Security & Threat Intelligence
The Watch
FortiMail's zero-day lets attackers sign phishing that passes DMARC as your domain.
The bug is an unauthenticated file write on the appliance terminating inbound SMTP, and CISA lists it as exploited. A patched build closes the hole, not the incident: any DKIM key or TLS private key an intruder copied still works after the upgrade, as does the LDAP bind credential. Gateways almost never run EDR, so nothing on the box will show you the implant.
In Play
FortiMail Email-Gateway Zero-Day
CISA added an actively exploited Fortinet FortiMail zero-day to its Known Exploited Vulnerabilities catalog Thursday, per The Hacker News; the flaw is an unauthenticated arbitrary file write on the appliance that terminates your inbound SMTP. Patch status alone won't tell you whether you were hit — the gateway holds DKIM signing keys, TLS private keys, and the LDAP bind credential used for recipient verification. An attacker who owns it reads mail in transit and signs outbound phishing that passes DMARC as your domain, so rotate those secrets, not just the build.
Ask ClarityIran Escalation Window Meets Edge Exploitation
The Iran conflict now carries a stated date: President Trump said strikes resume after the November midterms absent a deal, with about 9,000 US troops and a third carrier heading to the region and an Iran-linked plot against a US-operated UK base just foiled, per Morning Brew. Iranian clusters such as Pioneer Kitten historically answer kinetic pressure by exploiting internet-facing VPNs and firewalls — the exact appliances already under a fresh wave of zero-days. Google Threat Intelligence Group separately found in-the-wild exploitation nearly doubled from January 2025 to August 2026, so your pre-November edge-hardening sprint is now dual-purpose.
Ask ClarityAI Coding-Agent Endpoint Surface
Anthropic's new Claude Code mods are TypeScript add-ons installed via /plugin, distributed through a public directory, that run with the same machine access as Claude Code itself — and Claude will write one on request, per Simplifying AI. On the laptops holding your source code, cloud credentials, and signing keys, that is an unsandboxed extension supply chain with no vetting layer. Outflank separately showed Codex and Claude Code drift from the base MCP spec, so the schema the model sees can differ from what the server sent, weakening the human-in-the-loop control your policy assumes.
Ask ClarityAI Vendors Leave the Public-Disclosure Perimeter
AI holding company Long Lake closed its roughly $6.3B take-private of Amex Global Business Travel at $9.50/share, moving your executives' itineraries and passport data to a new owner and off public-market disclosure, per Augment. In the other direction, Anthropic is targeting a November IPO — a draft prospectus obtained by Reuters shows ~$518B in compute commitments against $4.6B of 2025 revenue — which would subject it to SEC 8-K incident disclosure for the first time. For private vendors, your contract, not an SEC filing, is now the only thing guaranteeing you hear about a breach.
Ask Clarity
Deep Dives
- ●
FortiMail: The Box Inspecting Your Mail May Be Reading It
An actively exploited, unauthenticated file-write zero-day puts the appliance that terminates your inbound mail into assume-breach territory — and the blast radius is the signing keys it holds, not the firmware.
Why a mail gateway is the worst appliance to lose The flaw is an unauthenticated arbitrary file write. On an appliance, that primitive escalates to code execution and persistent implants by overwriting web-served paths, scheduled jobs, or configuration. It tops…
3 action items
- ●
Iran Put a Date on Retaliation — Your Edge Sprint Is Now Dual-Purpose
The same internet-facing appliances you are patching are precisely the targets Iran's edge-exploiting clusters favor, and the conflict has a publicly stated escalation window.
A stated window is a planning horizon for both sides Iran's state operators have a record of answering kinetic and economic pressure with destructive and disruptive cyber operations . The new element is a calendar. Strikes may resume after the…
3 action items
- ●
Claude Code Mods: An Unsigned-Binary Marketplace on Your Dev Laptops
A one-shot prompt injection can now become durable persistence with full machine access, because the agent can write and install its own extensions and nothing reviews them.
Mods give prompt injection a persistence path it lacked last quarter Prompt injection against coding agents has been session-scoped . A poisoned README or issue mattered only while it sat in context. Claude Code mods remove that limit. Mods are…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn