Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower Edition 009: The Operating Window Is Closing

The Signal Watchtower: Security, Privacy, AI
Edition 009

The operating window is closing. Speed is now the control test.

FocusSecurity · Privacy · AI

Coverage window1 – 15 June 2026

AuthorVenkat Mangudi, Founder & CEO, Elytra Security

What the first half of June told us

No single event. One pattern. The operating window between exposure and exploitation is compressing — and the systems organizations rely on to run the enterprise are what attackers test first.

Judgment windows are closing. The question for boards is not whether the enterprise has been tested — it is whether the systems that carry the enterprise are governed with the seriousness their role now demands.

01Executive Overview

Speed is now the control test

June exposed a fundamental timing problem in enterprise cyber defense. The signals from 1–15 June connected into one pattern: AI, supply chain, control planes, and identity moving simultaneously — faster than most governance processes were built to absorb.

AI accelerated discovery and offensive tooling. Developer package ecosystems became self-propagating attack surfaces. Control planes drew sustained exploitation pressure. Identity became the preferred entry point. Security teams now face a harder problem: faster decisions, incomplete information, across systems they once treated as support infrastructure. Those systems are no longer support. They are what attackers target first.

The five lead signals

Signal 01 · AI

AI is compressing the vulnerability cycle

Researchers demonstrated a self-replicating AI worm that used local open-weight models to reason through a test network, generate target-specific attack strategies, and propagate without human steering. Controlled lab — not in-the-wild. The significance is the operating model it represents. AI-linked movement also appeared across Redis, OpenSSL, FFmpeg, Langflow, LiteLLM, and model governance.

Why this matters

AI now touches every stage of the cyber cycle — discovery, weaponization, execution, governance, response. Organizations still treating it as a usage-policy question are already behind.

Signal 02 · AI Governance

Fable and Mythos turned model capability into a governance question

Anthropic’s Fable / Mythos release became the defining AI governance signal of the period. Within days of Fable’s launch as a broadly available Mythos-class model, the public debate moved through jailbreak claims, export-control pressure, foreign-national access restrictions, and dual-use capability questions.

Why this matters

Frontier model capability is now a matter of access control, jurisdiction, and board-level oversight. When similar underlying capability reaches different audiences through different access layers, governance becomes part of the product architecture.

Signal 03 · Supply Chain

Supply-chain attacks are operating ecosystem-wide

Miasma, Hades, IronWorm, AUR compromise, affected Microsoft repositories, and compromised npm and PyPI packages all appeared in the same fortnight. Developer ecosystems are now active propagation surfaces — not isolated incidents.

Why this matters

Developer machines carry code, credentials, build authority, and deployment reach. A compromised package, extension, or build script becomes a production-risk event without ever touching production.

Signal 04 · Control Planes

Control planes remained priority targets

Check Point VPN, Cisco Catalyst SD-WAN Manager, Ivanti Sentry, ServiceNow, Splunk Enterprise, Veeam Backup & Replication, Oracle PeopleSoft, and SolarWinds Serv-U all appeared in the first-half June intake.

Why this matters

These are not ordinary applications. They connect, manage, observe, recover, and route the enterprise. A weakness here creates leverage over everything behind it.

Signal 05 · Response Speed

Exploited-vulnerability response now requires executive tempo

CISA KEV additions, actively exploited VPN and SD-WAN flaws, a Chrome V8 zero-day, Oracle PeopleSoft exploitation, LiteLLM exploitation, and SolarWinds Serv-U exploitation all converged in a single fortnight. The pressure on response timelines is measurable.

Why this matters

Internet-facing, identity-adjacent, and control-plane vulnerabilities require pre-authorized emergency workflows. The next routine maintenance window is not a defensible timeline.

02AI Systems, Agents & Exploitation Compression

AI moved into every layer of the security stack

Discovery, weaponization, autonomous research, coding agents, model governance, and the infrastructure behind AI applications — all appeared in the June intake. The question is no longer about safe prompting or acceptable-use policy. It is whether organizations can govern AI-enabled systems with the same discipline they apply to identity, infrastructure, and privileged access.

Adaptive AI Worm

Self-replicating AI worm demonstrated in controlled lab

Public ResearchHigh

Researchers demonstrated a worm that used local open-weight models to inspect a test network, reason about weaknesses, generate target-specific attack strategies, and propagate without human steering. Traditional worms rely on fixed exploit logic. This model can adapt its next step based on what it observes — a different defensive problem.

Why this matters

Detection, containment, and exposure management must account for adaptive behavior, not only known exploit chains. The defensive model changes when reasoning becomes part of propagation.

Fable 5 · Mythos 5

Model release became a live governance stress-test

WatchHighAI Governance

Fable was positioned as a broadly available Mythos-class model with cybersecurity safeguards; Mythos remained restricted to vetted access. Within days: jailbreak claims, vendor rebuttal, export-control pressure, and debate over whether safety layers can contain dual-use capability at scale.

Why this matters

When similar underlying capability is accessible through different access layers, governance becomes architecture. This is an enterprise governance issue, a national-security question, and a cyber-risk matter — simultaneously.

LiteLLM

AI model gateway exploited and added to CISA KEV

ConfirmedHighCVE-2026-42271CISA KEV

CISA added a LiteLLM vulnerability to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. LiteLLM serves as an interface layer across multiple large language model providers — a position of production trust in AI-enabled enterprises.

Why this matters

AI gateways and model-routing tools are production infrastructure. They require exposure review, patch discipline, authentication controls, logging, and segmentation — not just development-environment hygiene.

Langflow

AI workflow builder exploited — arbitrary file write on exposed systems

ConfirmedHighCVE-2026-5027

Active exploitation of a Langflow flaw allowed attackers to write files to arbitrary locations on exposed systems. Langflow is used to build AI workflows and agent applications — increasingly in production environments without mature operational controls.

Why this matters

AI application builders are entering production faster than security controls follow. Exposed without segmentation and access discipline, they become server-side attack surfaces with direct AI-workflow reach.

Agentjacking

AI coding agents manipulated through ordinary workflow artifacts

Public ResearchHighAI Coding Agents

Researchers described Agentjacking as a class of attack that tricks AI coding agents into executing malicious code through crafted error reports and routine workflow artifacts. The agent interprets context, inspects files, follows instructions, and may execute tools — with the trust assumptions of an authenticated developer session.

Why this matters

Security governance must cover the environment around the agent — its inputs, permissions, execution rights, and connected tools — not the agent itself in isolation.

OpenClaw · Gemini

AI assistants manipulated through ordinary user inputs

Public ResearchMed–HighAgentic Input Abuse

Separate research showed that AI agents could be manipulated through contacts, vCards, location pins, notifications, and messaging content — ordinary inputs indistinguishable from legitimate user data. As assistants gain access to email, calendars, devices, calls, and files, the surface for instruction injection expands directly.

Why this matters

Context integrity is now a core AI security requirement. Organizations deploying assistants with broad system access must govern what those assistants receive, not only what they produce.

AI-Discovered Vulnerabilities

AI accelerates discovery — in Redis, OpenSSL, FFmpeg, and beyond

SignalHighDiscovery Compression

The period included confirmed and reported instances of AI-assisted vulnerability discovery across Redis, OpenSSL, FFmpeg, and Project Glasswing-style findings. AI-assisted discovery compresses the time between vulnerability existence and attacker awareness.

Why this matters

When discovery and weaponization move faster than organizational response, the defender advantage built into responsible disclosure erodes. Exposure validation cadence must keep pace.

03Software Supply Chain & Developer Infrastructure

Developer infrastructure is production-adjacent

Package registries, IDE extensions, GitHub workflows, CI/CD credentials, AI coding assistants, build scripts, and developer machines form one connected system. Attackers treat them as one system.

Miasma — Microsoft Repositories

Supply-chain attack reaches Azure, Azure-Samples, and MicrosoftDocs

ConfirmedHighSupply Chain

Microsoft temporarily removed repositories after a Miasma-related incident injected information-stealing logic into open-source projects. Affected repositories spanned Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations.

Why this matters

When supply-chain activity reaches major vendor repositories, ecosystem trust becomes the exposure surface. Sample code, documentation, and CI/CD workflows carry implicit authority downstream.

Hades / Shai-Hulud — PyPI

ConfirmedHigh

Python packages and wheel artifacts compromised to deliver credential-stealing behavior. Developer dependency decisions now require security controls, not only engineering convenience.

IronWorm — npm

ConfirmedHigh

Rust-based infostealer delivered via infected npm packages. A stolen developer credential can unlock repositories, cloud environments, and CI/CD pipelines. Treat developer credential theft as a serious enterprise event.

Arch Linux AUR — 400+ packages

ConfirmedHigh

400+ AUR packages hijacked to install a Rust credential stealer with eBPF rootkit capability when elevated privileges were available. Community repositories are part of the real supply chain.

npm 12 — install scripts off by default

DefensiveHigh

GitHub announced npm 12 will require explicit opt-in before dependency install scripts execute. A meaningful ecosystem control change — acknowledges that automatic lifecycle execution has become a primary abuse path.

VS Code — extension update delay

DefensiveMed

VS Code introduced a delay before automatic extension updates to reduce exposure to compromised extensions. Extensions sit close to code, terminals, credentials, and cloud tooling — update speed must be balanced against supply-chain risk.

Claude Code GitHub Action flaw

ConfirmedHigh

A flaw in a Claude Code GitHub Action reportedly allowed a malicious issue to influence workflows and create a path to repository compromise. AI coding agents inside CI/CD require stronger trust boundaries; issues and error reports are inputs to automated decision-making.

OpenAI Codex UI supply-chain attack

ConfirmedHigh

A legitimate-looking npm package associated with a Codex remote web UI attracted significant downloads while stealing authentication tokens. Attackers are targeting the convenience layer around AI tools: fake helpers, fake UIs, unofficial packages. Installation trust is now part of AI security.

04Edge, VPN & Control-Plane Exploitation

Nine control-plane platforms under active pressure

VPN, SD-WAN, backup, observability, ITSM, file transfer, ERP, and mobile gateways all appeared. These platforms hold administrative reach, trusted network position, and recovery authority. Compromise here travels far.

Oracle PeopleSoft · ShinyHunters

ERP zero-day exploited — universities and institutions targeted

ConfirmedHighCVE-2026-35273CISA KEV

Oracle PeopleSoft was exploited in data-theft attacks attributed to ShinyHunters / UNC6240, with universities heavily affected. Google confirmation and additional reporting strengthened the signal. Oracle released mitigation guidance.

Why this matters

ERP systems carry institutional data, process context, and operational intelligence. Compromise here is both a data breach and an intelligence operation — attackers leave understanding how the organization works.

Check Point VPN — Qilin ransomware

ConfirmedHighCVE-2026-50751CISA KEV

Critical Remote Access VPN / Mobile Access flaw exploited; linked to Qilin ransomware activity. VPN compromise turns an external attacker into an internal operator. Emergency response capability is required the moment exploitation is confirmed.

Cisco Catalyst SD-WAN Manager

ConfirmedHighCVE-2026-20245CISA KEV

Active exploitation with no patch initially available; mitigations required. SD-WAN management is the control plane for distributed enterprise connectivity. Exploitation threatens routing, management, and operational trust across every connected location.

Ivanti Sentry — mobile gateway

ConfirmedHigh

Maximum-severity flaw enabling root code execution on exposed mobile gateways. Mobile gateways sit between devices, identity, and enterprise services. Root-level compromise at this layer has control-plane consequences across the mobile estate.

ServiceNow — customer instances

ConfirmedHigh

ServiceNow disclosed exploitation against some customer instances. ServiceNow carries operational knowledge: assets, incidents, changes, approvals, and users. Unauthorized access exposes how the enterprise operates and responds.

Splunk Enterprise

ConfirmedHighCVE-2026-20253

Critical flaw allowing unauthenticated file operations and potential remote code execution. Observability platforms aggregate logs, telemetry, and security context. Compromise of the observer weakens detection and investigation across the board.

Veeam Backup & Replication

ConfirmedHighCVE-2026-44963

RCE by an authenticated domain user on the backup server. Backup systems are central to ransomware resilience. A compromise path into backup infrastructure directly affects recovery confidence — the safety net has a vulnerability.

SolarWinds Serv-U

ConfirmedHighCVE-2026-28318CISA KEV

CISA added this to KEV after confirmed exploitation. File-transfer infrastructure is exposed, trusted, and connected to sensitive partner workflows. It remains a recurring attacker target for consistent operational reasons.

HTTP/2 Bomb — DoS at protocol layer

WatchHigh

Remote denial-of-service technique affecting default HTTP/2 configurations across NGINX, Apache HTTPD, IIS, Envoy, and Cloudflare Pingora. HTTP/2 is embedded in the availability surface for web servers, APIs, proxies, and cloud-facing ingress.

05Identity, Collaboration & Trusted Workflow Abuse

Six routes to enterprise compromise — no malware required

Tokens, support workflows, mobile behavior, messaging, URI handlers, and executive mailboxes. The pattern: obtain trusted access, then operate inside normal systems without raising alarms.

Microsoft 365 Android — token exposure

ConfirmedHigh

A development flag left enabled allowed other apps on the same Android device to request signed-in Microsoft account tokens. A valid token provides direct access to email, files, calendar, and collaboration data — with no password prompt required. Token governance requires the same seriousness as password governance.

Meta AI support — Instagram account takeovers

ConfirmedMed–High

Attackers abused Meta’s AI-powered support workflow to take over high-profile Instagram accounts. When AI support workflows can be manipulated, the recovery layer becomes a route to takeover — the system designed to restore access enables unauthorized access.

Tchap — 73,000 French government accounts

ConfirmedHigh

A breach of France’s Tchap encrypted messaging platform affected over 73,000 public-sector accounts. Government collaboration systems carry identity, coordination, and operational context — they require governance equal to any sensitive enterprise platform.

Exchange Server OWA — actively exploited

ConfirmedHighCVE-2026-42897CISA KEV

Exploited OWA flaw in on-prem Exchange. On-premises Exchange remains identity-integrated and operationally connected. Residual exposure in under-maintained deployments continues to create enterprise risk at scale.

Windows Search URI — NTLMv2 hash leak

Public ResearchMed

Unpatched URI handler issue leaks Net-NTLMv2 hashes to attacker-controlled SMB paths. In NTLM-heavy networks, relay opportunities can convert a moderate identity exposure into a meaningful compromise path through trusted OS behavior.

Stock exchange executive mailbox — months-long access

ConfirmedHigh

Attackers maintained access to a senior executive’s Outlook mailbox for months, exfiltrating data in small batches through trusted cloud services. Executive mailbox access exposes strategy, deal flow, regulatory communication, credential reset paths, and market-sensitive intelligence.

06Critical Infrastructure, Nation-State & Reconnaissance

Patient, persistent actors — durable access as the objective

Activity continued against government, telecom, energy, military, academic, and public-sector environments. The method: durable access through identity systems, appliances, trusted software, and reconnaissance infrastructure — then wait.

JDY botnet — 1,500+ devices, China-linked

ConfirmedHigh

China-linked JDY botnet expanded to over 1,500 SOHO and IoT devices operating as a high-performance scanner for exposed services. Continuous infrastructure mapping at this scale gives attackers a strategic view of enterprise exposure before selecting targets.

Fuel tank monitoring — government warning

ConfirmedHigh

U.S. agencies warned that internet-exposed automatic tank gauges were being targeted. Critical infrastructure does not always fail through sophisticated malware. It can fail through unmanaged exposure of ordinary internet-connected operational systems.

Chinese authentication-stack persistence

ConfirmedHigh

Reported long-term access maintained by compromising authentication stack components — giving attackers visibility into administrative activity over an extended period. If authentication components are compromised, attacker activity can appear operationally legitimate indefinitely.

Velvet Ant — Linux PAM and OpenSSH backdoor

ConfirmedHigh

A China-linked actor backdoored Linux PAM and OpenSSH components to maintain access over many years. Authentication components require integrity monitoring and rebuild discipline. Availability alone is insufficient when the login path itself may be altered.

Gamaredon — WinRAR exploitation

ConfirmedHighCVE-2025-8088CISA KEV

Russia-aligned groups continued exploiting a WinRAR path-traversal flaw against Ukrainian organizations. Older exploited vulnerabilities remain operationally useful when archive workflows, removable media, and network shares continue to support delivery.

Dragon Weave — Czech Republic, Taiwan

ConfirmedHigh

China-aligned activity targeting officials and citizens via spear-phishing and AdaptixC2 delivery. Geopolitical targeting continues to rely on practical delivery mechanics — phishing, archives, and adapted commodity tooling.

VerdantBamboo — Linux appliance backdoors

ConfirmedHigh

China-nexus espionage cluster deployed backdoors against Linux and BSD-like appliance environments. Appliances are under-inventoried, difficult to rebuild cleanly, and operate with trusted network position — making them attractive long-term footholds.

07Signals & Patterns

Six patterns that defined the first half of June

1

The discovery-to-exploitation buffer is shrinking AI-assisted discovery, public exploit logic, active exploitation, and KEV movement point to a shorter operational window. Vulnerability management must be tied to exposure, asset criticality, and exploitation status — not only CVSS scores.

2

Developer infrastructure has production-level risk exposure npm, PyPI, AUR, GitHub repositories, VS Code, Claude Code, and Codex tooling all appeared in the same fortnight. The developer environment carries credentials, build authority, and deployment influence. It requires production-grade protection.

3

AI agents expand the instruction surface beyond the agent itself Agentjacking, OpenClaw manipulation, Gemini notification hijacking, and Claude Code workflow concerns show that context consumed by an agent is a security boundary. Governance must cover inputs, permissions, execution rights, and connected tools.

4

Control planes are under direct, sustained pressure VPN, SD-WAN, backup, observability, ITSM, ERP, mobile gateway, and file-transfer platforms appeared across the June intake. These platforms require privileged-access discipline, exposure review, and executive escalation paths.

5

Identity exposure is the preferred first move Tokens, AI support abuse, collaboration platform compromise, URI-handler NTLM leakage, and long-term authentication-stack persistence all share the same logic: trusted access travels farther and quieter than malware.

6

Public exploitability requires emergency operations — not patch cycles KEV-class exposure, no-patch mitigations, and public PoCs require pre-built emergency workflows. The decision path must be known and authorized before the vulnerability arrives.

08Defender Actions

Eight actions for executive and security leadership

01

Pre-authorize 12-hour and 72-hour response paths

Establish pre-authorized escalation for KEV, VPN, identity-layer, and actively exploited flaws: 12 hours for internet-facing exposure; 72 hours for high-impact control-plane systems. Define validation, compensating controls, approval, testing, rollback, and executive escalation before the next incident — not during it.

02

Treat AI infrastructure as production infrastructure

Inventory LiteLLM, Langflow, agent frameworks, model gateways, vector databases, and AI development servers. Apply patching, authentication, segmentation, logging, backup, and monitoring expectations consistent with other production systems — not with experimental tooling.

03

Govern agentic coding tools explicitly

Inventory Claude Code, Codex, Copilot, Cursor, GitHub Actions integrations, MCP servers, and IDE plugins. Define what each can read, write, execute, and access. Separate experimentation from production repositories and credentials. Absence of a policy is a policy — a permissive one.

04

Protect developer workstations as production-adjacent

Enforce EDR, secrets scanning, browser hardening, repository access review, token hygiene, and package-install monitoring. Maintain hard separation between personal, development, staging, and production credentials. Developer machines carry production-level authority.

05

Move package execution to explicit trust

Package lifecycle scripts, build hooks, and post-install behavior require governance. Disable automatic execution where possible; move to explicit allow-listing for trusted packages, trusted maintainers, and controlled build contexts. npm 12’s default is the right model.

06

Reclassify control-plane platforms as tier-one assets

VPN, SD-WAN, backup, observability, ITSM, ERP, file-transfer, and mobile-gateway platforms require privileged-access controls, exposure review, emergency patching, configuration baselines, and dedicated monitoring — equivalent to Active Directory and identity infrastructure.

07

Monitor tokens with the discipline applied to passwords

OAuth tokens, mobile app tokens, GitHub tokens, npm tokens, cloud API keys, service principals, and session cookies must be logged, reviewed, and rotated based on risk. Track issuance, use, refresh, source application, geography, privilege level, and abnormal behavior.

08

Preserve credibility by separating confirmed from claimed

Confirmed exploitation, vendor advisories, and KEV entries must remain separate from threat-actor claims, leak-site posts, and social-media assertions. This discipline protects decision quality. Conflating the two degrades the signal value of every future alert.

09Closing Note

The operating model is under pressure. AI is shortening cycles. Agents are expanding reach. Supply chains are propagating attacks. Control planes are attracting the most serious attention. Identity gives attackers a cleaner, quieter path than malware ever did.

The lesson is direct. Risk is moving faster than governance was built to move.

Boards don’t need volume. They need clear decision authority, fast exposure triage, ownership with accountability, and hard separation between confirmed fact and unverified claim.

The organizations that adapt are not the ones chasing headlines. They are the ones that know: which systems own the business, which exposures demand immediate action, who decides, and how fast the enterprise can move.

About The Signal Watchtower

Published by Elytra Security, creators of Threat Lens. Signal-only threat intelligence across security, privacy, and AI — confirmed facts kept rigorously separate from claims.

Authored by Venkat Mangudi · Founder & CEO, Elytra Security

Integrity. Trust. Clarity.

An ISO/IEC 27001:2022 Certified Company


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading