Security & Threat Intelligence

The Watch

The Signal

Upgrading an exploited SMA 1000 destroys the logs that prove whether an operator landed.

Exploitation ran ahead of the fix, which makes every exposed appliance a compromise question rather than a change ticket. Rotating or truncating logs on reboot is not unique to this platform. And CVE-2026-9586 is dropping the same pre-auth reverse shells on Switchvox PBXs at the same edge, so the triage you scope this week covers two boxes, not one.

In Play

  1. Machine-Speed Exploit Discovery Goes Commodity

    OpenAI rated its unreleased Astra model Critical for cyber capability after it discovered and chained two V8 zero-days unaided, reported across The Information and Pivot 5. AINews puts Google's Gemini 3.8 Flash Cyber at 86.2% on a vulnerability-discovery benchmark against 47.2% on patching, priced at commodity inference rates. Discovery scales faster than remediation, which reprices every patch SLA written for human-speed bug hunting.

  2. Confirmed Compromise of Developer Tooling

    Australian police arrested two alleged TeamPCP members, and Risky.Biz confirms the group's 2026 campaign compromised Trivy, KICS, LiteLLM and Telnyx: two security scanners, an LLM gateway and a communications API. Arrests do not un-poison artifacts already cached in your registries, nor rotate the credentials those tools held inside CI runners. The same reporting notes one alleged leader is 21 years old.

  3. Assurance and Payments Layers Consolidate

    Payments and assurance consolidated in the same week, and the assurance half is the one nobody is scoring. Term Sheet has SOC 2 assessor A-LIGN acquiring offensive-security firm Pathfynder, putting the party that tests controls and the party that attests to them inside one P&L. Your third-party register almost certainly scores these as separate suppliers, and your audit independence rests on an engagement letter nobody has re-read this year.

Deep Dives

  1. The Patch Closes the Door. It Does Not Evict the Tenant.

    Two internet-facing platforms are being exploited without credentials, and the appliance upgrade you schedule tonight will destroy the evidence you need tomorrow.

    Sequence matters more than speed The SonicWall SMA 1000 flaws were exploited before the fix existed. That makes every internet-exposed appliance in the fleet a prior-compromise candidate rather than a patch ticket. A firmware upgrade and reboot also rotates or…

    3 action items

  2. Exploit Discovery Went Commodity. Your Patch Window Is the Control You Own.

    Two labs crossed the autonomous-exploitation line in one week, but the number that should reset your SLAs is the gap between how well these systems find bugs and how badly they fix them.

    The asymmetry inside the benchmark Google's numbers for Gemini 3.8 Flash Cyber, reported by AINews: 86.2% on a discovery benchmark and 47.2% on patching , plus 70%+ discovery across 20 programming languages, held at Flash-level pricing on purpose. An attacker…

    3 action items

  3. The Consent Grant Is the Perimeter Nobody Audits

    One campaign the FBI has tracked since late 2025 and one six-day-old beta CRM abuse the same surface, and your account-compromise playbook closes both incidents while they are still live.

    Why the playbook fails, step by step The chain is legible. Initial access is spearphishing via service, delivered on a commercial messaging app. The mail gateway never sees it, so DMARC evaluation and link detonation are irrelevant. Credential access is…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn