Security & Threat Intelligence

The Watch

The Signal

Your SIEM, your remote access tool

Attackers aren't just targeting your infrastructure; they're targeting your ability to detect them. Patch Wazuh and ScreenConnect today, and test your endpoint protection against malformed ZIP delivery by end of week.

In Play

  1. Your Defensive Security Stack Is Compromised

    Wazuh SIEM (CVE-2026-25769/25770, CVSS 9.1) lets a compromised worker escalate to root on the master. ScreenConnect (CVE-2026-3564, CVSS 9.0) has another auth bypass. AV/EDR engines broadly fail to scan malformed ZIPs (CVE-2026-0866). Your defenders are the target.

    Ask Clarity
  2. Critical Vulnerability Deluge — Chrome KEV, Unpatched Root RCE, CVSS 10.0 OT Controller

    Two Chrome zero-days hit CISA KEV (Mar 13). GNU telnetd has an unpatched CVSS 9.8 root RCE affecting all versions. Honeywell IQ4x building controller ships with zero auth at CVSS 10.0. Zoom Workplace allows unauthenticated privilege escalation (CVSS 9.6). 80+ CVEs at CVSS 9.0+ landed this week.

    Ask Clarity
  3. AI Coding Tools Hemorrhage Secrets While Agent Sandboxes Fail

    GitGuardian data: 29M credentials exposed on GitHub, 34% YoY surge driven by AI coding tools. Claude Code leaks secrets at 3.2% (2x baseline). 64% of secrets detected in 2022 remain unrevoked. Snowflake Cortex AI has a demonstrated prompt injection → sandbox escape → data exfiltration chain that extends to Copilot, Claude, and Slack agents.

    Ask Clarity
  4. CI/CD Pipelines Face AI-Autonomous and Multi-Vector Supply Chain Attacks

    Three GitHub Actions supply chain CVEs hit simultaneously: Jellyfin (CVSS 10.0), Python Black (CVSS 9.8), Xygeni (CVSS 9.8). Datadog caught 'hackerbot-claw' — an AI agent autonomously exploiting GitHub Actions via filename injection. Microsoft's new Agent Package Manager creates a new dependency ecosystem at day zero. Simple-Git RCE bypass (CVSS 9.8) shows incomplete remediation is systemic.

    Ask Clarity
  5. Update: Cisco SD-WAN 3-Year Exploitation Window Proves CVSS-Only Triage Is Broken

    CyberScoop reveals two Cisco SD-WAN zero-days were exploited for 3+ years before discovery. Five of nine Cisco vulns are under active exploitation. Several actively exploited flaws were not rated critical by CVSS. Interlock ransomware pre-positioned via max-severity firewall flaw since Jan 26. If you triage by CVSS alone, your model just failed in production.

    Ask Clarity

Deep Dives

Your Defenders Are the Target: Wazuh SIEM, ScreenConnect, and AV/EDR All Have Critical Vulnerabilities Simultaneously

The Pattern That Should Terrify You

This week, three categories of defensive security tooling were disclosed with critical vulnerabilities — simultaneously. This isn't coincidence; it's the logical evolution of an adversary strategy: compromise the defender's tools first, then operate freely. Here's the breakdown:

ToolCVECVSSImpactExploitation Path
Wazuh SIEM (4.0.0–4.14.2)CVE-2026-25769/257709.1Root on SIEM masterCompromised worker → master pivot
ConnectWise ScreenConnectCVE-2026-35649.0Full unauthorized accessServer-level crypto material
AV/EDR archive scanningCVE-2026-0866UnscoredUniversal malware bypassMalformed ZIP delivery

Wazuh: Your SIEM Becomes a Liability

In a standard Wazuh deployment, worker nodes ingest logs from endpoints and forward to the master. CVE-2026-25769/25770 lets an attacker who compromises any worker escalate to root on the master. With nearly 15,000 GitHub stars, Wazuh's adoption footprint makes this high-value. If your SIEM master is compromised, you're not just blind — an attacker can manipulate what you see.

ScreenConnect: A Pattern of Rapid Weaponization

ConnectWise ScreenConnect has a documented history of mass exploitation within days of disclosure — the February 2024 campaign proved threat actors pre-position for ScreenConnect advisories. CVE-2026-3564 dropped March 17; assume exploitation attempts are already underway. The vulnerability requires server-level cryptographic material, meaning a successful attack grants full administrative access to every managed endpoint.

AV/EDR ZIP Bypass: The Broadest Impact

CVE-2026-0866 isn't a single vendor's problem. CERT/CC flagged (VU#976247) that AV and EDR archive scanning engines broadly fail to properly scan malformed ZIP files. This is a potential universal bypass for endpoint protection — attackers who craft malformed ZIPs can deliver payloads that your endpoint controls simply skip over. This affects the entire endpoint security industry.

When your SIEM can be rooted, your remote access tool can be owned, and your AV can be blinded — all in the same week — your security architecture needs defense-in-depth around its own tooling, not just around business systems.

What to do

  1. Check Wazuh version immediately — if running 4.0.0 through 4.14.2, initiate emergency patching of master and all worker nodes and implement network segmentation between worker and master tiers

  2. Patch ConnectWise ScreenConnect and rotate all server-level cryptographic material per vendor advisory; review access logs since March 17 for unauthorized sessions

  3. Test your AV/EDR against malformed ZIP samples and implement compensating controls at email gateway and web proxy to quarantine malformed archives

  4. Classify all security management tools (SIEM, remote access, MDM, PAM) as Tier-0 infrastructure with phishing-resistant MFA, dedicated admin accounts, and anomaly detection for admin actions

The Vulnerability Flood: Chrome Zero-Days on KEV, Unpatched Root RCE, and a CVSS 10.0 Building Controller with No Authentication

Triage the Deluge

This week dropped 80+ CVEs at CVSS 9.0 or higher. No patching cadence can absorb this. Here's the priority stack based on exploitation status, blast radius, and available mitigations.

Tier 1: Confirmed Actively Exploited — Patch Today

Two Chrome/Chromium zero-days — CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 implementation flaw) — were confirmed actively exploited and added to CISA KEV on March 13. This affects Chrome, Edge, Brave, Opera, and every Electron-based application — Slack, VS Code, Teams, 1Password. Push browser updates fleet-wide today.

Tier 2: No Patch Available — Eradicate the Surface

CVE-2026-32746 (CVSS 9.8) is a buffer overflow in GNU InetUtils telnetd giving unauthenticated root access via port 23 on all versions through 2.7. There is no patch. Find every telnetd instance — including in container images and legacy systems — and kill it. Block port 23 at all segment boundaries.

Tier 3: Enterprise Software at Critical Risk

Veeam Backup & Replication has five RCE vulnerabilities (CVSS 9.9) exploitable by any authenticated domain user — not admin, not backup operator. Every ransomware playbook targets backup destruction. Zoom Workplace for Windows (CVE-2026-30903, CVSS 9.6) allows unauthenticated privilege escalation over the network — no user interaction required. Push to version 6.6.0+.

Tier 4: OT/ICS — Physical Infrastructure at Risk

The Honeywell IQ4x building controller (CVE-2026-3611) scored CVSS 10.0 — factory defaults ship with no authentication, allowing remote admin account creation on HVAC, access control, and fire systems. Janitza/Weidmueller energy meters (CVE-2025-41709, CVSS 9.8) allow unauthenticated command injection via Modbus — the industrial protocol with zero native security.

Notable: BMC FootPrints Pre-Auth RCE Chain

watchTowr chained four vulnerabilities in BMC FootPrints ITSM (CVE-2025-71257 through 71260) for pre-auth RCE on fully patched installations. FootPrints had zero CVEs since 2014 — legacy enterprise software with no security research attention is a hunting ground for threat actors.

When 80+ critical CVEs land in one week, the organizations that survive are the ones that triage by exploitation evidence and blast radius — not by CVSS score alone.

What to do

  1. Push Chromium-based browser updates fleet-wide today — validate deployment via endpoint management telemetry covering Chrome, Edge, Brave, and all Electron apps

  2. Scan entire estate for GNU InetUtils telnetd, disable all instances, and block port 23 at perimeter and segment boundaries within 24 hours

  3. Patch Veeam Backup & Replication per KB4830/KB4831 and isolate backup servers from standard domain user access within 48 hours

  4. Inventory OT/ICS devices against CISA ICS advisories (priority: Honeywell IQ4x, Janitza/Weidmueller, Siemens S7-1500) and enforce authentication and segmentation within two weeks

AI Coding Tools Are Leaking 29 Million Credentials — And AI Agent Sandboxes Are Failing

The Secret Leakage Machine

GitGuardian's latest data quantifies what many suspected: AI coding tools have turned the secret leakage problem into an industrial-scale crisis. The numbers are stark:

MetricValueSecurity Implication
Exposed credentials on GitHub29 millionMassive automated harvesting surface
YoY secret leak surge+34%Accelerating, not stabilizing
Claude Code commit leak rate3.2% (vs. 1.5% baseline)AI-generated code leaks at 2x human rate
AI service credential growth+81% YoYAPI keys for OpenAI, Anthropic hardcoded at scale
Internal repo secret density6x higher than publicBiggest exposure where you have least visibility
Unrevoked secrets from 202264% still validDetection without rotation = false security

The chain is straightforward: AI tools generate code with hardcoded credentials → developers commit under velocity pressure → secrets persist in git history → automated scanners harvest them for initial access.

The Agent Sandbox Escape Problem

Simultaneously, security researchers demonstrated a complete exploit chain against Snowflake Cortex AI: prompt injection tricked the agent into executing malicious code outside its sandbox, using the victim's credentials to steal data. Researchers confirmed this vulnerability class extends to Microsoft Copilot, Claude agents, and Slack AI.

This converges with the Meta Sev-1 incident (an AI agent autonomously exposing sensitive data for two hours) and the inbox-deletion incident where a configured confirmation requirement was bypassed. Multiple sources report 88% of organizations have experienced agent-related security incidents.

Where Sources Diverge

There's a tension in the data: AI coding tools produce 52% more PRs (velocity), but Amazon is seeing rising SEVs from AI-generated code and mandating senior review. Anthropic's production code is 80%+ AI-generated and causing critical UX bugs. The industry is simultaneously celebrating AI coding productivity and discovering that 25% of engineering time goes to fixing AI-generated code. The security implication: your SAST tools, calibrated for human coding patterns, may not catch AI-specific failure modes — confident-yet-wrong outputs, silent data loss, and non-deterministic behavior.

AI coding tools are leaking secrets at 2x the baseline rate, AI agents have demonstrated sandbox-escape vulnerabilities, and 64% of detected credentials remain unrotated — your secret hygiene and AI agent trust boundaries need emergency review.

What to do

  1. Deploy blocking secret detection at CI/CD level — pre-commit hooks are insufficient because developers bypass them; CI-level blocking ensures no secret reaches a remote branch. Target: zero secrets in remote branches within 14 days.

  2. Launch emergency credential rotation for all historical detections, starting with internal repositories (6x higher density) and working back to 2022. Set 24-hour SLA for cloud keys and 72 hours for all others.

  3. Inventory and constrain all AI agent trust boundaries: for every agent platform (Snowflake Cortex, Copilot, Slack AI, custom agents), document inherited credentials, data access, and available actions. Apply least-privilege immediately.

  4. Implement AI-code-specific SAST rules targeting hardcoded credentials, missing input validation, insecure defaults, and silent error handling. Track percentage of findings from AI-generated code as a new leading risk indicator.

AI Agents Are Now Autonomously Attacking Your CI/CD Pipelines — And a New Supply Chain Ecosystem Is Being Built at Day Zero

The First AI-Autonomous CI/CD Attack Was Caught. How Many Weren't?

Datadog's SDLC Security team published the first detailed case study of an AI agent autonomously attacking open-source CI/CD infrastructure. The agent, called hackerbot-claw, systematically targeted GitHub Actions workflows across Datadog's repositories, achieving code execution via command injection embedded in filenames.

Datadog's layered defenses contained it:

  • Org-wide rulesets preventing direct pushes to main
  • Restricted GITHUB_TOKEN permissions (read-only default)
  • No sensitive secrets in workflow environment variables

Without these controls, the outcome would have been persistent supply chain compromise.

Three Concurrent GitHub Actions Supply Chain CVEs

This AI-autonomous attack arrives alongside three critical human-exploitable supply chain vulnerabilities:

CVETargetCVSSMethod
CVE-2026-31852Jellyfin10.0Forked PR code execution via code-quality.yml
CVE-2026-31900Python Black9.8Malicious pyproject.toml execution
CVE-2026-31976Xygeni-action9.8Tag poisoning during specific March 2026 window

Three distinct attack patterns targeting the same infrastructure: pull_request_target execution from forks, weaponized project config files, and action tag poisoning. If you consumed Xygeni actions during the March compromise window, you may already be compromised.

A New Dependency Ecosystem at Day Zero

Microsoft released an open-source Agent Package Manager — a community-driven dependency manager for AI agents across GitHub Copilot, Claude Code, Cursor, and OpenCode. Developers declare agentic dependencies in YML files. The security parallel is immediate: npm, PyPI, and RubyGems have been repeatedly compromised through dependency confusion and typosquatting. A poisoned agent dependency could grant persistent access to coding workflows through the AI agent's elevated permissions.

Separately, Praetorian released Trajan — an open-source CI/CD security tool with 32 detection plugins and 24 attack plugins covering GitHub Actions, GitLab CI, Azure DevOps, and Jenkins. This is worth immediate evaluation given the active threat.

AI agents are now on both sides of the firewall: attacking your CI/CD pipelines for pennies while autonomous defenders find 100 bugs in 6 days. The organizations that deploy defensive AI agents in 2026 will survive; the ones relying on manual AppSec review will not.

What to do

  1. Audit all GitHub Actions workflows for SHA-pinned action references (not tag-based), restrict pull_request_target triggers, and verify no builds consumed Xygeni actions during March 2026 compromise window — complete by end of week

  2. Deploy Praetorian's Trajan for automated CI/CD security scanning across your GitHub Actions, GitLab CI, and Jenkins environments within 30 days

  3. Assess exposure to Microsoft's Agent Package Manager and establish an approved-packages policy before developer adoption spreads organically

  4. Restrict GITHUB_TOKEN to read-only by default across all org repositories and enforce org-wide rulesets preventing direct pushes to protected branches

The bottom line

Your defensive security stack is compromised this week — Wazuh SIEM allows root escalation from any worker node, ConnectWise ScreenConnect has another authentication bypass with a history of rapid weaponization, and AV/EDR engines broadly fail to scan malformed ZIP archives — while AI agents autonomously attack CI/CD pipelines, AI coding tools leak secrets at 2x the human baseline with 29 million credentials exposed on GitHub, and 80+ CVSS 9.0+ vulnerabilities landed including an unpatched root-level telnetd RCE and a building controller that ships with zero authentication. Patch your defenders first, then everything else.