Security & Threat Intelligence
The Watch
The Artifactory flaw in CISA's KEV is already minting admin tokens upstream of your CI.
Patching does not revoke the token. Anything the registry published while it was held is unverified, and the pipelines downstream trusted all of it. Three other entries in the same batch, LiteLLM, Kestra and Starlette, sit where agent-based scanners never look. Starlette usually arrives only as a transitive FastAPI dependency, so it will not appear in the inventory you are working from.
In Play
KEV Moves Into the Build and AI Gateway Layer
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog this cycle, and four sit in developer and AI infrastructure rather than perimeter gear, per Risky.Biz: LiteLLM (CVE-2026-59822), JFrog Artifactory (CVE-2026-82329), Kestra (CVE-2026-49869) and Starlette (CVE-2026-48710). CSO First Look reports the Artifactory flaw is being used to mint admin tokens, putting an attacker upstream of every artifact your pipelines ship. These assets rarely appear in agent-based scanning, and Starlette often arrives only as a transitive FastAPI dependency.
Ask ClarityEndpoint Security Agents as Privilege Escalation Paths
One researcher published working local privilege-escalation exploits against four endpoint agents at once — CrowdStrike Falcon (dubbed FalconFlank), Microsoft Defender, Avast and Kaspersky — with proof-of-concept code on public GitHub, per Risky.Biz. The Hacker News notes the Falcon claim carries no CVE, no CVSS and no vendor advisory, and that disclosure was uncoordinated. Your highest-privileged agent is the escalation path. Vendor substitution does not fix it: the same researcher hit four products.
Ask ClarityRemote Identity Proofing Lost Its Last Two Factors
The dark-web market Nexus sold scans of more than 153 million US and Canadian driver's licenses, including the infrared and ultraviolet layers verification systems use to prove a document is genuine. It went dark only after Krebs on Security exposed it. The FBI's New Orleans field office is probing IDScan.net, which runs roughly 21 million identity checks a month for Hertz, Target and 1,000-plus dispensaries. In the same cycle the FCC cut 14 providers from its Robocall Mitigation Database, so caller ID is degrading as an identity signal too.
Ask ClarityMCP Servers Shipping Wildcard-Bound and Unauthenticated
SANS catalogued a repeatable failure across the Model Context Protocol ecosystem — the integration layer coding agents use to reach tools: listen on every interface, skip authentication. UI-TARS-desktop's mcp-http-server defaulted its listen address to '::' (CVE-2026-81735, CVSS 10.0), ToolUniverse allowed unauthenticated Python sandbox escape (10.0), Chainlit had command injection on POST /mcp (9.8), and Telnyx MCP and mcp-router shipped with no auth on HTTP transport (both 9.1). Exposure tracks how many developers ran a quickstart, not your patch coverage.
Ask ClarityDead Botnet C2, Live Infections, Thinner Federal Support
Law enforcement permanently severed the 23-year-old Sality peer-to-peer botnet, which infected more than 11 million devices; CrowdStrike and Shadowserver supplied private-sector capability, per CyberScoop. Officials are only now working with ISPs to identify machines that remain infected, so the malware body is still resident on hosts your EDR never covered. Risky.Biz reports CISA simultaneously discontinued six free critical-infrastructure assessments after shedding more than a third of its staff, while State posted a $10M bounty on the IRGC-CEC commander directing CyberAv3ngers.
Ask Clarity
Deep Dives
- ●
KEV Now Lists the Systems That Sign Your Software
Patching an artifact registry that has been minting admin tokens for an attacker closes the flaw and leaves every binary it published this month unverified.
CSO First Look reports the JFrog Artifactory flaw was exploited in the wild to generate admin tokens . The consequence is provenance, not server control. An attacker holding an admin token can publish or replace artifacts that CI/CD consumes and…
3 action items
- ●
The Agent With the Highest Privilege on Every Host Now Has a Public PoC
Four endpoint agents fell to one researcher in the same week, which retires vendor substitution as a response and makes tamper-state telemetry the control you actually own.
The count decides the response, not the exploit. Risky.Biz reports one researcher published working local privilege-escalation code against CrowdStrike Falcon, Microsoft Defender, Avast and Kaspersky . The Falcon variant circulates as "FalconFlank," and proof-of-concept code sits on public GitHub. Four…
3 action items
- ●
The Covert Layers of 153 Million Driver's Licenses Are on the Market
Document images, caller ID and voice all failed as identity signals in the same cycle, which leaves your help desk running remote proofing on three broken factors at once.
Document authentication rests on an asymmetry. The fraudster sees the front of the card. The verifier sees the covert layers. The Nexus corpus removes that asymmetry for 153 million people. The records included infrared and ultraviolet captures , the security-feature…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn