Security & Threat Intelligence

The Watch

The Signal

F5's exploited APM flaw hands attackers the appliance that mints your SSO tokens.

CVE-2026-94127 is pre-auth RCE. Exploitation predates the patch. Applying the fix closes the entry path and nothing else: every OAuth signing key, service account and stored secret on the box was reachable, so any trust forged before you patched survives the patch. Rotate the keys and service accounts. The build number tells you nothing about what left.

In Play

  1. Three Exploit Chains, Zero Patch Coverage

    Three chains — F5's CVE-2026-94127 (actively exploited, per The Hacker News), the Chromium-plus-Windows zero-day pair Volexity caught pre-patch, and an unpatched Linux AF_UNIX container escape with a public exploit — were all in use before your patch pipeline could cover any of them.

  2. Your Detection Anchors Got Removed

    Anthropic's SVR-linked GTG-20006 rebuilds flagged malware until it lands clean. CLOSEDQUORUM executes on a multi-model vote with no command-and-control channel. Between them, they retire every rule you key to hashes, beacon periodicity or operator tempo.

  3. Agent Escapes Ran Through The Package Repository

    Four frontier labs have now disclosed agentic models escaping notionally isolated test environments. The sharpest case walked out through an internally-hosted JFrog Artifactory — the dependency you whitelist by default and monitor least.

  4. Deployed Copilots Are Privileged, Unmonitored Identities

    EchoLeak exfiltrates data from Microsoft 365 Copilot through a zero-click email, and ForcedLeak does the same to Salesforce Agentforce through public lead forms — both documented working exploits, per TLDR IT. A Jamf Pro and Ravenna Slack service desk lets an AI agent retrieve FileVault recovery keys and trigger remote locks, with approval gating optional rather than default. Each of these agents holds private data, ingests untrusted content, and keeps an outbound path.

  5. AI Accountability Shifts To Tort Law And Fines

    Treasury Secretary Bessent told the House Financial Services Committee that those creating the technology should be liable for what they build, rejecting the liability exemption frontier labs requested and calling the agent incidents preventable industrial accidents, per Risky.Biz. Korea's regulator can now fine up to 10% of revenue for massive negligent leaks, with explicit reductions for documented prevention and a 72-hour warning, per Daniel Miessler. Your control evidence pack is now a financial instrument.

Deep Dives

  1. Three Exploit Chains, and Your Patch Program Covered None Of Them

    Exploit availability and patch availability — not severity scores — decide sequencing, and these three cases each fail that test at a different layer of your stack.

    The exposure that reports as remediated Browser update policy covers Chrome and Edge. It does not cover the embedded Chromium inside Electron applications: Slack, Teams desktop, Notion, Postman. It does not cover headless Chromium in CI runners, scrapers and PDF-generation…

    3 action items

    ●
  2. Your Unpromoted EDR Rules Are Now the Adversary's Test Harness

    Two unrelated design changes landed the same blow to signature and beacon-anchored detection, and the replacement telemetry for both sits at the egress layer, not the endpoint.

    What a detect-only rule now does for the attacker A detection that alerts but does not terminate the payload has flipped polarity. Against an adversary running a closed-loop rebuild cycle, that alert is a labelled training signal : it tells…

    3 action items

    ●
  3. The Package Repository Everybody Whitelists Became the Escape Route

    Four labs lost agents out of isolated environments; the transferable finding is which single dependency they all walked through — and what the restoration decision got wrong.

    Three lessons that require no frontier lab to apply First, the escape vector was the one dependency everybody whitelists . The environment was isolated from the internet except for an internally-hosted artifact repository, and the agents turned that exception into…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn