lilli platform in 2 hours, accessing 46.5M chats with write access to AI behavior instructions. Both attacks turned trusted tools into weapons.

    Ask Clarity
  5. Adversary AI Capabilities Accelerating

    AI-generated malware is now in active ransomware campaigns (Hive0163's Slopoly backdoor). 'Promptmorphism' generates polymorphic variants at scale. CAICT found reasoning models produce 200% more harmful output under adversarial prompts. PostTrainBench showed AI agents autonomously modify evaluation frameworks and contaminate training data. Inference scaling measurably boosts cyber-offensive success.

    Ask Clarity

Deep Dives

Ransomware Actors Stopped Encrypting and Started Stealing — Your Defense Model Is Obsolete

The Business Model Flip

The ransomware economy just completed a fundamental strategic pivot that invalidates most organizations' primary defense investment. Data exfiltration now occurs in 77% of intrusions (up from 57%), while successful encryption deployment dropped from 54% to 36%. Leak site posts surged 48% to 7,784. The message from threat actors is clear: why bother encrypting when you can steal data and extort the victim with exposure threats?

This means your carefully architected backup and recovery strategy — the one your board approved as your ransomware defense — is solving for a declining threat model. The new attack chain ends with "we have your data and we're posting it in 72 hours," not "pay us to decrypt your files."


The Speed Problem Is Existential

Threat actor HexStrike exploited thousands of Citrix Netscaler products in under 10 minutes using a single CVE. CISA's typical patch timeline is 15 days. That's not a gap — it's a chasm measured in orders of magnitude. Booz Allen Hamilton's new report frames this as proof that threat actors have adopted AI faster than defenders, identifying two emerging paradigms:

  • Amplifier model: LLMs assist human operators to run recon across dozens of targets simultaneously — operational today and explains HexStrike-class speed
  • Orchestration model: AI agents execute attack chains autonomously with set parameters — emerging and represents the next escalation

Where They're Getting In

Exploited vulnerabilities in Fortinet, SonicWall, Palo Alto Networks, and Citrix VPNs and firewalls account for one-third of all ransomware initial access. Stolen credentials provide another 21%. That's over half of all entry points concentrated in two controllable vectors. Meanwhile, VMware ESXi hypervisors were targeted in 43% of ransomware cases (up from 29%) — attackers compromise one hypervisor, destroy dozens of VMs, and wipe forensic evidence.

The initial access broker market has commoditized to the point where most hacked networks sell for under $3,000, with valid accounts lacking MFA as the dominant product category.

What Cross-Source Analysis Reveals

Multiple intelligence streams this week confirm the same pattern from different angles: the cybercrime infrastructure is industrializing. AI-generated malware is now in active ransomware campaigns — IBM X-Force reports Hive0163 deployed Slopoly, an AI-generated backdoor. Gen Digital researchers documented "promptmorphism" — using AI to rapidly generate unique polymorphic variants, dramatically accelerating signature evasion. Combined with the sub-$3K IAB market, the economics now favor attackers who can move from purchase to exfiltration in hours.

What to do

  1. Shift ransomware defense model from recovery to data theft prevention: deploy or enhance egress DLP, establish data movement baselines, and build a data-extortion-specific IR track with legal/comms/regulatory workflows

  2. Emergency audit all internet-facing Fortinet, SonicWall, Palo Alto, and Citrix appliances against CISA KEV catalog; deploy virtual patches for any CVE you cannot patch within 48 hours

  3. Harden VMware ESXi as Tier 0: isolate management to dedicated VLAN, enable lockdown mode, forward all logs to SIEM (attackers destroy local forensic evidence), restrict SSH and vMotion

  4. Stress-test SOC detection-to-containment workflows against a 10-minute full-chain exploitation scenario modeled on HexStrike; identify where human triage creates fatal bottlenecks

Emergency Patch Convergence: CrackArmor, Veeam 9.9s, Chrome Zero-Day, and Cisco SD-WAN Hit Simultaneously

This Is Not a Normal Patch Week

Five distinct critical vulnerability sets dropped simultaneously, each targeting a different layer of your stack. The combination demands cross-functional triage — your Linux team, backup team, browser fleet, network team, and Windows admins all have emergency work today.


CrackArmor: Container Escape Since 2017

Nine vulnerabilities in AppArmor — the kernel security module enforcing container isolation — enable root escalation and container escape across every major Linux distro and Kubernetes since 2017. Ubuntu, Debian, SUSE, and all Kubernetes clusters running AppArmor are affected. A public technical write-up is available, meaning weaponization is expected imminently. This has been silently exploitable for seven years — assume adversaries with kernel exploit capabilities are already aware.

Veeam: Your Backup Infrastructure Is the Target

Veeam patched five vulnerabilities including three at CVSS 9.9/10. This is near-total compromise of backup infrastructure — the exact system ransomware operators target first. With ransomware actors pivoting to data theft (77% exfiltration rate), compromised backup infrastructure provides both the data and the leverage. No exploitation reported yet, but the combination of Veeam + active ransomware campaign data makes this a race condition.

Chrome: One Patched, One Pending

Google patched one actively exploited Chrome zero-day, but a second zero-day mentioned in initial patch notes was removed and remains unpatched — fix expected later this week. Force the available update fleet-wide now and prepare rapid deployment for the second patch.

Cisco SD-WAN + Windows RRAS

Three Cisco SD-WAN vulnerabilities are under active exploitation, and VulnCheck expects CVE-2026-20133 to be targeted imminently. Separately, Microsoft re-released hotpatch KB5084597 for three RRAS RCE flaws (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) — the re-release indicates the initial patch may have failed silently.

VulnerabilitySeverityExploitation StatusAction
CrackArmor (9 CVEs)CriticalWrite-up public; weaponization expectedPatch all Linux/K8s immediately
Veeam (3 of 5 CVEs)CVSS 9.9No exploitation yetEmergency patch; verify backup integrity
Chrome zero-dayHighActively exploitedForce update fleet-wide now
Cisco SD-WAN (4 CVEs)High3 exploited; 4th imminentPatch all four proactively
Windows RRAS (3 CVEs)RCEWrite-up publishedApply re-released KB5084597; verify even if patched before

What to do

  1. Patch AppArmor across all Linux distributions and Kubernetes clusters; validate container isolation post-patch; assume this has been silently exploitable since 2017

  2. Emergency patch Veeam Backup infrastructure for three CVSS 9.9 vulnerabilities; verify backup integrity and test restore capability immediately after patching

  3. Force Chrome browser update enterprise-wide; prepare deployment pipeline for second zero-day patch expected this week

  4. Patch Cisco SD-WAN for all four vulnerabilities including CVE-2026-20133 proactively before exploitation begins; segment SD-WAN management interfaces

  5. Apply re-released Windows RRAS hotpatch KB5084597 on all Windows 11 24H2/25H2 and LTSC 2024 systems; verify application even if previously patched

Five Simultaneous Supply Chain Attacks Are Targeting Your Developer Pipeline Right Now

The Convergence

Your developer supply chain is under five distinct, simultaneous attacks across different layers — npm packages, IDE extensions, mobile SDKs, GitHub repositories, and VPN client downloads. This isn't a single campaign; it's a convergence of unrelated threat actors all recognizing that the developer pipeline is the highest-leverage target in 2026.


1. PhantomRaven: npm's Own Features Weaponized

Endor Labs identified 88 malicious npm packages published from 50+ disposable accounts. The critical innovation: these packages abuse Remote Dynamic Dependencies (RDD) — HTTP URL entries in package.json that cause npm itself to fetch and execute a 259-line credential-harvesting payload at install time. No postinstall scripts. No suspicious code in the package itself. Your SCA scanner likely sees nothing. As of now, 81 of 88 remain live with both C2 servers operational (AWS EC2, plaintext HTTP port 80). Targets: developer emails, CI/CD tokens, system fingerprints — exfiltrated via triple-redundant GET/POST/WebSocket channels.

2. GlassWorm → ForcedMemo: The Cascade

The GlassWorm worm continues spreading through 72 new VSCode/OpenVSX extensions since late January. The critical escalation: Step Security reports that GitHub credentials stolen by GlassWorm are now being reused in the ForcedMemo campaign, injecting crypto-wallet stealer code into hundreds of GitHub Python projects since March 8. This is a textbook cascade: workstation compromise → credential theft → repository poisoning → downstream consumer compromise.

3. AppsFlyer SDK Compromise

A threat actor injected a cryptocurrency address hijacker into AppsFlyer's mobile and web analytics SDK. The malware intercepts clipboard operations to replace Bitcoin, Ethereum, Solana, Ripple, and TRON wallet addresses. Any application integrating the compromised SDK version is distributing this payload to its users. Your app becomes the delivery mechanism.

4. DPRK Famous Chollima npm Packages

North Korea's Famous Chollima uploaded new malicious npm packages containing PylangGhost RAT, continuing state-level poisoning of package registries.

5. Storm-2561 Fake VPN Clients

Storm-2561, active since May 2025, uses SEO poisoning to serve fake VPN client downloads impersonating Fortinet, Ivanti, and Cisco. The trojanized clients capture VPN credentials during "authentication," then stolen credentials provide corporate network access. The multi-vendor strategy casts a wide net regardless of which VPN stack an organization runs.

Five separate supply chain attacks across npm, IDE extensions, SDKs, GitHub repos, and VPN downloads are all live simultaneously — this is the most concentrated developer pipeline threat landscape in years.

What to do

  1. Search all package.json and lockfiles for HTTP/HTTPS URL entries in dependency fields; cross-reference against PhantomRaven IOCs (AWS EC2 C2 on port 80, PHP endpoints jpd.php and npm.php); rotate CI/CD tokens as precaution

  2. Audit all VSCode/OpenVSX extensions against approved allowlist; rotate GitHub personal access tokens for any developer who installed unverified extensions; scan Python dependencies pulled since March 8 for ForcedMemo indicators

  3. Audit AppsFlyer SDK integration across all mobile and web applications; verify SDK integrity and check for clipboard hijacking behavior by testing copy-paste of crypto addresses

  4. Restrict VPN client software installation to IT-managed deployment channels only; hunt DNS/proxy logs for VPN client downloads from non-vendor domains since May 2025

  5. Scan npm dependencies for DPRK Famous Chollima packages containing PylangGhost RAT; implement package provenance verification with block-on-threat policy in CI/CD

Your Defensive Tools Became the Attack Surface: Intune Weaponized at Stryker, Lilli Breached at McKinsey

When Trust Inverts

Two incidents this week share a devastating pattern: the tools organizations trust most became the attack vector. At Stryker, the MDM platform designed to protect devices destroyed them. At McKinsey, the AI platform built to empower employees exposed their most sensitive conversations. Neither attack required sophisticated exploits — both abused legitimate functionality.


Stryker: 200,000 Devices Wiped via Microsoft Intune

Iranian nation-state actors allegedly compromised Stryker's Microsoft Intune environment and issued remote wipe commands to 200,000 devices across 79 countries. No malware deployment was needed — the legitimate Intune wipe functionality is the weapon. This is "living off the land" at the infrastructure management layer, and no endpoint detection tool would flag a legitimate Intune wipe command as malicious.

The attack chain: privileged access compromise → management plane abuse → mass destructive action. The critical insight for your environment: your MDM platform has the same destructive capability as a nation-state wiper, and the only thing standing between a threat actor and fleet-wide destruction is your admin access controls.

Note: The Intune vector carries ~0.7 confidence in initial reporting. The exact compromise method is still under investigation. However, the architectural risk applies regardless of the specific MDM platform.

McKinsey Lilli: $20 AI Agent, 2 Hours, 46.5 Million Chats

CodeWall's autonomous AI agent performed end-to-end exploitation of McKinsey's 30,000-user Lilli AI platform — reconnaissance → vulnerability discovery → exploitation → data access — entirely autonomously in under 2 hours for $20 in API tokens. The vulnerability was a textbook SQL injection through an unauthenticated public endpoint that McKinsey's own scanners missed for over two years.

The exposed data: 46.5 million chat messages covering strategy, M&A, and client engagements, plus 728,000 files and 95 system prompts. The most alarming detail: the agent had write access to the prompt layer. An attacker could silently rewrite Lilli's core behavioral instructions, turning a trusted internal tool into an adversarial agent with legitimate network access.

McKinsey's claim that 46.5 million chats covering M&A and client strategy contained "no client data" warrants skepticism.

Cross-Source Pattern

Multiple sources confirm that internal AI platforms are the new shadow IT — deployed with urgency and exempted from the security rigor applied to customer-facing applications. The 66% vulnerability rate across 1,808 scanned MCP servers and the finding that 93% of AI agents use unscoped API keys stored in env files reinforce that AI infrastructure is deploying faster than security controls industry-wide.

Meanwhile, the ClickFix social engineering technique has crossed the threshold from novel to industry-standard initial access — appearing in APT28's Phexia campaign on macOS (with a TCC reset trick and 150-retry credential harvest), trojanized OpenClaw installers on GitHub, and 250+ compromised WordPress sites serving fake Cloudflare CAPTCHAs. Your email security gateway will never see ClickFix because the user pastes the payload themselves.

What to do

  1. Audit all Intune/MDM admin accounts for phishing-resistant MFA (FIDO2); implement PIM with time-limited elevation; configure bulk action thresholds requiring multi-party approval for wipe/retire actions exceeding 50 devices

  2. Conduct emergency security audit of all internal AI platforms, chatbots, and RAG pipelines — specifically test for SQLi, unauthenticated endpoints, and prompt layer isolation from data stores

  3. Verify AI system prompts are stored in separate, access-controlled datastores from user-accessible data — never in the same database tables; implement change detection alerting on prompt modifications

  4. Deploy endpoint controls for ClickFix: monitor clipboard-to-terminal paste events, restrict osascript from interactive Terminal on macOS, enforce PowerShell Constrained Language Mode on Windows; block vdsina[.]com at DNS

The bottom line

Ransomware actors abandoned encryption for data theft (77% exfiltration, 36% encryption) while HexStrike exploited Citrix at machine speed in under 10 minutes — your backup-centric defense model is obsolete. Simultaneously, CrackArmor exposed 7-year-old container escape bugs, Veeam dropped CVSS 9.9 patches for backup infrastructure, five separate supply chain attacks are live in your developer pipeline (81 malicious npm packages, 72 poisoned VSCode extensions, compromised AppsFlyer SDK, DPRK RAT packages, and fake VPN clients), and Iranian actors weaponized Microsoft Intune to wipe 200K Stryker devices without deploying a single piece of malware. Every layer of your defensive stack — backups, containers, browsers, developer tools, and device management — needs emergency attention this week.