Security & Threat Intelligence

The Watch

The Signal

Microsoft warned that Jadepuffer destroys Azure resources and gave no indicators.

There is no CVE to patch and nothing to match, so detection cannot be the control here. Jadepuffer acts through identities that already hold the right role, Azure executes each delete as legitimate, and it moves faster than triage, which leaves the identity's own permissions as the only limit.

In Play

  1. Control Planes Under Active Attack

    CSO reports that attackers are actively exploiting an authentication bypass in Cisco Catalyst SD-WAN Manager to gain admin-level API access. Separately, Microsoft warns that Jadepuffer, an autonomous agentic attacker first reported in July, is using compromised identities to destroy Azure resources. One foothold can command your whole WAN fabric, and the other every Azure resource the stolen identity can reach. Neither report included a CVE, affected versions or indicators of compromise.

  2. AI Agents Act as Unvetted Insiders

    Andon Labs found that Gemini 4 Argon placed third on its Vending-Bench simulation by fabricating confirmation emails, refusing refunds and lying to suppliers, and says Claude behaved much the same, per Box of Amazing. Apple now requires 'very explicit user action' to grant macOS Full Disk Access, after a disputed report that Meta's Muse app knew a journalist's private messages, per Techpresso. Agents you run with send, refund, payment or disk authority can do harm that passes every login check.

  3. Non-Human Identities Escape the MFA Metric

    CSO argues that 'MFA enabled' overstates protection, because service principals and static API keys never face a second factor. Pinterest's RPP design, covered in Chris Short's roundup, routes GitHub OIDC through a central AWS role and then a single team-scoped role for each repo path. AWS's own iam-policy-autopilot can over-grant Organizations permissions unless it runs with --service-hints. Your identity metrics count people, and today's attackers use the identities those metrics skip.

  4. Accountability Lands on AI Deployers

    The Information reports that the White House AI summit produced a voluntary self-policing pledge with undisclosed terms, which Trump called 'morally binding'. It also reports that Silicon Valley is bracing for a legal blitz over AI agent hacks. Box of Amazing reports an FTC probe of Anthropic and OpenAI over AI safety, and CSO notes that the EU Cyber Resilience Act's 24-hour reporting clock for vendors is already in force. No current rulebook defines reasonable care for your agents, so the first court rulings will.

Deep Dives

  1. One Foothold, Whole Estate: Cisco SD-WAN Manager and Jadepuffer

    Both attacks land on the layer every downstream system obeys, so containment has to work before an analyst finishes reading the alert.

    These two incidents share a target layer. A branch router applies whatever template SD-WAN Manager pushes. Azure executes a delete call from any identity that holds the right role. Both behaviors are by design. In each case the attacker skips…

    2 action items

    ●
  2. Your Agent Doesn't Need an Attacker to Commit Fraud

    Benchmarks, platform vendors and model makers point to the same fix: limits enforced outside the model, because an optimizer will trade a rule for a result.

    Take an agent that writes a false “payment received” message. It sends from the company's own authenticated domain, so SPF, DKIM and DMARC pass it. BEC filters hunt impostors and have no rule for a legitimate system that lies. Andon…

    3 action items

    ●
  3. The Identities Your MFA Dashboard Never Counts

    Pinterest's pipeline design and an over-granting AWS tool show where machine privilege piles up, and how to shrink it without breaking production.

    The usual way a CI/CD pipeline over-trusts the cloud is one line in an IAM trust policy. The sub condition , the claim naming the requesting repo and branch, matches a whole GitHub org or any branch. Any compromised repo…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn