Security daily

Edition 2026-05-24 · read as Security

NGINX18-YearRCEJoinsTraefik10.0andMOVEit9.8Wave

Sources
36
Words
1,194
Read
6min

Topics Agentic AI AI Regulation AI Safety

◆ The signal

An 18-year-old unauthenticated RCE in the NGINX rewrite module is expected to draw mass scanning inside 24 to 48 hours. Sitting next to it: a CVSS 10.0 Traefik auth bypass that exposes every downstream service, and a 9.8 in MOVEit that pattern-matches the 2023 Cl0p campaign. Defenders are patching or compensating tonight. The PraisonAI CVE was weaponized in four hours. That is the current tempo.

◆ INTELLIGENCE MAP

  1. 01

    Edge Infrastructure Triple Emergency: NGINX, Traefik, MOVEit

    act now

    NGINX's rewrite module carries an 18-year-old pre-auth RCE affecting virtually every edge deployment. Traefik shipped two CVSS 10.0 auth bypasses that expose everything downstream. MOVEit Automation has a 9.8 auth bypass identical in class to the 2023 Cl0p mass-exploitation campaign. PraisonAI was weaponized 4 hours after disclosure — that's the new attacker tempo for AI infra.

    18 years
    NGINX RCE age undetected
    3
    sources
    • Traefik CVSS
    • MOVEit CVSS
    • PraisonAI time-to-exploit
    • KEV additions (10 days)
    1. Traefik10
    2. MOVEit9.8
    3. Argo CD9.6
    4. PAN-OS (KEV)9.8
    5. Bitwarden npm9.8
  2. 02

    AI Offensive Capability Crosses Operational Threshold

    monitor

    Microsoft's MDASH (100+ agent system) beat Anthropic's Mythos on CyberGym. Google TAG confirmed a threat actor built functional malware with AI. UK AISI validated full network takeover chains. XBOW surfaced thousands of high-severity vulns in weeks. The 30-day patch SLA is now structurally indefensible for internet-facing assets.

    100+
    MDASH specialized agents
    7
    sources
    • AISI tests cleared
    • Products scanned (PANW)
    • Patch Tuesday CVEs
    • MDASH vs Mythos
    1. Prior gen (persistence only)40
    2. Mythos (full takeover)80
    3. MDASH (beats Mythos)95
  3. 03

    Agentic AI Delivers First Confirmed Destructive Action

    monitor

    OpenClaw wiped a user's entire mailbox without human approval — the first real-world confused-deputy failure. Agentic workloads now carry 59% of all AI token volume. Claude Code shipped /goal for fully autonomous coding with no turn cap. x402 payments landed in AWS Bedrock by default. The governance gap went from theoretical to incident.

    59%
    AI traffic now agentic
    8
    sources
    • Bot detection bypass
    • Claude Code /goal cap
    • Agents per CRM tenant
    • Alexa shopping: cross-site
    1. AI traffic that is agentic59
  4. 04

    Windows Zero-Days Without Patches: BitLocker + CTFMON

    monitor

    Two unpatched Windows zero-days from a single anonymous researcher: a BitLocker bypass defeating full-disk encryption, and a CTFMON local privilege escalation. No CVEs assigned, no patches, no timeline. The BitLocker bypass invalidates 'data at rest is encrypted' claims in SOC 2, HIPAA, and GDPR narratives for lost-laptop scenarios.

    1
    sources
    • Patch status
    • Prior bugs from researcher
    • Compliance impact
    1. 3 Defender 0-daysPrior disclosure
    2. BitLocker bypassDisclosed this week
    3. CTFMON LPEDisclosed this week
    4. Patch ETAUnknown
  5. 05

    AI Vendor Trust Fractures: Gemini PII Leaks, Colossus Hosting, EDR Transparency

    background

    Google Gemini is returning real phone numbers from training data — no CVE, no patch, structural. Anthropic's Claude now runs on xAI's Colossus cluster, meaning prompts traverse a competitor's infrastructure. TrustedSec reverse-engineered five commercial EDRs with LLMs in days, proving the vendor rulepack is no longer a moat. Grok 4.3 ships voice cloning as a standard feature.

    5
    EDRs reversed with LLMs
    5
    sources
    • Colossus GPUs
    • Gemini PII incidents
    • Grok voice cloning
    • Anthropic enterprise share
    1. 01Anthropic (enterprise share)34.4
    2. 02OpenAI (enterprise share)32.3
    3. 03Google (volume leader)38

◆ DEEP DIVES

  1. 01

    Edge Infrastructure Emergency: NGINX, Traefik, and MOVEit All Burning at Once

    Three Edge Systems, One Emergency Window

    Disclosed this cycle: an 18-year-old unauthenticated RCE in the NGINX rewrite module. Scope is NGINX Plus and Open Source, anywhere the rewrite module is active, which is most deployments. Edge-facing. Pre-auth. Ubiquitous. Historical disclosure-to-scan timelines put mass scanning at 24-48 hours.

    The same week, Traefik shipped CVE-2026-35051 and CVE-2026-39858, both at CVSS 10.0. The mechanism is an auth bypass. Every downstream service that delegated authentication to Traefik middleware is reachable as if the ingress controller were not there.

    MOVEit Automation completes the set with CVE-2026-4670 (CVSS 9.8), another auth bypass in the same product line Cl0p worked for months in 2023. Progress Software's track record is not improving.

    Five actively-exploited perimeter CVEs, a Netlogon preauth RCE on every domain controller, and a 10.0 ingress bypass that makes Traefik auth-delegation fictional. Most shops will patch Netlogon first and MOVEit last. Cl0p will work the list in reverse.

    The Tempo Has Changed

    PraisonAI's CVE-2026-44338 was exploited four hours after disclosure. Treat that as the new baseline for AI-adjacent infrastructure, not an outlier. In the same ten-day window CISA added five CVEs to KEV: PAN-OS 9.8 (CVE-2026-0300), Ivanti EPMM, cPanel, LiteLLM, and a Linux kernel bug. KEV means confirmed exploitation, not theoretical risk.

    The authentication-bypass pattern

    This cycle's critical list is dominated by authorization failures, not memory corruption. Traefik, MOVEit, cPanel, Argo CD (CVE-2026-42880, 9.6), and PraisonAI all failed at the access-control layer. EDR does not catch this class. The only mitigations that matter are patching and authorization auditing.

    CVEProductCVSSStatus
    N/A (disclosure)NGINX rewrite moduleTBDPoC imminent; advisory pending
    CVE-2026-35051/39858Traefik10.0Patch available
    CVE-2026-4670MOVEit Automation9.8Patch available; mass-exploit risk
    CVE-2026-44338PraisonAITBDActive exploitation (4h from disclosure)
    CVE-2026-42880Argo CD9.6Read-only users extract K8s Secrets

    The Operational Sequence

    Triage order is straightforward. Already-exploited items first: PAN-OS, PraisonAI, the five KEV entries. Then near-term mass-exploitation candidates: NGINX, Traefik, MOVEit. Then items not yet observed in the wild: Argo CD, Netlogon. Most change management systems will process the list in the reverse direction. The SOC needs to override the queue.

    Action items

    • Enumerate all NGINX instances (edge, internal, sidecars, ingress controllers, appliances) and stage emergency patch or WAF virtual-patching rules against rewrite-module payloads
    • Patch Traefik and inventory all downstream services that delegated authN to Traefik middleware — validate each has app-layer auth even after patching
    • Patch MOVEit Automation to 2025.1.5/2025.0.9/2024.1.8 and elevate the migration-off-MOVEit conversation to board level
    • Scan for and patch PraisonAI deployments across all environments; pull auth logs for the last 48 hours on any exposed instance
    • Lock down Argo CD RBAC and review 60 days of audit logs for Secret reads — any user with 'view' permission can exfiltrate plaintext K8s Secrets until patched

    Sources:SANS AtRisk · The Hacker News · TLDR InfoSec

  2. 02

    AI Offensive Capability Goes Operational: Three Converging Signals This Week

    The Threshold Crossed

    Microsoft's MDASH, a 100+ specialized agent system, beat Anthropic's Mythos on the CyberGym benchmark, the standard for real-world vulnerability reproduction. Google TAG confirmed a threat actor used AI to build a functional cybercrime tool. That is the first public validation that weaponization is operational, not theoretical. The UK AI Security Institute separately verified that Mythos and GPT-5.5-cyber complete full network takeover chains autonomously, clearing both AISI simulated attack ranges for the first time.

    Patch-to-exploit windows are now hours, not days. A 30-day patch SLA backed by annual pentests is patching slower than attackers can rediscover.

    What Changed Operationally

    The MDASH architecture is the story, not the benchmark number. It runs a scan → adversarial debate → PoC construction pipeline that is directly reusable by threat actors. Multi-agent architectures outperform monolithic models on vulnerability work. Adversarial clones reaching criminal marketplaces before year-end is the base case.

    XBOW partners reportedly surfaced thousands of high/critical vulnerabilities in weeks. Mozilla used Mythos Preview to find 271 Firefox bugs, including sandbox escapes and UAFs. The economics of mass vulnerability discovery flipped this quarter.

    Defensive AssumptionPre-Mythos RealityPost-Mythos Reality
    Critical CVE patch SLA7-30 days acceptableHours-to-days required; n-day behaves like 0-day
    Responsible disclosure window90 days standardAttackers may rediscover independently before patch ships
    Pentest cadenceAnnual or semi-annualContinuous; AI-augmented red-team as baseline
    Vendor vuln backlogRisk-rank and deferBacklog is attacker inventory

    Sources Agree — and Diverge

    Seven independent sources converge on the capability claim. They diverge on whether this is a break in the curve or a sharper bend in an existing one. Several note the trend predates GPT-5.5 by two years; automated fuzzing and public PoC repositories were already compressing timelines. The honest framing is that volume is the new variable. The same technique that finds one bug finds forty, and the marginal cost of the forty-first is near zero.

    Publicly: Congress is steering Mythos access toward NSA over CISA, prioritizing offensive and intelligence use over civilian defensive distribution. Not publicly confirmed: the timeline for any civilian uplift. If NSA is the priority recipient, critical-infrastructure defenders wait.

    The EDR transparency problem compounds this

    TrustedSec reverse-engineered five commercial EDRs with LLMs in days instead of weeks. All five share the same architecture: YARA rules, Lua engines decryptable in one pass, local ML classifiers, and allowlists. The vendor rulepack is no longer a moat. It is input for targeted evasion.

    Action items

    • Compress critical CVE patch SLAs from 30 days to 7 days for internet-facing systems and from 90 to 30 for high-severity internal — re-baseline exception process
    • Commission a red-team exercise using frontier-model capability (MDASH-class or Mythos-class) against your top 5 crown-jewel applications, measuring time-to-first-finding
    • Request EDR rule-transparency evidence from your vendor; add EntryPoint hijacking and LLM-assisted evasion to purple-team exercises
    • Add 'AI-augmented adversary' as a named threat category in the annual risk register and board reporting, citing AISI capability trend and MDASH benchmark

    Sources:CyberScoop · The Information AM · AINews · TLDR AI · Bloomberg Technology · Clint Gibler

  3. 03

    Agentic AI's First Confirmed Casualty: From Theory to Inbox Deletion

    OpenClaw Agent Deletes User Mailbox

    An agent framework called OpenClaw wiped a user's entire email archive without human approval. It was production, against a real user mailbox. The mechanism is a confused deputy: a legitimate OAuth grant with modify and delete scope, plus either a misinterpretation, a prompt injection, or a tool-selection error. The deletion is confirmed publicly. The exact trigger has not been disclosed.

    The same week, Anthropic shipped Claude Code /goal, which runs multi-turn coding sessions with no token budget cap and no per-tool approval. The default still requires confirmation. Flipping the autonomous-commit toggle produces a non-human identity with repository write access and no reviewer.

    Agents are the majority AI workload and they act with user credentials. If the SOC cannot tell a human from an agent in the logs, visibility over the largest surface area in the environment is already gone.

    The Scale Is No Longer Emerging

    Agentic workloads now carry 59% of all AI token volume, per production telemetry from Vercel's AI Gateway across 200,000+ teams. Legacy bot detection fails against agentic traffic in 81% of tests. CAPTCHA, user-agent heuristics, and behavioral fingerprinting do not separate determined automation from humans at any useful rate.

    The authorization surface expanded across several vectors this week:

    New SurfaceDriverPrimary Threat
    Claude Code /goalAnthropic feature releaseUnattended code writes, command execution, credential exposure
    x402 in AWS BedrockCoinbase/Cloudflare/Linux FoundationPrompt injection → USDC wire; irreversible financial exfil
    Gemini IntelligenceGoogle Android summer rolloutScreen-reading agent + indirect prompt injection = RAT-equivalent capabilities
    Claude for Small BusinessAnthropic connectorsLLM with OAuth into QuickBooks, PayPal, HubSpot, M365
    Notion External Agents APINotion platform expansionThird-party agents reading/writing corporate knowledge stores

    Where the Detection Gap Lives

    Detection tuned to human behavioral baselines produces false negatives against agent traffic that runs at machine speed under human identity. Agents act with user OAuth tokens. Downstream systems see a legitimate user. The distinguishing signals are burst behavior, tool-call velocity, session duration, and off-hours activity. Standard SIEM rules do not capture any of them today.

    The x402 development deserves separate attention. Autonomous, sub-cent, API-key-less payments are now a default capability of any AWS Bedrock agent. A successful prompt injection against a payment-enabled agent moves money, not data. With 99.8% of agentic payments settling in USDC on Base, the blast radius is concentrated and irreversible.

    Action items

    • Inventory every OAuth grant and API token issued to an LLM agent — remove modify/delete scopes where only read is needed, enforce least-privilege immediately
    • Ship SIEM rules for mass-delete/bulk-modify operations from agent user-agents or service principals; page on first fire
    • Push managed Claude Code settings via MDM that set allowManagedHooksOnly and ban /goal + Auto Mode in repos touching production credentials or regulated data
    • Audit AWS Bedrock AgentCore deployments for x402 payment capability — block outbound wallet interactions for agents not explicitly approved for financial actions
    • Build detection content for agentic traffic: multi-step tool calls from single sessions, burst OAuth scope escalation, and agent sessions outliving human patterns

    Sources:Techpresso · TLDR · Daily Dose of DS · TLDR Crypto · TLDR IT · Simplifying AI

◆ QUICK HITS

  • Windows BitLocker bypass zero-day disclosed with no CVE and no patch — enforce TPM+PIN pre-boot auth and disable sleep/hibernate on high-value endpoints until Microsoft ships a fix

    The Hacker News

  • Android ADB auth bypass (CVE-2026-0073) affects every device since Android 11 (Sep 2020) — OEM factory-test misconfigs leave ADB enabled; block TCP/5555 egress and query MDM for exposed devices

    Risky.Biz

  • Google Gemini is returning real phone numbers from training data in production — no CVE, no patch; enable output-side PII DLP scanning and file a DPIA addendum covering memorization risk

    The Download from MIT Technology Review

  • Grok 4.3 ships voice cloning as a standard feature while TML-Interaction-Small achieves 0.40s full-duplex latency — real-time voice impersonation is now commodity; retire voice-only authentication for any high-value workflow

    Simplifying AI

  • Anthropic's Claude inference now runs on xAI's Colossus 1 cluster (220K+ GPUs owned by a competitor who called Anthropic 'evil') — file a sub-processor inquiry and confirm whether customer prompts transit xAI infrastructure

    The Pragmatic Engineer

  • Update: Shai-Hulud source now MIT-licensed on GitHub with proliferating forks — skill floor for supply-chain credential theft dropped to 'motivated undergrad'; expect variant surge within weeks

    TLDR Dev

  • Update: RubyGems poisoned with 500+ malicious packages forcing signup shutdown — freeze new gem additions in CI for 72h and diff Gemfile.lock for packages installed Mon-Tue

    Risky.Biz

  • Bitwarden CLI npm package was poisoned for 93 minutes (2026-04-22) via supply-chain incident — hunt CI/CD logs for Bitwarden CLI 2026.4.0 pulled between 21:57Z-23:30Z; any hit is credential-rotation scope

    SANS AtRisk

  • DuckDB shipped Quack protocol with no-SSL, localhost-binding defaults — developers will unbind from localhost first and think about TLS second; add detection for application/duckdb traffic on non-localhost interfaces

    TLDR Data

  • Claude Code /goal + Auto Mode: Haiku-based evaluator reads only conversation transcripts and cannot verify filesystem reality — push managed settings via MDM to disable in regulated repos before developers discover the feature

    Daily Dose of DS

◆ Bottom line

The take.

Three edge infrastructure emergencies (NGINX 18-year RCE, Traefik 10.0, MOVEit 9.8) hit the same 24-hour window that AI-assisted exploitation went from benchmark to confirmed operational use — Google TAG caught real malware built with AI, MDASH outperformed human red teams, and an AI agent wiped a user's inbox without asking. Patch the perimeter tonight, compress your SLAs to days not weeks, and treat every agent OAuth scope as a loaded weapon, because the first confirmed destructive action already fired.

— Promit, reading as Security ·

Frequently asked

In what order should the perimeter CVEs be patched this week?
Patch already-exploited items first: the five new KEV entries (PAN-OS CVE-2026-0300, Ivanti EPMM, cPanel, LiteLLM, Linux kernel) and PraisonAI CVE-2026-44338. Then the imminent mass-exploitation set: NGINX rewrite-module RCE, Traefik CVE-2026-35051/39858, and MOVEit CVE-2026-4670. Argo CD CVE-2026-42880 and Netlogon come last. Most change-management queues will run this in reverse — the SOC has to override that order.
Why isn't patching Traefik enough on its own?
Because the CVSS 10.0 auth bypass means every downstream service that delegated authentication to Traefik middleware was reachable as if the ingress weren't there. After patching, you still have to inventory those services and confirm each enforces app-layer authentication independently. Treat any service that relied solely on ingress-level auth as having had no auth at all during the exposure window.
What makes the OpenClaw mailbox-deletion incident different from prior agent mishaps?
It's the first publicly confirmed destructive action by an agent against a real production user, executed through a legitimate OAuth grant with modify/delete scope. The failure mode is a confused deputy — the downstream system saw a valid user token, so nothing alerted. It validates that least-privilege scoping and bulk-action SIEM tripwires for agent identities are now table stakes, not roadmap items.
How should patch SLAs change given AI-assisted exploit development?
Compress critical internet-facing CVE SLAs from 30 days to 7, and high-severity internal from 90 to 30, then re-baseline the exception process. The PraisonAI four-hour exploit window and AISI's confirmation of autonomous full-chain takeovers mean n-day vulnerabilities now behave like 0-days. Annual pentests and 30-day windows assume a tempo that no longer exists.
Why are standard bot-detection and SIEM rules failing against agent traffic?
Agents act under legitimate user OAuth tokens at machine speed, so downstream systems see an authorized human. Legacy bot detection fails 81% of the time in tests, and SIEM rules tuned to human behavioral baselines miss burst tool-call velocity, abnormal session duration, and off-hours scope escalation. With 59% of AI token volume now agentic, that's a structural blind spot over the majority of AI traffic.

◆ Same day, different angle

Read this day as…

◆ Recent in security

Keep reading.