Security & Threat Intelligence

The Watch

The Signal

The Artifactory flaw in CISA's KEV is already minting admin tokens upstream of your CI.

Patching does not revoke the token. Anything the registry published while it was held is unverified, and the pipelines downstream trusted all of it. Three other entries in the same batch, LiteLLM, Kestra and Starlette, sit where agent-based scanners never look. Starlette usually arrives only as a transitive FastAPI dependency, so it will not appear in the inventory you are working from.

In Play

  1. KEV Moves Into the Build and AI Gateway Layer

    CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog this cycle, and four sit in developer and AI infrastructure rather than perimeter gear, per Risky.Biz: LiteLLM (CVE-2026-59822), JFrog Artifactory (CVE-2026-82329), Kestra (CVE-2026-49869) and Starlette (CVE-2026-48710). CSO First Look reports the Artifactory flaw is being used to mint admin tokens, putting an attacker upstream of every artifact your pipelines ship. These assets rarely appear in agent-based scanning, and Starlette often arrives only as a transitive FastAPI dependency.

  2. Endpoint Security Agents as Privilege Escalation Paths

    One researcher published working local privilege-escalation exploits against four endpoint agents at once — CrowdStrike Falcon (dubbed FalconFlank), Microsoft Defender, Avast and Kaspersky — with proof-of-concept code on public GitHub, per Risky.Biz. The Hacker News notes the Falcon claim carries no CVE, no CVSS and no vendor advisory, and that disclosure was uncoordinated. Your highest-privileged agent is the escalation path. Vendor substitution does not fix it: the same researcher hit four products.

  3. Remote Identity Proofing Lost Its Last Two Factors

    The dark-web market Nexus sold scans of more than 153 million US and Canadian driver's licenses, including the infrared and ultraviolet layers verification systems use to prove a document is genuine. It went dark only after Krebs on Security exposed it. The FBI's New Orleans field office is probing IDScan.net, which runs roughly 21 million identity checks a month for Hertz, Target and 1,000-plus dispensaries. In the same cycle the FCC cut 14 providers from its Robocall Mitigation Database, so caller ID is degrading as an identity signal too.

  4. MCP Servers Shipping Wildcard-Bound and Unauthenticated

    SANS catalogued a repeatable failure across the Model Context Protocol ecosystem — the integration layer coding agents use to reach tools: listen on every interface, skip authentication. UI-TARS-desktop's mcp-http-server defaulted its listen address to '::' (CVE-2026-81735, CVSS 10.0), ToolUniverse allowed unauthenticated Python sandbox escape (10.0), Chainlit had command injection on POST /mcp (9.8), and Telnyx MCP and mcp-router shipped with no auth on HTTP transport (both 9.1). Exposure tracks how many developers ran a quickstart, not your patch coverage.

  5. Dead Botnet C2, Live Infections, Thinner Federal Support

    Law enforcement permanently severed the 23-year-old Sality peer-to-peer botnet, which infected more than 11 million devices; CrowdStrike and Shadowserver supplied private-sector capability, per CyberScoop. Officials are only now working with ISPs to identify machines that remain infected, so the malware body is still resident on hosts your EDR never covered. Risky.Biz reports CISA simultaneously discontinued six free critical-infrastructure assessments after shedding more than a third of its staff, while State posted a $10M bounty on the IRGC-CEC commander directing CyberAv3ngers.

Deep Dives

  1. KEV Now Lists the Systems That Sign Your Software

    Patching an artifact registry that has been minting admin tokens for an attacker closes the flaw and leaves every binary it published this month unverified.

    CSO First Look reports the JFrog Artifactory flaw was exploited in the wild to generate admin tokens . The consequence is provenance, not server control. An attacker holding an admin token can publish or replace artifacts that CI/CD consumes and…

    3 action items

  2. The Agent With the Highest Privilege on Every Host Now Has a Public PoC

    Four endpoint agents fell to one researcher in the same week, which retires vendor substitution as a response and makes tamper-state telemetry the control you actually own.

    The count decides the response, not the exploit. Risky.Biz reports one researcher published working local privilege-escalation code against CrowdStrike Falcon, Microsoft Defender, Avast and Kaspersky . The Falcon variant circulates as "FalconFlank," and proof-of-concept code sits on public GitHub. Four…

    3 action items

  3. The Covert Layers of 153 Million Driver's Licenses Are on the Market

    Document images, caller ID and voice all failed as identity signals in the same cycle, which leaves your help desk running remote proofing on three broken factors at once.

    Document authentication rests on an asymmetry. The fraudster sees the front of the card. The verifier sees the covert layers. The Nexus corpus removes that asymmetry for 153 million people. The records included infrared and ultraviolet captures , the security-feature…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn