Security & Threat Intelligence

The Watch

The Signal

Next.js fixed two unauthenticated RCEs that carry no CVE your scanner can key on.

Patched lines are 16.3.3 and 15.5.24. For 14.x there is no stated path, which makes a major-version upgrade the entire remediation plan for anyone still running it. One request reaches the rendering process holding session signing secrets, upstream API keys and database connection strings. The disclosure moved through community channels before any vulnerability feed carried it, so a patch cycle that waits on feed ingestion heard about this late.

In Play

  1. Next.js Pre-Auth RCE With No CVE Attached

    React Status reports two critical unauthenticated remote code execution flaws in Next.js are now patched, with fixes in 16.3.3 and 15.5.24. Unauthenticated means nothing stands between a mass scanner and your server-rendering runtime — the process that holds session signing secrets, upstream API keys and database strings. Only those two branches are named as remediated; 14.x and earlier have no stated fix path in the disclosure. No CVE IDs or CVSS vectors were published with it.

  2. Offensive Capability Is Now a Download

    Aikido Security put 10 models against 32 freshly disclosed CVEs, three runs each, and DeepSeek V4 Pro — open weights, downloadable — rediscovered 28 of 32, per Executive Offense. TrustedSec separately found 27–31B models on under-desk hardware handling SQLi auth bypass, JWT manipulation and IDOR. Refusal filters, rate limits and vendor abuse telemetry were implicit controls in your risk register, and a downloaded model has none of them. Weaponization still trails discovery badly, which is where sources diverge.

  3. Localhost Stopped Being a Boundary

    Computerworld reports a DNS rebinding flaw that lets any visited web page reach an AI agent's unauthenticated local Ollama server and write instructions that persist across future conversations. No malware, no phishing payload — a browser tab. AINews adds Nous Research's Hermes Agent, which browses "as you" using a managed copy of a user's real Chrome profile and live logins. Both produce telemetry your stack reads as legitimate activity, and neither leaves an artifact EDR was built to see.

  4. Prompt Injection Reaches Actuators

    Anthropic opened a research preview of the Model Hardware Standard, a shared driver spec that lets agents discover and operate microscopes, liquid handlers, robotic arms and laser systems through one interface. Early access includes Genentech, Carnegie Mellon, QuEra, Universal Robots, Doosan Robotics, Danaher and AWS. TLDR Hardware notes the spec as described ships read/write primitives plus natural-language device metadata, with no authentication, authorization or interlock layer. Injection now ends in motion.

  5. Your Vendor Block List Just Lost in Court

    A federal judge ordered the Pentagon to rescind its "supply-chain risk" designation of Anthropic, ruling it unlawful First Amendment retaliation for policy criticism, as reported by The Information and MIT Technology Review. Judge Rita Lin's 59-page opinion notes the Pentagon kept working with Anthropic after blacklisting it. If your third-party risk workflow auto-ingests government designations as hard vendor blocks, you own a false positive with no audit defense. An appeal is expected.

Deep Dives

  1. Two of the Worst Bugs in This Briefing Have No CVE ID

    Your queue is ordered by identifiers that the most exploitable findings never received, and the evidence that a public exploit signals real danger has collapsed.

    The finding with no identifier at all A public proof-of-concept exists for the Log4j2 serialized-event receiver . Per Matt Johansen's reporting there is no CVE, no fixed release, and Apache treats it as hardening rather than a vulnerability. Exploitation requires…

    3 action items

  2. The Agent Plane on Your Endpoints Has No Auth and No Logs

    Four separate reports this cycle put an unauthenticated network service, six pooled vendor credentials and a live browser session on the same developer laptop, and none of it appears in your asset inventory.

    The chain is four steps and needs no malware A local inference server binds to loopback and accepts API calls with no authentication , on the industry-wide assumption that localhost is unreachable. An attacker-controlled page, visited rather than installed, serves…

    3 action items

  3. Prompt Injection With a Torque Spec

    The friction that has quietly served as your access control on lab and factory instruments — weeks of bespoke vendor integration per device — is exactly what this research preview removes.

    Where the safety envelope actually comes from The Model Hardware Standard encodes tacit physical knowledge into machine-readable natural language : a robot arm's weight, once known only to a paper manual or an engineer. Read it as a security engineer…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn