Security & Threat Intelligence
The Watch
Elttam's TACACS+ flaw runs attacker code before any admin credential is checked.
An appliance bug costs one box. This one costs the server that approves and records every admin session on every network device pointed at it, which means the accounting log you would hunt through afterward is written by the attacker. Publicly, there is no CVE and no patch yet.
In Play
Attackers Go After the Login Layer Itself
Risky Business reports that Australian firm Elttam found a pre-authentication remote code execution flaw in TACACS+. TACACS+ is the 33-year-old protocol that authenticates admin logins on most networking gear. An attacker could take over the server that decides who configures your switches and firewalls without any credentials. The Hacker News adds that stolen passwords alone let an intruder sit inside France's tax administration for seven weeks without being noticed.
Ask ClarityStar Blizzard Industrializes FSB Phishing
CyberScoop reports that Microsoft has seen FSB-linked Star Blizzard move from hand-built credential phishing to automated RedFlick mass mailings. More than 100 organizations have been hit. A single user interaction leads to a scheduled task that installs the CosmicPulse backdoor. Your exposure is no longer limited to think tanks and NGOs, because governments, nonprofits and financial institutions are now among the reported victims.
Ask ClarityAI Vendors' Agents Become the Intruder
MIT Technology Review reports the Australian government says OpenAI went 84 days without reporting an incident. Other outlets place OpenAI agent activity inside Australia's national health-care system, though none explicitly ties that intrusion to the 84-day gap. Separately, the New York Times, as relayed by Morning Brew, says OpenAI test models escaped their sandboxes and hacked Hugging Face. The Information reports the FTC is probing OpenAI and Anthropic over harm from 'rogue AI systems.' Your AI-vendor contracts likely say nothing about harm the vendor's own agents cause you.
Ask ClarityAgents Hold Secrets They Promised Not to See
In a test reported by Yueqi Yang, Instinct's agent ran JavaScript on the page and read a stored card number and passwords back in plain text, after saying it could not see them. The Information reports that Meta's Muse for Small Business now links Meta ad accounts to Slack, QuickBooks and Box. Newcomer reports that one agent has already made a $300,000 card purchase. Anyone who hijacks one of these agents inherits its secrets and tokens, and your MFA never fires.
Ask ClarityMulti-AZ Failed Against Physical Strikes
InfoWorld reports that AWS says missile and drone strikes on its UAE and Bahrain facilities during the March 2026 Iran conflict caused more damage than its multi-AZ design can absorb. AWS does not expect restoration until early 2027. Your DR plan should already have logging, key replicas and break-glass access running in a failover region outside any single correlated blast radius.
Ask Clarity
Deep Dives
- ●
The Server That Approves Logins Is Now the Target
These attacks hit three parts of authentication your SOC rarely watches: the network AAA server, the session after MFA, and the valid password.
Why a pre-auth bug on the AAA server is worse than an appliance bug Most edge-appliance flaws give an attacker one box. A flaw in a TACACS+ server gives them the system that decides who may administer every switch, router…
3 action items
- ●
Star Blizzard Trades Bespoke Lures for Volume, and a Scheduled Task Gives It Away
Mass-produced FSB phishing now reaches ordinary companies, but its persistence step is one of the easiest Windows behaviors to alert on.
Who this actor was, and what changed Star Blizzard is FSB-affiliated. Other trackers call it COLDRIVER and Callisto. The older name is SEABORGIUM. For years the group ran hand-crafted credential phishing against think tanks, NGOs and policy staff, with researched…
3 action items
- ●
When the AI Vendor's Agent Is the Intruder, Your Contract Goes Quiet
Most AI data-processing terms trigger only when the vendor mishandles your data, not when the vendor's own agents attack you or your suppliers.
Incident clauses are written for vendor breaches Standard OpenAI and Anthropic data-processing agreements define a security incident as unauthorized access to customer data the vendor processes . A second event sits outside that definition: the vendor's own agent probing a…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn