Security & Threat Intelligence

The Watch

The Signal

A Sequoia-backed startup just proved that commodity AI agents

Simultaneously, 12+ critical CVEs (CVSS 9.0–10.0) surfaced this week across AI tools your teams are running without security review — FastGPT, Claude Code CLI, llama.cpp, LiteLLM.

In Play

  1. Commodity AI Exploits 84% of CISA KEVs Autonomously

    Buzz chained off-the-shelf LLMs to exploit 103/122 CISA KEVs without human oversight, most in under an hour. React2Shell fell in 22 minutes. Skill barrier for sophisticated exploitation has collapsed to an API key and a prompt. Chevron's CISO recommends assuming breach and prioritizing segmentation over patching speed.

    Ask Clarity
  2. Salt Typhoon Breaches FBI Through Commercial ISP

    FBI declared a 'major incident' after China-linked actors breached FBI systems through a commercial ISP, accessing law enforcement sensitive data including surveillance target identities. This escalates Salt Typhoon's 2024 lawful intercept campaign into direct federal compromise. No public countermeasures report exists 18 months after the original campaign.

    Ask Clarity
  3. AI/ML Tool CVE Explosion: 12+ Critical Vulns in Your Shadow AI Stack

    A dozen critical CVEs surfaced in AI infrastructure this week: FastGPT CVSS 10.0 (unauthenticated HTTP proxy), Claude Code CLI CVSS 9.8 (credential-stealing command injection), llama.cpp CVSS 9.8 (RCE via deserialization), LiteLLM CVSS 9.1 (auth bypass), plus 6 PraisonAI CVEs. Most require zero authentication. 12K+ Flowise instances remain exposed. These tools are likely running in your environment without security review.

    Ask Clarity
  4. EvilToken + ClickFix: New Campaigns Targeting Default-Enabled Features

    EvilToken PhaaS solved device code phishing's 15-minute expiration problem by generating codes dynamically at click-time via Railway.com, then maps org charts via Microsoft Graph for targeted executive exfiltration. ClickFix MaaS bundles its own Node.js runtime, evades 30+ security products, and loads fileless infostealers via Tor C2. Both exploit features you intentionally enabled.

    Ask Clarity
  5. Shadow AI Data Governance: The 60-Trillion-Token Blind Spot

    Meta's leaked Claudeonomics dashboard revealed 60 trillion tokens consumed via Anthropic's Claude in 30 days — the top user alone hit 281 billion tokens. Meta shut it down after data leaked externally. Separately, 46% of enterprise identity activity occurs outside IAM visibility and 40% of accounts are orphaned. Your AI governance gap is measurable and growing.

    Ask Clarity

Deep Dives

Commodity AI Exploits 84% of CISA KEVs in Under an Hour — Your Patch Window Just Collapsed to Zero

The Data That Changes Your Planning Assumptions

Sequoia-backed cybersecurity startup Buzz published research this week demonstrating that an AI agent — assembled from off-the-shelf Anthropic, OpenAI, and Google models — autonomously exploited 103 of 122 CISA Known Exploited Vulnerabilities without human oversight. Most completed in under an hour. React2Shell, one of 2025's most dangerous flaws, fell in 22 minutes.

This is not Mythos. This is not a restricted frontier model behind a $100M consortium. This was built with commodity API access anyone can purchase today. Co-founders Niv Hoffman and Yair Saban fed the AI agent CISA's public KEV catalog — the same list designed to help defenders prioritize patching — and the agent treated it as a machine-readable target list.

"We're now in this gap where attackers are by default early adopters of AI, and defenders by default aren't — they're risk averse, don't want to touch production much, and that definitely needs to change." — Niv Hoffman, Buzz co-founder

The Exploitation Speed Asymmetry

MetricAI Agent (Buzz)Human AttackerDefender (Patch)
KEV Exploitation Rate84.4% (103/122)Variable, skill-dependentN/A
Time to ExploitUnder 1 hour (most)Several daysDays to weeks to patch
React2Shell22 minutesDaysDays to weeks
Skill BarrierAPI keyAdvanced skillsSysadmin + change mgmt
ScalabilityMassively parallelLimited by headcountLimited by headcount

Separately, the Internet Bug Bounty program paused new submissions this week, explicitly citing that AI-assisted research "radically lowered the cost of vulnerability discovery." The economics of offense have collapsed. Chevron CISO Jon Raper put it bluntly: "Finding vulnerabilities isn't the problem — it's remediating them in time."


The CISA KEV Catalog Paradox

CISA built the KEV catalog to help defenders prioritize. It now equally functions as an AI-readable attack playbook. Buzz literally fed it to their agent. This doesn't mean CISA should stop publishing — transparency still helps — but the window between KEV publication and AI-automated exploitation is now measured in minutes, not days.

What This Means for Your Defense Model

When patching speed can never match exploitation speed, your defensive strategy must shift from "patch before exploit" to "contain during exploit." Microsegmentation, behavioral detection, and automated containment become survival controls, not aspirational improvements. The risk of deploying AI-assisted defense imperfectly is now demonstrably lower than the risk of defending at human speed.

What to do

  1. Pull your current CISA KEV patch coverage report and identify every unpatched KEV in production by end of day Friday

  2. Verify React2Shell remediation across all environments including containers and third-party deployments within 48 hours

  3. Accelerate microsegmentation deployment to critical assets this quarter — prioritize identity infrastructure, databases, and CI/CD

  4. Deploy automated host isolation and network quarantine playbooks for known KEV exploitation signatures this month

  5. Brief the board within two weeks: 'AI has compressed exploitation from days to minutes; our defense model assumes days; we need budget to close this gap'

Salt Typhoon Breached FBI Through a Commercial ISP — Your Telecom Vendor Is Attack Surface

The Escalation

The FBI has formally declared a "major incident" after China-linked actors breached FBI systems through a commercial Internet Service Provider, accessing law enforcement sensitive data including returns from legal process and PII of investigation subjects. This means Chinese intelligence now knows — or can infer — who the FBI is surveilling.

This is a direct escalation of Salt Typhoon's 2024 campaign, which compromised telecom companies' lawful intercept portals and targeted calls and metadata of approximately 40 individuals including political figures. The 2026 breach is worse: the attack vector shifted from targeting telecom companies directly to pivoting through a commercial ISP into federal infrastructure.

There has been no in-depth public report detailing exactly what happened in the 2024 Salt Typhoon breaches or appropriate countermeasures — an 18-month gap between discovery and systematic defensive guidance.

Why This Changes Your Threat Model

The attack chain is deceptively simple and broadly applicable:

  1. Compromise a commercial ISP (which has network-level access to customers)
  2. Pivot from ISP infrastructure into customer networks
  3. Access sensitive data through trusted connectivity

Your ISP is not just a service provider — it is a network-adjacent trust relationship with visibility into your traffic. If Chinese APTs can use that position to pivot into the FBI, they can use it to pivot into any customer on that ISP's infrastructure. This applies to every organization with dedicated circuits, MPLS connections, or co-location relationships with connectivity providers.

Simultaneously: Forest Blizzard's SOHO Campaign Scales

In a related development, Microsoft Threat Intelligence confirmed that Forest Blizzard (Fancy Bear/GRU) and sub-group Storm-2754 have compromised 5,000+ SOHO routers across 200 organizations since August 2025. They hijack DNS via dnsmasq to conduct adversary-in-the-middle attacks against Outlook Web Access users, with confirmed data interception from three African government organizations. The FBI's Operation Masquerade disrupted the U.S. segment, but the adversary will adapt.

Two major nation-state actors — China and Russia — are simultaneously exploiting the connectivity infrastructure layer as an attack vector. The common thread: your security stack sits above the network layer these actors are targeting.

What to do

  1. Request security attestations and incident disclosure statements from all connectivity providers within 30 days — specifically ask about compromise detection capabilities and law enforcement cooperation segmentation

  2. If your organization processes CALEA compliance or lawful intercept requests, segregate those systems from general infrastructure this week

  3. Enforce DNS-over-HTTPS on all managed endpoints via MDM/GPO immediately to bypass SOHO router DNS hijacking

  4. Issue SOHO router hygiene guidance to all remote workers this week: reset DNS, update firmware, change default credentials

12+ Critical CVEs in AI/ML Tools Your Teams Deployed Without Security Review

The AI Tool Vulnerability Landscape This Week

A wave of critical vulnerabilities in AI/ML infrastructure surfaced this week — not in frontier models, but in the agent frameworks, proxy gateways, inference engines, and developer CLIs your teams spun up without security review. SANS declared that for the first time in RSAC keynote history, every one of the five most dangerous new attack techniques carries an AI dimension.

CVEProductCVSSVulnerabilityAuth Required?
CVE-2026-34162FastGPT10.0Unauthenticated HTTP proxy — full request forwardingNo
CVE-2026-35022Claude Code CLI / Agent SDK9.8OS command injection → credential theftNo
CVE-2026-34159llama.cpp9.8RCE via unbounded deserializationNo
CVE-2026-34612Kestra9.9SQL injection to RCENo
CVE-2026-35030LiteLLM9.1Auth bypass inheriting legitimate user identityNo
6 CVEsPraisonAI9.0–10.0Multiple critical vulnerabilitiesVaries

The pattern is unmistakable: these tools were designed for rapid experimentation and deployed to production without security maturity. Most require zero authentication for exploitation. A compromised Flowise instance (12K+ internet-exposed) isn't just one box — it's a pivot into LLM API keys, vector databases, and backend data sources the agent interacts with.


Developer Toolchain Under Simultaneous Attack

The attack surface extends beyond AI-specific tools into the developer toolchain itself:

  • Ruby LSP (CVE-2026-34060, CVSS 9.8): Arbitrary code execution via malicious .vscode/settings.json — cloning a repo is enough to get compromised
  • Nektos Act (CVE-2026-34041, CVSS 9.8): Environment injection in the most popular local GitHub Actions runner
  • Vite (CVE-2025-30208): File access bypass now under active exploitation on ISC honeypots — targeting standard web ports (80/443), not Vite's default 5173, indicating attackers are hunting production instances behind reverse proxies

The Vite exploitation detail is particularly telling: attackers aren't scanning for development tools on expected ports — they're looking for Vite instances accidentally deployed behind production reverse proxies. Your dev tools in production are being actively hunted.


The Governance Gap

Nearly 50% of organizations cannot fully track AI and non-human identities accessing critical systems, despite 87% claiming AI readiness. New tools are emerging — StepSecurity's dev-machine-guard scans developer machines for AI agents and MCP servers, Knostic's AgentSonar provides network-level shadow AI detection — but adoption lags the threat by months.

If you don't know which AI tools your engineers are running, you have blind spots with CVSS 10.0 exposure.

What to do

  1. Inventory all AI/ML tools across the organization this week — survey engineering, data science, and business analyst teams for FastGPT, llama.cpp, Claude Code CLI, LiteLLM, PraisonAI, and Flowise deployments

  2. Scan external attack surface for any internet-exposed Flowise, FastGPT, or AI agent builder instances immediately

  3. Deploy Elastic's supply-chain-monitor for PyPI/npm dependencies and evaluate StepSecurity dev-machine-guard for developer endpoint AI agent inventory this month

  4. Search proxy and load balancer configs for backend targets on port 5173 (Vite) this week — patch CVE-2025-30208 across all environments

  5. Establish mandatory security vetting for AI tool deployment — no AI framework goes to production without AppSec review

EvilToken and ClickFix: Two New Campaigns Exploiting Features You Intentionally Enabled

EvilToken: Device Code Phishing Solved Its Scalability Problem

Microsoft Defender researchers tracked a large-scale device code phishing campaign powered by the EvilToken Phishing-as-a-Service toolkit. The critical innovation: attackers use Railway.com to spin up ephemeral Node.js polling nodes that generate device codes dynamically at the moment of click, solving the fundamental 15-minute expiration limitation that previously made device code phishing impractical at scale.

Phishing emails are role-tailored — invoices for finance, RFPs for procurement, manufacturing workflows for operations — boosting interaction rates. Post-authentication, attackers use Microsoft Graph API to enumerate organizational structures and zero in on financial and executive accounts for email exfiltration. This is targeted intelligence collection, not spray-and-pray.

Why Default-Enabled Device Code Flows Are the Problem

M365 device code authentication flows are enabled by default in most Entra ID tenants. Most organizations never touch this setting because device code auth is a legitimate feature for headless devices and kiosks. EvilToken weaponizes this gap between feature intent and security exposure.


ClickFix: Enterprise-Grade Evasion in a MaaS Package

Netskope Threat Labs identified a ClickFix campaign using a fake CAPTCHA prompting execution of a PowerShell command that downloads a Node.js-based RAT. The sophistication is notable:

  • Bundles its own Node.js runtime — doesn't depend on victim having Node installed
  • Installs in a "LogicOptimizer" folder with Registry persistence
  • Routes all C2 through Tor
  • Scans for 30+ security products before deploying payloads
  • Dynamically loads infostealer modules into memory only — never touching disk
  • Uses gRPC-based C2 with real-time Telegram alerts to affiliates on successful crypto wallet thefts

An OPSEC failure by the operators exposed the admin panel, revealing the full C2 architecture. But the operational model — fileless payloads, Tor routing, 30+ AV evasion — means your disk-based AV and signature-based detection will miss this entirely.


The Common Thread

Both campaigns exploit features you intentionally enabled: device code flows for device registration, PowerShell for administration. The attack surface expanded because the feature surface expanded. Your SOC needs detection rules tuned for these specific behavioral patterns, not just signatures.

What to do

  1. Create a Conditional Access policy in Entra ID blocking device code authentication for all users except explicitly approved device registration scenarios — do this today

  2. Review Entra ID sign-in logs for anomalous device code tokens issued in the past 90 days — look for Railway.com infrastructure or unusual polling patterns

  3. Deploy behavioral detection rules for ClickFix indicators: msiexec spawning Node.js child processes, Tor connections from non-browser processes, Registry persistence under 'LogicOptimizer' paths

  4. Audit Grafana instances for enabled AI/LLM features and restrict image source domains this week

The bottom line

Commodity AI agents — built from off-the-shelf models anyone can buy — just proved they can exploit 84% of CISA's Known Exploited Vulnerabilities in under an hour with zero human oversight, while simultaneously, a dozen critical unauthenticated RCE vulnerabilities (CVSS 9.0–10.0) exist in the AI tools your teams deployed without telling you, China breached the FBI through a commercial ISP, and two new phishing/malware campaigns are exploiting M365 features you left enabled by default. The question is no longer whether your defenses are good enough — it's whether they operate at machine speed, because your adversaries now do.