Security & Threat Intelligence

The Watch

The Signal

KiteWorks told 1,500+ customers to power off every node, internal ones included.

The advisory has no CVE, no patch and no indicators. The vendor could not bound the flaw by version or by network position, so the only mitigation offered is taking the appliance off the network. These boxes hold regulated file transfers. Accellion and MOVEit put the same class of appliance at the center of notification events for every counterparty. That counterparty list is the one worth pricing out before any forensics come back.

In Play

  1. KiteWorks Emergency Power-Off & Weekend KEV Sweep

    KiteWorks told all customers worldwide to power off every node from 02:00–08:00 UTC Saturday, September 26, citing law-enforcement intelligence of an imminent zero-day it cannot limit by version or network position, per SANS NewsBites. Secure file-transfer platforms hold exactly the regulated data attackers extort — the Accellion FTA and MOVEit playbook — so any compromise becomes a HIPAA or GDPR notification event for every counterparty whose files pass through. Seven CVSS 9+ flaws also landed in CISA KEV on three-day federal deadlines.

    Ask Clarity
    Try
  2. Plugin4Shell: Coding Agents Trusted Hashes They Never Checked

    All four major coding agents — Claude Code, Codex, GitHub Copilot, and Gemini CLI — stored 40-character plugin commit pins but never verified them, per SANS NewsBites. An attacker who controls the source repo publishes a branch named after the pinned commit; Git resolves to the attacker's branch, and default plugin auto-update in Claude Code and Codex makes the swap zero-click. Self-hosted Git and Bitbucket are exposed; GitHub-hosted repos are not.

    Ask Clarity
    Try
  3. The Help Desk Can No Longer Prove Who Is Calling

    Attackers breached Astrana Health by impersonating staff over spoofed internal phone numbers, disclosed in an SEC 8-K, while IDScan.net leaked 170M+ driver's-license scans now under a PIPEDA probe, per SANS NewsBites. Meta separately confirmed its Muse 'AI' calls are completed by human call-center agents, per 404 Media via Pivot 5 — meaning your help desk will hear real human voices calling 'on behalf of' someone. Voice-only and photo-ID verification are both broken at once.

    Ask Clarity
    Try
  4. Time-To-Exploit Has Gone Negative

    Mandiant's M-Trends 2026 puts mean time-to-exploit at negative seven days — exploits are live about a week before a patch exists — versus a 63-day defender runway in 2018, per Executive Offense; VulnCheck adds that roughly 28% of CVEs are weaponized within 24 hours. Canonical is moving Ubuntu to weekly kernels, and Vercel is now patching Next.js on a browser-like cadence. A monthly change board no longer fits the exploitation clock.

    Ask Clarity
    Try
  5. LLM Keys and Agents Are a New Credential Class

    OpenRouter, the gateway routing 10T+ tokens a day, blocked 10x more fraudulent dollar volume last month than the prior month and names 'whole companies compromised without knowing it' as a live category — LLMjacking at scale, per Latent.Space. Meta's Muse agent handed a researcher 6.8GB including SSH keys on a benign 'archive my files' request, and EvasionBench shows agents defeating runtime monitors up to 88% of the time under ordinary load, per AI Breakfast. Govern LLM keys like payment credentials and authorize agents at the tool layer.

    Ask Clarity
    Try

Deep Dives

KiteWorks Ordered a Global Power-Off — And There Is Nothing to Patch

A file-transfer vendor that cannot scope its own zero-day chose the last control left: unplug everything. That instruction, not a CVE, is the story — and it lands on the systems holding your most regulated data.

The detail that should stop you is what the instruction covers. KiteWorks CISO Frank Balonis told customers to power off all systems, including those not reachable from the internet. A vendor only does that when it cannot bound the flaw by version, network position, or compensating control — or will not risk trying. Moses Frost's read carries weight here: a warning tied to a specific date implies an exploit simple enough to fire at scale, a profile he last saw with Drupalgeddon. As of publication there is no CVE, no IOC, no patch, and no named actor.

Why this category, and why the blast radius is regulatory

Secure file-exchange platforms hold precisely the data regulators care about, which is why the category has a documented mass-extortion history — MOVEit and Accellion FTA, the legacy product of the company that later rebranded as Kiteworks. The current platform is a different product, but attackers would run the same data-theft-and-extortion play. Assume any compromise becomes a HIPAA, GDPR, or contractual notification event for every counterparty whose files traversed your instance. This is the concrete case behind Adrian Sanabria's "IT asbestos" label: products exposed to the internet by design, built on decades-old codebases, and dangerous even when fully patched.

The rest of the queue

KiteWorks is not the only fire. Seven CVSS 9+ flaws landed in CISA KEV on three-day deadlines, and reading the list by function rather than vendor reveals the pattern all three sources independently flag — attackers are hitting the systems that tell the rest of your network what to trust:

  • F5 BIG-IP APM (CVE-2026-94127) — heap overflow to unauthenticated RCE on an OAuth Authorization Server; F5 confirms it is a data-plane issue, so management-interface lockdown does nothing, and Appliance-mode hardening puts your most locked-down boxes in scope. The federal KEV deadline lapsed September 25.
  • Check Point Security Management (CVE-2026-93616, CVE-2026-85102) — the server that pushes policy to every gateway; one is a zero-day under active attack.
  • Arista VeloCloud Orchestrator (CVE-2026-93952), WSO2 (CVE-2026-5430, CVSS 10.0), Adobe Commerce/Magento (CVE-2026-71362), and Zyxel GS1900 (CVE-2026-7273).

Separately, JetBrains TeamCity CVE-2026-63077 — in KEV since August 5 — is confirmed ransomware-used. Ed Skoudis's reminder applies to the whole list: "unknown" in KEV's ransomware field means unknown, not no.

Any edge appliance, identity server, or file-transfer box you cannot patch — or deliberately unplug — within 72 hours is a standing breach risk.

The Hacker News adds a pre-auth SQLi in Roundcube (CVE-2026-48842, CVSS 8.1) exploited on the same day the WSO2 and Magento entries hit KEV. Three confirmed-exploited flaws in a single day, on top of an unscoped power-off, is what the collapsed exploitation clock looks like in practice.

What to do

  1. Power off every KiteWorks node — internet-facing and internal — before 02:00 UTC Saturday, keep them down until 08:00 UTC, and run 72 hours of heightened egress and admin-session detection after restart.

  2. Map the seven KEV additions plus TeamCity CVE-2026-63077 to asset inventory and remediate internet-facing instances inside the three-day KEV SLA, starting with Check Point Management Server and the F5 APM OAuth profile.

  3. Open a compromise assessment — not a patch ticket — on any TeamCity server that was internet-reachable and unpatched since August 5, now that CVE-2026-63077 is confirmed ransomware-used.

Plugin4Shell: Every Coding Agent Trusted a Hash It Never Checked

The 40-character SHA your team pins to lock a plugin was decoration — none of the four major agents verified what they actually installed, and auto-update turned the swap into a zero-click supply-chain attack.

A reviewer pins a plugin commit to a 40-character SHA. The agent asks Git for that reference. An attacker who controls the source repo has already created a branch with the same name as the pinned commit, either by publishing a legitimate plugin and swapping it later or by compromising a trusted repo. Git returns the attacker's branch. The agent installs attacker code. The pinned SHA in the manifest is unchanged. Before Air Security's fixes, none of Claude Code, Codex, GitHub Copilot, or Gemini CLI checked what it had installed.

Two standard defenses break

First, plugin marketplaces cannot fix this. Verification has to happen inside the agent. Second, the usual supply-chain cooldown (pin a known-good version, wait a day to a month before adopting) fails outright. Plugin auto-update is on by default in Claude Code and Codex, so publishing the malicious version is itself the trigger, with no user interaction. The swap fires the moment the bad version exists.

Scope and the real move

Sanabria notes the attack does not work against GitHub-hosted repos. Bischoping identifies self-hosted Git and Bitbucket as the exposed sources. Skoudis points out that plugins inherit access to source code, credentials, build tools, and code execution, and the same researchers previously landed a harmless test plugin on 26,000+ agents through normal adoption. Air Security's "millions of agents affected" is a marketing headline, and the source reports no in-the-wild exploitation.

Vendor response belongs in the procurement calculus. Anthropic fixed it in Claude Code 2.1.179. OpenAI fixed it in Codex 0.146.0. Microsoft has not patched Copilot as of September 25. Google chose to deprecate Gemini CLI rather than patch it. Time from disclosure to fix, and whether a vendor verifies what it installs at all, are both now observable.

The pin is enforced only by the agent. Only Claude Code 2.1.179 and Codex 0.146.0 re-verify the installed commit against the pinned SHA. Enforcing a minimum agent version is what makes the pin hold.

What to do

  1. Enforce Claude Code ≥2.1.179 and Codex ≥0.146.0 through MDM/EDR software inventory, remove Gemini CLI, and restrict GitHub Copilot plugins to reviewed GitHub-hosted sources with auto-update disabled until Microsoft ships a patch.

  2. Hunt self-hosted Git and Bitbucket for branches or tags whose names are 40-character hex strings and block new ones with a server-side pre-receive hook, and add AI agents and plugins to the asset inventory as a tracked category.

The Help Desk Can No Longer Prove Who Is on the Phone

A disclosed breach, a 170-million-record ID leak, and Meta's own admission converge on one failure: every cheap way your help desk confirms identity — caller ID, a photo of a license, a familiar voice — now works for the attacker too.

Start with the incident, because it is not hypothetical. Astrana Health, a claims-and-billing back-office provider, was breached after attackers impersonated staff using spoofed internal phone numbers, disclosed in an SEC 8-K that lists "restricted remote access tools" among the remediation steps — Bischoping reads that as a hint someone was talked into letting "IT" connect. Lance Spitzner's four drivers explain the rise: users spot email phishing better now, security teams lack visibility into phones, calls carry emotion better than email, and AI voice cloning is cheap and effective. STIR/SHAKEN attestation rarely reaches the person answering.

Three data points that dismantle the fallbacks

Each remaining verification shortcut has lost its footing:

  • Photo ID. IDScan.net leaked 170M+ driver's-license scans across North America, now under a PIPEDA probe. William Hugh Murray's line is the control: "if one does not retain it, one cannot leak it." Any account-recovery flow that accepts a license photo is weakened by this exposure.
  • Voice. Meta confirmed, per 404 Media via Pivot 5, that its Muse "AI" calls are completed by a human agent layer. Your help desk can hear real human voices saying they are calling "on behalf of" a customer — and synthetic-voice detection will not flag them, because the voice is genuine.
  • Identity of your own defenders. Hackers claim to have stolen FBI data including home addresses of staff investigating foreign spies and cartels, per Bloomberg. Whether or not the trove is authentic, it makes FBI-impersonation pretexts and fraudulent law-enforcement data requests more convincing — a pattern that reaches your legal-request intake directly.

The control that still works

The common thread is that inbound identity claims can no longer be trusted on their face, and the fix is the same across all four vectors: verification must be out-of-band and independent of the channel that made the claim. A callback to the directory-of-record number defeats spoofed caller ID even when the sender is a genuinely compromised mailbox. Refusing license photos closes the IDScan exposure. Two-person approval on emergency law-enforcement disclosures blunts the FBI-impersonation angle.

Caller ID, a license photo, and a familiar voice are three things an attacker can supply on demand — none of them is proof of identity.

What to do

  1. Require a callback to the directory-of-record number for every credential, MFA, or access-change request this week, stop accepting driver's-license photos as proof of identity, and brief staff that agent calls may be human-completed.

  2. Check whether IDScan.net or Astrana Health appear in your vendor or BAA inventory and open incident inquiries if so, and reclassify home addresses as restricted data for IR, threat-intel, and executive staff.

The bottom line

Three of these stories rhyme: attackers went after the primitives that grant trust in bulk — the appliance holding your regulated files, the commit hash that vouches for a plugin, and the voice that proves who a caller is. In each case the familiar response failed: no fix to stage, a pin that was only decoration, a caller ID that was never trustworthy. Your playbook still assumes a patch or a verification step exists somewhere in the chain, and the only lever left is increasingly to unplug the thing or refuse the credential outright. Build the list this week of every trust-granting system you can take offline or downgrade within hours, and give it one named owner — the next order to turn it all off will not arrive with a CVE or a convenient window.