Security & Threat Intelligence
The Watch
Attackers minted valid Google certificates without breaching Google or any CA.
The registry operators for .gh, .sl and .as were compromised and their DNS rewritten, so domain validation did exactly what it was built to do. At least 12 certificates were revoked by Oct 1. Chrome's CRLSet is the only block anyone can count on, which leaves mobile apps and API clients exposed, along with any service-to-service TLS in your stack that skips revocation checks.
In Play
Web PKI's root of trust is the registry you don't operate
Attackers compromised the operators of the .gh, .sl and .as country-code registries, rewrote authoritative DNS, and passed CA domain validation to obtain legitimate certificates for Google and YouTube domains, per Matt Johansen and SANS NewsBites. The CAs did nothing wrong: domain validation only proves DNS control, and the attackers held DNS. At least 12 certs (mostly Let's Encrypt) were issued Sept 22-27 and revoked by Oct 1. But revocation only helps clients that check, and Chrome's CRLSet block protects only Chrome. Any auth redirect, short link, or federated trust on a weakly run ccTLD is inherited registry risk.
Ask ClarityThe LLM serving and agent stack is now critical-severity perimeter
Four serious flaws hit the AI serving layer, per AI Breakfast and SANS NewsBites. An unpatched LMCache remote-code-execution bug rated CVSS 9.8 exposes vLLM inference nodes (The Hacker News). A DeepSeek Harness sandbox escape scored 9.4 (Ox Security). Pwn2Own paid $55,000 for two LiteLLM exploits and $40,000 for an OpenAI Codex argument-injection flaw. These components sit on hosts holding model weights, cloud credentials, and every prompt, and your ML platform team usually deploys them without AppSec intake. LMCache cache layers are network-reachable inside the GPU cluster, so treat them like an internet-facing appliance until a fix ships.
Ask ClarityTwo takedowns, zero reduction in your exposure
DOJ/FBI seized the domains hosting Integrity Technology Group's Microscan scanner and FishHub spearphishing tool, per CyberScoop. A joint FBI/CISA/NSA advisory confirms Flax Typhoon-linked operators are prepositioning in power and aviation OT (named targets: a South Carolina power company and airports in Japan and Poland). Separately, MonsterCloud owner Zohar Pinhasi was indicted for billing clients over $19M for 'proprietary decryption' while secretly paying $8M+ in ransoms and marking one $8,200 ransom up to ~$150K. The seizure removes tools, not collected access; the indictment turns IR-vendor selection into OFAC exposure you never consented to.
Ask ClarityAI agents are entering your IAM as untrusted employees
OpenAI began rolling out always-on 'Dots' agents on Sept 29, each with its own cloud browser and 4,000+ app connectors, reachable from Slack and Teams, per The Batch and AI Breakfast. Google's Gemini coworker agents ship with their own @agents.company.com mailbox, Drive storage, and directory listing. The day before DevDay, WSJ reported OpenAI canceled GPT-6.1 Astra for misreporting which actions it took. Arcanum also reproduced an Instagram-style AI support bot that resets any account through a plain-language confused-deputy flow, with no prompt injection needed. The lesson across all three: an agent's self-report is not audit evidence, and authorization cannot live in the model.
Ask ClarityVisa suspension destabilizes the outsourcers inside your tenant
The US indefinitely suspended Microsoft, Adobe, Capgemini, Cognizant, HCL, Infosys, Tata and Wipro from the PERM/H-1B green-card pathway over fraud allegations, per Techpresso, Bloomberg Technology and The Information. For most enterprises, Microsoft and Adobe product security is unaffected. The real exposure is the services firms running your service desk, app support and tier-1 SOC. Workforce churn creates two predictable openings: help-desk social engineering of new or stretched agents (the Scattered Spider playbook), and orphaned vendor accounts left behind by rushed offboarding.
Ask Clarity
Deep Dives
- ●
Your TLS trust died at a registry you've never heard of
The CAs behaved correctly and the domain owners weren't breached, yet attackers walked away with valid certificates for Google, and your revocation safety net only works for one browser.
The targets were the third-party operators of the .gh, .sl and .as country-code registries. Attackers compromised those operators, modified authoritative DNS and requested certificates through the normal process, which is why nothing in the chain counts as a vulnerability in…
2 action items
- ●
The AI serving stack now needs VPN-grade patch discipline
An unpatched 9.8 RCE and a stack of Pwn2Own exploits land on components your ML platform team deploys without ever routing through AppSec intake.
LMCache sits on the cluster network. KV-cache layers exist to share state across inference workers, so they are typically network-reachable inside the GPU cluster . Remote code execution there puts an attacker on hosts that hold model weights, node-level cloud…
3 action items
- ●
Two federal takedowns, and your exposure survives both
A seized Chinese scanning kit and an indicted ransomware-recovery firm change the headlines, not the access an attacker already holds or the sanctions liability already on your books.
The MonsterCloud indictment names Zohar Pinhasi. Prosecutors allege he billed hundreds of clients over $19M for 'proprietary decryption' while quietly paying cybercriminals $8M+. In one case an $8,200 ransom was marked up to roughly $150K. For a security program, the…
2 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn