The operating window is closing. Speed is now the control test.
What the first half of June told us
No single event. One pattern. The operating window between exposure and exploitation is compressing — and the systems organizations rely on to run the enterprise are what attackers test first.
Judgment windows are closing. The question for boards is not whether the enterprise has been tested — it is whether the systems that carry the enterprise are governed with the seriousness their role now demands.
01Executive Overview
Speed is now the control test
June exposed a fundamental timing problem in enterprise cyber defense. The signals from 1–15 June connected into one pattern: AI, supply chain, control planes, and identity moving simultaneously — faster than most governance processes were built to absorb.
AI accelerated discovery and offensive tooling. Developer package ecosystems became self-propagating attack surfaces. Control planes drew sustained exploitation pressure. Identity became the preferred entry point. Security teams now face a harder problem: faster decisions, incomplete information, across systems they once treated as support infrastructure. Those systems are no longer support. They are what attackers target first.
The five lead signals
Signal 01 · AI
AI is compressing the vulnerability cycle
Researchers demonstrated a self-replicating AI worm that used local open-weight models to reason through a test network, generate target-specific attack strategies, and propagate without human steering. Controlled lab — not in-the-wild. The significance is the operating model it represents. AI-linked movement also appeared across Redis, OpenSSL, FFmpeg, Langflow, LiteLLM, and model governance.
AI now touches every stage of the cyber cycle — discovery, weaponization, execution, governance, response. Organizations still treating it as a usage-policy question are already behind.
Signal 02 · AI Governance
Fable and Mythos turned model capability into a governance question
Anthropic’s Fable / Mythos release became the defining AI governance signal of the period. Within days of Fable’s launch as a broadly available Mythos-class model, the public debate moved through jailbreak claims, export-control pressure, foreign-national access restrictions, and dual-use capability questions.
Frontier model capability is now a matter of access control, jurisdiction, and board-level oversight. When similar underlying capability reaches different audiences through different access layers, governance becomes part of the product architecture.
Signal 03 · Supply Chain
Supply-chain attacks are operating ecosystem-wide
Miasma, Hades, IronWorm, AUR compromise, affected Microsoft repositories, and compromised npm and PyPI packages all appeared in the same fortnight. Developer ecosystems are now active propagation surfaces — not isolated incidents.
Developer machines carry code, credentials, build authority, and deployment reach. A compromised package, extension, or build script becomes a production-risk event without ever touching production.
Signal 04 · Control Planes
Control planes remained priority targets
Check Point VPN, Cisco Catalyst SD-WAN Manager, Ivanti Sentry, ServiceNow, Splunk Enterprise, Veeam Backup & Replication, Oracle PeopleSoft, and SolarWinds Serv-U all appeared in the first-half June intake.
These are not ordinary applications. They connect, manage, observe, recover, and route the enterprise. A weakness here creates leverage over everything behind it.
Signal 05 · Response Speed
Exploited-vulnerability response now requires executive tempo
CISA KEV additions, actively exploited VPN and SD-WAN flaws, a Chrome V8 zero-day, Oracle PeopleSoft exploitation, LiteLLM exploitation, and SolarWinds Serv-U exploitation all converged in a single fortnight. The pressure on response timelines is measurable.
Internet-facing, identity-adjacent, and control-plane vulnerabilities require pre-authorized emergency workflows. The next routine maintenance window is not a defensible timeline.
02AI Systems, Agents & Exploitation Compression
AI moved into every layer of the security stack
Discovery, weaponization, autonomous research, coding agents, model governance, and the infrastructure behind AI applications — all appeared in the June intake. The question is no longer about safe prompting or acceptable-use policy. It is whether organizations can govern AI-enabled systems with the same discipline they apply to identity, infrastructure, and privileged access.
Adaptive AI Worm
Self-replicating AI worm demonstrated in controlled lab
Public ResearchHigh
Researchers demonstrated a worm that used local open-weight models to inspect a test network, reason about weaknesses, generate target-specific attack strategies, and propagate without human steering. Traditional worms rely on fixed exploit logic. This model can adapt its next step based on what it observes — a different defensive problem.
Detection, containment, and exposure management must account for adaptive behavior, not only known exploit chains. The defensive model changes when reasoning becomes part of propagation.
Fable 5 · Mythos 5
Model release became a live governance stress-test
WatchHighAI Governance
Fable was positioned as a broadly available Mythos-class model with cybersecurity safeguards; Mythos remained restricted to vetted access. Within days: jailbreak claims, vendor rebuttal, export-control pressure, and debate over whether safety layers can contain dual-use capability at scale.
When similar underlying capability is accessible through different access layers, governance becomes architecture. This is an enterprise governance issue, a national-security question, and a cyber-risk matter — simultaneously.
LiteLLM
AI model gateway exploited and added to CISA KEV
ConfirmedHighCVE-2026-42271CISA KEV
CISA added a LiteLLM vulnerability to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. LiteLLM serves as an interface layer across multiple large language model providers — a position of production trust in AI-enabled enterprises.
AI gateways and model-routing tools are production infrastructure. They require exposure review, patch discipline, authentication controls, logging, and segmentation — not just development-environment hygiene.
Langflow
AI workflow builder exploited — arbitrary file write on exposed systems
ConfirmedHighCVE-2026-5027
Active exploitation of a Langflow flaw allowed attackers to write files to arbitrary locations on exposed systems. Langflow is used to build AI workflows and agent applications — increasingly in production environments without mature operational controls.
AI application builders are entering production faster than security controls follow. Exposed without segmentation and access discipline, they become server-side attack surfaces with direct AI-workflow reach.
Agentjacking
AI coding agents manipulated through ordinary workflow artifacts
Public ResearchHighAI Coding Agents
Researchers described Agentjacking as a class of attack that tricks AI coding agents into executing malicious code through crafted error reports and routine workflow artifacts. The agent interprets context, inspects files, follows instructions, and may execute tools — with the trust assumptions of an authenticated developer session.
Security governance must cover the environment around the agent — its inputs, permissions, execution rights, and connected tools — not the agent itself in isolation.
OpenClaw · Gemini
AI assistants manipulated through ordinary user inputs
Public ResearchMed–HighAgentic Input Abuse
Separate research showed that AI agents could be manipulated through contacts, vCards, location pins, notifications, and messaging content — ordinary inputs indistinguishable from legitimate user data. As assistants gain access to email, calendars, devices, calls, and files, the surface for instruction injection expands directly.
Context integrity is now a core AI security requirement. Organizations deploying assistants with broad system access must govern what those assistants receive, not only what they produce.
AI-Discovered Vulnerabilities
AI accelerates discovery — in Redis, OpenSSL, FFmpeg, and beyond
SignalHighDiscovery Compression
The period included confirmed and reported instances of AI-assisted vulnerability discovery across Redis, OpenSSL, FFmpeg, and Project Glasswing-style findings. AI-assisted discovery compresses the time between vulnerability existence and attacker awareness.
When discovery and weaponization move faster than organizational response, the defender advantage built into responsible disclosure erodes. Exposure validation cadence must keep pace.
03Software Supply Chain & Developer Infrastructure
Developer infrastructure is production-adjacent
Package registries, IDE extensions, GitHub workflows, CI/CD credentials, AI coding assistants, build scripts, and developer machines form one connected system. Attackers treat them as one system.
Miasma — Microsoft Repositories
Supply-chain attack reaches Azure, Azure-Samples, and MicrosoftDocs
ConfirmedHighSupply Chain
Microsoft temporarily removed repositories after a Miasma-related incident injected information-stealing logic into open-source projects. Affected repositories spanned Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations.
When supply-chain activity reaches major vendor repositories, ecosystem trust becomes the exposure surface. Sample code, documentation, and CI/CD workflows carry implicit authority downstream.
Hades / Shai-Hulud — PyPI
ConfirmedHigh
Python packages and wheel artifacts compromised to deliver credential-stealing behavior. Developer dependency decisions now require security controls, not only engineering convenience.
IronWorm — npm
ConfirmedHigh
Rust-based infostealer delivered via infected npm packages. A stolen developer credential can unlock repositories, cloud environments, and CI/CD pipelines. Treat developer credential theft as a serious enterprise event.
Arch Linux AUR — 400+ packages
ConfirmedHigh
400+ AUR packages hijacked to install a Rust credential stealer with eBPF rootkit capability when elevated privileges were available. Community repositories are part of the real supply chain.
npm 12 — install scripts off by default
DefensiveHigh
GitHub announced npm 12 will require explicit opt-in before dependency install scripts execute. A meaningful ecosystem control change — acknowledges that automatic lifecycle execution has become a primary abuse path.
VS Code — extension update delay
DefensiveMed
VS Code introduced a delay before automatic extension updates to reduce exposure to compromised extensions. Extensions sit close to code, terminals, credentials, and cloud tooling — update speed must be balanced against supply-chain risk.
Claude Code GitHub Action flaw
ConfirmedHigh
A flaw in a Claude Code GitHub Action reportedly allowed a malicious issue to influence workflows and create a path to repository compromise. AI coding agents inside CI/CD require stronger trust boundaries; issues and error reports are inputs to automated decision-making.
OpenAI Codex UI supply-chain attack
ConfirmedHigh
A legitimate-looking npm package associated with a Codex remote web UI attracted significant downloads while stealing authentication tokens. Attackers are targeting the convenience layer around AI tools: fake helpers, fake UIs, unofficial packages. Installation trust is now part of AI security.
04Edge, VPN & Control-Plane Exploitation
Nine control-plane platforms under active pressure
VPN, SD-WAN, backup, observability, ITSM, file transfer, ERP, and mobile gateways all appeared. These platforms hold administrative reach, trusted network position, and recovery authority. Compromise here travels far.
Oracle PeopleSoft · ShinyHunters
ERP zero-day exploited — universities and institutions targeted
ConfirmedHighCVE-2026-35273CISA KEV
Oracle PeopleSoft was exploited in data-theft attacks attributed to ShinyHunters / UNC6240, with universities heavily affected. Google confirmation and additional reporting strengthened the signal. Oracle released mitigation guidance.
ERP systems carry institutional data, process context, and operational intelligence. Compromise here is both a data breach and an intelligence operation — attackers leave understanding how the organization works.
Check Point VPN — Qilin ransomware
ConfirmedHighCVE-2026-50751CISA KEV
Critical Remote Access VPN / Mobile Access flaw exploited; linked to Qilin ransomware activity. VPN compromise turns an external attacker into an internal operator. Emergency response capability is required the moment exploitation is confirmed.
Cisco Catalyst SD-WAN Manager
ConfirmedHighCVE-2026-20245CISA KEV
Active exploitation with no patch initially available; mitigations required. SD-WAN management is the control plane for distributed enterprise connectivity. Exploitation threatens routing, management, and operational trust across every connected location.
Ivanti Sentry — mobile gateway
ConfirmedHigh
Maximum-severity flaw enabling root code execution on exposed mobile gateways. Mobile gateways sit between devices, identity, and enterprise services. Root-level compromise at this layer has control-plane consequences across the mobile estate.
ServiceNow — customer instances
ConfirmedHigh
ServiceNow disclosed exploitation against some customer instances. ServiceNow carries operational knowledge: assets, incidents, changes, approvals, and users. Unauthorized access exposes how the enterprise operates and responds.
Splunk Enterprise
ConfirmedHighCVE-2026-20253
Critical flaw allowing unauthenticated file operations and potential remote code execution. Observability platforms aggregate logs, telemetry, and security context. Compromise of the observer weakens detection and investigation across the board.
Veeam Backup & Replication
ConfirmedHighCVE-2026-44963
RCE by an authenticated domain user on the backup server. Backup systems are central to ransomware resilience. A compromise path into backup infrastructure directly affects recovery confidence — the safety net has a vulnerability.
SolarWinds Serv-U
ConfirmedHighCVE-2026-28318CISA KEV
CISA added this to KEV after confirmed exploitation. File-transfer infrastructure is exposed, trusted, and connected to sensitive partner workflows. It remains a recurring attacker target for consistent operational reasons.
HTTP/2 Bomb — DoS at protocol layer
WatchHigh
Remote denial-of-service technique affecting default HTTP/2 configurations across NGINX, Apache HTTPD, IIS, Envoy, and Cloudflare Pingora. HTTP/2 is embedded in the availability surface for web servers, APIs, proxies, and cloud-facing ingress.
05Identity, Collaboration & Trusted Workflow Abuse
Six routes to enterprise compromise — no malware required
Tokens, support workflows, mobile behavior, messaging, URI handlers, and executive mailboxes. The pattern: obtain trusted access, then operate inside normal systems without raising alarms.
Microsoft 365 Android — token exposure
ConfirmedHigh
A development flag left enabled allowed other apps on the same Android device to request signed-in Microsoft account tokens. A valid token provides direct access to email, files, calendar, and collaboration data — with no password prompt required. Token governance requires the same seriousness as password governance.
Meta AI support — Instagram account takeovers
ConfirmedMed–High
Attackers abused Meta’s AI-powered support workflow to take over high-profile Instagram accounts. When AI support workflows can be manipulated, the recovery layer becomes a route to takeover — the system designed to restore access enables unauthorized access.
Tchap — 73,000 French government accounts
ConfirmedHigh
A breach of France’s Tchap encrypted messaging platform affected over 73,000 public-sector accounts. Government collaboration systems carry identity, coordination, and operational context — they require governance equal to any sensitive enterprise platform.
Exchange Server OWA — actively exploited
ConfirmedHighCVE-2026-42897CISA KEV
Exploited OWA flaw in on-prem Exchange. On-premises Exchange remains identity-integrated and operationally connected. Residual exposure in under-maintained deployments continues to create enterprise risk at scale.
Windows Search URI — NTLMv2 hash leak
Public ResearchMed
Unpatched URI handler issue leaks Net-NTLMv2 hashes to attacker-controlled SMB paths. In NTLM-heavy networks, relay opportunities can convert a moderate identity exposure into a meaningful compromise path through trusted OS behavior.
Stock exchange executive mailbox — months-long access
ConfirmedHigh
Attackers maintained access to a senior executive’s Outlook mailbox for months, exfiltrating data in small batches through trusted cloud services. Executive mailbox access exposes strategy, deal flow, regulatory communication, credential reset paths, and market-sensitive intelligence.
06Critical Infrastructure, Nation-State & Reconnaissance
Patient, persistent actors — durable access as the objective
Activity continued against government, telecom, energy, military, academic, and public-sector environments. The method: durable access through identity systems, appliances, trusted software, and reconnaissance infrastructure — then wait.
JDY botnet — 1,500+ devices, China-linked
ConfirmedHigh
China-linked JDY botnet expanded to over 1,500 SOHO and IoT devices operating as a high-performance scanner for exposed services. Continuous infrastructure mapping at this scale gives attackers a strategic view of enterprise exposure before selecting targets.
Fuel tank monitoring — government warning
ConfirmedHigh
U.S. agencies warned that internet-exposed automatic tank gauges were being targeted. Critical infrastructure does not always fail through sophisticated malware. It can fail through unmanaged exposure of ordinary internet-connected operational systems.
Chinese authentication-stack persistence
ConfirmedHigh
Reported long-term access maintained by compromising authentication stack components — giving attackers visibility into administrative activity over an extended period. If authentication components are compromised, attacker activity can appear operationally legitimate indefinitely.
Velvet Ant — Linux PAM and OpenSSH backdoor
ConfirmedHigh
A China-linked actor backdoored Linux PAM and OpenSSH components to maintain access over many years. Authentication components require integrity monitoring and rebuild discipline. Availability alone is insufficient when the login path itself may be altered.
Gamaredon — WinRAR exploitation
ConfirmedHighCVE-2025-8088CISA KEV
Russia-aligned groups continued exploiting a WinRAR path-traversal flaw against Ukrainian organizations. Older exploited vulnerabilities remain operationally useful when archive workflows, removable media, and network shares continue to support delivery.
Dragon Weave — Czech Republic, Taiwan
ConfirmedHigh
China-aligned activity targeting officials and citizens via spear-phishing and AdaptixC2 delivery. Geopolitical targeting continues to rely on practical delivery mechanics — phishing, archives, and adapted commodity tooling.
VerdantBamboo — Linux appliance backdoors
ConfirmedHigh
China-nexus espionage cluster deployed backdoors against Linux and BSD-like appliance environments. Appliances are under-inventoried, difficult to rebuild cleanly, and operate with trusted network position — making them attractive long-term footholds.
07Signals & Patterns
Six patterns that defined the first half of June
The discovery-to-exploitation buffer is shrinking AI-assisted discovery, public exploit logic, active exploitation, and KEV movement point to a shorter operational window. Vulnerability management must be tied to exposure, asset criticality, and exploitation status — not only CVSS scores.
Developer infrastructure has production-level risk exposure npm, PyPI, AUR, GitHub repositories, VS Code, Claude Code, and Codex tooling all appeared in the same fortnight. The developer environment carries credentials, build authority, and deployment influence. It requires production-grade protection.
AI agents expand the instruction surface beyond the agent itself Agentjacking, OpenClaw manipulation, Gemini notification hijacking, and Claude Code workflow concerns show that context consumed by an agent is a security boundary. Governance must cover inputs, permissions, execution rights, and connected tools.
Control planes are under direct, sustained pressure VPN, SD-WAN, backup, observability, ITSM, ERP, mobile gateway, and file-transfer platforms appeared across the June intake. These platforms require privileged-access discipline, exposure review, and executive escalation paths.
Identity exposure is the preferred first move Tokens, AI support abuse, collaboration platform compromise, URI-handler NTLM leakage, and long-term authentication-stack persistence all share the same logic: trusted access travels farther and quieter than malware.
Public exploitability requires emergency operations — not patch cycles KEV-class exposure, no-patch mitigations, and public PoCs require pre-built emergency workflows. The decision path must be known and authorized before the vulnerability arrives.
08Defender Actions
Eight actions for executive and security leadership
Pre-authorize 12-hour and 72-hour response paths
Establish pre-authorized escalation for KEV, VPN, identity-layer, and actively exploited flaws: 12 hours for internet-facing exposure; 72 hours for high-impact control-plane systems. Define validation, compensating controls, approval, testing, rollback, and executive escalation before the next incident — not during it.
Treat AI infrastructure as production infrastructure
Inventory LiteLLM, Langflow, agent frameworks, model gateways, vector databases, and AI development servers. Apply patching, authentication, segmentation, logging, backup, and monitoring expectations consistent with other production systems — not with experimental tooling.
Govern agentic coding tools explicitly
Inventory Claude Code, Codex, Copilot, Cursor, GitHub Actions integrations, MCP servers, and IDE plugins. Define what each can read, write, execute, and access. Separate experimentation from production repositories and credentials. Absence of a policy is a policy — a permissive one.
Protect developer workstations as production-adjacent
Enforce EDR, secrets scanning, browser hardening, repository access review, token hygiene, and package-install monitoring. Maintain hard separation between personal, development, staging, and production credentials. Developer machines carry production-level authority.
Move package execution to explicit trust
Package lifecycle scripts, build hooks, and post-install behavior require governance. Disable automatic execution where possible; move to explicit allow-listing for trusted packages, trusted maintainers, and controlled build contexts. npm 12’s default is the right model.
Reclassify control-plane platforms as tier-one assets
VPN, SD-WAN, backup, observability, ITSM, ERP, file-transfer, and mobile-gateway platforms require privileged-access controls, exposure review, emergency patching, configuration baselines, and dedicated monitoring — equivalent to Active Directory and identity infrastructure.
Monitor tokens with the discipline applied to passwords
OAuth tokens, mobile app tokens, GitHub tokens, npm tokens, cloud API keys, service principals, and session cookies must be logged, reviewed, and rotated based on risk. Track issuance, use, refresh, source application, geography, privilege level, and abnormal behavior.
Preserve credibility by separating confirmed from claimed
Confirmed exploitation, vendor advisories, and KEV entries must remain separate from threat-actor claims, leak-site posts, and social-media assertions. This discipline protects decision quality. Conflating the two degrades the signal value of every future alert.
09Closing Note
The operating model is under pressure. AI is shortening cycles. Agents are expanding reach. Supply chains are propagating attacks. Control planes are attracting the most serious attention. Identity gives attackers a cleaner, quieter path than malware ever did.
The lesson is direct. Risk is moving faster than governance was built to move.
Boards don’t need volume. They need clear decision authority, fast exposure triage, ownership with accountability, and hard separation between confirmed fact and unverified claim.
The organizations that adapt are not the ones chasing headlines. They are the ones that know: which systems own the business, which exposures demand immediate action, who decides, and how fast the enterprise can move.
About The Signal Watchtower
Published by Elytra Security, creators of Threat Lens. Signal-only threat intelligence across security, privacy, and AI — confirmed facts kept rigorously separate from claims.
Authored by Venkat Mangudi · Founder & CEO, Elytra Security
Integrity. Trust. Clarity.
An ISO/IEC 27001:2022 Certified Company
