Security & Threat Intelligence

The Watch

The Signal

The $10,000 iAuthFlow kit survives account containment by enrolling its own passkey.

The target is the registration ceremony, not the authenticator. Once the victim clears the proxy, an attacker-controlled credential lands on their Google, Microsoft, LinkedIn or iCloud account. Password reset and session revocation, which is where most runbooks stop, leave that credential fully valid, so the containment checklist your team runs today closes the incident on paper and nowhere else.

In Play

  1. Attacker-Enrolled Passkeys and Identity-Fabric Persistence

    iAuthFlow v2, a phishing kit sold for $10,000, automatically enrolls the attacker's own passkey into a victim's Google, Microsoft, LinkedIn or iCloud account after a successful phish, per Risky Business. The stated design goal is surviving password resets and session revocation — the two steps most account-compromise runbooks stop at. Mandiant separately reports three Russian APT clusters shifting phishing toward OAuth consent and device-code flows, and Palo Alto Networks measured a 4x year-over-year rise in phishing delivered through collaboration platforms rather than email.

    Ask Clarity
    Try
  2. Unauthenticated Interfaces, Owned and Unowned

    Four disclosures landed the same day sharing one defect class: a privileged interface that accepts requests with no credentials, per The Hacker News. Elementor Pro carries an unauthenticated PHP upload leading to remote code execution (CVE-2026-324xx, identifier truncated in reporting) on a plugin with a very large WordPress install base. CDN Tsunami abuses how major CDNs translate client HTTP/3 into HTTP/1.1 origin requests for up to 350x amplification, and Risky Business reports only two CDNs have shipped a fix since notification.

    Ask Clarity
    Try
  3. AI-Written Exploit Scripts Against Siemens S7 Controllers

    US agencies warned on Aug. 20 that attackers are using AI-generated exploitation scripts against Siemens S7 PLCs and other industrial controllers across the water, energy, food, chemical, manufacturing and commercial sectors, per CyberScoop. Siemens says no new S7 vulnerabilities were identified, so no patch is coming; exploitation leverages known flaws, default configurations and internet exposure. MIT Technology Review adds that officials link activity against Siemens devices in water facilities to suspected Iran-nexus actors — an attribution the joint advisory itself does not make.

    Ask Clarity
    Try
  4. Your Exposure Window Is Outliving Your Audit Logs

    Microsoft patched CoSnitch, a one-click Copilot data-exfiltration chain, roughly eight months after disclosure — around December 2025 to August 2026, per CSO Update. Default Microsoft Purview audit retention on many licensing tiers is 180 days, so the earliest months of that window are already unrecoverable. Meanwhile enterprise SSD pricing rose another 5% in July, with a 30TB TLC drive listed at $22,600 — which puts hot-tier SIEM retention on the list of things finance trims first.

    Ask Clarity
    Try
  5. Agent Identities Arriving as Vendor Defaults

    Anthropic moved computer use, browser tool, Skills API and a 1TB-per-org Files API to general availability, and OpenAI gave Codex authority over git and CI in shared projects, per AINews. Slack Code shipped across all Slack plans, with human approval scoped only to production merges. Each capability is a non-human identity holding credentials, memory and outbound network paths, and none of it arrived through a change ticket your team reviewed. The near-term work is inventory and credential scoping, not policy writing.

    Ask Clarity
    Try

Deep Dives

The Containment Runbook Now Has a Missing Step

Password reset plus session revocation was never a threat model — it was an assumption about how credentials get created, and a commodity kit sold on forums has priced that assumption at five figures.

The mechanism to understand is the enrollment path, not the authenticator. A passkey is a hardware-bound credential that cannot be replayed or relayed. That is why "phishing-resistant MFA" became shorthand for it. The property holds only if the registration ceremony is trusted. iAuthFlow v2 attacks the ceremony. After the victim authenticates through the proxy, the kit registers an authentication method on the victim's behalf and lands an attacker-controlled passkey in the account. Every check the identity provider applies to that credential then passes.

Which is why the standard runbook fails. A password reset invalidates a secret the attacker no longer needs. Session revocation kills tokens the attacker can re-mint on demand. Both steps produce clean-looking closure notes.

MechanismSurvives password resetSurvives session revocationWhere the evidence lives
Attacker-enrolled passkeyYes — by designYes — by designAuthentication-method enrollment logs
OAuth consent grantYesPartiallyConsent grant and service principal sign-ins
Device-code flow abuseNo, but re-phishableNoDevice-code sign-in telemetry
Stolen passwordNoNoStandard identity protection

Where the sources converge

Risky Business is the primary account of the kit itself. The corroboration is directional rather than duplicative, and it points one way. Mandiant reports three Russian APT clusters migrating phishing toward OAuth flows, device codes and instant-messaging account takeover. Sublime Security profiled DOUBLOON DREDGER running device-code phishing through the EvilTokens service. Palo Alto Networks measured a 4x year-over-year increase in phishing delivered through collaboration platforms rather than email. That last number is the one to sit with. The delivery channel the gateway does not inspect feeds the enrollment path the IdP does not alert on. State and criminal tradecraft are converging on the credential lifecycle, not the credential.

A tenant that cannot produce, today, a list of every passkey enrolled in the last 90 days mapped to a known device is carrying an exposure with a published market price.

What your telemetry probably does not cover

Three gaps recur. First, credential-enrollment events are usually retained and rarely alerted on, because enrollment is a normal onboarding action. The high-fidelity alert is narrow and cheap: new authentication method registered shortly after a risky or anomalous sign-in. Second, the OAuth device-code grant is enabled by default in most tenants and used legitimately by almost nobody outside kiosk and CLI scenarios. Scoping it in Conditional Access removes an entire branch of the tree. Third, IR closure criteria are written as checklists, so validation never happens. The fix is a purple-team exercise that implants a rogue credential and measures whether responders find it and remove it.

One honest caveat. The kit's capability set is as described by researchers, and pricing on criminal forums is a marketing claim as much as a fact. Neither changes the defensive work, which is identical whether the tool costs $10,000 or is later cloned for free.

What to do

  1. Pull 90 days of authentication-method enrollment events from Entra ID, Google Workspace and iCloud this week, reconcile each to a known user device, and open an investigation on every unmatched credential.

  2. Rewrite the account-compromise runbook by end of sprint to require enumeration and removal of all authentication methods, app passwords, OAuth grants and registered devices before an incident can be closed.

  3. Block or narrowly scope the OAuth device-code grant in Conditional Access and alert on device-code authentications from unmanaged networks.

Four Products, One Defect: Privileged Interfaces With No Authentication

Two of these exposures sit in software you patch, and two sit in infrastructure someone else patches — which splits your response into a change window and a written vendor commitment.

Sort this set by who owns remediation. That decides whether the answer is a ticket or a contract.

The one that gets mass-scanned

Elementor Pro. The CVE is reported as CVE-2026-324xx, with the identifier truncated in the source reporting. The mechanism is an unauthenticated PHP file upload leading to remote code execution. Enormous install base, no credentials required. That combination is the most reliably automated exploitation pattern in the WordPress ecosystem, and it typically moves from disclosure to commodity scanning in days. Patching is not the hard part. Inventory is. The highest-risk host is a campaign microsite or an acquired company's domain that never reached the CMDB. Where patching lags, a WAF rule blocking .php, .phtml and .phar uploads to Elementor endpoints, plus file-integrity monitoring on wp-content/uploads, buys the window.

The two you cannot patch

CDN Tsunami abuses the way major CDNs translate a client's HTTP/3 request into HTTP/1.1 requests toward the origin, yielding up to 350x amplification. The flaw sits in the provider's protocol-translation layer. Risky Business reports only two CDNs have deployed mitigations since notification. Two controls stay in-house: origin authentication, so the origin refuses traffic that did not come through the edge, and a SIEM rule on edge-request-to-origin-request ratio divergence. The second is the amplification canary and requires nobody's cooperation.

The second issue is subtler. Researchers pulled a JWT out of a co-located tenant's Cloudflare Worker at up to 12 bits per second. In production, not a lab. The low bandwidth is the good news and the design instruction at once. At 12 bits per second a long-lived bearer token is worth stealing and a ten-minute sender-constrained token is not. Rotating signing keys, cutting TTLs to minutes and moving to mTLS- or DPoP-bound tokens is unilateral work that does not wait on the provider.

DisclosurePre-authWho remediatesYour detection signal
Elementor Pro RCEYes — unauth uploadYouNew executable files in wp-content/uploads
CDN Tsunami (350x)Yes — no credentialsCDN providerEdge-to-origin request ratio divergence
Workers Spectre JWT leakCo-tenant onlyProvider plus your token designToken replay from unexpected ASN or geography
NASA/JPL AIT-GUIYes — arbitrary commandsYou, if deployedAny unauthenticated operator console access

Where the reporting is thin

Both sources flag their own gaps. The Elementor CVE identifier is partial. The affected CDNs are unnamed. The marquee research came from commercial vendors publishing alongside sponsored placements. The technical findings are credible. The urgency framing is demand generation. Verify against vendor advisories before any of this reaches a board deck or a customer notification. The failure mode in a set like this is the item with the better headline displacing the one that is actually mass-exploitable.

Three of these disclosures live in infrastructure the defender does not own. The available controls are short-lived credentials, origin authentication and a written vendor answer, not a patch window.

What to do

  1. Inventory every WordPress instance including marketing microsites and acquired-company domains this week, then patch or WAF-block PHP-extension uploads to Elementor endpoints.

  2. Cut JWT TTLs to minutes and rotate signing keys resident in edge serverless environments by end of sprint, moving to mTLS- or DPoP-bound tokens.

  3. Send written inquiries to every CDN and edge provider asking whether they are affected by HTTP/3-to-HTTP/1.1 translation amplification and on what timeline, and file the responses in the vendor-risk register.

No New S7 Bug — Just More People Who Can Write the Script

The federal warning on industrial controllers contains no vulnerability, which is precisely why it lands on configuration and exposure owners rather than the patch pipeline.

The load-bearing sentence in the Aug. 20 alert belongs to the vendor. CyberScoop reports Siemens stating that no new S7 vulnerabilities have been identified while it coordinates with CISA. No patch, because no new bug. What changed is who can build a working exploit, and how fast. The alert says AI lowers the skill and time needed to produce ICS exploit code, helps locate exposed controllers through internet scanning, and can disguise malicious scripts as legitimate monitoring tooling.

That third item is the detection problem. OT monitoring baselines are usually built around expected engineering traffic, allowlisted by protocol. A script that looks like polling passes. The control that holds is allowlisting by engineering-workstation identity and function code, not by protocol.

The configuration debt nobody filed as a risk

Neither soft spot in a typical S7 estate is a CVE. Legacy S7-300/400 controllers have no meaningful native authentication, so there is nothing to harden. Only to make them non-routable from the enterprise and the internet. On S7-1200/1500, protective features ship permissive: access protection often left at the lowest level, and legacy PUT/GET communication commonly still enabled because a decade-old HMI or reporting integration once needed it. An AI-authored script does not need a zero-day for that. It needs a route.

Where the sources diverge

Publicly: CyberScoop frames the tradecraft as explicitly vendor-agnostic, so a remediation scope limited to a Siemens inventory query closes the ticket over a still-exposed estate. Rockwell, Schneider, Mitsubishi and Omron owners are exposed by the same logic. Reported, but not in the advisory: MIT Technology Review says officials link activity against Siemens devices in water facilities to suspected Iran-nexus actors. Treat that as context, not advisory content. Neither source publishes a CVE, a CVSS score or an affected firmware list. Risky Business independently places the same S7 activity alongside CISA and FBI messaging. Techpresso carries it with no agency or advisory ID at all. Pull the primary advisory before this reaches leadership.

Sector scope in the alert runs water, energy, food, chemical, manufacturing and commercial facilities. The stated impact ordering is operational disruption, then safety incidents, then data exposure. The authors were reasoning about process consequences, not confidentiality.

Detection content that survives machine-generated variants

Signature and hash matching degrades when variant volume is cheap. Effect-based detection does not. Tune OT monitoring to alert on s7comm job function codes for PLC control and stop (0x28/0x29) and block download sequences (0x1A–0x1D), plus Modbus function codes 5/6/15/16 and 8, from any source that is not an approved engineering workstation. A read from a historian is noise. A block download from an unexpected host is an incident.

Patch pipelines are waiting for a CVE that will never arrive; the deliverable here is exposure removal and controller configuration, not a firmware version.

What to do

  1. Run an external sweep of your own public ranges and OT-adjacent netblocks for TCP/102, Modbus 502, SNMP 161 and PROFINET DCP this week, cross-checked against Shodan and Censys for your ASN, and give every hit a same-day disposition.

  2. Set S7-1200/1500 access protection to the most restrictive level the process tolerates and disable legacy PUT/GET unless a documented dependency exists, enumerating S7-300/400 separately for isolation.

  3. Deploy function-code-level alerting on write, block-download and PLC-stop operations from any non-engineering-workstation source before the next change freeze.

You Cannot Prove a Negative With Expired Logs

Two unrelated forces — a vendor's remediation latency and the price of flash — are converging on the same outcome: exposure windows that outlast the telemetry needed to investigate them.

CoSnitch is a one-click Microsoft Copilot exfiltration chain, described in the disclosure as producing no obvious red flags. It surfaced around December 2025 and was patched around August 2026. Default Purview audit retention on many licensing tiers is 180 days. Run that arithmetic and a patch note becomes a compliance problem: by the time a retro-hunt starts, the first two to three months of the exposure window have nothing left in them to hunt. Where Copilot was licensed to users touching regulated data, the statement that survives an audit is "assumed exposure, evidence partially expired", not "no indication of compromise." Put that distinction in writing before someone else opens the conversation.

The second squeeze is financial, and nobody files a risk exception for it

Enterprise SSD prices rose another 5% in July, with a single 30TB TLC drive listed at $22,600. When storage inflates, the dataset that gets trimmed is the high-volume, write-heavy one with no revenue attached. That is the hot SIEM tier. Retention shortens inside a budget spreadsheet, and the bill arrives months later when an IR timeline stops short of initial access. One caveat for that conversation: the source reporting is internally inconsistent on the magnitude of the multi-quarter increase, with a headline figure of 6.5% against body text of roughly 6.5x. Confirm with a reseller before anyone re-baselines capacity on it. The direction is not in doubt; the multiplier is.

Why this compounds rather than adds

The techniques that most need long retention are the ones built to look ordinary. TWINLOOT malware runs command-and-control through SharePoint, Teams, Azure and the victim's own Edge browser. Destination reputation, domain allowlists and TLS inspection exceptions all work in the attacker's favor there, so detection falls to behavioral deviation on sanctioned services: Graph API writes from non-interactive or service identities, anomalous per-identity SharePoint and Teams write volume, Edge launched with headless or remote-debugging flags by a non-browser parent. Every one of those is baseline-dependent. A shortened hot tier deletes the baseline and the historical comparison in the same pass.

Computerworld's coverage of MIT research adds a third layer for anyone attesting to AI governance. The finding is attribution decay: individual training examples exert less measurable influence as diffusion models scale. That raises the bar for single-sample poisoning and, in the same motion, removes the ability to prove what a model learned or that a sample was actually removed. Any SOC 2 narrative, DPA or customer commitment promising training-data traceability or verifiable deletion is technically fragile at production scale.

Retention is not a storage line item. It is the difference between reporting an incident and reporting that you cannot rule one out.

The through-line is uncomfortable and cheap to act on. Two of the three fixes are configuration changes rather than projects: raise audit retention on identity and AI-assistant sources, and export what exists to immutable storage before it rotates.

What to do

  1. Extend Purview audit retention to 365 days and export existing Copilot interaction logs to immutable storage this week, then document in writing where retention falls short of the exposure window.

  2. Publish a written log-retention floor tied to PCI DSS, SOC 2 and HIPAA obligations and get finance sign-off that those tiers are out of scope for storage cost reduction this quarter.

  3. Re-tier rather than truncate: move logs older than 30-90 days to searchable cold object storage and test restore-to-search times against your incident response SLA.

The bottom line

One shift with two halves: adversaries are relocating persistence into the credential lifecycle and into services you are contractually obliged to trust, while the records that would prove or disprove their presence are being shortened by vendor latency and by procurement. That breaks the operating assumption behind most closure notes — that containment is a checklist and that logging is a solved cost. The programs that come out of this quarter clean will be the ones that treated credential creation as a monitored event and retention as a control with an owner, not a budget line. Name that owner this week and make them accountable for both.