Security & Threat Intelligence

The Watch

The Signal

Z.ai's open-weights release ships with a public map of 2,436 bugs across 269 projects.

Adversaries got the ledger on the same day defenders did. The named code lives in container base images and vendored source, and in appliance firmware, which is precisely the layer the dependency scanner in your pipeline never reads. Some of the flagged code dates to 1981.

In Play

  1. Rails Secrets Flaw Exploited in the Wild

    Risky Business reports that CVE-2026-66066, nicknamed KindaRails2Shell, is being exploited against Ruby on Rails apps running the default Active Storage configuration. The flaw needs no authentication, and the payoff is the application's secret_key_base and stored credentials rather than a shell. That means forged sessions, database access and cloud IAM keys on any app patched late. Rotation closes this exposure, not the version bump.

  2. ClickFix Splits Into Three Variants

    Risky Business documents ClickFix forking three ways: ClickExfil repurposes the paste-to-fix lure for pure data theft, TerminalFix installs a reverse-tunnel implant through terminal commands, and CRPx0 ransomware now arrives through ClickFix campaigns. Microsoft spotted the TerminalFix variant. Your rules and awareness decks almost certainly still describe the original clipboard-to-Run-dialog lure, and the exfil-only variant leaves no malware artifact to find.

  3. Agent Credentials Nobody Has Inventoried

    Uber disclosed that more than 70% of its pull requests now come from agents running 3,600-plus skills through 1,000-plus MCP tools, the interface layer between agents and internal systems. Risky Business separately counted 155 abandoned MCP servers on public marketplaces that an attacker can take over. Each of those paths carries a production credential, and tool-call telemetry rarely reaches the SIEM. You cannot revoke what no register lists.

  4. Open Weights Ship With a 2,436-Bug Ledger

    Z.ai published GLM-5.3's open weights after the model found 2,436 vulnerabilities across 269 open source projects, some in code dating to 1981, according to Z.ai's own disclosure. The findings now sit in a public ledger that works equally well as a target list. Most of those projects live inside container base images, vendored source and appliance firmware, which is exactly where software composition analysis is blindest.

  5. Security Vendor Viability and Compute Custody

    Hunterbrook Media published a critical report on Tenable while Hunterbrook Capital disclosed a short position in the same stock. The same coverage notes CoreWeave carrying $35B of on-balance-sheet debt at 13% yields, and Nvidia extending roughly $230B in lease backstops and residual-value support across nominally independent GPU hosts. If your exposure data, model weights or inference logs sit with those counterparties, the renewal question is custody under distress rather than uptime.

Deep Dives

  1. Patching CVE-2026-66066 Leaves the Intruder Logged In

    The disclosed value is a signing key, so every session cookie your application trusts can be minted by whoever read it, and the order you rotate in decides whether they lose access.

    What the disclosed key buys Rails derives cookie signing and encryption from secret_key_base . An attacker who reads it does not need the vulnerability again. They can mint session cookies the application accepts as authentic, privileged accounts included, and unwrap…

    3 action items

  2. Your Agent Layer Is a Credential Plane With No Register

    Production tokens now sit behind unsigned marketplace prompts, abandoned tool servers and a menu-bar toggle, and every control you would show an auditor still sees an approved application.

    Ollama v0.33 registers as a gateway provider inside Claude Desktop Ollama v0.33 ships a Claude Desktop integration that registers as a third-party gateway provider. One switch in the Ollama menu bar puts a user's entire local model library into Claude…

    3 action items

  3. The 269-Project Diff Your Composition Scanner Cannot Run

    One model's findings were published as a ledger, handing defenders and adversaries the same map on the same day, and the code it names hides in layers dependency tooling never reads.

    The ledger is the security consequence Z.ai's own report calls GLM-5.3's exploitation skill emergent : as post-training scaled, the capability grew faster than the lab expected. They hardened it and released the weights anyway. The consequence is the artifact left…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn