<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Strategic Briefs on Security Unlocked</title><link>https://securityunlocked.com/weekly-intelligence/</link><description>Recent content in Strategic Briefs on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 08 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/weekly-intelligence/index.xml" rel="self" type="application/rss+xml"/><item><title>The Registry Trusted the Token</title><link>https://securityunlocked.com/weekly-intelligence/the-registry-trusted-the-token/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-registry-trusted-the-token/</guid><description>GitHub OIDC trusted-publishing solved the stored-credential problem and created a new attack surface in the same motion: three independent actors exploited it in a single week, producing malicious packages carrying valid provenance attestations.</description></item><item><title>Trusted Vendor, Compromised Namespace: Miasma Escalates Supply Chain Risk While AI Cements Its Role in Ransomware Development</title><link>https://securityunlocked.com/weekly-intelligence/trusted-vendor-compromised-namespace-miasma-escalates-supply-chain-risk-while-ai-cements-its-role-in-ransomware-development/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trusted-vendor-compromised-namespace-miasma-escalates-supply-chain-risk-while-ai-cements-its-role-in-ransomware-development/</guid><description>The Mini Shai-Hulud worm now operates inside Red Hat&amp;rsquo;s official npm namespace, proving that vendor-maintained packages are viable supply chain targets; simultaneously, the first confirmed AI-assisted ransomware toolchain documents a qualitative shift in what moderately skilled operators can build.</description></item><item><title>The Agent Trusts the Answer</title><link>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-answer/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-answer/</guid><description>Two CVSS 9.8 vulnerabilities this week share an identical root cause: AI agent frameworks treat LLM output as safe to execute, the same cognitive error that produced SQL injection in 2003.</description></item><item><title>When Attackers Show You the Wrong Problem: SRG Goes Physical, MuddyWater Goes Ransomware</title><link>https://securityunlocked.com/weekly-intelligence/when-attackers-show-you-the-wrong-problem-srg-goes-physical-muddywater-goes-ransomware/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/when-attackers-show-you-the-wrong-problem-srg-goes-physical-muddywater-goes-ransomware/</guid><description>Two threat actor reports published this week document attackers who design their operations to trigger the wrong defensive response: Silent Ransom Group physically walks someone into a law firm when remote attacks fail, and MuddyWater deploys ransomware as cover for espionage.</description></item><item><title>Signing-as-a-Service Exposed: Fox Tempest Sold Microsoft's Code-Signing Trust Per Payload</title><link>https://securityunlocked.com/weekly-intelligence/signing-as-a-service-exposed-fox-tempest-sold-microsofts-code-signing-trust-per-payload/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/signing-as-a-service-exposed-fox-tempest-sold-microsofts-code-signing-trust-per-payload/</guid><description>Microsoft&amp;rsquo;s Fox Tempest takedown exposes a criminal market for code-signing trust sold per payload; a PAN-OS zero-day with six weeks of state-sponsored exploitation went unreported through all of W21; and Shai-Hulud nearly doubled in scope with Grafana&amp;rsquo;s source code as the first named downstream casualty.</description></item><item><title>Three Point One</title><link>https://securityunlocked.com/weekly-intelligence/three-point-one/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/three-point-one/</guid><description>When a vulnerability transmits your database credentials to a third-party endpoint by design and scores CVSS 3.1, the problem is not the vulnerability, it is the triage system that will deprioritize it.</description></item><item><title>AI Writes the Exploit: UNC2814's Gemini Zero-Day and the Automation Gap That Just Closed</title><link>https://securityunlocked.com/weekly-intelligence/ai-writes-the-exploit-unc2814s-gemini-zero-day-and-the-automation-gap-that-just-closed/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/ai-writes-the-exploit-unc2814s-gemini-zero-day-and-the-automation-gap-that-just-closed/</guid><description>Google GTIG&amp;rsquo;s confirmation of the first AI-generated zero-day deployed in a live attack closes the loop on Monday&amp;rsquo;s AI agent vulnerability wave, connecting the attack surface (vulnerable AI frameworks) to the attack tool (AI-generated exploits) in the same reporting week.</description></item><item><title>The Agent Trusts the Output</title><link>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-output/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-output/</guid><description>Eight AI agent frameworks disclosed the same class of remote code execution vulnerability in a single week because the entire ecosystem shares a cognitive failure: treating LLM output as trusted data rather than untrusted instructions.</description></item><item><title>ShinyHunters Adds 275 Million Students to Monday's Breach Wave, PAN-OS Zero-Day Leaves Perimeter Gaps Until May 13</title><link>https://securityunlocked.com/weekly-intelligence/shinyhunters-adds-275-million-students-to-mondays-breach-wave-pan-os-zero-day-leaves-perimeter-gaps-until-may-13/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/shinyhunters-adds-275-million-students-to-mondays-breach-wave-pan-os-zero-day-leaves-perimeter-gaps-until-may-13/</guid><description>ShinyHunters expanded Monday&amp;rsquo;s identity breach wave to 275 million education users via Canvas and pivoted to cloud data warehouse infrastructure at Vimeo; separately, an unpatched PAN-OS RCE zero-day leaves internet-facing firewalls exposed until at least May 13.</description></item><item><title>What the Model Returns, the Shell Executes</title><link>https://securityunlocked.com/weekly-intelligence/what-the-model-returns-the-shell-executes/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/what-the-model-returns-the-shell-executes/</guid><description>Eight AI agent frameworks disclosed the same architectural vulnerability in a single week, revealing that the AI agent ecosystem is repeating the early-web SQL injection era under exploitation timelines that leave no room to learn slowly.</description></item><item><title>LiteLLM's 36-Hour Exploitation Window Confirms the AI Attack Surface Has Moved Up the Stack</title><link>https://securityunlocked.com/weekly-intelligence/litellms-36-hour-exploitation-window-confirms-the-ai-attack-surface-has-moved-up-the-stack/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/litellms-36-hour-exploitation-window-confirms-the-ai-attack-surface-has-moved-up-the-stack/</guid><description>The rapid exploitation of CVE-2026-42208 in LiteLLM marks the first confirmed weaponization of the AI API proxy layer, while TeamPCP&amp;rsquo;s new ransomware partnership turns out to be a wiper with no recovery path.</description></item><item><title>AI Infrastructure Exploited Within 24 Hours of Disclosure</title><link>https://securityunlocked.com/weekly-intelligence/the-advisory-is-the-starting-gun/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-advisory-is-the-starting-gun/</guid><description>Four AI infrastructure platforms (Langflow, Marimo, LMDeploy, Flowise) were exploited within 24 hours of vulnerability disclosure last week. The patching window has collapsed to under one attacker shift.</description></item><item><title>The Protocol Is Doing Its Job</title><link>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</guid><description>MCP&amp;rsquo;s trust architecture makes any exposed management interface a pre-authenticated command shell by design, not by accident, and two RCE vulnerabilities in the same week reveal a deployment curve that has outrun both audit methodology and detection playbooks.</description></item><item><title>Mythos Finds Zero-Days. npm Found Three More.</title><link>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</link><pubDate>Sun, 12 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</guid><description>The same week Anthropic unveiled an AI that autonomously finds zero-days, its own CLI shipped a CVSS 9.8 command injection, exposed by a debugging artifact that had been sitting in an npm package since March 31.</description></item><item><title>Trust Is the Exploit</title><link>https://securityunlocked.com/weekly-intelligence/trust-is-the-exploit/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trust-is-the-exploit/</guid><description>From a six-month DPRK social engineering operation to mass exploitation of developer ecosystems, this week&amp;rsquo;s threat landscape reveals that the most reliable attack surface is the trust we extend by default.</description></item><item><title>The Mental Model Is the Vulnerability</title><link>https://securityunlocked.com/weekly-intelligence/the-mental-model-is-the-vulnerability/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-mental-model-is-the-vulnerability/</guid><description>Five AI infrastructure disclosures in one day share the same root cause: the gap between what users believe their security settings do and what the framework actually executes.</description></item><item><title>Trust Is the Attack Surface</title><link>https://securityunlocked.com/weekly-intelligence/trust-is-the-attack-surface/</link><pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trust-is-the-attack-surface/</guid><description>Every major incident this week exploited institutional or interpersonal trust rather than technical vulnerabilities. The adversary&amp;rsquo;s target is not the system. It is the relationship.</description></item></channel></rss>