Security & Threat Intelligence

The Watch

The Signal

NIST permanently stopped enriching non-priority CVEs on April 15 — no CVSS scores

Today, 8 actively exploited CVEs hit CISA KEV (including 3 coordinated Cisco SD-WAN Manager CVEs), mean time-to-exploit has collapsed to 20 hours, and a convicted ransomware negotiator just proved your IR vendor may be feeding your insurance limits to the attackers.

In Play

  1. NIST NVD Goes Dark on Most CVEs While Exploitation Timelines Collapse

    NIST NVD stopped enriching non-KEV, non-federal CVEs on April 15 — permanently. No CVSS, CWE, or CPE data for most vulnerabilities. Simultaneously, 8 exploited CVEs hit KEV (3 Cisco SD-WAN) and mean time-to-exploit collapsed from 2.3 years (2018) to 20 hours (2026). Your scanner output just went partially blind.

    Ask Clarity
  2. IR Vendor Insider Threat: Ransomware Negotiator Convicted of Colluding with BlackCat

    DigitalMint negotiator Angelo Martino pleaded guilty to feeding BlackCat/ALPHV clients' insurance limits, negotiation posture, and willingness to pay — while posing as their trusted adviser. He also conspired with other IR professionals to deploy ransomware. $10M+ seized. Your IR retainer's access to crisis data is a confirmed attack vector.

    Ask Clarity
  3. Anthropic Mythos Breached via Supply Chain — Found 271 Firefox Zero-Days

    Anthropic's restricted Mythos model — withheld as too dangerous — was accessed by unauthorized users via Mercor breach credentials chained into a third-party dev environment. The same model found 271 zero-days in Firefox 150. AI-powered offensive capability just leaked, and your threat model must assume adversaries have equivalent tools.

    Ask Clarity
  4. Enterprise AI Tools as Active Attack Surface: Azure SRE, Meta MCI, Code Review Collapse

    Azure SRE Agent leaks credentials to any Entra ID account holder. Meta is keystroke-logging employees including third-party comms (no opt-out). Shopify data shows AI-generated PRs growing 30% MoM with absolute bug counts rising. 92% of enterprises have zero visibility into AI identities. Enterprise AI tooling is an unaudited attack surface.

    Ask Clarity
  5. Ransomware-as-Terrorism: Legislative Push + Healthcare Incidents Doubled

    Healthcare ransomware nearly doubled (238→460 incidents YoY). Former FBI Cyber Deputy urged Congress to designate hospital ransomware as terrorism with homicide charges for patient deaths. The Gentlemen group hit 240+ victims in 3.5 months. Japan data: only 60% recovered data after paying. Terrorism designation would reshape reporting, insurance, and legal exposure.

    Ask Clarity

Deep Dives

NIST NVD Stopped Enriching Most CVEs — Your Vulnerability Management Program Just Went Partially Blind

What Happened

As of April 15, 2026, NIST's National Vulnerability Database only enriches CVEs meeting one of three criteria: listed in CISA's KEV catalog, affecting US federal government software, or qualifying as critical under EO 14028. Everything else — the vast majority of CVEs — receives a CVE number and nothing more. No CVSS score. No CWE classification. No CPE mapping. This is not a temporary backlog issue; it's a permanent policy shift driven by unsustainable volume growth.


Why This Matters Now

Your vulnerability scanners, SCA tools, SIEM correlation rules, compliance dashboards, and executive reports almost certainly consume NVD enrichment data. Without CVSS scores, your severity-based SLAs don't fire. Without CPE data, your asset-to-vulnerability mapping breaks. Without CWE classifications, your root cause analysis loses a primary taxonomy. Every downstream process that assumes NVD enrichment exists is now operating with incomplete data.

This collides with two other developments that amplify the impact:

  • 8 new CISA KEV entries dropped today — including three simultaneous Cisco Catalyst SD-WAN Manager CVEs (CVE-2026-20122, CVE-2026-20128, CVE-2026-20133) that suggest coordinated targeting of network management infrastructure, plus Zimbra, TeamCity, Kentico, Quest KACE, and PaperCut
  • Mean time-to-exploit collapsed to 20 hours (down from 2.3 years in 2018), per the CSA/SANS 'Mythos-Ready' CISO Framework co-authored by Jen Easterly and Bruce Schneier

Two-thirds of mass-internet scanning surges precede vendor disclosures by a median of 11 days. Your attackers are scanning before the CVE exists, exploiting within 20 hours of disclosure, and now the enrichment data your triage depends on won't arrive for most vulnerabilities — ever.

A 12-day average patch time was described by one expert as 'essentially a suicide note for your network' — and that was before NVD went dark on enrichment.

Cross-Source Analysis

Five independent sources converge on the same conclusion: the traditional vulnerability management model is structurally broken. The NVD enrichment gap means you can't triage by severity. The 20-hour MTTE means you can't wait for enrichment even if it existed. The pre-disclosure scanning data means attackers are ahead of you before the race starts. And thousands of Apache ActiveMQ instances remain unpatched weeks after active exploitation — proving that even with full enrichment, organizations aren't patching fast enough.

The only area of disagreement across sources is what replaces NVD. Options cited include the GitHub Advisory Database, OSV, VulnDB, and Snyk Vuln DB. No single source provides equivalent coverage. Your program likely needs multiple supplemental feeds — and the integration work starts now.

The 8 KEV Entries Demand Immediate Action

CVEProductAction
CVE-2026-20122/20128/20133Cisco SD-WAN ManagerPatch or restrict management plane
CVE-2025-48700Zimbra CollaborationPatch immediately
CVE-2024-27199JetBrains TeamCityPatch — older CVE now confirmed exploited
CVE-2025-2749Kentico CMSPatch immediately
CVE-2025-32975Quest KACEPatch immediately
CVE-2023-27351PaperCutPatch — 2023 CVE now exploited

Note: CVE-2024-27199 (TeamCity) and CVE-2023-27351 (PaperCut) are older CVEs now confirmed exploited in the wild. If you deprioritized these because they weren't initially seen as exploited, that assumption just expired.

What to do

  1. Map every tool, dashboard, SIEM rule, and compliance report consuming NVD enrichment data — identify which will break or degrade without CVSS/CWE/CPE

  2. Patch or mitigate all 8 CISA KEV entries by end of week — prioritize Cisco SD-WAN Manager (3 CVEs suggest coordinated campaign)

  3. Evaluate GitHub Advisory Database, OSV, VulnDB, and Snyk Vuln DB as supplemental enrichment sources by end of month

  4. Integrate EPSS scores into your vulnerability triage workflow alongside CVSS this quarter

Your Ransomware Negotiator Was Working for BlackCat — The IR Ecosystem Has a Confirmed Trust Problem

The Breach of Trust

Angelo John Martino III, a former ransomware negotiator at DigitalMint, pleaded guilty to colluding with BlackCat/ALPHV affiliates. During active engagements where he was trusted to represent victim organizations, Martino fed attackers the intelligence that determines how much a victim pays: insurance coverage limits, negotiation posture, organizational desperation, and willingness to pay. Five clients paid ransoms while Martino played both sides. Authorities seized approximately $10 million in assets. He faces up to 20 years at sentencing in July 2026.

This is not an isolated actor. Martino conspired with other IR professionals to deploy BlackCat ransomware against additional US firms in 2023 — meaning the insider threat extends across multiple individuals in the response ecosystem.


Why Four Sources Flagged This Simultaneously

Four independent intelligence sources elevated this story to priority status today, and the convergence is instructive. Each highlights a different facet of the same structural vulnerability:

  • The operational intelligence angle: During a ransomware incident, negotiators typically access insurance policy limits, business interruption estimates, board-level payment authorization, and the full scope of technical compromise
  • The threat actor angle: This is functionally an intelligence operation embedded inside the victim's crisis response — MITRE ATT&CK T1199 (Trusted Relationship) weaponized at the human layer
  • The ecosystem angle: If IR professionals are both deploying ransomware and negotiating on behalf of victims, the trust model underpinning the entire incident response industry requires re-examination
  • The detection angle: Your detection capability for this vector is almost certainly zero — no SIEM rule catches a trusted adviser sharing privileged information via side channel
Your IR vendor has the keys to your worst day. After the Martino conviction, if you haven't compartmentalized insurance and negotiation data from your IR vendors, you're giving threat actors a cheat sheet to your willingness to pay.

Compartmentalization Framework

The same zero-trust principles you apply to your network must now apply to your crisis response chain. During a ransomware incident, information should be separated into distinct streams with different access controls:

Information StreamAccessExcluded From
Technical remediationIR firm, internal securityInsurance details, payment strategy
Business continuityC-suite, operationsDetailed technical findings, attacker comms
Financial/insuranceCFO + outside counsel onlyIR firm, technical team, negotiator
Negotiation strategyCounsel + designated execAnyone not directly authorizing payment

No single external party should have visibility across all four streams. The Martino case demonstrates that a negotiator with cross-stream access is an intelligence goldmine for the adversary.

What to do

  1. Review all IR retainer and ransomware negotiation contracts this week for information compartmentalization requirements, personnel vetting clauses, and conflict-of-interest disclosures

  2. Implement need-to-know compartmentalization in your ransomware response playbook — separate insurance data, negotiation strategy, and technical remediation into distinct access-controlled streams

  3. Request updated background checks and conflict-of-interest disclosures from all active IR and negotiation retainer firms

  4. Add dual-authorization requirements and communication monitoring provisions to IR retainer contracts at next renewal

Anthropic's Restricted Mythos Model Was Breached on Announcement Day — And It Found 271 Firefox Zero-Days

The Dual-Edge Inflection Point

Anthropic's Mythos model — deliberately withheld from public release because of its cyberattack capabilities — was accessed by unauthorized users through a chained supply chain compromise. Seven independent sources reported on the breach and its implications, making this the most widely flagged AI security story of the day. Simultaneously, Mozilla disclosed that Mythos discovered 271 security vulnerabilities in Firefox 150 during a controlled engagement — a step-function increase over human researcher yield.

The attack chain was devastatingly simple: credentials exposed in Mercor's prior data breach were used to authenticate into a third-party development environment that Anthropic maintains for partner organizations under Project Glasswing. Through this environment, attackers gained access to Mythos and other unreleased models. At least one attacker had access through employment at a third-party contractor.

If the most safety-conscious AI lab can't keep its restricted models restricted, your threat model needs to assume offensive AI capabilities are already widely available.

The 271-Vulnerability Problem

The Mythos-Firefox result demands a recalibration of your vulnerability management expectations. Mozilla acknowledged these findings could have been made by elite researchers or automated fuzzing — but Mythos compressed months of effort into days. The implications cascade:

DimensionBefore AI Vuln DiscoveryAfter Mythos-Class Tools
Yield per codebaseDozens per releaseHundreds per release
Discovery speedWeeks to monthsHours to days
Attacker access barrierElite skills requiredAPI access to frontier model
Patch window pressure30-90 days manageableDays before stockpile exploitation

The dual-use math is unforgiving: defenders can use Mythos-class tools to find bugs, but the containment failure proves adversaries can access equivalent capabilities. One source flagged that OpenAI's Sam Altman called Anthropic's restriction 'fear-based marketing' — suggesting the industry may shift toward broader defensive access rather than tighter restriction. Watch for Anthropic to expand Project Glasswing access.


Cross-Source Tension

Sources diverge on one critical question: was this breach significant or contained? Anthropic's official position is that unauthorized access didn't impact core systems. Bloomberg confirmed the breach independently. Sources closest to the technical details note the attackers reportedly used Mythos for benign tasks (building websites), suggesting opportunistic access rather than offensive weaponization — this time. But the access path is proven and repeatable.

Anthropic has responded by requiring government-issued IDs and selfies for high-stakes accounts — a reactive control that addresses authentication but not the supply chain vector that enabled the breach. The Mercor-to-Anthropic chain is the proof point that one vendor's breach can unlock another vendor's crown jewels.

The strategic takeaway is clear: AI model containment through access restriction alone doesn't survive contact with a supply chain breach. If you participate in any AI company's research, red team, or early access program, your credentials are part of the attack surface for that lab's most sensitive assets.

What to do

  1. Update your threat model this sprint to assume adversaries have access to frontier offensive AI capabilities — prioritize detection of AI-augmented attack patterns (automated vuln discovery, polymorphic payloads, AI-generated phishing)

  2. Audit all AI vendor partner credentials — verify any research program, red team, or early access credentials are unique, rotated, and not shared with other platforms

  3. Evaluate AI-powered SAST/DAST integration into your SDLC this quarter — run a POC comparing AI findings against your last pen test on your highest-risk codebase

  4. Ensure Firefox is patched to 150+ fleet-wide and set alerting for new Mozilla security advisories over the next 60 days

The bottom line

NIST permanently stopped enriching most CVEs the same week a ransomware negotiator was convicted of feeding victim intelligence to BlackCat and Anthropic's restricted offensive AI model was breached through a third-party supply chain — your vulnerability management pipeline, your IR vendor trust chain, and your threat model for AI-assisted attacks all need structural updates this week, not next quarter.