Security & Threat Intelligence

The Watch

The Signal

A CVSS 10 SonicWall SMA1000 zero-day is under active exploitation right now.

Unauthenticated, internet-facing SSRF. No workaround. Patch before EOD and hunt logs for requests to /__api__/login and /wsproxy. Microsoft's Patch Tuesday runs to 622 CVEs, a record. Two are active zero-days, in ADFS and SharePoint. Triage those two ahead of the other 620.

In Play

  1. Active Exploitation Fires — Patch Before EOD

    SonicWall SMA1000 (CVSS 10, unauth SSRF) is being exploited; hotfix-only. Microsoft's record 622-CVE Patch Tuesday hides two exploited zero-days — ADFS (CVE-2026-56155) and SharePoint (CVE-2026-56164). ServiceNow shipped a pre-auth RCE fix (CVE-2026-6875); a LegacyHive PoC dropped within hours.

    Ask Clarity
  2. AI Industrializes Offense and Floods the CVE Queue

    Cato Networks drove GPT-5.5 in a custom harness to domain admin in 40 minutes — collapsing detection windows to a lunch break. AI bug-finding tripled Microsoft CVEs (206→622), burying real zero-days in noise. Immunefi logged a record 207 DeFi incidents in H1 2026 as AI-tooled attackers carpet-bomb under-resourced targets.

    Ask Clarity
  3. M365 Takeover Beats Your Containment Playbook

    Forg365, a Telegram-sold PhaaS kit, chains AI lures + device-code phishing + attacker-side session refresh — so a password reset won't evict the intruder. Entra ID makes passkeys the default Sept 1 2026 and retires Microsoft SMS/voice MFA Feb 1 2027, a hard deadline for every SMS-dependent service account and break-glass path.

    Ask Clarity
  4. Threat-Landscape & Vendor-Concentration Shifts

    US kinetic strikes on Iran plus a Hormuz blockade historically precede Iranian APT retaliation (APT33/34/35, CyberAv3ngers) against banks, energy, and exposed OT within days. Stripe's $53B bid for PayPal would concentrate $3.69T in annual payment volume under one entity — a vendor SPOF and PCI-DSS integration event. Bland AI raised $100M to industrialize synthetic voice calls.

    Ask Clarity

Deep Dives

Three Active Fires, One 'Triage by Exploitability' Rule

The 622-CVE headline is noise; the signal is four internet-facing and identity-tier exploitation paths that outrank your entire backlog.

Triage by exploitability, not headline volume. This ledger leaves no other option. The SonicWall SMA1000 flaw is the sharpest: an unauthenticated, internet-facing SSRF scored CVSS 10, confirmed in multiple incidents, with no workaround but the hotfix. SonicWall published log-based IOCs. Watch for unexpected requests to /__api__/login and /wsproxy. That lets you tell whether you were breached before patching. Assume breach. Hunt first.

The two Microsoft zero-days matter for where they live. CVE-2026-56155 (AD FS) sits on the federated-identity layer. Treat active exploitation as a possible Golden SAML token-forgery event and review token-issuance logs for the prior two weeks after applying the KB. CVE-2026-56164 (SharePoint Server) is a network-reachable auth bypass. Hunt for webshells and anomalous file access. Both landed inside a record 622-CVE release. A working PoC, LegacyHive, for a User Profile Service EoP dropped within hours of the patch. The monthly-cadence assumption is dead.

ThreatID / SeverityVectorAction
SonicWall SMA1000CVSS 10.0Unauth internet-facing SSRFHotfix now + hunt IOCs
Microsoft AD FSCVE-2026-56155Federated identity, exploitedPatch + Golden SAML hunt
Microsoft SharePointCVE-2026-56164Network auth bypass, exploitedPatch + webshell hunt
ServiceNowCVE-2026-6875Pre-auth RCE, Rhino escapeVerify fix + retro-hunt

ServiceNow rounds out the fires. CVE-2026-6875 abuses GlideRecord query filters to escape the Rhino sandbox and run unsandboxed code. Mitigated within 24 hours. That stops future exploitation and nothing else. Confirm your instance received the Guarded Script and retro-hunt for prior pre-auth GlideRecord activity, new admin accounts, and commands on connected proxy servers.

Patch SonicWall first and the two exploited Microsoft zero-days next — the other 620 CVEs can wait for your KEV feed.

What to do

  1. Patch or isolate every internet-facing SonicWall SMA1000 appliance immediately, then hunt logs for requests to /__api__/login and /wsproxy to confirm pre-patch compromise.

  2. Fast-track CVE-2026-56155 (ADFS) and CVE-2026-56164 (SharePoint) ahead of the other 620 CVEs, and retro-hunt ADFS token-issuance logs for Golden SAML before declaring the patch sufficient.

  3. Confirm your ServiceNow instance received the CVE-2026-6875 mitigation and hunt for anomalous pre-auth GlideRecord activity and new admin accounts.

40 Minutes to Domain Admin: Your Cadence Just Became Existential

The same AI efficiency that reached DA in 40 minutes is inflating your CVE queue and making your long-tail assets economically worth attacking.

The number that matters is not the CVE count. It's the clock. Cato Networks wrapped GPT-5.5 in a custom harness that ran a full attack chain to domain administrator in 40 minutes. Tenable, Proofpoint, and SpecterOps have built model-agnostic harnesses that swap the underlying LLM and hold results steady. The capability lives in the harness, in operational context and system integration, not the model. AI-speed attacks are now portable and commoditizing. An hourly SOC rhythm does not survive a 40-minute time-to-DA.

The same efficiency explains the 622-CVE flood. June's prior record was 206. Researchers attribute the 3x spike to AI bug-finding tooling, not a real surge in risk. That puts Microsoft on pace for 2,000–3,000 CVEs this year against 2020's record of 1,245. Hand-triaging by CVSS is finished. Automate against CISA KEV and EPSS so genuine zero-days surface above the noise.

Crypto is the leading indicator. Immunefi logged a record 207 DeFi incidents in H1 2026 while aggregate losses fell below $1B, down more than 50% year over year. This is a bifurcated economy. Well-resourced targets deploy AI-hardening. Attackers use GLM 5.2/GPT 5.6-class tooling to carpet-bomb the long tail. The pattern generalizes past crypto. LLM tooling collapses the cost of recon and exploit generation. That makes a forgotten subsidiary app, an orphaned integration, or an unmaintained service worth attacking at machine speed.

Defenders who monitor only crown jewels are defending the wrong perimeter. The economics inverted the risk model. The weakest, least-watched asset is now the most probable entry point. Detection tuned for human-paced recon will miss the campaign.

When an AI harness reaches domain admin in 40 minutes, exploitation evidence is the only triage key that still matters. Vulnerability volume is not.

What to do

  1. Re-architect patch prioritization around CISA KEV and EPSS automation this quarter, treating 500+ monthly Microsoft CVEs as the new baseline instead of hand-triaging by CVSS.

  2. Purple-team a 40-minute time-to-domain-admin scenario this sprint and validate automated containment on Tier-0 privilege anomalies and lateral movement.

  3. Extend detection coverage to long-tail assets — orphaned integrations, unmaintained apps, low-traffic subsidiaries — this sprint, not just high-value systems.

Forg365 Survives Your Reset — and the Entra SMS Cliff Is Dated

A Telegram PhaaS kit engineered to defeat containment lands the same week Microsoft sets a hard deadline to kill SMS MFA.

The mechanism worth watching in Forg365 is persistence, not delivery. Device-code phishing abuses a legitimate OAuth flow. The victim authenticates on a genuine Microsoft page, so there's no lookalike domain for URL filters to catch. Once tokens are captured, attacker-side session refresh keeps the adversary authenticated indefinitely. A password reset evicts nobody. It's sold as-a-service over Telegram with AI-generated lures. That commoditizes full M365 tenant takeover, which puts it a step past a one-off exploit.

The containment runbook is the gap. On takeover you have to revoke refresh tokens, force global sign-out, invalidate all sessions, and rotate every credential the account touched. Then verify no new tokens mint. Highest-value prevention is an Entra Conditional Access policy blocking the device-code flow for populations that don't need it. Run report-only first to confirm no legitimate onboarding breaks.

Microsoft is pushing the same direction from the platform side, with dates attached. Entra ID makes passkeys the default on September 1, 2026, auto-prompts SMS/voice users to enroll at next MFA, and retires Microsoft-provided SMS/voice MFA entirely on February 1, 2027. Continued SMS then requires paid telecom partners via the Microsoft Security Store. SMS OTP is phishable and SIM-swappable, so the hygiene is net-positive. It will also silently break any workflow secretly dependent on SMS, including service accounts and break-glass paths.

Treat the two dates as one project. Inventory every SMS/voice dependency and decide the paid telecom fallback before the September default flip, not the February cliff. The migration surfaces exactly the undocumented automation and recovery paths an attacker would look for first.

A password reset no longer evicts a phished M365 attacker — without device-code auth disabled and session revocation forced, breached accounts stay breached.

What to do

  1. Deploy an Entra Conditional Access policy blocking device-code authentication for populations that don't need it (report-only first), and enforce FIDO2/passkeys for privileged users this sprint.

  2. Rewrite the M365 takeover runbook to revoke refresh tokens, force global sign-out, and rotate touched app credentials — do not rely on password reset alone.

  3. Charter the Entra SMS/voice-to-passkey migration this quarter, inventorying every service account and break-glass path before the Sept 1 2026 default flip.

Iran Escalation Resets Your Threat Model

Kinetic strikes and a Hormuz blockade are a reliable leading indicator of Iranian-nexus cyber retaliation against banks, energy, and exposed OT.

Iranian retaliation follows US escalation on a predictable lag. After the 2020 Soleimani strike, CISA issued Shields-Up warnings. Iranian actors ran the Ababil DDoS campaign against US banks in 2012–13. CyberAv3ngers hit exposed water-utility PLCs in 2023. The current trigger is a seven-hour overnight strike on Iranian missile, drone, and coastal-defense sites, plus a reimposed naval blockade near the Strait of Hormuz. The prior ceasefire is broken. Brent is back above $85.

The expected pattern is the Iranian-nexus playbook, not novel zero-days. Opportunistic, high-volume tactics against exposure. The likely TTPs map cleanly to monitoring:

ActorTypical targetPrimary TTPs
APT33 / Peach SandstormEnergy, aerospacePassword spraying (T1110.003), spearphishing (T1566)
APT34 / OilRigFinancial, gov, energyPublic-facing app exploitation (T1190)
APT35 / Charming KittenBroad, incl. individualsCredential harvesting, social engineering
CyberAv3ngersExposed OT/ICSDefault-cred access to internet-facing PLCs/HMIs

Financial services, energy, and internet-facing OT are the historical target set. Defenders in those sectors typically move pre-incident: loading Iran-nexus IOCs, deploying detections for password spraying and public-facing-app exploitation, validating DDoS scrubbing capacity, and hunting exposed HMIs/PLCs with default credentials. The market signal is noise. CrowdStrike (+12%) and Okta (+11%) rallied on CPI-driven risk-on sentiment. The escalation is the actual indicator.

US strikes on Iran are a reliable leading indicator of cyber retaliation against banks, energy, and exposed OT. The window to prepare closes when the first DDoS lands, not before.

What to do

  1. Pull current CISA advisories on Iranian APTs, load Iran-nexus IOCs, and deploy detections for password spraying (T1110.003) and public-facing-app exploitation (T1190) now — pre-incident.

  2. Audit internet-exposed OT/ICS for default-credential HMIs/PLCs and validate DDoS scrubbing capacity for customer-facing financial services this sprint.

The bottom line

Treat exploitation evidence — not vulnerability volume — as your triage key, invest detection engineering where containment already fails, and raise your posture ahead of predictable retaliation.