Security & Threat Intelligence

The Watch

The Signal

Defender's own boot driver can wipe your EDR before your first telemetry event exists.

Check Point drove the Microsoft-signed remediation driver to kernel file and registry operations pre-boot, so WDAC, driver blocklists and signature enforcement all wave it through.

In Play

  1. A Signed Component That Kills Your EDR

    Check Point Research demonstrated that Microsoft Defender's boot-time remediation driver can be driven to perform kernel-level file and registry operations, including deleting security software at boot, as reported by The Hacker News. Because the driver is signed by Microsoft, signature enforcement, WDAC-style allowlists and vulnerable-driver blocklists offer nothing. It runs before user-mode EDR telemetry exists. No patch is available and no CVSS has been assigned, so detection engineering owns this one.

    Ask Clarity
    Try
  2. Exploited Code Injection and Five Perfect Scores

    GitLab's CVE-2026-19478 is a CVSS 9.4 code injection flaw, and watchTowr reports exploitation in the wild within days of disclosure, per The Hacker News. Cisco separately shipped nine fixes for Crosswork and Secure Workload, five of them rated CVSS 10.0, with no public exploitation reported yet. Both platforms hold privileged credentials — CI/CD tokens on one side, device credentials and microsegmentation policy on the other. Patching without rotating leaves stolen credentials valid.

    Ask Clarity
    Try
  3. Unnamed Models and Unsigned Skills in the SDLC

    An unattributed model called 'Ox Alpha' reached production code review within 48 hours, and one prominent developer merged eight pull requests on its approval, per AINews. It was served through OpenRouter, Cline, Hermes Agent and OpenCode, so gateways that allowlist by provider rather than by model ID passed it through untouched. ByteByteGo separately documents agent skills — unsigned instructions plus scripts from single-maintainer repositories — executing with developer credentials.

    Ask Clarity
    Try
  4. Automated Account Suspension Priced at Nine Figures

    The Dutch DPA fined Uber €825 million ($966 million) on 17 August 2026 for suspending accounts through automation with no prior warning and no human review, per Techpresso. It is the second-largest GDPR penalty after Meta's €1.2 billion in 2023. Uber is appealing, and its argument that only 126 European drivers were deactivated on ratings in 2021 did not reduce the fine. Your SOAR and UEBA response paths disable EU data subjects the same way.

    Ask Clarity
    Try
  5. Agent Panels Vote Down the Decisive Signal

    Anthropic ran the classic hidden-profile test on four-agent AI panels, where only one agent holds the decisive evidence. Most model families reached the correct decision in 17–36% of runs. A single agent handed the entire evidence base was right nearly every time, per Exponential View. Every low-and-slow intrusion has that shape: benign majority telemetry, one weak decisive indicator. The figures arrived without linked methodology, so treat the magnitude as directional.

    Ask Clarity
    Try

Deep Dives

Patching GitLab Is Half of Remediating It

Two vendors shipped critical fixes for platforms that store your credentials, and in both cases the update closes the hole while leaving whatever the attacker already took fully valid.

What an exploited instance costs

A self-hosted GitLab holds CI/CD variables, runner registration tokens, personal access tokens, deploy keys, SSH keys, and every pipeline definition that describes how software reaches production. It is a credential store with a web front end. Code execution on that box reads all of it. The patch for CVE-2026-19478 closes the injection path. It does not invalidate a single token that already left the building.

watchTowr reported in-the-wild exploitation within days of disclosure. An internet-facing instance that sat unpatched for more than 48 hours is therefore an incident, not a change ticket. The follow-on work: rotation of CI/CD variables, runner registration tokens, PATs, deploy keys and SSH keys; a diff of pipeline definitions and webhook configurations against a known-good commit; job logs read for secret access no human requested. Patching stops the bleeding. Rotation closes the ticket.


Cisco's five 10.0s are administrative reach, not a foothold

Five simultaneous CVSS 10.0 ratings in one round imply unauthenticated code execution or authentication bypass over the network with no user interaction. The products matter more than the scores. Crosswork orchestrates network automation and Secure Workload enforces microsegmentation. Both hold privileged device credentials. Both push configuration across the fleet. An attacker who owns them has no need to move laterally, because pushing configuration is the platform's job. No public exploitation has been reported yet. That gap is the whole window.

Cisco described the round as part of a continued comprehensive internal security review. That phrasing is a pre-announcement. The next batch comes from the same review, and teams that wait for it will book change windows twice.


The reporting is thinner than the remediation needs

Both stories arrived without the detail a ticket requires. Individual CVE identifiers and the Cisco affected-version matrix were not in the coverage. The account of Citrix's NetScaler round in CSO Update, a memory overflow paired with an authentication bypass, carried no identifier at all. A vulnerability-management entry reading "critical flaw in an edge appliance" cannot carry an SLA. The vendor advisories and the watchTowr write-up hold the version matrix. The coverage does not.

The Citrix item corroborates the pattern. On gateways, session material recovered from appliance memory survives the update. That is the same defect as an unrotated GitLab token in a different product. The build number is evidence of patching, not of remediation.


The SLA arithmetic no longer works

Disclosure-to-exploitation measured in days makes a 30-day patch SLA a guaranteed exposure window for anything internet-facing. Process discipline alone does not close it, because testing time has to come from somewhere. A compensating control in front of the asset is the only way to keep both. Virtual patching through WAF or RASP rules is the unglamorous answer, and it buys back the testing runway without accepting the risk in the meantime.

A build number proves you patched. Only a rotation record proves you remediated.

What to do

  1. Patch every GitLab instance for CVE-2026-19478 today, and open an IR case for any internet-facing instance that was unpatched longer than 48 hours.

  2. Confirm this week that Cisco Crosswork and Secure Workload are unreachable from user and internet segments, then schedule the nine-flaw patch round and rotate the device credentials those platforms hold.

  3. Cut the patch SLA for internet-facing developer and SCM platforms to 72 hours this quarter, and fund WAF or RASP virtual patching as the bridging control.

The EDR Kill Switch Microsoft Signed

A trusted component that runs before your telemetry does turns detection into a hunt for missing signals, and it exposes how few preventive controls in your estate report that they are still alive.

Start with what the technique requires

This is not initial access. Driving Defender's boot-time remediation component to perform kernel-level file and registry operations requires administrator or SYSTEM already in hand. That places it at the impact stage: ATT&CK T1562.001, impair defenses, executed with vendor-blessed authority. It matters for triage. Anyone who finds evidence of this has an earlier failure to hunt, and the intrusion that granted SYSTEM is the actual incident. A novel primitive does not reorder the investigation.

What is genuinely new is that the usual countermeasures contribute nothing. The component is signed by Microsoft and trusted by design, so driver signature enforcement, allowlisting and vulnerable-driver blocklists all pass it. There is no malicious driver to block. It acts at boot, before user-mode telemetry exists, which means the agent cannot report its own deletion.


Absence of signal is the detection

The rule that catches this does not look for the technique. It looks for the consequence. A host records a boot event and the EDR or AV agent never checks in inside a defined window. Most SOCs already hold that data and have never written the alert, because agent-health monitoring sits with the endpoint team and reads as an operations metric rather than detection content. Pair it with two narrower signals: unexpected modification of Defender's boot-time remediation configuration, and changes to security-service registry keys. Then verify that tamper protection is enforced across the fleet rather than assumed.

Then test it. A controlled tamper exercise on a lab host is the only way to know the alert fires and routes to a human who acts. An untested absence rule is an assumption with a dashboard attached.


The pattern this belongs to

This is the second control-monitoring failure in this reporting. THE DECODER reported that Anthropic's bioweapons safeguard sat inoperative for roughly a year without the vendor noticing. Different domain, identical defect. A control existed and nothing monitored the control. SOC 2 Type II did not surface it, because the audit scope covers corporate process rather than inference-time filters.

Most estates have the same shape. EDR check-in, tamper protection state, DLP policy enforcement, MFA coverage and the log pipeline itself are preventive controls that fail quietly and report nothing when they do. Control liveness is the monitoring category most programs have never named. It is also cheaper to build than any new detection content.


Confidence, and what would change it

Publicly: a single research disclosure, no observed in-the-wild use, no CVSS, no patch. Weaponization is a reasonable expectation because the barrier is low for an actor already at SYSTEM, but nothing so far says one has used it. Treat it as detection work on a two-week horizon, not as an emergency. The trigger to escalate is the first public tooling that automates the sequence. The trigger to relax is a Microsoft mitigation that constrains what the component will execute.

When the control is the weapon, the only honest telemetry is the alert that fires when the control goes quiet.

What to do

  1. Ship an 'agent absent after boot' detection this sprint, then prove it with a controlled tamper test against Defender's boot-time remediation configuration and security-service registry keys.

  2. Stand up control-liveness monitoring this quarter for five preventive controls: EDR check-in, tamper protection state, DLP policy enforcement, MFA coverage and log-pipeline heartbeat.

  3. Reissue AI and security vendor assurance requests this quarter demanding evidence of continuous safeguard testing and contractual notification when a control fails or is disabled.

Your Code Review Chain Now Includes Models Nobody Can Name

Model routers, unsigned agent skills and browser agents riding live sessions each bypass a different control you already own, and the fix in every case is verification you enforce yourself.

Nobody can name the legal entity behind the model call

The operative detail in the 'Ox Alpha' episode is not the merged pull requests. It is that a model with no vendor, no model card and no terms of service has no retention policy to breach, no jurisdiction to assess and no counterparty to notify. Researchers spent the day arguing whether it was a GLM-5.3 or 5.4 Vision derivative and settled nothing. It was already being served through OpenRouter, Cline, Hermes Agent and OpenCode. Routers multiplex dozens of models behind a single hostname, so a provider-level allowlist saw an approved domain and let it through. Egress policy has to match on model identifier, deny unknown identifiers by default, and alert on first-seen IDs.


Skills are unsigned third-party code holding a developer's credentials

ByteByteGo's breakdown of the agent-skill ecosystem describes the same failure one layer down. A skill is instructions plus scripts. The instructions can override developer intent. The scripts execute. The twelve most-starred skill repositories as of August 2026 are dominated by individual maintainers, with no signing, no SBOM entry and no compile step to inspect. Compromise one maintainer, merge a benign-looking commit, and every agent pulling from HEAD changes behavior. Blast radius equals whatever the agent can reach: repository write access, cloud tokens in the environment, CI secrets, connected MCP servers.

Two of the most popular entries, graphify and Understand-Anything, exist specifically to ingest an entire codebase, and neither documents its data flow. That is a source-code egress question, and it belongs in review before either reaches a standard developer image.


The identity layer is being bypassed, not attacked

AINews documented a local agent build that drove Playwright over already-authenticated SSO session cookies to navigate university systems and pull records. No new login, no MFA prompt, no impossible-travel signal, and a legitimate managed device. The IdP has nothing to alert on. The CASB sees ordinary traffic to a sanctioned application, and EDR sees a developer tool doing developer-tool things. The anomaly surfaces in one place, application logs: request velocity, navigation with no human dwell time, missing front-end telemetry beacons, headless and CDP fingerprints. Mapped to ATT&CK that is T1550.004 layered on T1078. The same technique that retrieves a record makes destructive state changes on any system that trusts an active session.


Where independent reports converge

Latent.Space argues the enforcement boundary for agentic coding moved from a human clicking approve to a declarative permission file, and notes that harness configuration alone swung measured capability by 23.8 points across identical tasks. Box of Amazing reports developers approving 93% of AI code suggestions out of approval fatigue. AINews reaches the same conclusion from the AI industry's own history: verification, not generation, is the control point.

The operating rule follows from that. Agent output is auto-mergeable only where automated verification already exists: tests, policy-as-code, SAST. IAM policy, cryptography, network ACLs and detection logic stay human-approved, and "a developer accepted it" stops counting as review.

If your gateway allowlists providers instead of model identifiers, you do not know which model approved your last release.

What to do

  1. Enforce a model-ID allowlist at the LLM egress gateway within two weeks, denying unknown identifiers by default and alerting on first-seen model IDs.

  2. Require one human CODEOWNER approval on every protected branch this sprint, bar agent approvals from satisfying review, and label agent-authored commits with provenance metadata.

  3. Pin every agent skill to a reviewed commit SHA in an internal mirror this sprint, and sweep internal and external ranges for unauthenticated Ollama, vLLM and SGLang endpoints.

A $966M Fine for an Automated Account Suspension

Machine-speed containment is still lawful in Europe; what the regulator priced was the missing evidence trail, and most response runbooks cannot produce it for a single action.

The evidence test: the last ten containment actions

Take the last ten times automation in the environment disabled an account or revoked a session. For each, three artifacts: the notification sent to the affected person, the immutable record of the evidence that drove the decision, and the documented route by which that person reached a human. Most programs produce none of the three. Response tooling was built to minimize mean time to contain. Due process was never in the requirements document.

The Dutch regulator's finding turned on that gap. Automation was not the violation. Automation without prior warning and without an accessible human-intervention path was. Uber is appealing. Its argument that only 126 European drivers were deactivated on ratings in 2021 did not reduce the penalty. The decision priced the architecture, not the volume.


The pattern is already in the runbook

Risk-score-triggered account disablement. UEBA-driven session revocation. Conditional-access lockout on impossible travel. Fraud-signal suspension of a customer account. Each is a consequential automated decision about an identifiable EU data subject, executed in milliseconds, usually with no notice and no recorded human review. GDPR Article 22 does not forbid it. Fraud prevention remains a legitimate basis for automated processing. The safeguards are mandatory: the right to obtain human intervention, and the right to contest the outcome.


Containment speed is not what gets traded

The missing artifacts are cheap against the exposure. An approval gate for non-emergency actions, or a documented post-hoc review window where speed genuinely matters. Prompt notification to the affected person. An immutable decision log capturing the signals, the rule version and the outcome. A published contest path with an SLA, plus a DPIA refresh that names these flows explicitly. None of it slows a containment action. All of it converts a defensible decision into an evidenced one. That is the difference the regulator charged for.


The second clock in the same room

ByteByteGo notes that EU AI Act transparency and marking obligations for AI-generated content became applicable in August 2026, and that the duty sits with the deployer rather than with a model vendor's watermarking scheme. Two regimes, one requirement: an automated system needs a decision record its operator owns and can produce on demand. Triage or auto-remediation tooling that begins generating consequential outcomes for identifiable people runs both clocks at once. Build the record once and it serves both.

An automated containment action that cannot produce a decision record is not a fast control. It is an unevidenced one.

What to do

  1. Inventory every automated action in SOAR, the IdP and fraud engines that suspends or restricts an EU data subject within 30 days, flagging which paths run with no notification and no human review.

  2. Add an immutable decision log, a notification step and a published contest SLA to those paths this quarter, and refresh the DPIA to cover them.

  3. Assign a named owner this quarter for EU AI Act Article 50 marking obligations on each generative feature you ship, with the evidence artifact identified per surface.

The bottom line

The pattern running through this briefing is not a new adversary technique. It is a class of control that runs, produces no alarm, and has nothing watching it: trusted components, live sessions, guardrails absorbed into weights, verdicts issued at machine speed with no record behind them. That breaks the assumption underneath most control narratives, which is that a deployed control is an evidenced control. Make control liveness a named owner's job this week — every preventive control gets a heartbeat, a tamper alert and a decision record — and require anything automated to beat a documented baseline before it stands in for a human.