Engineering & Technical

The Engineer

The Signal

Microsoft fixed an exploited 10.0 in Entra ID and left you nothing to patch.

The fix landed server-side, past the tenant boundary, so there is no build number to bump and no artifact in your environment that attests whether you were hit. There is a reading where nothing happened in your tenant, and it is unfalsifiable from where you sit, which is not the same thing as reassuring. What stays in scope: sign-in and audit logs aging out on default retention, and any consent grants issued during exploitation that are still valid today. Those logs expire on a clock you did not set.

In Play

  1. Exploitation Arrives Two Days After The Patch

    Every failure in today's edition executed before the control meant to stop it, so where the enforcement point sits now matters more than how fresh the fix is. GitLab's out-of-cycle patch for CVE-2026-19478 was being exploited in watchTowr's honeypots two days later. The first dive below sequences it against Zimbra, Citrix and Entra by who can actually fix each one.

  2. A Maximum-Severity Flaw You Are Not Allowed To Patch

    Microsoft's exploited CVSS 10.0 RCE in Entra ID comes with no customer action to take. That is exactly why the first dive below ranks these criticals by remediation agency instead of score.

  3. Agent Bills Are Governed By Cache Hit Ratio

    OpenRouter data charted by Peter Walker and summarized by a16z shows agents now consume nearly 5x the tokens humans do, up roughly 14x since February 2026. The second dive below explains why cache hit ratio, not model tier, sets the bill.

  4. AI Execution Paths Inherit Ambient Privilege

    A patched sandbox escape and a macOS plug-in asking for Full Disk Access are the same failure, one arriving through a CVE and one through a click. The third dive below maps what each of those processes actually holds.

  5. Provenance Metadata Replaces AI-Text Detection

    A new study finds 90% of biomedical papers show signs of AI use, per The Download from MIT Technology Review, and Pew's sample of English web pages puts more than a third of pages published after November 2022 in the same category. At those base rates an AI-text detector flags nearly everything, so it has no discriminating power as an ingestion gate. The workable replacement is asserted provenance in your schema: DOI, retraction status, publisher tier, byline and publish date.

Deep Dives

  1. Sequence These Criticals By Who Can Fix Them

    Four maximum-or-near-maximum severity events landed on the same patch capacity, and CVSS ranks them wrong — remediation agency and blast radius do not.

    The auth layer never ran GitLab shipped out-of-cycle patches for CVE-2026-19478 on August 17. watchTowr's honeypots logged exploitation attempts two days later, per SANS NewsBites. Fixed self-managed builds: 19.2.4, 19.1.6, 19.0.8, 18.11.11. The injection sits in a GraphQL directive ,…

    3 action items

  2. Your Agent Bill Is Set By Prompt Assembly, Not Model Choice

    Turns and cached prefix dominate agentic cost arithmetic, which means the cheapest per-token model on your shortlist can still produce the largest invoice.

    The four ways teams silently disable their own cache More than 85% of agent token burn is the cached prompt, per a16z's OpenRouter data. Cache hit ratio sets the bill, not model tier. Prefix caching needs a byte-identical prefix .…

    3 action items

  3. Model Output Is Now Executing Inside Processes That Hold Your Credentials

    Four unrelated products converged on the same design error: the thing running untrusted content inherits whatever privilege its host session already had.

    Where a sandbox escape actually lands A type-confusion bug in a JavaScript sandbox widely used to run model-generated code was patched, per CSO First Look. It allows guest-to-host escape and remote code execution. This is a predictable failure class, not…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn