Security & Threat Intelligence

The Watch

The Signal

Defender's own boot driver can wipe your EDR before your first telemetry event exists.

Check Point drove the Microsoft-signed remediation driver to kernel file and registry operations pre-boot, so WDAC, driver blocklists and signature enforcement all wave it through.

In Play

  1. A Signed Component That Kills Your EDR

    Check Point Research demonstrated that Microsoft Defender's boot-time remediation driver can be driven to perform kernel-level file and registry operations, including deleting security software at boot, as reported by The Hacker News. Because the driver is signed by Microsoft, signature enforcement, WDAC-style allowlists and vulnerable-driver blocklists offer nothing. It runs before user-mode EDR telemetry exists. No patch is available and no CVSS has been assigned, so detection engineering owns this one.

  2. Exploited Code Injection and Five Perfect Scores

    GitLab's CVE-2026-19478 is a CVSS 9.4 code injection flaw, and watchTowr reports exploitation in the wild within days of disclosure, per The Hacker News. Cisco separately shipped nine fixes for Crosswork and Secure Workload, five of them rated CVSS 10.0, with no public exploitation reported yet. Both platforms hold privileged credentials — CI/CD tokens on one side, device credentials and microsegmentation policy on the other. Patching without rotating leaves stolen credentials valid.

  3. Unnamed Models and Unsigned Skills in the SDLC

    An unattributed model called 'Ox Alpha' reached production code review within 48 hours, and one prominent developer merged eight pull requests on its approval, per AINews. It was served through OpenRouter, Cline, Hermes Agent and OpenCode, so gateways that allowlist by provider rather than by model ID passed it through untouched. ByteByteGo separately documents agent skills — unsigned instructions plus scripts from single-maintainer repositories — executing with developer credentials.

  4. Automated Account Suspension Priced at Nine Figures

    The Dutch DPA fined Uber €825 million ($966 million) on 17 August 2026 for suspending accounts through automation with no prior warning and no human review, per Techpresso. It is the second-largest GDPR penalty after Meta's €1.2 billion in 2023. Uber is appealing, and its argument that only 126 European drivers were deactivated on ratings in 2021 did not reduce the fine. Your SOAR and UEBA response paths disable EU data subjects the same way.

  5. Agent Panels Vote Down the Decisive Signal

    Anthropic ran the classic hidden-profile test on four-agent AI panels, where only one agent holds the decisive evidence. Most model families reached the correct decision in 17–36% of runs. A single agent handed the entire evidence base was right nearly every time, per Exponential View. Every low-and-slow intrusion has that shape: benign majority telemetry, one weak decisive indicator. The figures arrived without linked methodology, so treat the magnitude as directional.

Deep Dives

  1. Patching GitLab Is Half of Remediating It

    Two vendors shipped critical fixes for platforms that store your credentials, and in both cases the update closes the hole while leaving whatever the attacker already took fully valid.

    What an exploited instance costs A self-hosted GitLab holds CI/CD variables, runner registration tokens, personal access tokens, deploy keys, SSH keys, and every pipeline definition that describes how software reaches production. It is a credential store with a web front…

    3 action items

  2. The EDR Kill Switch Microsoft Signed

    A trusted component that runs before your telemetry does turns detection into a hunt for missing signals, and it exposes how few preventive controls in your estate report that they are still alive.

    Start with what the technique requires This is not initial access. Driving Defender's boot-time remediation component to perform kernel-level file and registry operations requires administrator or SYSTEM already in hand . That places it at the impact stage: ATT &…

    3 action items

  3. Your Code Review Chain Now Includes Models Nobody Can Name

    Model routers, unsigned agent skills and browser agents riding live sessions each bypass a different control you already own, and the fix in every case is verification you enforce yourself.

    Nobody can name the legal entity behind the model call The operative detail in the 'Ox Alpha' episode is not the merged pull requests. It is that a model with no vendor, no model card and no terms of service…

    3 action items

  4. A $966M Fine for an Automated Account Suspension

    Machine-speed containment is still lawful in Europe; what the regulator priced was the missing evidence trail, and most response runbooks cannot produce it for a single action.

    The evidence test: the last ten containment actions Take the last ten times automation in the environment disabled an account or revoked a session. For each, three artifacts: the notification sent to the affected person, the immutable record of the…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 4 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn