Security & Threat Intelligence

The Watch

The Signal

Palo Alto Cortex XDR agents below version 9.1 have a hardcoded whitelist that silently

Simultaneously, HPE Aruba AOS-CX switches have a CVSS 9.8 pre-auth admin password reset flaw (CVE-2026-23813) requiring zero credentials. Upgrade all Cortex XDR agents to 9.1+ with content version ≥2160 and run a retroactive hunt for suppressed T1003 activity — then patch every Aruba AOS-CX switch before end of day.

In Play

  1. Your EDR and Network Switches Have Critical Blind Spots

    Cortex XDR's AES-encrypted rule files contained a global whitelist bypassing ~50% of BIOC detections including LSASS dumps. HPE Aruba CVE-2026-23813 (CVSS 9.8) enables unauthenticated admin password reset on enterprise switches. Two actively exploited Chrome zero-days have a March 27 CISA KEV deadline.

    Ask Clarity
  2. Your Incident Response Trust Chain Was Weaponized

    DOJ indicted ransomware negotiator Angelo Martino (DigitalMint) for colluding with ALPHV BlackCat operators across 10 attacks generating $75.25M. Separately, the Kratos PhaaS campaign chains through 7 trusted services — JP Morgan branding, Cisco SEG redirects, Cloudflare CDN — to harvest M365 credentials, defeating reputation-based defenses at every hop.

    Ask Clarity
  3. TLS 200-Day Deadline Is Live and PQC Clock Runs Alongside It

    TLS certificate maximum validity dropped to 200 days on March 15. DigiCert and SSL.com already enforce it. The compression continues to 100 days (Mar 2027) and 47 days (Mar 2029). Simultaneously, harvest-now-decrypt-later campaigns are active with $3T+ estimated U.S. exposure, and PQC migration must now encompass AI agent identities most orgs haven't inventoried.

    Ask Clarity
  4. OpenClaw RCE + AI Agent Security Gap Now Quantified

    OpenClaw CVE-2026-25253 RCE affects 15,200 exposed instances right as AWS launches managed OpenClaw on Lightsail. Research shows 23% prompt injection success against OpenAI Operator. VCs confirm the gap: Kai ($125M) and Surf AI ($57M) raised specifically for agentic AI security. Jensen Huang publicly flagged OpenClaw security flaws at GTC while pitching NemoClaw.

    Ask Clarity
  5. AI Impersonation and Deepfake Fraud Industrializing

    FTC data confirms AI impersonation losses grew 8x in 4 years ($55M to $445M) for older adults alone. Proof-of-personhood solutions (Worldcoin, VeryAI, Quartz) remain fragmented and immature. An incarcerated attacker bypassed MFA on iCloud via social engineering, and deepfakes are now actively weaponized in the Iran conflict as tools of war.

    Ask Clarity

Deep Dives

Cortex XDR Was Blind to Credential Theft + Aruba Switches Owned Without Credentials: Patch Now

Two Defensive Pillars Broken Simultaneously

Your EDR and your network infrastructure both have critical blind spots discovered this week. Together, they represent the most immediately actionable new intelligence since the Veeam 9.9 disclosures.

Cortex XDR: Encrypted Rules Hiding a Global Bypass

InfoGuard Labs decrypted AES-256-CBC-encrypted CLIPS rule files shipped with Cortex XDR agents 8.7 and 8.8 (content version 1790-16658) and found a hardcoded global whitelist. Any process with :\Windows\ccmcache in its command line is exempted from approximately 50% of all BIOC detections — including LSASS dump prevention mapped to MITRE T1003/TA0006.

The exploitation is trivial: an attacker appends this path string to their command line and bypasses credential dumping detection, process injection monitoring, and other behavioral rules. The whitelist was removed in Agent 9.1 with content version 2160, but individual rule-level exceptions remain exploitable even in upgraded agents.

If you ran Cortex XDR agents below 9.1, assume credential theft attempts went undetected. A retrospective hunt for T1003 activity is not optional — it's incident response.

HPE Aruba AOS-CX: No Credentials Needed

CVE-2026-23813 (CVSS 9.8) allows an unauthenticated remote attacker to reset the admin password on HPE Aruba AOS-CX network switches — the devices that form the backbone of your network segmentation. Four versions are affected (before 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001). Three additional high-severity command injection CVEs (CVE-2026-23814 through 23816) affect the same products.

No exploitation evidence exists yet, but pre-auth admin takeover on network switches is a CVSS 9.8 for a reason. If management interfaces are exposed beyond a dedicated out-of-band management network, you are one scan away from total network compromise.

Chrome Zero-Days: March 27 CISA Deadline

Two actively exploited Chrome zero-days round out the emergency patch list. CVE-2026-3909 (OOB write in Skia) and CVE-2026-3910 (arbitrary code execution in V8) are on the CISA KEV catalog with a March 27 compliance deadline. Google removed one zero-day's description from its advisory, indicating it will be fixed in a future release — monitor release notes.

CVEProductCVSSStatusDeadline
CVE-2026-23813Aruba AOS-CX9.8Patch available, no known exploitationImmediate
CVE-2026-3909Chrome (Skia)HighActively exploitedMarch 27
CVE-2026-3910Chrome (V8)HighActively exploitedMarch 27

What to do

  1. Upgrade all Cortex XDR agents to 9.1+ with content version ≥2160 and run retrospective hunt for T1003 LSASS access patterns and any 'ccmcache' command-line strings outside legitimate SCCM operations

  2. Emergency patch all HPE Aruba AOS-CX switches to 10.10.1180, 10.13.1161, 10.16.1030, or 10.17.1001+ and verify management interfaces are restricted to OOB management networks

  3. Push Chrome 146.0.7680.75+ to all managed endpoints via MDM/GPO and enforce mandatory restart policies before March 27 CISA deadline

  4. Evaluate whether single-vendor EDR reliance is acceptable given the opacity of encrypted detection rules — consider layered detection or periodic independent rule audits

Your Ransomware Negotiator Worked for the Attacker: The ALPHV Collusion Indictment Breaks the IR Trust Model

$75.25 Million in Ransom Payments — Steered by the Negotiator

The DOJ unsealed charges against Angelo Martino, a ransomware negotiator at DigitalMint, for actively colluding with ALPHV BlackCat operators. Co-conspirators Kevin Tyler Martin (also DigitalMint) and Ryan Clifford Goldberg (IR manager at Cygnia Cybersecurity Services) have already pleaded guilty as of December 2025.

The attack model was devastatingly simple: Martino fed confidential client intelligence to ALPHV — information about DigitalMint's own clients — to help maximize ransom demands. He received a cut of payments. One ransom went directly to the trio; five others to ALPHV after Martino exploited his position as the trusted negotiator sitting between victim and attacker.

This is not a theoretical insider threat scenario. A ransomware negotiator, hired to protect victims, was maximizing the ransom they paid — across 10 confirmed attacks.

Implications for Your IR Retainer

Every organization with a ransomware negotiation or incident response retainer needs to reassess their trust model. The Martino case exposes three specific gaps:

  • Information compartmentalization: IR firms often get full-scope access to your environment, attack timeline, business impact, and insurance coverage. All of this is leverage for an attacker.
  • Conflicts of interest: Negotiation firms that handle multiple simultaneous engagements create a concentration of victim intelligence that's valuable to threat actors.
  • Vetting gaps: Background checks and contractual controls for IR retainers rarely match the rigor applied to permanent security hires.

The Kratos Campaign: Trusted Services as Attack Infrastructure

A separate but thematically linked finding: the Kratos PhaaS campaign chains through seven trusted services to harvest M365 credentials. The kill chain exploits trust at every hop — DKIM-validated JP Morgan emails pass SPF/DKIM/DMARC, Cisco Secure Email Gateway redirect links are whitelisted, Nylas tracking pixels are legitimate SaaS, and the landing page sits behind Cloudflare with anti-bot validation that defeats automated sandboxing.

Both the Martino indictment and the Kratos campaign demonstrate the same principle: the most effective attacks don't break trust boundaries — they weaponize them.

What to do

  1. Review all incident response and ransomware negotiation retainer agreements for background check requirements, conflict-of-interest disclosures, and information compartmentalization protocols

  2. Implement time-of-click URL analysis in email security to detect Cisco SEG redirect abuse and add Kratos PhaaS IOCs from the Outpost24 report to threat intel feeds

  3. Establish a policy of engaging multiple independent firms for cross-validation during major ransomware incidents rather than relying on a single negotiator

Two Cryptographic Clocks Are Ticking: TLS Automation Deadline Is Live, PQC Migration Must Start Now

200 Days Is Already Here — 47 Days Is Coming

As of March 15, 2026, the CA/Browser Forum's 200-day maximum for TLS certificate validity is in effect. DigiCert moved to 199-day certificates on February 24; SSL.com followed on March 11. The compression trajectory is set and non-negotiable:

  • Now: 200-day maximum
  • March 2027: 100-day maximum → 3.5 renewals per certificate per year
  • March 2029: 47-day maximum → ~8 renewals per certificate per year

For any organization with more than a few dozen certificates, this is an automation-or-outage inflection point. Manual renewal processes that work at 200 days will fail catastrophically at 100 days. The 200-day window is your transition period — use it to implement ACME-based automation before the 2027 deadline makes it mandatory.


PQC: The Other Cryptographic Deadline

Multiple sources converge on the same warning: harvest-now-decrypt-later campaigns are actively collecting encrypted traffic today for future quantum decryption. Keyfactor CSO Chris Hickman estimates U.S. economic exposure exceeds $3 trillion.

What makes this more than a theoretical risk is the scope of the migration challenge. Post-quantum cryptography doesn't just mean upgrading TLS certificates. It requires reaching every cryptographic dependency — and that now includes authenticating thousands or millions of AI agent identities, a dependency most organizations haven't inventoried.

PQC Readiness DimensionCurrent State (Most Orgs)Migration Complexity
TLS / Web PKIClassical RSA/ECCMedium — tooling exists
VPN / Site-to-SiteClassical IKEv2/IPsecMedium — vendor dependent
AI / Machine IdentitiesUnmanaged / uninventoriedHigh — scale + visibility gaps
Supply Chain / PartnersNo visibilityHigh — contractual + technical
Even if your organization migrates to PQC perfectly, data transiting partner networks using classical-only crypto remains harvestable. PQC is a supply chain problem, not just an internal one.

The recommended approach is a hybrid model: bridging classical and NIST-standardized quantum-resistant algorithms during transition. Prioritize data flows that must remain confidential for 10+ years — IP, M&A activity, customer PII — for immediate hybrid PQC deployment.

The upside of TLS automation: infrastructure capable of automated certificate rotation can also rotate to post-quantum algorithms without manual intervention when the time comes. These two deadlines are converging, and solving one accelerates the other.

What to do

  1. Complete a full certificate inventory across all environments by end of April, including AI agent and machine identities, and identify current maximum validity periods

  2. Evaluate and select ACME-compatible CA and automation tooling with a target of 100% automation by Q4 2026 — well before the March 2027 100-day deadline

  3. Implement hybrid PQC encryption on your highest-sensitivity data flows (IP, M&A, customer PII at rest and in transit) using NIST-standardized algorithms

  4. Add PQC readiness assessment to vendor risk questionnaires and include cryptographic standards requirements in new contracts

OpenClaw RCE Hits 15K Instances While AI Agent Security Gets Its First Price Tag: $182M

The Vulnerability, the Data, and the Market Signal

Three converging data points quantify the AI agent security gap for the first time this week:

  1. CVE-2026-25253: A confirmed RCE in OpenClaw affects an estimated 15,200 externally exposed instances. AWS launched managed OpenClaw on Lightsail with Bedrock integration the same week — expanding the attack surface at the worst possible time.
  2. 23% prompt injection success rate: Research against OpenAI's Operator agent shows nearly 1 in 4 prompt injection attacks succeed against a production agent with browser and filesystem access. This is against one of the most well-resourced AI companies — baseline success rates against less mature deployments are almost certainly higher.
  3. $182M in security funding: Kai raised $125M (Evolution Equity Partners) and Surf AI raised $57M (Accel) specifically for agentic AI security, confirming VCs see this as a large unsolved problem — which means your existing security stack doesn't cover it.

The Architectural Problem

Jensen Huang stood on the GTC stage and publicly called out security vulnerabilities in OpenClaw while pitching Nvidia's NemoClaw as the enterprise alternative. China's cybersecurity agency separately declared OpenClaw "totally insecure." When a $4 trillion company's CEO and a nation-state's security agency agree something is broken, believe them.

The combination of RCE + supply chain risk + overly permissive agent permissions creates a triple-threat scenario: exploitation gives attackers not just code execution, but the agent's full operational scope — file system access, browser sessions, API credentials, and sub-agent delegation chains.

Enterprise AI agent adoption is bottlenecked by permissioning, sandboxing, and regulatory caution — not model capability. The security gap is the constraint, and it's now priced at $182M by the VC market.

What's Different From This Week's Earlier Agent Coverage

Previous briefings covered agent terminal access patterns and NemoClaw's launch. What's new today is the convergence of a specific RCE CVE with quantified prompt injection success rates and venture funding that confirms the gap is real, not theoretical. OpenClaw now has a known vulnerability, a quantified attack success rate, and a market valuation of its security deficiency — all in the same week.

What to do

  1. Scan all environments for OpenClaw instances including shadow deployments, developer workstations, and CI/CD pipelines — patch or isolate any instance exposed to CVE-2026-25253 before the weekend

  2. Establish an AI agent security policy gate: no agent deploys to production with browser, filesystem, or API access without a security review covering scoped credentials, prompt injection hardening, and data flow mapping

  3. Evaluate Kai and Surf AI for POC if deploying agents at scale, and assess NemoClaw's OpenShell restrictions as a baseline containment framework

  4. Block Solana RPC endpoints at the network perimeter for non-crypto environments to disrupt GlassWorm's blockchain-based C2 channel

The bottom line

Your Palo Alto EDR silently suppressed half its behavioral detections — including LSASS credential dumping — through a hardcoded whitelist, your HPE Aruba switches can be admin-owned without credentials (CVSS 9.8), your ransomware negotiator may have been working for the attacker ($75.25M in colluded payments indicted), TLS certificates now max out at 200 days with 47-day compression coming, and OpenClaw has a live RCE across 15,200 instances while prompt injection succeeds 23% of the time against OpenAI's best agent — upgrade Cortex XDR to 9.1, patch Aruba before lunch, hunt for suppressed T1003 activity, and accept that every trust assumption in your defensive stack needs independent verification.