Security & Threat Intelligence
The Watch
Next.js fixed two unauthenticated RCEs that carry no CVE your scanner can key on.
Patched lines are 16.3.3 and 15.5.24. For 14.x there is no stated path, which makes a major-version upgrade the entire remediation plan for anyone still running it. One request reaches the rendering process holding session signing secrets, upstream API keys and database connection strings. The disclosure moved through community channels before any vulnerability feed carried it, so a patch cycle that waits on feed ingestion heard about this late.
In Play
Next.js Pre-Auth RCE With No CVE Attached
React Status reports two critical unauthenticated remote code execution flaws in Next.js are now patched, with fixes in 16.3.3 and 15.5.24. Unauthenticated means nothing stands between a mass scanner and your server-rendering runtime — the process that holds session signing secrets, upstream API keys and database strings. Only those two branches are named as remediated; 14.x and earlier have no stated fix path in the disclosure. No CVE IDs or CVSS vectors were published with it.
Ask ClarityOffensive Capability Is Now a Download
Aikido Security put 10 models against 32 freshly disclosed CVEs, three runs each, and DeepSeek V4 Pro — open weights, downloadable — rediscovered 28 of 32, per Executive Offense. TrustedSec separately found 27–31B models on under-desk hardware handling SQLi auth bypass, JWT manipulation and IDOR. Refusal filters, rate limits and vendor abuse telemetry were implicit controls in your risk register, and a downloaded model has none of them. Weaponization still trails discovery badly, which is where sources diverge.
Ask ClarityLocalhost Stopped Being a Boundary
Computerworld reports a DNS rebinding flaw that lets any visited web page reach an AI agent's unauthenticated local Ollama server and write instructions that persist across future conversations. No malware, no phishing payload — a browser tab. AINews adds Nous Research's Hermes Agent, which browses "as you" using a managed copy of a user's real Chrome profile and live logins. Both produce telemetry your stack reads as legitimate activity, and neither leaves an artifact EDR was built to see.
Ask ClarityPrompt Injection Reaches Actuators
Anthropic opened a research preview of the Model Hardware Standard, a shared driver spec that lets agents discover and operate microscopes, liquid handlers, robotic arms and laser systems through one interface. Early access includes Genentech, Carnegie Mellon, QuEra, Universal Robots, Doosan Robotics, Danaher and AWS. TLDR Hardware notes the spec as described ships read/write primitives plus natural-language device metadata, with no authentication, authorization or interlock layer. Injection now ends in motion.
Ask ClarityYour Vendor Block List Just Lost in Court
A federal judge ordered the Pentagon to rescind its "supply-chain risk" designation of Anthropic, ruling it unlawful First Amendment retaliation for policy criticism, as reported by The Information and MIT Technology Review. Judge Rita Lin's 59-page opinion notes the Pentagon kept working with Anthropic after blacklisting it. If your third-party risk workflow auto-ingests government designations as hard vendor blocks, you own a false positive with no audit defense. An appeal is expected.
Ask Clarity
Deep Dives
- ●
Two of the Worst Bugs in This Briefing Have No CVE ID
Your queue is ordered by identifiers that the most exploitable findings never received, and the evidence that a public exploit signals real danger has collapsed.
The finding with no identifier at all A public proof-of-concept exists for the Log4j2 serialized-event receiver . Per Matt Johansen's reporting there is no CVE, no fixed release, and Apache treats it as hardening rather than a vulnerability. Exploitation requires…
3 action items
- ●
The Agent Plane on Your Endpoints Has No Auth and No Logs
Four separate reports this cycle put an unauthenticated network service, six pooled vendor credentials and a live browser session on the same developer laptop, and none of it appears in your asset inventory.
The chain is four steps and needs no malware A local inference server binds to loopback and accepts API calls with no authentication , on the industry-wide assumption that localhost is unreachable. An attacker-controlled page, visited rather than installed, serves…
3 action items
- ●
Prompt Injection With a Torque Spec
The friction that has quietly served as your access control on lab and factory instruments — weeks of bespoke vendor integration per device — is exactly what this research preview removes.
Where the safety envelope actually comes from The Model Hardware Standard encodes tacit physical knowledge into machine-readable natural language : a robot arm's weight, once known only to a paper manual or an engineer. Read it as a security engineer…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn