Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower Edition 008: Trust Is No Longer a Static Assumption

The Signal Watchtower: Security, Privacy, AI
Edition 008

Trust is no longer a static assumption. It is a live control.

FocusSecurity · Privacy · AI

Coverage window16 – 31 May 2026

AuthorVenkat Mangudi, Founder & CEO, Elytra Security

What the second half of May told us

No single defining event — a defining pattern. The systems organizations rely on to secure, route, build and recover are the systems attackers are testing first.

The sharper question is no longer whether a company has been breached — but whether the systems it trusts have been governed with the seriousness their role now demands.

Executive Overview

Attackers are moving through the systems organizations already trust

The second half of May confirmed a sharper version of the same pattern. The strongest signals did not come from one sector or one attack type — they came from security tools, endpoint management, AI coding tools, package registries, cloud APIs, web infrastructure, VPN clients and Linux estates alike.

The five lead signals

1

Microsoft Defender under active exploitation Two Defender vulnerabilities exploited in the wild, both added to CISA’s KEV catalog. When attackers exploit the protection layer itself, the issue stops being endpoint hygiene and becomes a trust failure inside the defensive stack.

2

FortiClient EMS turned into a delivery path Endpoint-management infrastructure abused to push the EKZ Infostealer through managed policy. When a control layer is compromised, trusted administrative features become malware-distribution channels.

3

Developer-ecosystem boundaries collapsing Packagist hooks, malicious npm targeting Claude directories, NuGet financial-SDK impersonation and GitHub Actions abuse. Registries, CI/CD, GitHub tokens, cloud credentials and workstations are now one connected execution surface.

4

AI-related security risk expanding fast A Claude Code deeplink RCE, AI-chatbot recommendation poisoning, and Project Glasswing finding high-severity candidates at scale. CERT-In responded by calling for 12-hour remediation of known exploited, internet-facing flaws.

5

Trusted cloud infrastructure as transport Webworm’s GraphWorm backdoor uses Microsoft Graph API and OneDrive for command-and-control — blending into enterprise cloud traffic many organizations inherently trust.

Trust is no longer a static assumption. It is a live control.

02Security Tooling & Management Layers Under Attack

The lead signal of the cycle: attackers moving into the very tools deployed to defend, manage and connect the enterprise.

Microsoft Defender

Two Defender flaws confirmed under active exploitation

ConfirmedHighCVE-2026-41091CVE-2026-45498CISA KEV

Microsoft disclosed two Defender vulnerabilities under active exploitation — a privilege-escalation flaw that can grant SYSTEM, and a denial-of-service flaw — both added to CISA’s Known Exploited Vulnerabilities catalog. Confirm Defender platform versions, verify update flow, and investigate abnormal tampering, service disruption or suspicious exclusions.

Why this matters

Defender is not a peripheral app — it is the security-control layer across enterprise Windows. When attackers exploit the protection layer itself, this is no longer endpoint hygiene; it is a trust failure inside the defensive stack.

FortiClient EMS

Endpoint management abused to push an infostealer

ConfirmedHighCVE-2026-35616

Attackers abused an improper-access-control flaw to modify endpoint policy and inject malicious scripts across managed devices, deploying EKZ Infostealer — disguised as a Fortinet patch — which harvested browser passwords, cookies, session data and autofill. Stolen session cookies can enable account takeover even with MFA in place.

Why this matters

EMS is a control layer, not ordinary software. Compromise turns trusted administrative features into a malware-distribution path — the clearest signal of the second half of May.

F5 BIG-IP

Edge appliance became the pivot into the enterprise

ConfirmedHighEnd-of-life build

An internet-facing BIG-IP became the entry point for a broader compromise — SSH to a Linux host, internal recon, an exploited Confluence server, credential harvesting and movement toward Active Directory. The device was an Azure-hosted Virtual Edition running an end-of-life build.

Why this matters

Load balancers, VPN gateways and proxies are trusted infrastructure with routing reach, certificates and privileged position. Misgoverned, the appliance becomes a bridge into everything behind it.

OpenVPN Connect for macOS

ConfirmedMedCVE-2026-9560

A privileged-helper flaw (v3.5.1–3.8.1, fixed in 3.8.2 / build 6009) lets a local attacker run commands as the background service via crafted IPC messages — turning a Mac foothold into elevated control.

YellowKey — BitLocker bypass

MitigationMedCVE-2026-45585

Abuses Windows Recovery Environment behaviour with physical access; risk is strongest for TPM-only BitLocker. Mitigate by moving high-risk systems to TPM + PIN and removing the vulnerable recovery path. Encryption strength depends on boot-chain integrity.

03Software Supply Chain & the Developer Ecosystem

Package registries, CI/CD identity, GitHub Actions, cloud federation and AI coding environments are no longer separate risk zones. They are one connected execution surface.

Packagist / Composer

JavaScript hooks smuggled into PHP packages

ConfirmedHigh8 packages

A coordinated campaign placed malicious logic in package.json rather than composer.json across eight Composer packages. The postinstall script downloaded a Linux binary from a GitHub Releases URL, wrote it to a hidden /tmp path, made it executable and ran it in the background. The malicious versions were removed.

Why this matters

A classic trust-boundary failure. Teams inspect Composer metadata for PHP risk and miss JavaScript lifecycle hooks bundled into the same project. Real build pipelines are polyglot.

Mini Shai-Hulud / TeamPCP

Worm-like registry campaign — and an unverified mega-breach claim

Confirmed campaignBreach claim unverifiedHigh

A TeamPCP-linked campaign affecting npm and PyPI: CI/CD credential theft, encrypted exfiltration, persistence and worm-like propagation. Microsoft’s durabletask PyPI versions 1.4.1–1.4.3 were yanked and remain under watch. Claims that TeamPCP stole and listed thousands of internal GitHub repositories stay unverified pending confirmation.

Why this matters

Confirmed package removal must be distinguished from broader impact claims. That discipline protects credibility and prevents unverified narratives from becoming premature conclusions.

Malicious npm targeting Claude workspaces

ConfirmedHigh

mouse5212-super-formatter posed as a deployment-sync utility but stole files from a Claude user-data directory — authenticating to GitHub with a found or fallback token and uploading local files to an attacker repo. AI workspaces are now part of the attack surface.

Sicoob NuGet & npm secret-stealers

ConfirmedHigh

A Sicoob.Sdk NuGet package (v2.0.0–2.0.4, ~500 downloads) stole Brazilian banking integration credentials — client IDs, PFX certificates and passwords. Parallel npm campaigns target CI/CD secrets and cloud tokens. The registry becomes the route into institutional trust.

Megalodon — GitHub Actions poisoning

Public reposMed

Thousands of malicious commits pushed into public repositories via throwaway accounts, abusing GitHub Actions workflows. No evidence yet of private-repo breach — treat as public-repository poisoning and CI/CD workflow abuse, which can still reach build secrets and cloud credentials.

04AI Platform Governance & Trusted Discovery Risk

AI is no longer only a system that generates text or code. It is becoming a trust router — and attackers are responding by targeting its recommendation paths, workspaces and tooling.

Claude Code

Deeplink remote code execution in AI developer tooling

ConfirmedHighPatched 2.1.118

A public write-up disclosed an RCE in Claude Code’s deeplink handling. Argument parsing around the claude-cli:// handler meant a crafted deeplink could cause attacker-supplied content to be treated as legitimate configuration and execute commands through Claude Code hooks. Reportedly fixed in version 2.1.118.

Why this matters

AI coding tools sit inside workstations, repositories, terminals, secrets and cloud credentials. A deeplink-to-command path here is not just a product bug — it is a warning about agentic tooling as an execution surface.

AI chatbot recommendation poisoning

Trusted discovery abused to push malware downloads

ConfirmedMed

A campaign manipulated AI chatbot recommendations to steer users toward malicious download sites for disk, driver, GPU and codec utilities — focusing on high-performance GPUs to make cryptomining more profitable. It evolved from conventional SEO poisoning into manipulation of LLM-based recommendation flows.

Why this matters

Users increasingly ask AI systems where to download software and which link to trust. If attackers can influence those answers, AI becomes part of the delivery chain. AI-provided links should not be treated as trusted sources.

Project Glasswing / Claude Mythos

Signal

Anthropic’s defensive initiative reportedly identified thousands of high- and critical-severity vulnerability candidates across widely used software, with validated findings and upstream patches flowing. Not a breach — a compression signal: discovery is accelerating, and weaker-governance hands will compress the window to weaponization.

CERT-In — 12-hour KEV remediation

Regulatory

CERT-In called for known exploited vulnerabilities on internet-facing and critical systems to be remediated within 12 hours where feasible, framed around AI-assisted exploitation. The operational standard is shifting from calendar-based patching to exposure-based response — in hours, not weeks.

05Critical Infrastructure, Cloud Trust & APT Signals

When attackers move command-and-control into the cloud platforms enterprises inherently trust, the issue is no longer malicious binaries — it is legitimate SaaS as the attacker’s transport plane.

Webworm / GraphWorm · China-aligned

Microsoft Graph API & OneDrive used for command-and-control

ConfirmedHigh

ESET reported that Webworm added two backdoors: EchoCreep, using Discord for C2, and GraphWorm, using the Microsoft Graph API. GraphWorm relies on OneDrive endpoints to retrieve jobs and upload victim information, with separate OneDrive directories per victim.

Why this matters

This is a trust-layer signal. C2 inside Graph API and OneDrive blends into ordinary enterprise cloud usage. Blocking the platform is unrealistic; governing tokens, service principals, OAuth grants and abnormal API behaviour becomes essential.

Nimbus Manticore / MiniFast · Iran-linked (UNC1549)

AI-assisted backdoor campaign across strategic sectors

ConfirmedHigh

Check Point reported the IRGC-affiliated group resurfaced with phishing, SEO poisoning, trojanized Zoom and SQL Developer installers, fake meeting lures, AppDomain hijacking and a new backdoor, MiniFast — which shows signs of AI-assisted development. That means AI may have helped accelerate the build, not that the malware is autonomous.

Why this matters

One campaign connects three themes: geopolitical targeting, trusted-software deception and AI-accelerated development. Trojanized installers exploit user trust; SEO and meeting lures exploit search and workflow trust. The AI signal is speed.

fast16 — historical sabotage research

Strategic, not operational

A suspected pre-Stuxnet sabotage framework (~2005) designed to interfere with high-precision engineering and scientific-calculation software resurfaced in research. There is no clear evidence it is currently spreading. The reminder: the next trust boundary is not only the network — it is the correctness of the calculations, models and simulations leadership assumes to be true.

06Exploitation, Ransomware & Financial Roundup

Edge, collaboration and infrastructure layers stayed in the crosshairs — confirmed exploitation kept separate from public-PoC exposure.

Microsoft Exchange Server

ConfirmedHighCVE-2026-42897

An OWA flaw in on-prem Exchange (2016 / 2019 / Subscription Edition) lets a crafted email run arbitrary JavaScript in the browser context. Exploited in attacks; Exchange Online unaffected. Residual on-prem Exchange stays exposed and identity-integrated.

Microsoft SharePoint Server

PatchedMedCVE-2026-45659

A deserialization RCE; an attacker with only Site Member permissions can execute code over the network — no admin rights required. A lateral-movement and persistence concern in under-monitored collaboration estates.

NGINX — rewrite module, njs & PoolSlip

ConfirmedWatchHigh

CVE-2026-42945 (rewrite module) saw active exploitation; CVE-2026-8711 fixed in njs 0.9.9; PoolSlip / CVE-2026-9256 reported high-risk, PoC vs in-the-wild still to be distinguished. NGINX sits on the traffic path for proxies, gateways and ingress.

Ghost CMS

ConfirmedHighCVE-2026-26980

A Content-API SQL injection compromised 700+ legitimate domains — universities, fintech, AI, media — injecting JavaScript and serving fake-CAPTCHA ClickFix lures. Unauthenticated reads exposed API keys; the victim’s trust is borrowed from the compromised brand.

Windows “MiniPlasma” & Linux “CIFSwitch / DirtyDecrypt”

Public PoCMedCVE-2026-31635

Three local-privilege-escalation issues with PoC code: MiniPlasma reaches SYSTEM on fully patched Windows; CIFSwitch abuses the Linux kernel CIFS client / cifs-utils; DirtyDecrypt is a kernel flaw on affected builds. Post-compromise accelerants that turn a foothold into root or SYSTEM control.

Ransomware & Financial Malware

NightSpire ransomware

ConfirmedHigh

A durable chain of ordinary tools: RDP access; persistence via Chrome Remote Desktop and AnyDesk; Everything for file discovery; 7-Zip for staging; MEGAsync for exfiltration. Notable precisely because the technique is ordinary — and still works.

Grandoreiro & BTMOB — banking malware

ConfirmedMed

Grandoreiro (Spain, Portugal, Mexico) uses phishing, DLL side-loading, WebRTC/STUN/ICE peer-to-peer and anti-analysis. BTMOB is an Android malware-as-a-service RAT (Brazil) abusing fake Play listings and accessibility permissions. Banking malware is increasingly modular and service-driven.

07Signals & Patterns

Read across the cycle, six patterns define the period more sharply than any single incident.

1

Security tools are now part of the attack surface Defender, FortiClient EMS, OpenVPN, BitLocker and F5 BIG-IP all appeared this cycle. Trusted tools carry broad privilege, network position and user confidence — which is exactly what makes them attractive. Stop treating them as invisible infrastructure.

2

Developer workstations are production-risk assets Registries, Claude directories, GitHub Actions and CI/CD credentials point to one conclusion: a compromised developer machine can become a production event without ever touching production first.

3

AI is becoming a trust router Users ask AI what to install; developers run it in terminals and repositories. The risk is not that AI is malicious — it is that AI is being inserted into workflows before organizations have defined its trust boundaries.

4

Cloud APIs are becoming covert control channels GraphWorm shows Microsoft Graph API and OneDrive abused for C2 and data movement. The traffic looks like ordinary cloud usage; governing tokens, grants and anomalous API behaviour is the defensible path.

5

Edge and control-plane systems remain priority targets F5 BIG-IP, NGINX, Exchange OWA, FortiClient EMS and SharePoint reinforce one point: the target is the infrastructure that routes, authenticates, manages, publishes and proxies the application — not only the application.

6

Exploitation windows are shrinking AI-assisted discovery, public PoC release and active exploitation are compressing the time from disclosure to compromise. Patch committees and quarterly cycles cannot keep pace with this operating tempo.

08Defender Actions

Eight moves that align defensive tempo with attacker speed — from classifying security tools as high-value assets to standing up an exposure-based response path.

01

Treat security tools as high-value assets EDR, EMS, VPN, MDM, SIEM, identity, backup and remote-support platforms are control systems. Confirm versions, harden management interfaces, restrict access and monitor administrative changes.

02

Build a 12-hour KEV response path Define who authorizes action, who validates exposure, who applies compensating controls and who confirms remediation — before a crisis. KEV on internet-facing systems needs a standing emergency workflow.

03

Reduce control-plane exposure Public access should be the exception. Admin portals, VPN gateways, MDM and EMS consoles, firewall management and reverse proxies need urgent exposure review. Patch availability is not risk reduction.

04

Govern developer workstations as production-adjacent EDR, application control, secrets scanning, package-install telemetry, browser hardening, AI-tool inventory — and separation between personal, dev, staging and production credentials.

05

Validate build & package pipelines Check artifact provenance, package pinning, signing, CI/CD secrets and registry accounts. Lifecycle hooks across npm, Packagist, Composer, PyPI and NuGet need explicit review.

06

Govern AI tooling before it becomes shadow infrastructure Inventory coding assistants, local models, MCP servers, agent connectors and IDE plugins. AI-provided links should not be treated as trusted software sources.

07

Monitor cloud APIs as security telemetry Graph API, OneDrive, SharePoint, Slack, Discord and GitHub can become C2 or exfiltration channels. Watch abnormal API usage, token grants, file staging and service-principal behaviour.

08

Reclassify trusted web platforms as delivery risk CMS and brand-owned sites become malware lures when compromised. Web-integrity monitoring, CMS patching, admin API-key rotation and detection for unauthorized JavaScript injection are now standard.

Closing note

The second half of May did not produce one defining event. It produced a defining pattern.

The systems organizations rely on to secure, observe, route, authenticate, build, automate, recover, collaborate, browse and govern are now the systems attackers are testing first. This is not a call for panic. It is a call for sharper trust management.

In the next phase of cyber risk, the most important question may not be whether a system is trusted — but whether that trust has been earned, scoped, monitored and continuously revalidated.

About The Signal Watchtower

Published by Elytra Security, creators of Threat Lens. Clear, signal-only updates across security, privacy and AI — confirmed facts kept separate from claims.

Authored by Venkat Mangudi · Founder & CEO

Integrity. Trust. Clarity.

An ISO/IEC 27001:2022 Certified Company


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading