This website uses cookies

Read our Privacy policy and Terms of use for more information.

Cyber AI Chronicle
❝

Forwarded this? Project Overwatch is a weekly read for people who run security functions. The signal across cyber, AI and resilience, from someone who does the job. Subscribe here.

Simon

Table of Contents

THE SIGNAL

For four issues running, this column has been about the attacker: agents that breach, agents that wander, agents that exploit faster than we patch. This week I want to look at our own estate instead, specifically a layer most of us have never drawn on an architecture diagram. It sits between our people, our agents and the model providers, and it is made of LLM proxies, AI gateways, agent runtimes and MCP servers. Call it the AI middle layer. This week it was farmed in the wild and picked up a CVSS 9.9.

The in-the-wild part is a campaign Lumen's Black Lotus Labs calls Canto Incognito. According to The Register, a suspected Italian-speaking actor has infected more than 3,000 servers since April with malware dubbed PoeLLM, peaking above 800 active infections a day. Initial access targets exposed LiteLLM and Ollama instances, the LLM proxy and local model runtime that half the engineering teams I know have stood up "just to try something". Gotenberg, Gitea and Ivanti Sentry (CVE-2026-10520) are on the list too. The C2 is the clever bit. The malware reads a poem on GitHub, "On the Nature of Connection", pulls four words out of fixed phrases, maps them to numbers and assembles an IP address. There is no domain to block and no address in the binary. Today the payload is a cryptominer plus a scanner that recruits the next victim. I would not plan around it staying that modest, because a LiteLLM box usually holds the API keys for every model provider the company pays for.

The 9.9 sits elsewhere in the same layer. GitLab disclosed CVE-2026-90970 in its self-hosted AI Gateway, the component behind GitLab Duo. The Hacker News reports that any logged-in user with Duo Agent Platform access can escape the prompt template sandbox with a crafted flow configuration and run commands on the gateway, in versions from 18.1.6 through the 19.1 line. CISA lists exploitation as "none" so far. The risk is in what the gateway holds: JWT signing keys that GitLab's install guide says to treat as sensitive credentials, and the organisation's AI model provider credentials. BleepingComputer notes GitLab contacted affected customers before going public, which tells you how seriously they took it.

The week's research points the same way. Zenity Labs showed that an Amazon Bedrock AgentCore agent could reach its instance metadata service, so one prompt from chat-only access returned the agent's temporary IAM credentials, scoped by default to every AgentCore resource in the region, Secrets Manager included. AWS says it has fixed the issues and that the research "misrepresents documented behavior". OX Security's census of 15,465 public MCP servers found no signing or vetting, and 2.3% of them on dangling or expired domains anyone could register for $4 to $12.

What ties these together is a thin layer of fast-moving software, usually deployed by an enthusiastic team rather than by IT, that holds some of the most valuable keys in the building. We spent five years learning that lesson with VPN concentrators, and we are about to learn it again.

THE MAP

❝

The AI middle layer holds the keys, and in most organisations nobody owns it. Every call from your people and agents to a model provider passes through a proxy, gateway, runtime or MCP server, and this week each of those boxes took a hit. The layer is internet-reachable, privileged and patched by whoever installed it. That is the profile that made edge appliances the decade's favourite target.

AROUND THE PERIMETER

  • Atlassian Data Center, CVE-2026-21589: CVSS 9.3 pre-auth file read across eight self-hosted products, including Jira, Confluence and Bitbucket. Exploitation started within two hours of watchTowr's PoC write-up, and where Jira is integrated with Crowd the readable files include secrets. Patch, then rotate whatever those files contained.

  • Citrix NetScaler, again: CVE-2026-88779, a SAML memory overflow, was exploited as a zero-day, including against appliances already patched for last week's PitScaler pair. On 9 October Citrix added CVE-2026-107406, a CVSS 9.5 remote code execution bug in the same SAML configurations. If you don't need SAML on NetScaler, switch it off this week.

  • Flax Typhoon and the 2015 club: CISA added five actively exploited CVEs, including ProFTPD and ISC BIND from 2015 and Apache Struts from 2016, with a federal deadline of today. A China-linked actor is still getting mileage out of decade-old bugs. Your asset inventory will do more for you here than your threat feed.

  • GhostAction and the Tensorlake worm: since 7 October more than 500 GitHub accounts have committed a fake security-audit.yml workflow to tens of thousands of repositories, sending CI secrets and AI API keys (Anthropic, OpenAI, OpenRouter) to the attacker. Separately, Shai-Hulud hit the Tensorlake AI agent SDK, and this variant watches the stolen GitHub token. Revoke it and a destructive payload fires on the infected machine. Most playbooks say rotate first. For this worm the order is isolate, rebuild, then rotate.

Why 1.1M+ readers open this AI newsletter every day

From ML engineers to founders, 1.1M+ readers use TLDR AI to spot new tools and research before they go mainstream. One free email, every morning.

CALM THE NOISE

The loudest AI headline of the week came from Seoul. South Korea's president said AI agents had been used to hack at least seven banks, exposing data on 68,000 customers, and that "it's now become possible to use AI to hack with ease even without specialized skills." For a CISO that sentence lands hard, so it's worth checking against the evidence.

The breach is real. Borrowing histories, income data and phone numbers were stolen. The ways in were ordinary. CrowdStrike's write-up names a loan-progress inquiry service at one bank and an employee mobile work-support system at another: internet-facing applications of the kind every bank runs and every pentest covers. The AI, an open-source Chinese agentic pentest tool called ARTEX running on cheap rented model backends, gave the actor speed, with several intrusions packed into a few weeks. It did not find a new way in.

It also got them caught. CrowdStrike found the operation through open directories on the attacker's own server, full of Claude Code session histories, ARTEX configs and memory files. Agentic tooling logs everything, and this actor left the logs public. The Hacker News report on the campaign also covers SCARLET LOOP, a crew that ran 12 million credentials through a multi-model stuffing platform and got 11,832 valid logins, a hit rate under 0.1%.

Compare the week's biggest number. FortiBleed has taken over 86,644 FortiGate firewalls and VPN gateways in 194 countries, per the FBI and Secret Service, using stolen passwords, spraying and GPU-cracked hashes. No AI, no zero-day, and at least 12 ransomware attacks built on the access. Phishing-resistant MFA and a short list of exposed services would have blunted both campaigns.

TRAJECTORY

Last week I argued that the sharp end of the next few quarters would be the edge, because those appliances combine internet reachability, privileged position and slow patching. NetScaler obliged with two more critical bugs. What interests me more is that the same profile is being rebuilt from scratch inside the AI stack.

Each box on this week's Map is a broker. It takes requests from people or agents, holds long-lived credentials to something valuable and passes traffic across a trust boundary. Each also arrived through the side door. An LLM proxy is one docker run away, an MCP server is a line in a config file, and an agent runtime ships with whatever IAM role the default template gave it. None of them went through the architecture review a new VPN concentrator would face, because they were filed as experiments, not infrastructure.

Attackers know where the keys are. GhostAction's workflow lists Anthropic, OpenAI and OpenRouter keys next to AWS. The Tensorlake worm looks for Claude, Cursor and Windsurf config files. A year ago an AI API key was a billing risk. Now it opens a proxy, the proxy opens every provider, and behind those sit the prompts, documents and tool access.

Over the next two to four quarters I expect the AI middle layer to follow the edge-appliance curve on a shorter clock. Opportunistic farming like PoeLLM comes first. Next, infostealers start harvesting AI credentials as routinely as browser cookies. After that come targeted intrusions through the gateway into whatever the agents can reach. The fix is the one we eventually applied to VPNs: put the layer in the CMDB, give it an owner, take it off the internet and treat its secrets as tier-zero. Doing it while the payload is still a cryptominer is much cheaper than doing it after.

READINESS - your move this week

  • Run one external scan for your AI middle layer before Friday. Look for LiteLLM (default port 4000), Ollama (11434), self-hosted GitLab AI Gateway and remote MCP endpoints across your ranges and cloud accounts. Anything internet-reachable comes off this week or gets an owner and an expiry date. Upgrade GitLab AI Gateway to 19.2.4, 19.3.2 or 19.4.1.

  • Search every GitHub organisation for security-audit.yml and github_actions_security.yml, and every lockfile for [email protected]. On a Tensorlake hit, isolate and rebuild the machine before revoking the GitHub token, then rotate every AI provider key that machine or pipeline could read.

  • List the IAM role attached to each production AI agent and what it can reach. If the answer is "everything in the region", or nobody knows, scope it down this week. AgentCore's default made one prompt enough.

THE BOARD ANGLE

The software connecting our staff and agents to AI providers now holds some of our most valuable credentials, so I am putting it under the same ownership, inventory and patching discipline as our firewalls, before attackers move from mining crypto on it to stealing from it.

WISDOM OF THE WEEK

❝

The first principle is that you must not fool yourself - and you are the easiest person to fool.

Richard Feynman

AI Influence Level

Level 4 - AI Created, Human Basic Idea / The whole newsletter is generated via Claude workflow based on hundreds of news and research articles. Human-in-the-loop to review the selected articles and subjects.

Till next time!

Project Overwatch is how a CISO gets ready for what is coming. Every week, the signal across cybersecurity, AI, and resilience, filtered down to what changes your decisions, by someone who actually does this job. Not breaking news. Foresight you can act on.