Security Unlocked

Strategic Briefs

Sharp analysis of the cybersecurity developments that matter most, with strategic context most coverage misses.

The Registry Trusted the Token

GitHub OIDC trusted-publishing solved the stored-credential problem and created a new attack surface in the same motion: three independent actors exploited it in a single week, producing malicious packages carrying valid provenance attestations.

supply-chain npm oidc developer-security slsa github TeamPCP miasma

Trusted Vendor, Compromised Namespace: Miasma Escalates Supply Chain Risk While AI Cements Its Role in Ransomware Development

The Mini Shai-Hulud worm now operates inside Red Hat's official npm namespace, proving that vendor-maintained packages are viable supply chain targets; simultaneously, the first confirmed AI-assisted ransomware toolchain documents a qualitative shift in what moderately skilled operators can build.

supply-chain teamPCP miasma ransomware ai-assisted ShinyHunters android nation-state midweek

The Agent Trusts the Answer

Two CVSS 9.8 vulnerabilities this week share an identical root cause: AI agent frameworks treat LLM output as safe to execute, the same cognitive error that produced SQL injection in 2003.

ai-security llm-vulnerabilities input-validation mcp starlette CVE-2026-47391 CVE-2026-25879 CVE-2026-48710

When Attackers Show You the Wrong Problem: SRG Goes Physical, MuddyWater Goes Ransomware

Two threat actor reports published this week document attackers who design their operations to trigger the wrong defensive response: Silent Ransom Group physically walks someone into a law firm when remote attacks fail, and MuddyWater deploys ransomware as cover for espionage.

luna-moth silent-ransom-group muddywater social-engineering ransomware-decoy dll-side-loading ClickFix ghost-cms CVE-2026-41091 CVE-2026-45498 CVE-2026-26980 midweek

Signing-as-a-Service Exposed: Fox Tempest Sold Microsoft's Code-Signing Trust Per Payload

Microsoft's Fox Tempest takedown exposes a criminal market for code-signing trust sold per payload; a PAN-OS zero-day with six weeks of state-sponsored exploitation went unreported through all of W21; and Shai-Hulud nearly doubled in scope with Grafana's source code as the first named downstream casualty.

fox-tempest vanilla-tempest rhysida code-signing supply-chain shai-hulud teamPCP grafana pan-os cve-2026-0300 cisa midweek

Three Point One

When a vulnerability transmits your database credentials to a third-party endpoint by design and scores CVSS 3.1, the problem is not the vulnerability, it is the triage system that will deprioritize it.

dbt MCP CVSS credential-security AI-toolchain developer-security vulnerability-management CVE-2026-44970 CVE-2026-44968

AI Writes the Exploit: UNC2814's Gemini Zero-Day and the Automation Gap That Just Closed

Google GTIG's confirmation of the first AI-generated zero-day deployed in a live attack closes the loop on Monday's AI agent vulnerability wave, connecting the attack surface (vulnerable AI frameworks) to the attack tool (AI-generated exploits) in the same reporting week.

ai-security zero-day supply-chain unc2814 apt45 shinyhunters exim cve-2026-45185 cve-2026-44336 cve-2026-40217 midweek

The Agent Trusts the Output

Eight AI agent frameworks disclosed the same class of remote code execution vulnerability in a single week because the entire ecosystem shares a cognitive failure: treating LLM output as trusted data rather than untrusted instructions.

ai-security rce semantic-kernel langchain vm2 agent-frameworks prompt-injection agentic-ai

ShinyHunters Adds 275 Million Students to Monday's Breach Wave, PAN-OS Zero-Day Leaves Perimeter Gaps Until May 13

ShinyHunters expanded Monday's identity breach wave to 275 million education users via Canvas and pivoted to cloud data warehouse infrastructure at Vimeo; separately, an unpatched PAN-OS RCE zero-day leaves internet-facing firewalls exposed until at least May 13.

shinyhunters breach palo-alto-networks pan-os cve-2026-0300 education cloud-security snowflake linux-kernel cve-2026-31431 midweek

What the Model Returns, the Shell Executes

Eight AI agent frameworks disclosed the same architectural vulnerability in a single week, revealing that the AI agent ecosystem is repeating the early-web SQL injection era under exploitation timelines that leave no room to learn slowly.

ai-security agent-frameworks vulnerability-management supply-chain flowise paperclip gemini-cli n8n-mcp mem0 sgLang onnx ssrf pickle-deserialization command-injection

AI Infrastructure Exploited Within 24 Hours of Disclosure

Four AI infrastructure platforms (Langflow, Marimo, LMDeploy, Flowise) were exploited within 24 hours of vulnerability disclosure last week. The patching window has collapsed to under one attacker shift.

ai-security vulnerability-management exploit-development patch-management langflow marimo lmdeploy flowise cisa-kev huggingface mcp inference-servers

The Protocol Is Doing Its Job

MCP's trust architecture makes any exposed management interface a pre-authenticated command shell by design, not by accident, and two RCE vulnerabilities in the same week reveal a deployment curve that has outrun both audit methodology and detection playbooks.

mcp ai-security agentic-tooling langchain praisonal-ai rce cve-2026-30617 attack-surface agent-security

Mythos Finds Zero-Days. npm Found Three More.

The same week Anthropic unveiled an AI that autonomously finds zero-days, its own CLI shipped a CVSS 9.8 command injection, exposed by a debugging artifact that had been sitting in an npm package since March 31.

ai-security claude-code command-injection cicd supply-chain cve-2026-35022 anthropic agentic-tooling

Trust Is the Exploit

From a six-month DPRK social engineering operation to mass exploitation of developer ecosystems, this week's threat landscape reveals that the most reliable attack surface is the trust we extend by default.

social-engineering supply-chain dprk fortinet react2shell trust-exploitation

The Mental Model Is the Vulnerability

Five AI infrastructure disclosures in one day share the same root cause: the gap between what users believe their security settings do and what the framework actually executes.

supply-chain-security prompt-injection ai-frameworks vulnerability-disclosure agent-security trust-exploitation

Trust Is the Attack Surface

Every major incident this week exploited institutional or interpersonal trust rather than technical vulnerabilities. The adversary's target is not the system. It is the relationship.

supply-chain-security trust-exploitation hacktivism ai-safety social-engineering living-off-the-land