Security & Threat Intelligence

The Watch

The Signal

RPKI validated the hijacked route that served poisoned Virtualizor updates for 33 hours.

The forged path kept Hetzner's ASN as apparent origin, and the attacker held a valid TLS certificate in Softaculous's name. Every check passed. If the controls you lean on to catch a hostile update channel are origin validation and TLS, both of them signed off on this one.

In Play

  1. Poisoned Update Channel Behind a Valid Certificate

    An unknown actor announced 162.55.80.0/24 from AS62390 at 20:57 UTC on 28 August and held it for roughly 33 hours, per Risky.Biz. That prefix carries production systems for Softaculous, maker of the Virtualizor VPS panel. The attacker obtained a valid TLS certificate in Softaculous's name and served malicious Virtualizor updates. Because the forged AS path retained Hetzner's AS24940 as apparent origin, RPKI route-origin validation accepted the route. Virtualizor has no logs and cannot say who was affected.

  2. Credential-Concentrator Platforms Under Active Exploitation

    ServiceNow patched three maximum-severity flaws that are remotely exploitable with no user interaction, per CSO — which published no CVE identifiers and no affected build ranges. VulnCheck confirms in-the-wild exploitation of Langflow's CVE-2026-0768 at CVSS 9.8, which never received a patch and is being used to steal OpenAI and AWS keys. WatchTowr saw JFrog Artifactory's CVE-2026-82329 exploited three days after the fix shipped. All three hold credentials for systems well beyond themselves.

  3. The Identity Plane Did All the Volume Work

    McKesson confirmed on 31 August that attackers reached cloud-hosted accounts across its oncology, multispecialty and medical-surgical businesses. ShinyHunters claims it phished credentials and pulled millions of rows of health information from Snowflake and Salesforce, with a reported $55 million extortion demand. No CVE is in that chain. Datadog separately tracked password spraying against AWS root accounts at 150-plus organizations since 24 July, and Palo Alto's Unit 42 tracked Spring Ring impersonating IT help desk through external Teams accounts at 10-plus companies.

  4. Roughly Half of Remote IT Applicants Carry DPRK Patterns

    Applications carrying North Korean fraud patterns in U.S. remote IT roles rose from 11% in Q3 2024 to 44% a year later, with an estimated 47% last quarter, drawn from 175,000 flagged applications in data Endorsed gave Fortune. The published tells are deliberately banal — Texas claimed as origin in 26.5% of cases, University of North Texas and UT Austin degrees, first names Sai, Michael, David and Kevin — so screening on them creates Title VII exposure rather than security. The Hacker News reports the operations have expanded into healthcare and sales roles.

  5. The AI Vendor Chain Re-Papered Itself Without a Change Ticket

    Three vendors inside a typical AI stack changed owners in about two weeks: Hugging Face to Nvidia at a reported $12.9bn, OpenRouter to Stripe at a reported $7.5bn, and Cursor to SpaceX, per Benedict Evans. Anthropic separately layered roughly $120bn of compute commitments across Lambda, Nscale and SpaceX, with Hut 8 — a former bitcoin miner — developing the Nueces County, Texas site while Nvidia holds the lease and supplies the chips. Every subprocessor list and attestation on file predates all of it.

Deep Dives

  1. Hypervisor-Tier Access Arrived Dressed as a Software Update

    Rented VPS panels sit two vendor hops below your risk register, and the only available evidence about the 33-hour window is a written answer from a company that kept no logs.

    The blast radius sits below the vendor map Virtualizor is the panel hosting companies use to provision rented VPS fleets. A poisoned update hands hypervisor-tier access to every virtual machine under that panel , including workloads owned by other tenants…

    3 action items

  2. ServiceNow Patched. Nothing Rotated the Credentials It Brokers.

    Two independent reads reach the same uncomfortable conclusion: the instance logs that would clear the pre-patch window usually never reached your SIEM, so exposure can only be assumed.

    The platform is a credential vault and an execution engine ServiceNow stores the secrets used to reach the systems it manages and runs privileged actions against them by design. Connection and credential aliases, OAuth entities and app registrations, MID Server…

    3 action items

  3. Recruiting Is an Ingress Path With No Logging and No Owner

    The screening signals that survive contact with this adversary are physical and financial, not biographical — and the biographical ones carry more legal risk than the infiltration they miss.

    Everything the candidate types is adversary-controlled The geographic and employer distribution is the useful part of the Endorsed dataset. Flagged applications optimize for the median American software engineer résumé rather than forging anything exotic. California sits at 14.4% and Florida…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn