Security & Threat Intelligence

The Watch

The Signal

Any website could pull live vault tokens from N-able Passportal for up to 100 days.

Decryption happens server-side, so a stolen token is the vault, not a step toward it. The 3.49.6 patch stops new leakage only. Tokens harvested before it still authenticate, and MSP concentration means one compromised provider discloses vaults across every customer it manages, including yours.

In Play

  1. Password Manager Handed Out Live Vault Tokens

    N-able Passportal's browser extension returned live vault access and refresh tokens to any website or embedded iframe, per SANS NewsBites. Because Passportal is MSP-concentrated, one extension bug becomes an event across every tenant an affected provider manages.

    Ask Clarity
    Try
  2. Agent Logs Are Credential Stores Nobody Can Read

    A joint team from MATS Research, ELLIS Institute Tubingen and the Max Planck Institute showed that the encrypted reasoning blocks Anthropic, OpenAI and Google return to API clients can be replayed into a cheaper model in the same family, which then prints the hidden chain-of-thought in plaintext. Plaintext secret scanning finds none of it, because the secret sits inside an envelope no scanner decrypts.

    Ask Clarity
    Try
  3. The Exploited Bugs Are Months Old, and MFA Is Being Walked Around

    CISA added an actively exploited Oracle HTTP Server / WebLogic flaw to the KEV catalog, against a fix that shipped in January 2026. The Hacker News and Risky.Biz both report a SharePoint chain moving from public proof-of-concept to in-the-wild exploitation inside a week. And the Mirage2FA phishing-as-a-service kit is defeating Microsoft 365 two-factor by abusing legitimate login flows.

    Ask Clarity
  4. Package Registries Are Being Used as Delivery, Not Payload

    CloudSEK documented BRIDGEHEAD, a cluster of 40 typosquatted npm packages that pivots into Windows Subsystem for Linux to run a Rust infostealer where most Windows endpoint agents collect no telemetry, per Risky.Biz. A separate ClickFix campaign uses 24 npm packages that are individually harmless on install, serving lures from the unpkg CDN your proxy already allowlists. Step Security counts 56 supply chain attacks since August 2025, 50 of them in 2026, most spread by self-replicating worms rather than single malicious releases.

    Ask Clarity
  5. Your Telemetry Pipeline Changed Owners

    Roughly $5.35B of observability M&A closed in about 90 days: Palo Alto Networks bought Chronosphere for $3.35B, Snowflake took Observe for $1B, Dynatrace paid $915M for Arize AI and Elastic acquired Deductive AI for $85M. Several telemetry vendors now sit under new parents, new roadmaps and new subprocessor chains, and in the Palo Alto case enforcement and visibility land inside one vendor's blast radius. The layer that routes security logs before your SIEM sees them can also drop them, using supported product features and leaving no alert behind.

    Ask Clarity
    Try

Deep Dives

The Vault Was Decrypted Server-Side, So the Token Is the Vault

One extension bug in an MSP-favoured credential manager produces an N-tenant disclosure event, and the vendor's fast patch does nothing about the tokens already in circulation.

The architecture sets the remediation cost. Passportal decrypts vaults server-side rather than end-to-end, so vault contents are recoverable by anyone holding a valid token. The extension flaw was disclosed by James Arnott and is tracked as CVE-2026-15580. It is a browser-extension messaging failure of the familiar class: main-world and iframe contexts are not meaningfully isolated. Any site the user visited could request tokens and receive them. So could any iframe inside it, including a third-party ad tag.

N-able's PSIRT remediated within roughly one to three days of disclosure. That is genuinely fast. It does not change the exposure arithmetic. A patch stops issuance. It does not revoke. Both access and refresh tokens went out, which is why the window runs up to 100 days instead of ending at the next session expiry, and why live TOTP retrieval is in scope alongside stored passwords.


The multiplication factor is the customer list, not the CVSS

Passportal is concentrated among managed service providers. The population of affected vaults is therefore not the population of affected browsers. One MSP technician's leaked token can enumerate credentials for every downstream tenant that provider administers. That includes organizations running the extension nowhere at all. This is the rare case where full exposure coexists with zero affected assets in local inventory.

Remediation stepWhat it fixesWhat it leaves open
Upgrade to extension 3.49.6 and enable admin version lockingNew token leakage to sites and iframesEvery token issued before the upgrade
Revoke all access and refresh tokensReplay of harvested session materialSecrets already read out of the vault
Rotate stored secrets and re-enroll TOTP seedsValue of anything already enumeratedNothing, if scope is complete
MSP written attestationYour visibility into third-party exposureTenants whose provider does not answer

Where the compliance trap sits

An extension inventory showing 3.49.6 everywhere is the artifact that will be presented as remediation evidence. It demonstrates nothing about whether harvested tokens were invalidated. Any control narrative for credential management resting on "patched within SLA" breaks here, because the SLA clock and the risk clock are measuring different things. The closure record should carry rotation completion, not a version number.

The procurement consequence

SANS NewsBites frames the root cause as vendor architecture rather than a coding defect. That is the durable lesson. A credential store that can decrypt on its own servers holds a skeleton key with a vendor's name on it, and every bearer token it issues is functionally a copy of that key. Client-side-only decryption belongs in the gating criteria for secrets and credential management tooling, next to SOC 2 scope and breach-notification SLAs.

Patching the password manager does not close this. The leaked vault tokens stay valid, which makes this a credential-rotation exercise wearing a patch cycle's clothing.

Two caveats worth logging. Exploitation in the wild has not been reported. The 100-day figure describes token validity, not confirmed dwell time. Neither changes the rotation decision, because a negative cannot be proven against tokens nobody can see.

What to do

  1. Revoke every Passportal access and refresh token, rotate all stored secrets and re-enroll TOTP seeds within 72 hours, then confirm extension version 3.49.6 or later with admin version locking enabled

  2. Request written remediation and rotation attestation from every MSP with Passportal in its stack by end of week, naming your tenants explicitly

  3. Add client-side-only decryption as a gating requirement for credential and secrets management tooling at the next procurement review

Encrypted Reasoning Blocks Are Bearer Tokens With Your Secrets Inside

Researchers replayed provider-issued reasoning envelopes into cheaper sibling models and read the hidden traces back in plaintext, turning published agent logs into a credential store no scanner can inspect.

The cryptography held. The schema did not. The AEAD envelope providers wrap around reasoning traces authenticates block content, model name and model version. It does not authenticate the account that produced the block, or the conversation it belonged to. Those fields are absent from the authenticated portion. A valid envelope therefore functions as a universal bearer artifact across users, sessions and models. No patch applies, because nothing is broken in the sense a CVE describes.

The extraction chain requires no privileged access. Query a flagship model with something benign, discard the visible answer, keep the encrypted block, then open a fresh conversation with a weaker same-family model and ask it to transcribe the attached reasoning. Refusal training on the flagship never engaged, because the flagship was never asked anything harmful. Anti-distillation defences sit almost entirely in the expensive models. The cheap siblings tuned for cost and speed accept their relatives' blocks. A model family is only as secure as its least-protected member.

ProviderEnvelope fieldCross-model acceptanceYour replay exposure
Google (Gemini)thinkingSignatureEvery combination observedWidest of the three
Anthropic (Claude)signatureNearly all pairs; Fable 5 restricted to itselfCheapest, most reliable extraction
OpenAI (GPT)encrypted_contentGeneration-gated, newer accepts olderStrongest defences, still defeated

The number that sets priority

The research team pulled 6,708 public agent trajectories from GitHub and Hugging Face and decoded 315,320 reasoning blocks. Recovered from genuine user sessions: 62 API keys, 33 passwords, 24 access tokens, 7 private keys, 30 personal email addresses. 328 sessions leaked at least one item, a 4.9% base rate. Perfect scrubbing of visible text would not have moved that key count. All 62 API keys would still be there, because sanitisation operates on plaintext and nobody can read the envelope, including its owner.

Why this reaches internal repos too

A coding agent told to remove hardcoded credentials must first read those credentials, and they transit the reasoning trace before any answer exists. The highest-confidence leaks are the remediation tickets, not the careless ones. GitHub and Hugging Face secret scanning are structurally blind here. So is a pre-commit hook, unless the three field names go in as custom patterns.

Second-order vector worth naming for the SOC: a planted block carrying instructions to upload PowerPoint files was ported into an unrelated slide-editing session, and the generated script performed both the edit and the upload. Resuming a published agent trajectory is now an untrusted-code decision. The payload is invisible to human review.

Our agent logs are unredacted credential stores that neither we nor GitHub's scanner can read, and anyone who copies one decodes it for cents.

Confidence caveat: this is one research group's July-August 2026 snapshot, provider schemes were inferred from behaviour rather than documentation, and fidelity was validated across 120 programming problems. Some behaviour may already be patched. The credential exposure is not conditional on any of that.

What to do

  1. Grep repos, CI artifact stores, log buckets, ticketing systems and public org accounts for the JSON keys signature, encrypted_content and thinkingSignature, then strip and purge rather than attempting redaction

  2. Rotate every credential any coding or agentic session has read, prioritising sessions whose logs were committed or shared externally and explicitly including secret-removal remediation tasks

  3. Configure the LLM gateway to reject inbound reasoning envelopes it did not issue and to ban resumption of externally produced agent trajectories

August's Exploitation Is January's Patch, and MFA Is Being Circumvented Not Broken

Three independent reads converge on the same uncomfortable finding: nothing exotic is breaching networks, and two of the four KEV deadlines in this batch expired before most teams read the advisory.

Start with the latency, because the latency is the finding. CVE-2026-21962 is an improper access control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in. CVSS 10.0. Fixed in the January 2026 Critical Patch Update, KEV-listed, federal deadline August 27. CISA reports attackers using it to reach corporate environments and to steal or modify data. Exploitation in August against a January fix means the adversary is harvesting organisations running seven-month-old middleware. Nobody here is facing a zero-day.

The rest of the KEV batch reads the same way. TrueConf Server CVE-2026-72529, missing authentication, 9.8, deadline August 23. CVE-2026-73570 in Zimbra, OS command injection, 8.9, fixed in 10.1.20, deadline August 24. Both dates expired before the advisories reached most desks. TrueConf CVE-2026-72530 at 9.0 runs to September 3. At the other end of the curve, a SharePoint chain including CVE-2026-55040 moved from public proof-of-concept to in-the-wild exploitation inside a week. Disclosure-to-exploitation is shortening and patch-to-application is not. Manual change management sits between the two.


Where the three reads agree, and where one dissents

SANS NewsBites, Risky.Biz and The Hacker News independently rank the Oracle middleware item as the top action. All three describe it as pre-authenticated and confirmed exploited. The Hacker News flags a gap in its own source material: no CVE identifier, no affected version ranges, so validate scope against the KEV feed and Oracle's advisory before opening change tickets. That is a sourcing note, not a dispute over severity.

The authentication half

Two items in this batch involve no software vulnerability at all. Mirage2FA, a commercial phishing-as-a-service kit, has worked through roughly 4,500 US and EU organisations between 2024 and 2026, relaying legitimate Microsoft 365 login flows and taking post-MFA sessions. The miniOrange SAML 2.0 SSO plugin for WordPress carries two unauthenticated bypasses under active exploitation, both allowing sign-in as any user, administrators included. The pattern across both: authentication is not being broken, it is being routed around. Stolen sessions in one case, forged assertions in the other.

ItemStatusDoes patching resolve it?
Oracle HTTP Server / WebLogic CVE-2026-21962Exploited, KEV, deadline Aug 27Yes, plus assume-compromise hunt
SharePoint chain incl. CVE-2026-55040Exploited within a week of POCYes, plus webshell and admin-object hunt
miniOrange SAML 2.0 SSO (WordPress)Active exploitation attemptsYes, if you can find the shadow estate
Mirage2FA against Microsoft 365Industrial scale, 2024-2026No — needs phishing-resistant auth and token binding

Operationally, any compliance narrative that reads "MFA enforced, therefore account takeover mitigated" is factually wrong. Password-plus-OTP is a bypass available on subscription. That is what a four-figure victim count looks like.

The prioritisation signal came from the KEV catalogue, not from a model. Patch the internet-facing middleware, then retire password-plus-OTP for privileged identities.

What to do

  1. Inventory every internet-facing Oracle HTTP Server and WebLogic instance including forgotten /console, /em, T3 and IIOP listeners, and patch to the January 2026 CPU or take offline within 72 hours

  2. Enforce FIDO2 or passkeys for all privileged, finance and executive Microsoft 365 identities this sprint, then hunt 90 days of sign-in logs for MFA-satisfied sign-ins from new ASNs and new inbox forwarding rules

  3. Sweep the shadow WordPress estate including marketing microsites and acquired-company properties for the miniOrange SAML plugin, patch or disable, then audit admin users and rotate auth salts

The bottom line

These failures share a shape: none involved broken cryptography or an unpatched line of code, and every one turned on an artifact that was valid, portable and bound to nothing but itself. That breaks the assumption underneath most remediation plans — that shipping the fixed version ends the incident. When the thing in the adversary's hands was legitimately issued, only invalidation and binding close the exposure, and neither shows up in a version inventory. Run a replay drill: take one credential class your team believes is scoped, present it from an unrelated identity and machine, and record whether anything in the path refuses it.