§ Category
Category

AC

AC

CoreBreak: Tool Execution Without a Model Turn in Three Runtimes

Four CVEs across AWS, Google, and Vercel agent runtimes converge on one authorization failure: tool execution could proceed with no trustworthy binding to a model-authorized event. Here is what the audit record shows, what the detection actually looks like in CloudWatch and Splunk, and why the Strands branch that started it all is still open.

·
AC

Valid Credentials and Overbroad Grants: Inside the Hugging Face Intrusion

Hugging Face’s July 27 timeline of the autonomous agent intrusion reads as a sequence of identity operations: node impersonation via IMDS, TokenRequest minting, an over-scoped CSI ClusterRole spent on a privileged pod, and forged tokens from a stolen EdDSA signing key. The lessons sit in key custody and least privilege, plus one correction worth stating plainly: audience binding does not contain a compromised signer.

·
AC

Gmail Content Compliance: The Audit Event Retires After August

A PRC-nexus actor exfiltrated years of medical and defense research by creating a single domain-level Gmail content compliance rule that silently BCC’d matching mail to an attacker Gmail account. It produced no endpoint telemetry and no user-visible forwarding setting, and the admin audit event family that authoritatively records it is mid-migration, with the legacy events retiring after August 2026.

·
AC

Residential Exit Nodes Your Impossible-Travel Rule May Never See

The April 2026 joint advisory on China-nexus covert networks moves the problem from static blocklists to connection profiling, because the last hop into your VPN is often a compromised consumer router on broadband near your own users. Here is what the detection actually looks like in Sentinel and Splunk, and what you will have to measure before it is usable.

·
AC

DKM: The AD FS Master Key That Decrypts Your Token Signer

CVE-2026-56155 is an overly permissive ACL on the AD FS DKM container — the object holding the key that protects your token-signing certificate. The July patch ships the fix in audit mode, so read access to a Golden SAML enabler stays open until you flip a registry key or October arrives.

·
AC

Passkey Enrollment: The Most Direct Signal Is the Registration Event

O-UNC-066 appears built to walk a victim through a fake passkey enrollment while the operator registers an attacker-controlled passkey in the real Entra tenant. It survives the password reset, and the most direct durable evidence is the authentication-method registration audit trail — written from a session your controls let through because the registration action was protected only by relayable MFA.

·
AC

msDS-SupersededManagedAccountLink, the Target-Side Write That Forges a dMSA Migration

Microsoft’s August 2025 fix for BadSuccessor (CVE-2025-53779) works — but an attacker who controls a dMSA and can write a target’s migration-link attributes can forge the mutual pairing the KDC now demands and pull that account’s Kerberos key material out of the dMSA key package. The detection has to move from watching one attribute to watching the pairing on the target object.

·
AC

CVE-2026-3055: Appliance Logs Are Not Evidence of Non-Exploitation

The NetScaler memory-overread class has a third sequel. CVE-2026-3055 leaks session tokens through an endpoint the appliance barely logs — so its own logs won’t prove you’re clean, and the detection has to move upstream to the response size and downstream to the reused token, while patching does nothing to the sessions already bled.

·
AC

The Broker Refresh Token Can Register a Device in Entra ID

Device code phishing doesn’t defeat MFA — it redirects a legitimately MFA-completed sign-in — and the naive detection drowns in legitimate CLI traffic. The durable signal is the Authentication Broker redemption and the device registration that follows, and the real fix is a Conditional Access authentication-flows block.

·