Security & Threat Intelligence
The Watch
The $10,000 iAuthFlow kit survives account containment by enrolling its own passkey.
The target is the registration ceremony, not the authenticator. Once the victim clears the proxy, an attacker-controlled credential lands on their Google, Microsoft, LinkedIn or iCloud account. Password reset and session revocation, which is where most runbooks stop, leave that credential fully valid, so the containment checklist your team runs today closes the incident on paper and nowhere else.
In Play
Attacker-Enrolled Passkeys and Identity-Fabric Persistence
iAuthFlow v2, a phishing kit sold for $10,000, automatically enrolls the attacker's own passkey into a victim's Google, Microsoft, LinkedIn or iCloud account after a successful phish, per Risky Business. The stated design goal is surviving password resets and session revocation — the two steps most account-compromise runbooks stop at. Mandiant separately reports three Russian APT clusters shifting phishing toward OAuth consent and device-code flows, and Palo Alto Networks measured a 4x year-over-year rise in phishing delivered through collaboration platforms rather than email.
Ask ClarityUnauthenticated Interfaces, Owned and Unowned
Four disclosures landed the same day sharing one defect class: a privileged interface that accepts requests with no credentials, per The Hacker News. Elementor Pro carries an unauthenticated PHP upload leading to remote code execution (CVE-2026-324xx, identifier truncated in reporting) on a plugin with a very large WordPress install base. CDN Tsunami abuses how major CDNs translate client HTTP/3 into HTTP/1.1 origin requests for up to 350x amplification, and Risky Business reports only two CDNs have shipped a fix since notification.
Ask ClarityAI-Written Exploit Scripts Against Siemens S7 Controllers
US agencies warned on Aug. 20 that attackers are using AI-generated exploitation scripts against Siemens S7 PLCs and other industrial controllers across the water, energy, food, chemical, manufacturing and commercial sectors, per CyberScoop. Siemens says no new S7 vulnerabilities were identified, so no patch is coming; exploitation leverages known flaws, default configurations and internet exposure. MIT Technology Review adds that officials link activity against Siemens devices in water facilities to suspected Iran-nexus actors — an attribution the joint advisory itself does not make.
Ask ClarityYour Exposure Window Is Outliving Your Audit Logs
Microsoft patched CoSnitch, a one-click Copilot data-exfiltration chain, roughly eight months after disclosure — around December 2025 to August 2026, per CSO Update. Default Microsoft Purview audit retention on many licensing tiers is 180 days, so the earliest months of that window are already unrecoverable. Meanwhile enterprise SSD pricing rose another 5% in July, with a 30TB TLC drive listed at $22,600 — which puts hot-tier SIEM retention on the list of things finance trims first.
Ask ClarityAgent Identities Arriving as Vendor Defaults
Anthropic moved computer use, browser tool, Skills API and a 1TB-per-org Files API to general availability, and OpenAI gave Codex authority over git and CI in shared projects, per AINews. Slack Code shipped across all Slack plans, with human approval scoped only to production merges. Each capability is a non-human identity holding credentials, memory and outbound network paths, and none of it arrived through a change ticket your team reviewed. The near-term work is inventory and credential scoping, not policy writing.
Ask Clarity
Deep Dives
- ●
The Containment Runbook Now Has a Missing Step
Password reset plus session revocation was never a threat model — it was an assumption about how credentials get created, and a commodity kit sold on forums has priced that assumption at five figures.
The mechanism to understand is the enrollment path , not the authenticator. A passkey is a hardware-bound credential that cannot be replayed or relayed. That is why "phishing-resistant MFA" became shorthand for it. The property holds only if the registration…
3 action items
- ●
Four Products, One Defect: Privileged Interfaces With No Authentication
Two of these exposures sit in software you patch, and two sit in infrastructure someone else patches — which splits your response into a change window and a written vendor commitment.
Sort this set by who owns remediation . That decides whether the answer is a ticket or a contract. The one that gets mass-scanned Elementor Pro. The CVE is reported as CVE-2026-324xx, with the identifier truncated in the source reporting.…
3 action items
- ●
No New S7 Bug — Just More People Who Can Write the Script
The federal warning on industrial controllers contains no vulnerability, which is precisely why it lands on configuration and exposure owners rather than the patch pipeline.
The load-bearing sentence in the Aug. 20 alert belongs to the vendor. CyberScoop reports Siemens stating that no new S7 vulnerabilities have been identified while it coordinates with CISA. No patch, because no new bug. What changed is who can…
3 action items
- ●
You Cannot Prove a Negative With Expired Logs
Two unrelated forces — a vendor's remediation latency and the price of flash — are converging on the same outcome: exposure windows that outlast the telemetry needed to investigate them.
CoSnitch is a one-click Microsoft Copilot exfiltration chain, described in the disclosure as producing no obvious red flags . It surfaced around December 2025 and was patched around August 2026 . Default Purview audit retention on many licensing tiers is…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 4 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn