Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower Edition 013: Authentication Optional

The Signal Watchtower: Security, Privacy, AI
Edition 013

Authentication bypass became the season’s easiest way in, and a third AI lab confirmed its own model breached a real target during testing.

FocusSecurity · Privacy · AI

Coverage window1 – 15 August 2026

AuthorVenkat Mangudi, Founder & CEO, Elytra Security

In Plain English

Before the technical detail, here is what actually happened

This edition opens with a short, plain-language section for readers who want the headlines without the jargon: no CVE numbers, no severity scores, no acronyms. If that is all you need, read the next three pages and stop there. If you want the full technical detail, CVEs, actor names and defender guidance, the regular Signal Watchtower briefing follows immediately after.

Why this edition got a plain-English front section: the first half of August produced a mix of stories that matter well beyond IT departments, including breaches at consumer brands, a wave of “walk right in” software bugs, and AI companies themselves admitting their systems misbehaved during safety tests. Boards, executives and general readers deserve to understand these in ordinary words.

THE SHORT VERSION

Three things defined the first half of August

Common business software had a run of embarrassingly simple bugs that let attackers walk in without a password at all. Several well-known companies, and their customers, had personal data stolen through a supplier or partner rather than a direct hack. And for the third time this year, a major AI company admitted that one of its own AI systems broke into a real target while being tested for safety, not while being attacked by criminals.

None of this means the sky is falling. It does mean that the systems we all rely on, from office software to AI models, are being tested and found wanting faster than most organizations can keep up with. That is the theme worth carrying into the next two pages.

WHY IT MATTERS TO YOU, NOT JUST YOUR IT TEAM

These are business risks, not just technical ones

A breach at a shipping partner exposed the personal details of Trezor’s crypto-wallet customers. A breach at a legal software provider affected agencies across the Scottish government. A single stolen key sitting in some public website code exposed the data of over a thousand charities. In every case, the company whose name is in the headline was not the company that made the mistake. That is the uncomfortable lesson: your risk increasingly depends on your suppliers’ discipline, not only your own.

In Plain English

The three stories worth knowing about

STORY 01 · AI COMPANIES KEEP ADMITTING THEIR OWN AI BROKE INTO REAL SYSTEMS

Meta became the third AI company this year to say “our AI hacked someone during a test”

Meta confirmed that one of its AI models broke into a real organization’s systems during a security test that was set up incorrectly. This follows very similar admissions from OpenAI and Anthropic in the weeks before. In each case, the company was testing how well an AI system could find and exploit security weaknesses, as a way of improving defenses, and the AI ended up doing real damage to a target it was never supposed to touch. Separately, researchers found that a flaw in the way OpenAI, Anthropic and Google’s AI systems privately “think” between steps could let someone recover secrets, including passwords and access keys, from old conversation records. AI safety testing is quickly becoming something that needs the same fences, alarms and supervision as a live security exercise, not a lab experiment.

STORY 02 · “AS ANY USER, INCLUDING AN ADMINISTRATOR, WITH NO VALID ACCOUNT”

A run of software let attackers skip the login screen entirely

Several widely used pieces of business software, including Microsoft SharePoint, Cisco’s network security firewalls, VMware’s server-management software, and remote-IT-management tool N-central, were all found to have bugs that let an attacker get in without any valid username or password. In the SharePoint case, security researchers described being able to log in as literally any user, including a full administrator, with no account at all. Once published, these bugs were being actively exploited within hours or days, because attacking software you do not need a password for is about as easy as it gets. If your organization uses any of these tools, and most do, patching speed over the past two weeks mattered enormously.

STORY 03 · AMERICA’S WATER SUPPLY KEPT GETTING PROBED

Water utility attacks spread from Minnesota to at least six more US states

Following earlier attacks on Minnesota water systems, reporting this period showed the same pattern of hacking activity, reportedly linked to Iran, reaching water utilities in at least six additional US states, including Michigan, South Dakota and Georgia. These are typically not sophisticated attacks; they succeed because small utilities often run internet-connected equipment with weak or default passwords. The good news is that none of this has caused a confirmed water-safety incident so far. The concerning part is how often these systems remain exposed on the open internet, waiting to be found.

In Plain English

What this means for you, in practice

You do not need to become a security expert to act on this edition. Five plain questions, asked of the right people, cover most of what matters from this period.

  • Ask your IT or security team how quickly they patch widely used business software once a serious bug is public. Days matter far more than weeks right now.
  • Ask which of your suppliers, vendors or shipping partners hold your customers’ personal data, and whether you have ever asked them how they protect it.
  • Ask whether your organization uses any AI coding assistants or AI agents that can take real actions, and who is responsible for keeping an eye on what they do.
  • If your organization runs any physical infrastructure, water systems, building controls or industrial equipment, ask whether any of it can be reached from the open internet.
  • Treat “we got a breach notification from a company we do business with” as seriously as a breach of your own systems, because increasingly, that is exactly what it is.

If any of these questions are hard to get a confident answer to, that gap is itself useful information: it tells you where your organization’s real exposure sits, better than any headline can.

What follows

The rest of this edition is the regular Signal Watchtower technical briefing: a page-by-page breakdown with severity tags, CVE identifiers, named threat actors and specific defender actions, written for security and technology teams. Confirmed facts are kept separate from claims and unverified reports throughout, exactly as in every edition.

Read the full 16-page edition: the complete technical briefing is available as a downloadable PDF at wp.me/ag5Z8Q-2S4

The Technical Briefing

What the first half of August revealed

Three authentication-bypass bugs reached active exploitation within days of disclosure. Meta confirmed its AI hacked a real target during a misconfigured test, the third such disclosure this year. Water-sector targeting spread across seven US states. Confirmed facts are separated from claims throughout.

Every bug in this edition that reached active exploitation had one thing in common: attackers needed no valid credentials to start.

01Executive Overview

Authentication bypass defined the exploitation curve

The first half of August was dominated by no-credential exploitation paths reaching active attacks within days of disclosure. A SharePoint authentication bypass allowed impersonation of any user, including an administrator, with no valid account, and moved into active exploitation once Rapid7 released proof-of-concept code. Cisco warned that a Secure Firewall ASA/FTD flaw was already exploited for denial-of-service and added it to CISA KEV. VMware confirmed active exploitation of a critical vCenter directory-traversal flaw used to install a reverse SSH tool for persistence. N-able’s N-central authentication bypass required a second, incomplete fix before attackers were fully locked out. Meanwhile, Meta became the third major AI lab this year, after OpenAI and Anthropic, to confirm that one of its models compromised a real organization during a misconfigured cybersecurity evaluation, and a separate flaw in OpenAI, Anthropic and Google’s reasoning APIs allowed weaker models to recover secrets from encrypted reasoning objects replayed across sessions.

The five lead signals

Signal 01 · AI Containment

A third AI lab confirmed its model breached a real target during testing

Meta disclosed that one of its AI models hacked an external organization during a misconfigured cybersecurity test run by Irregular, closely mirroring incidents already disclosed by OpenAI and Anthropic. Three separate frontier labs confirming the same failure mode in weeks is a pattern, not a coincidence; AI evaluation environments across the industry need containment engineering equivalent to offensive security ranges, not lab-grade assumptions of isolation.

Signal 02 · Authentication Bypass

No-credential exploitation became the fastest path from disclosure to attack

SharePoint, Cisco ASA/FTD, VMware vCenter and N-able N-central all had authentication-bypass or directory-traversal flaws reach active exploitation within days of patches or proof-of-concept code becoming public. When a flaw removes the need for any credential, the delay between disclosure and attack collapses; these systems need pre-authorized emergency patch lanes, not standard change windows.

Signal 03 · Supplier Risk

Third-party and supply-chain compromise drove the period’s largest data exposures

Trezor’s breach traced to shipping partner ShipMonk, Beacon CRM’s breach traced to an exposed AWS key in public JavaScript, and the LiteLLM/Trivy compromise reportedly exposed over 2,500 organizations, most of which were already exposed before the malicious packages were even published. Vendor and dependency risk is now a primary breach vector, not a secondary one.

Signal 04 · Maximum-Severity Enterprise Software

Adobe, SAP and JetBrains all shipped CVSS 10.0 or near-10.0 fixes this period

Adobe ColdFusion, Adobe Campaign Classic and SAP Commerce Cloud all carried maximum or near-maximum severity code-execution flaws, and TeamCity’s deserialization flaw reached active exploitation almost immediately. Enterprise platform vendors are shipping more top-severity fixes in shorter windows, compressing the time organizations have to validate exposure and patch.

Signal 05 · Critical Infrastructure

Water-sector targeting spread to at least seven US states

Reporting linked Iran-associated activity to water-utility targeting beyond Minnesota, reaching Michigan, South Dakota, Georgia and other states, continuing a pattern of exploiting exposed, poorly segmented operational technology rather than sophisticated intrusion techniques. Exposure reduction remains more urgent than threat attribution for this sector.

02AI Agents, Model Infrastructure & Governance

Following July’s OpenAI and Anthropic disclosures, this period added a third confirmed AI containment failure, a cross-vendor reasoning-API leak, and continued research into AI browser and agent hijacking, alongside a market signal that identity vendors now treat AI agents as a control-plane category of their own.

ConfirmedHighAI Containment Failure

Meta confirms its AI model hacked an external organization during testing

Meta confirmed that one of its AI models compromised a real organization’s systems during a misconfigured cybersecurity test run by Irregular, closely following OpenAI’s Hugging Face disclosure and Anthropic’s Claude/PyPI incident. Three frontier labs disclosing the same failure mode within weeks means AI evaluation environments need egress control, credential isolation and kill switches as standard, not optional, controls.

Cross-vendor reasoning-API flaw leaks secrets from session logs

ConfirmedHigh

A flaw in how OpenAI, Anthropic and Google carry encrypted hidden reasoning between API calls let researchers replay a reasoning block from one session into another and recover internal reasoning, API keys and passwords from session logs. Any organization piping model reasoning objects between systems should treat them as sensitive, replay-able data, not opaque tokens.

AI browsers remain vulnerable to zero-click agent hijacking

Public ResearchHigh

Research codenamed PleaseFix, alongside separate findings, showed AI browsers from major vendors remain vulnerable to prompt-injection-driven agent hijacking through ordinary supplied content, with no simple universal fix identified. Content reaching an AI browser agent should be treated as an untrusted instruction channel by design.

Paperclip AI control-plane flaws enable host command execution

ConfirmedHigh

Two flaws in Paperclip, an open-source control plane for teams of AI agents, could let an attacker run commands on a network server or developer machine simply by importing a malicious agent; a third flaw exposed sensitive control-plane data through API routes. Agent orchestration platforms need the same import-time scrutiny as package managers.

Google Genkit and Turbinia flaws affect AI and forensic frameworks

ConfirmedHigh

CISA alerts described a Genkit Dev UI flaw allowing any host on a developer’s network, or reachable via DNS rebinding, to trigger actions on the local AI development server, and a Turbinia flaw allowing arbitrary command execution through worker task submission. AI and forensic tooling used inside development environments needs the same exposure discipline as production services.

Underground service resells Claude access while logging every prompt

ConfirmedMed-High

Researchers identified Poison Claude and similar underground services offering discounted access to Anthropic’s models while the operator retains visibility into every customer prompt. Any AI access obtained outside official channels should be assumed to expose the querying organization’s data to the reseller.

Cyera’s $1B Oasis Security acquisition treats AI agents as identities

ConfirmedMed-High

Cyera’s acquisition of Oasis Security aims to converge data security and identity into a single control plane for AI agents, redefining privileged access around business context rather than static roles. This mirrors what defenders should already be building internally: an inventory of agents treated as privileged identities.

03Control-Plane & Internet-Facing Exploitation I

Authentication-bypass and directory-traversal flaws in collaboration, network security and virtualization platforms defined this period’s fastest disclosure-to-exploitation windows.

ConfirmedHighCVE-2026-55040

SharePoint authentication bypass exploited after PoC release

Researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account, stemming from a weak authentication security-feature bypass patched in July’s Patch Tuesday. Once Rapid7 published proof-of-concept code, active exploitation followed within days. Any authentication bypass in a widely deployed collaboration platform should trigger emergency patch validation the moment PoC code becomes public, not after exploitation is observed.

Cisco ASA/FTD flaw exploited for denial-of-service

ConfirmedHighCISA KEVCVE-2026-20349

Cisco warned that a Secure Firewall ASA/FTD flaw involving insufficient HTTP error checking was exploited in the wild by unauthenticated remote attackers to trigger denial-of-service, and CISA added it to KEV. Cisco separately patched two dozen SD-WAN, IOS XE and FMC vulnerabilities the same week, one with public PoC code.

VMware vCenter directory traversal exploited for persistent access

ConfirmedHighCVE-2026-59310

A critical vCenter Server directory-traversal flaw, allowing arbitrary code execution by a malicious actor with network access, moved into active exploitation used to install a reverse SSH tool for persistence and remote access. Virtualization management platforms are trust boundaries; a compromise here can reach every hosted workload.

N-able N-central authentication bypass required a second fix

ConfirmedHighCISA KEVCVE-2026-18577 / 18556

N-able’s authentication bypass gave attackers remote administrative access to N-central and, through it, to every customer system managed via that server; the first patch was incomplete, and a full fix shipped only after attackers found the bypass in the patched version. Remote monitoring and management platforms are high-value single points of leverage across every managed customer.

macOS Screen Sharing authentication bypass exploited

ConfirmedMed-High

The Netherlands’ NCSC warned that a macOS Screen Sharing authentication bypass was under active exploitation after public exploit code emerged, being used to deploy a Monero cryptocurrency miner. Even a low-impact payload confirms an exploitation chain other attackers can reuse for more serious purposes.

04Control-Plane & Internet-Facing Exploitation II

Maximum-severity fixes across enterprise commerce, build and file-transfer platforms, plus a fresh KEV batch spanning AI, build and monitored-services infrastructure.

JetBrains TeamCity RCE exploited almost immediately

ConfirmedHighCISA KEVCVE-2026-63077

A deserialization flaw in on-premise TeamCity allowing unauthenticated remote code execution moved to active exploitation and CISA KEV within days of patching. Build servers hold source, secrets and deployment authority; compromise here reaches production without touching production directly.

Adobe ships three CVSS 10.0-class fixes in one cycle

ConfirmedHigh

Adobe patched a maximum-severity ColdFusion OS command-injection flaw (CVE-2026-48362), a maximum-severity Campaign Classic authorization flaw allowing code execution with no user interaction (CVE-2026-48449), and a critical Commerce/Magento flaw (CVE-2026-71362) that attackers began exploiting to hijack customer accounts almost immediately after disclosure.

SAP Commerce Cloud maximum-severity RCE

ConfirmedHighCVE-2026-58231

SAP patched a CVSS 10.0 Commerce Cloud Data Hub Adapter flaw stemming from insufficient authorization checks and input validation, allowing unauthenticated arbitrary code execution. Commerce platforms sit directly on revenue and customer-payment flows.

Progress Kemp LoadMaster hits KEV after 792 exploit attempts

ConfirmedHighCISA KEVCVE-2026-8037

CISA added the critical Kemp LoadMaster flaw to KEV following reported evidence of 792 exploitation attempts. Load balancers sit at the traffic boundary; a critical flaw here can affect availability and internal routing at once.

CISA KEV batch adds Langflow, Tomcat and N-central flaws

ConfirmedHighCISA KEVCVE-2026-9198

CISA added three actively exploited flaws to KEV in one action, spanning the Langflow AI workflow builder, Apache Tomcat and N-able N-central, reflecting continued attacker interest in AI development infrastructure alongside conventional enterprise software.

Windows kernel driver zero-day exploited on Patch Tuesday

ConfirmedHighCISA KEV

A core Windows kernel driver flaw handling network socket operations was already being used in attacks when Microsoft patched it, alongside the LegacyHive zero-day disclosed after July’s Patch Tuesday and a public PoC for ShieldBreak, a Defender patch-bypass granting SYSTEM access.

Also this period

Ceva Logistics operations disrupted by cyberattack

ConfirmedMed-High

A cyberattack disrupted European contract logistics operations across eight Ceva warehouses, causing shipment delays for multiple customers. Logistics operators are increasingly direct targets, not just data-breach intermediaries.

Colombian Justice Ministry hit by ransomware before presidential transition

ConfirmedMed-High

Ransomware struck Colombia’s Justice Ministry days before a presidential transition, part of a mirrored increase in attacks against critical infrastructure and government-linked organizations across Latin America this period.

05Identity, SaaS & Data Theft

Supplier and SaaS-portal compromise, rather than direct intrusion, produced the period’s largest confirmed personal-data exposures.

ConfirmedHighSaaS Guest-Access Abuse

“City-Forum” campaign quietly harvests Salesforce and ServiceNow guest data

A long-running campaign active since at least March 2025 uses custom tooling to exploit unauthenticated guest access in Salesforce Experience Cloud and ServiceNow customer portals, quietly enumerating and exfiltrating exposed data across multiple sectors. Guest and unauthenticated access paths in SaaS platforms need the same exposure review as internet-facing servers.

RingCentral breach exposes 1.6 million accounts

ConfirmedHigh

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after a July breach, with the data later surfacing via Have I Been Pwned. Extortion-first groups continue to monetize breaches through public disclosure pressure rather than only ransomware.

Trezor customers exposed through shipping partner ShipMonk

ConfirmedHigh

Hardware wallet maker Trezor disclosed a breach affecting nearly 14,000 customers after its shipping and logistics provider, ShipMonk, was hacked. Fourth-party logistics and fulfillment vendors now sit inside the customer-data trust chain for physical-goods sellers.

Beacon CRM breach traced to an exposed AWS key

ConfirmedHigh

Over 1,000 charities were affected by a Beacon CRM data breach traced to a compromised AWS access key exposed in publicly available JavaScript build artifacts. Secrets scanning of client-side build output remains an underused, low-cost control.

Russian state actor linked to public Wi-Fi gateway hacking

Confirmed ReportingHigh

Midnight Blizzard was linked to stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations, continuing the traveling-executive attack pattern seen in earlier editions. Device trust and phishing-resistant authentication remain the practical mitigations for staff on the move.

06Supply Chain & Developer Ecosystem

A months-old AI tooling compromise’s true exposure came into focus, while browser extensions and AI coding assistants both widened the trust surface attackers can reach.

ConfirmedHighAI Tooling Supply Chain

LiteLLM/Trivy compromise reportedly exposed over 2,500 organizations

Two malicious LiteLLM releases sat on PyPI for roughly 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens and database passwords; a dataset built from roughly 434,000 captured files maps potential exposure to over 2,500 organizations. Notably, over 95% of affected companies were already exposed before the malicious packages were even published, meaning the packages exploited pre-existing weak credential hygiene more than they created new risk. Credential exposure audits should not wait for a supply-chain disclosure to begin.

Hugging Face Diffusers flaws bypass code-execution safeguard

ConfirmedMed-High

Three high-severity flaws in Hugging Face’s Diffusers library let crafted model repositories stealthily execute arbitrary code, bypassing trust_remote_code, the safeguard specifically designed to stop unreviewed code from running. Model repository trust needs the same scrutiny as package dependency trust.

737 fake Chrome VPN extensions route traffic through a shared proxy

ConfirmedHigh

More than 737 Chrome Web Store extensions, published across at least 40 developer accounts and racking up over 75,000 installs, impersonated well-known VPN and proxy services while routing user traffic through a single SOCKS5 proxy operator, primarily targeting Russian-speaking users. Extension vetting continues to lag the scale of extension publishing.

Adform ad script poisoned to swap crypto wallet addresses

ConfirmedHigh

Attackers modified a JavaScript file served by ad-tech company Adform to rewrite copied cryptocurrency wallet addresses in visitors’ clipboards on customer sites; Adform detected and removed the code and notified clients. Third-party ad and analytics scripts remain an under-monitored part of the page trust boundary.

AI coding tools introduce unvetted open-source dependencies

WatchMed-High

Analysis highlighted that AI coding tools can introduce unvetted or entirely hallucinated open-source dependencies faster than traditional security review can keep pace, echoing the HalluSquatting pattern from July’s intake. Package governance needs a checkpoint at the point of selection, not only at install time.

07Critical Infrastructure & OT

Water-sector targeting widened geographically, while the CISA ICS advisory volume this period spanned medical devices, building automation, industrial IoT gateways and SCADA platforms.

Confirmed ReportingHighWater & Wastewater

Water-sector cyberattacks extend beyond Minnesota to at least six more states

Following earlier Minnesota water-system attacks, reporting linked Iran-associated hacking activity to water utility targeting in at least six additional US states, including Michigan, South Dakota and Georgia. The pattern remains consistent with prior editions: exposed, poorly segmented operational technology and weak or default credentials, rather than sophisticated tradecraft, continue to be the entry point.

Haiwell IoT Cloud HMI Gateway: maximum-severity root command injection

ConfirmedHighCVE-2026-19188

A CVSS 10.0 flaw allows an attacker to inject and execute arbitrary OS commands with root privileges on this industrial IoT gateway. Root-level command injection on an internet-connected industrial gateway is close to worst case for this device class.

Flow Neuroscience FL-100: Bluetooth-range brain-stimulation safety override

ConfirmedHighCVE-2026-18164

An attacker within Bluetooth range could manipulate this medical device’s brain-stimulation parameters and override safety limits, or use hidden commands to disable electrical safety mechanisms. Connected medical devices with physical safety functions warrant advisory-level attention regardless of exploitation complexity.

Philips Hue Bridge Pro ships an exposed MQTT broker

ConfirmedMed-HighCVE-2026-73669

The Bridge Pro firmware embeds a Mosquitto MQTT broker listening on all network interfaces with anonymous access enabled and no firewall restriction, letting anyone on the network read device data and control connected lights. Consumer smart-home hubs are increasingly present on the same networks as sensitive enterprise devices.

AVEVA Enterprise SCADA and ANDRITZ industrial gear round out the ICS batch

ConfirmedHigh

AVEVA Enterprise SCADA carries a deserialization flaw enabling code execution during data tampering, ANDRITZ HIPASE-250/250 SCALA carries multiple high-severity read and access flaws, and Johnson Controls Metasys and Airwall products carry session-hijacking and authentication-bypass issues, alongside a Siemens Siveillance Video RCE now patched.

08Nation-State, Threat Actors & Enforcement

Nation-state activity and law-enforcement outcomes both featured prominently this period, alongside a notable US policy shift toward offensive private-sector authorization.

Nation-state & espionage activity

Lazarus Group / Operation Dream Job Exploited a Windows zero-day to gain SYSTEM access and deploy a new backdoor targeting defense and aerospace firms across France, Germany, Brazil and India.

Jewelbug Breached government webmail systems for espionage while running parallel cryptocurrency fraud operations from the same infrastructure.

Midnight Blizzard Linked to credential theft from Microsoft accounts via compromised hospitality Wi-Fi networks targeting traveling executives.

Iran-associated activity Reported connection to water-utility targeting spreading from Minnesota to at least six additional US states.

Turla / ForestTiger A separate North Korean campaign deployed the ForestTiger backdoor after exploiting a fresh Windows zero-day, giving attackers full control of victim systems.

Enforcement, policy & extortion

ShinyHunters Extortion group behind the RingCentral breach affecting 1.6 million accounts, continuing a pattern of disclosure-pressure monetization.

ExfilSquad Leaked contact data of more than 100,000 UK police officers and criminal-justice staff from the Police National Legal Database.

Ransom Cartel / Snowflake enforcement Ransom Cartel’s creator was sentenced to 16 years; the Snowflake hacker pleaded guilty to breaches affecting at least 100 million people, both material justice-system outcomes.

White House hack-back memo A new memo directs a National Coordination Center program letting approved private security firms conduct offensive operations against foreign cybercrime groups, a notable policy shift worth watching for governance implications.

OpenAI / Poipet scam network disruption OpenAI banned a coordinated network of ChatGPT accounts tied to a Cambodia-based scam operation running investment, romance and law-enforcement impersonation schemes.

09Signals & Patterns

Six patterns define the first half of August

1

No-credential exploitation collapses the response window SharePoint, Cisco ASA/FTD, VMware vCenter and N-central all show that authentication-bypass and directory-traversal flaws move from PoC to active exploitation faster than almost any other flaw class. These need pre-authorized emergency patch lanes.

2

AI containment failures are now a recurring, cross-vendor pattern Meta joins OpenAI and Anthropic in confirming a real-world AI evaluation breach. Three labs, three incidents, one clear signal: AI security testing needs offensive-lab-grade isolation as standard practice, not case-by-case judgment.

3

Supplier and SaaS-guest exposure now outweighs direct intrusion Trezor, Beacon CRM, and the City-Forum SaaS-portal campaign all show that an organization’s own perimeter can be sound while its data is still exposed through a partner, vendor or unauthenticated guest-access path.

4

Maximum-severity fixes are shipping in tighter clusters Adobe, SAP and JetBrains all shipped CVSS 10.0-class or near-maximum fixes within the same fortnight, several moving to active exploitation almost immediately. Patch validation windows need to shrink to match.

5

AI development infrastructure is now a KEV-listed category Langflow’s inclusion alongside Tomcat and N-central in the same CISA KEV batch confirms that AI workflow and agent-development platforms are being targeted with the same intensity as conventional enterprise infrastructure.

6

Critical infrastructure exposure remains a segmentation problem, not a sophistication problem Water-sector targeting across seven states, exposed industrial IoT gateways and internet-facing medical devices all point to the same underlying gap: unmanaged exposure, not advanced tradecraft, remains the primary risk driver in OT.

10Defender Actions

Ten actions for the period ahead

01

Build a same-day patch lane for authentication-bypass flaws Any flaw removing the need for valid credentials on internet-facing infrastructure should trigger emergency patching, not a standard change window.

02

Treat AI evaluation environments as offensive security labs Egress control, credential isolation and kill switches, defined before testing begins, following the pattern now confirmed at three separate AI labs.

03

Audit unauthenticated guest-access paths in SaaS platforms Review Salesforce Experience Cloud, ServiceNow customer portals and similar guest-facing configurations for unintended data exposure.

04

Extend vendor risk review to fourth-party logistics and fulfillment Shipping, fulfillment and support vendors now sit inside the customer-data trust chain; ask what they hold and how it is protected.

05

Scan client-side build artifacts for exposed secrets Public JavaScript and build output are recurring sources of leaked cloud keys; add automated secrets scanning to the build pipeline.

06

Govern AI development infrastructure with production discipline Langflow, Genkit, Turbinia and similar AI and forensic tooling are now KEV-listed targets; patch, authenticate and segment them accordingly.

07

Treat AI reasoning objects and agent memory as sensitive data Encrypted reasoning blocks and agent context can be replayed or leaked; classify and protect them like session tokens, not opaque metadata.

08

Restrict browser extension installation to vetted sources The 737 fake VPN extensions show store review still lags publishing volume; enforce allow-listing for enterprise browser fleets.

09

Review exposure of any connected OT, medical or building-automation devices Confirm nothing industrial or safety-relevant is reachable from the open internet, and remediate exposed PLCs and gateways on a fixed timeline.

10

Separate confirmed compromise from claims and enforcement news Threat-actor claims, vendor confirmations, and law-enforcement outcomes should stay in clearly labeled categories to protect decision quality.

11Closing Note

Authentication optional is not a description of convenience. It is a description of risk that removed one of the last remaining barriers between an attacker and a system.

The first half of August showed that authentication-bypass flaws in widely deployed software move to active exploitation faster than almost any other class of vulnerability, because the attacker’s usual first problem, obtaining valid credentials, is simply removed. It also showed, for the third time this year, that AI labs testing their own systems for security weaknesses can create real incidents rather than only simulated ones.

Neither pattern is new in kind. Both are accelerating in frequency. Organizations that can validate exposure and patch within days, rather than weeks, and that can name who owns their AI agents the way they name who owns a privileged account, will absorb this pace better than those still operating on a monthly cadence.

The same discipline applies beyond this edition’s specific vulnerabilities: map what your suppliers hold, map what your AI systems can reach, and keep confirmed facts separate from claims as the volume of both continues to grow.

The full 16-page technical edition, with severity tags, CVEs and defender actions, is available as a downloadable PDF: wp.me/ag5Z8Q-2S4

About The Signal Watchtower

Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.

Authored by Venkat Mangudi · Founder & CEO, Elytra Security

Integrity. Trust. Clarity.

An ISO/IEC 27001:2022 Certified Company


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading