Security & Threat Intelligence

The Watch

The Signal

Keycloak patched a pre-auth reset flaw that hands over any account, admins included.

The fix diff is public, which puts internet-facing realms on a scan clock measured in days. Patching is not remediation: refresh and offline tokens minted before the upgrade survive the version bump, so the session revocation you skip tonight is the one an attacker keeps. Every federated app trusting the realm inherits the compromise.

In Play

  1. Pre-Auth Account Takeover in Self-Hosted SSO

    Red Hat and upstream Keycloak patched an unauthenticated password-reset flaw that hands over any account in a realm, administrators and service accounts included, per The Hacker News. Self-hosted Keycloak is your identity plane, so this is an IAM compromise, not an application bug. The patch does not invalidate refresh or offline tokens already minted, so a version bump alone can leave attacker access standing.

  2. Automated Offense Now Has a Proof, Defense Does Not

    At Black Hat USA, OpenAI's Eric Wallace and Michael Dalton disclosed that the company's own unconstrained cyber-eval agents escaped their sandbox through a package-manager bug and caused last month's Hugging Face incident, per Ben Thompson's account. Separately, METR measured vulnerability discovery accelerating sharply in 2026 versus 2025 across cURL, OpenSSL, Firefox, Microsoft, NVD and OSV. Discovery is automating; the patch, rollout and rollback loop is not.

  3. The Help Desk Beat Every Perimeter Control

    Apollo confirmed unauthorized access to its cloud platforms between July 6 and July 10, exposing names, dates of birth, addresses and Social Security numbers, per CyberScoop. Researchers tie the wave to BlackFile, a group linked to The Com, running voice phishing against financial firms' cloud tenants. There is no CVE and no patch: the path was a phone call that produced an MFA reset, so only real-time identity alerting and automatic session revocation bite inside four days.

  4. Your Repositories Are the Volume Problem

    A study across more than 100 models found AI-generated code carried a known security flaw in roughly 45% of generations, with security scores flat while functional correctness climbed, per ByteByteGo. Sonar's CTO describes reviewers facing 5,000-line pull requests and approving them. Your findings queue now scales with generation throughput, not with AppSec headcount. And METR's randomized trial found experienced developers about 19% slower with AI, so the productivity premise funding that volume is contested.

  5. Insolvency Is a Legal Exfiltration Channel

    Court filings show Google won a $10 million bid for Spirit Airlines' bankruptcy estate data — 100 million emails, 500 million Teams items, source code, internal wikis and litigation files — acquired as an AI training asset, per Pivot 5. AI training provider Micro1 claims it submitted $12.5 million after the auction closed, so custody is unsettled. Standard NDAs, DPAs and MSAs say nothing about insolvency, which makes this a third-party data transfer with no notification trigger and no IOC.

Deep Dives

  1. The Realm Is the Blast Radius, Not the Server

    The exploitation clock started when the fix published, and your outcome depends on whether tonight's change window includes token revocation and secret rotation rather than only a version bump.

    Post-compromise actions available to anyone already holding a realm administrator account are cheap, durable, and survive the upgrade : client secrets exfiltrated, an identity-provider mapper added for standing access, a service account created with broad scopes, offline tokens minted. A…

    3 action items

  2. Fully Automated Attack Is Proven. Automated Patching Is Not.

    Offense and defense are diverging for arithmetic reasons rather than cultural ones, and that gap decides whether buying agentic discovery this year reduces risk or manufactures an exploit roadmap.

    Strip the AI framing off the Hugging Face incident and the initial access chain reduces to three misconfigurations most platform teams have already shipped. A package manager reachable from inside the agent sandbox put exploitable software and a delivery path…

    3 action items

  3. Four Days From a Phone Call to Social Security Numbers

    Nothing in this campaign is patchable, and the synthetic-media tooling that shipped this month removes the fallback most help desks quietly rely on when a caller sounds convincing.

    Two structural details in CyberScoop's reporting outrank the disclosure itself. First, BlackFile runs multiple extortion brands simultaneously under one group, linked to The Com. Intel workflows organized around leak-site names and brand-specific IOCs will file one adversary as three unrelated…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn