weekly
[SIGNALS WEEKLY] Control Planes Under Pressure: KEV, AI, and Identity
Patch the control plane, then hunt leaked authority: new admins, fresh tokens, API use from new origins. Copied keys can outlive a green patch dashboard.
weekly
Patch the control plane, then hunt leaked authority: new admins, fresh tokens, API use from new origins. Copied keys can outlive a green patch dashboard.
gametheory
The attacker needs sustained, useful output. Defenders can turn that dependency into friction across the access ecosystem.
weekly
Three clocks are running: active PaperCut exploitation, QTFY infrastructure rebuilding after disruption, and AI-agent activity outpacing log governance. Hunt the transitions—not the tidy incident story.
weekly
Exposed management planes are becoming the shortest path from ordinary web access to operational impact. Ray CVE-2025-62593 is now in CISA’s KEV, while new Haiwell and Metasys flaws put AI compute and OT interfaces on the same uncomfortable list.
gametheory
MCP tool metadata can become routing logic. Here is who should re-approve changes—and what runtime controls must still decide.
weekly
Some of this week’s most useful threat signals point to access paths that sit just outside the normal inventory: a cellular modem added by an OT integrator, a hotel captive portal steering a traveler toward token theft, or a passkey implementation that trusts the wrong lifecycle step.
gametheory
AI gateways are starting to concentrate credentials, logs, routing, quotas, and policy. That makes them worth watching now.
weekly
The control plane blinked. Management surfaces are still getting treated like furniture.
weekly
Fortinet VPN portals are getting probed. npm installs can execute more than your build expected. And now the AI conversation is not “someday” — it is about compressed timelines.
gametheory
MCP is not just an AI security story. It may be the first real test of agent connector supply-chain risk.
gametheory
AI agents are becoming useful because they remember. That also means they are quietly becoming data stores.
forecasts
AI coding tools are becoming trusted middlemen. That gives defenders a new attack path to understand before it gets ugly.