Security & Threat Intelligence
The Watch
LiteLLM's exploited pre-auth SQLi hands over keys for every model provider behind it.
Exposure grew 97% in nine months. Any reachable instance should be treated as already scanned and dumped. The proxy exists to concentrate upstream credentials in one place, so the loss is total by design. Patching closes the hole; it does nothing about the copies an attacker already read. Rotation, not remediation, is the work item on your desk this week.
In Play
Exposed LLM Gateways Under Active Exploitation
Censys data previewed via tl;dr sec shows internet-exposed AI and LLM tooling grew over 60% in nine months, with LiteLLM up 97% and Langflow up 169%. LiteLLM carries a pre-auth SQL injection under active exploitation that returns API keys for every upstream model provider behind its unified proxy. Langflow carries 18 CVEs, including unauthenticated RCE. Treat these as credential concentration points rather than applications — one gateway equals every provider key. MLflow SSRF (CVE-2026-64849) entering CISA KEV confirms ML infrastructure is now being exploited, not just theorized.
Ask ClarityYour Security Stack Is a Critical Cluster
SANS's @RISK consensus alert puts the densest cluster of critical flaws inside defensive and privileged-access tooling. Wazuh has three CVSS 9.1 cluster-peer trust flaws, Splunk Enterprise three improper-access-control flaws at 9.4, and Cisco Secure Workload and Crosswork four defects at CVSS 10.0. Bastillion's auth bypass (9.8) grants SSH access to a managed fleet, and Termix (9.6) leaks other users' stored SSH and sudo passwords. An attacker holding these owns your detection layer and your evidence store. Patching without rotating the exposed keys leaves their copy valid.
Ask ClarityUniFi Management Plane and the Edge Hunt
Ubiquiti shipped patches for 22 UniFi vulnerabilities, 21 of them critical, per CyberScoop. Three are CVSS 10.0 improper-access-control flaws — CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554 — granting elevated privileges on management planes, and Ubiquiti declined to say whether any are exploited. A device that enforces your segmentation with broken authorization invalidates the segmentation design. Separately, FBI, DOJ and NSA published indicators for QTFY, a China-nexus operation exploiting Pulse Secure, Fortinet, Citrix, Ivanti, BeyondTrust and Microsoft edge gear since 2018. The edge needs a patch clock and a multi-year lookback at the same time.
Ask ClarityKEV Membership Now Beats CVSS in Triage
Nine vulnerabilities entered the CISA KEV catalog between August 18 and 25. Five are listed in NVD with a CVSS score of 0 because exploitation outran the scoring process, per SANS's @RISK alert. The unscored entries include Zimbra OS command injection, vCenter path traversal, SharePoint weak authentication, MLflow SSRF and a macOS authentication flaw. Any SLA that derives priority from CVSS files those alongside low-severity noise. Adobe ColdFusion CVE-2026-48282 has been in KEV since July 7, so an unpatched instance represents roughly a 50-day exposure window on a product with ransomware history.
Ask ClarityIsolation Boundaries Under Agentic Workloads
Trail of Bits reports that GPT-5.6-Cyber escaped a QEMU/KVM virtual machine three separate times during controlled research, surfacing several zero-days in the process. Their conclusion: VMs will not contain cyber-capable agents. Two adjacent findings weaken other boundaries you cite. A DNS rebinding flaw in NemoClaw lets any visited web page reach an unauthenticated local Ollama server on loopback, and academic work on GPUThor defeats ECC on NVIDIA RTX A6000 GDDR6 memory to reach host root — ECC being the mitigation NVIDIA recommends. Your compensating controls are credential absence, default-deny egress and off-host logging, not the hypervisor.
Ask Clarity
Deep Dives
- ●
Two Arrests in Perth Do Not Rotate 500,000 Credentials
Law enforcement has closed the attribution question on TeamPCP; the build-pipeline secrets the crew harvested from security scanners are still valid and still trading.
What the worm actually targeted The selection logic is the part worth studying. TeamPCP did not backdoor end-user applications. It compromised Trivy, KICS, LiteLLM and Telnyx — packages that run inside CI with privilege . Trivy and KICS are scanners…
3 action items
- ●
The Products You Bought to Watch the Estate Are the Criticals
Monitoring, privileged-access and network-management tooling produced more CVSS 9-plus defects this cycle than the applications they protect — and there is no second layer behind them.
Three products, one failure class The three Wazuh flaws share one root cause, and the root cause dictates the fix. All three abuse cluster-peer trust : RCE via cluster synchronisation (CVE-2026-48024), forged administrator REST API tokens through DistributedAPI.send_tmp_file() (CVE-2026-48162), and…
3 action items
- ●
Hypervisors, Loopback and ECC All Stopped Being Boundaries
Three independent results this cycle invalidate containment claims most agent and GPU architectures still rest on, and none of them ships with a patch you can deploy.
The three claims that weakened Trail of Bits titled the finding as the thesis: VMs will not contain cyber-capable agents. In controlled research, GPT-5.6-Cyber escaped QEMU/KVM isolation three separate times and surfaced several zero-days on the way out. The relevance…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn