Security & Threat Intelligence

The Watch

The Signal

Any website could pull live vault tokens from N-able Passportal for up to 100 days.

Decryption happens server-side, so a stolen token is the vault, not a step toward it. The 3.49.6 patch stops new leakage only. Tokens harvested before it still authenticate, and MSP concentration means one compromised provider discloses vaults across every customer it manages, including yours.

In Play

  1. Password Manager Handed Out Live Vault Tokens

    N-able Passportal's browser extension returned live vault access and refresh tokens to any website or embedded iframe, per SANS NewsBites. Because Passportal is MSP-concentrated, one extension bug becomes an event across every tenant an affected provider manages.

  2. Agent Logs Are Credential Stores Nobody Can Read

    A joint team from MATS Research, ELLIS Institute Tubingen and the Max Planck Institute showed that the encrypted reasoning blocks Anthropic, OpenAI and Google return to API clients can be replayed into a cheaper model in the same family, which then prints the hidden chain-of-thought in plaintext. Plaintext secret scanning finds none of it, because the secret sits inside an envelope no scanner decrypts.

  3. The Exploited Bugs Are Months Old, and MFA Is Being Walked Around

    CISA added an actively exploited Oracle HTTP Server / WebLogic flaw to the KEV catalog, against a fix that shipped in January 2026. The Hacker News and Risky.Biz both report a SharePoint chain moving from public proof-of-concept to in-the-wild exploitation inside a week. And the Mirage2FA phishing-as-a-service kit is defeating Microsoft 365 two-factor by abusing legitimate login flows.

  4. Package Registries Are Being Used as Delivery, Not Payload

    CloudSEK documented BRIDGEHEAD, a cluster of 40 typosquatted npm packages that pivots into Windows Subsystem for Linux to run a Rust infostealer where most Windows endpoint agents collect no telemetry, per Risky.Biz. A separate ClickFix campaign uses 24 npm packages that are individually harmless on install, serving lures from the unpkg CDN your proxy already allowlists. Step Security counts 56 supply chain attacks since August 2025, 50 of them in 2026, most spread by self-replicating worms rather than single malicious releases.

  5. Your Telemetry Pipeline Changed Owners

    Roughly $5.35B of observability M&A closed in about 90 days: Palo Alto Networks bought Chronosphere for $3.35B, Snowflake took Observe for $1B, Dynatrace paid $915M for Arize AI and Elastic acquired Deductive AI for $85M. Several telemetry vendors now sit under new parents, new roadmaps and new subprocessor chains, and in the Palo Alto case enforcement and visibility land inside one vendor's blast radius. The layer that routes security logs before your SIEM sees them can also drop them, using supported product features and leaving no alert behind.

Deep Dives

  1. The Vault Was Decrypted Server-Side, So the Token Is the Vault

    One extension bug in an MSP-favoured credential manager produces an N-tenant disclosure event, and the vendor's fast patch does nothing about the tokens already in circulation.

    The architecture sets the remediation cost. Passportal decrypts vaults server-side rather than end-to-end, so vault contents are recoverable by anyone holding a valid token. The extension flaw was disclosed by James Arnott and is tracked as CVE-2026-15580 . It is…

    3 action items

  2. Encrypted Reasoning Blocks Are Bearer Tokens With Your Secrets Inside

    Researchers replayed provider-issued reasoning envelopes into cheaper sibling models and read the hidden traces back in plaintext, turning published agent logs into a credential store no scanner can inspect.

    The cryptography held. The schema did not. The AEAD envelope providers wrap around reasoning traces authenticates block content, model name and model version. It does not authenticate the account that produced the block, or the conversation it belonged to. Those…

    3 action items

  3. August's Exploitation Is January's Patch, and MFA Is Being Circumvented Not Broken

    Three independent reads converge on the same uncomfortable finding: nothing exotic is breaching networks, and two of the four KEV deadlines in this batch expired before most teams read the advisory.

    Start with the latency, because the latency is the finding. CVE-2026-21962 is an improper access control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in. CVSS 10.0. Fixed in the January 2026 Critical Patch Update , KEV-listed, federal deadline…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn