This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Stop making AI decisions in the dark.

Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.

You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.

You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.

CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.

This week, the threat signal clustered around identity platforms, source-code infrastructure, cloud identity, AI-assisted intrusion operations, financial-sector targeting, and third-party enterprise software.

Keycloak flaws can hand attackers account control. GitLab exploitation moved from disclosure to attacks in roughly two days. Microsoft disclosed an exploited maximum-severity Entra ID flaw. UAT-10147 shows AI being worked directly into real-world post-compromise operations. Apollo joined the growing list of financial organizations dealing with social-engineering-driven cloud compromise.

The message for the week ahead is simple: access is being attacked faster than ownership teams are getting comfortable with the ticket.

📈 Risk Forecast – The Week Ahead 📉

Trend (Macro)

Likelihood

Direction

Signal for the Week

Identity platform account takeover

86%

🔺 Rising

Keycloak password-reset weakness can bypass expected verification and hand over user accounts.

DevOps platform exploitation

84%

🔺 Rising

GitLab attacks began within days of disclosure, compressing remediation timelines again.

Cloud identity control-plane compromise

82%

🔺 Rising

Microsoft disclosed an exploited CVSS 10.0 Entra ID RCE with no privileges or user interaction required.

AI-assisted intrusion scaling

78%

🔺 Rising

UAT-10147 is incorporating AI into exploit refinement, reconnaissance, validation, and persistence.

Financial-sector social engineering

76%

🔺 Rising

Apollo’s breach reinforces that attackers are using people to reach cloud platforms holding sensitive financial data.

Third-party software breach exposure

70%

➡ Stable

SickKids shows supplier vulnerabilities can expose workforce data without touching core clinical systems.

🔎 Key Watchlist Items 🔍
  1. Critical Keycloak password-reset flaw enables account takeover — CVE-2026-18963 allows an unauthenticated attacker to interfere with the credential-reset flow and set a new password without completing the expected emailed verification step, making Keycloak account takeover an identity-platform emergency anywhere affected instances protect high-value applications.

  2. UAT-10147 integrates AI into real-world server exploitation — Cisco Talos-linked analysis shows the Chinese-speaking group using AI-assisted playbooks, exploit automation, troubleshooting, and post-compromise tooling against Windows and Linux web servers, making AI-assisted intrusion scaling a current operational threat rather than a conference-slide prediction.

  3. GitLab critical code-injection flaw exploited shortly after disclosure — Attackers began probing CVE-2026-19478 roughly two days after disclosure, and unauthenticated exploitation can modify or delete public projects and user data, making GitLab exploitation a patch-now issue for self-managed instances.

  4. Microsoft Entra ID CVSS 10.0 RCE was actively exploited — Microsoft disclosed CVE-2026-69836, an untrusted-deserialization flaw allowing unauthenticated remote code execution in Entra ID, with active exploitation already confirmed, making Entra ID RCE a cloud identity control-plane concern with about as much blast radius as the phrase “identity control plane” suggests.

  5. Apollo Global discloses breach amid attacks on financial firms — Hackers accessed personal information in Apollo cloud platforms after a social-engineering-driven intrusion, exposing information including names, addresses, birth dates, and Social Security numbers, making Apollo cloud compromise another warning that advanced security controls do not help much when the attacker successfully borrows a human.

  6. SickKids workforce data exposed through third-party software — Toronto’s Hospital for Sick Children disclosed that a supplier software vulnerability exposed information belonging to employees and job applicants while clinical systems and patient records remained unaffected, making third-party exposure a reminder that vendor risk can create breach obligations without attackers ever touching your primary production systems.

100 real-world tasks. 8 tool categories. 1 complete DevOps stack.

Master Git, Docker, Kubernetes, Linux, CI/CD, Terraform, and monitoring through structured tasks across real-job scenarios, and earn a shareable credential that proves you can apply what you’ve learned.

No lectures, no theory. Build a public portfolio as you go. Earn a verified badge. Free.

📊 Emerging Patterns 📊

Identity is becoming the shortest path to enterprise impact. Keycloak and Entra issues show how little room there is for error when authentication infrastructure itself becomes vulnerable.

Disclosure-to-exploitation timelines keep collapsing. GitLab moved from patch release to observed exploitation in roughly two days. Traditional weekly patch meetings are not built for that clock.

AI is becoming operational attacker infrastructure. UAT-10147 is important because AI is being integrated into troubleshooting and exploit workflows, not merely used to draft phishing emails.

Financial organizations remain premium social-engineering targets. Attackers increasingly understand that cloud access can be cheaper to obtain from an employee than from an exploit.

Third-party compromise keeps separating “our systems were fine” from “we still have a breach.” Supplier exposure still creates notification, identity, and reputational consequences.

Patch priority needs business context. An identity or DevOps vulnerability should move ahead of an equally severe bug sitting on a low-value isolated asset.

⏰ Call to Action ⏰

Keycloak containment: Identify affected Keycloak deployments, apply fixed Red Hat or upstream releases, audit recent password resets, review new credential enrollment, and invalidate suspicious active sessions.

GitLab patch proof: Upgrade self-managed GitLab to fixed versions immediately, review GraphQL access logs for suspicious directive usage, and inspect public projects for unexpected modification or deletion activity.

Entra identity review: Review Entra audit and sign-in telemetry around the disclosed exploitation window, verify Microsoft's mitigation status in your tenant, and escalate unexpected privileged or application activity.

AI-aware server hunting: Look for automated exploitation patterns, unusual batches of scripting activity, suspicious scheduled tasks, EDR bypass attempts, Linux rootkit indicators, and unexpected web-server persistence.

Social-engineering resistance: Tighten help-desk verification, require phishing-resistant MFA for privileged and financial roles, scrutinize requests involving cloud access changes, and require out-of-band confirmation for sensitive actions.

Vendor exposure validation: Require third parties to provide patch and containment evidence, map what workforce or customer data each vendor holds, and ensure incident-notification paths actually reach someone awake.

⚡ Monday Motivation ⚡

The good guys got a tangible win: a federal judge handed an eight-year prison sentence to a participant in a nationwide ATM jackpotting conspiracy responsible for more than $3.5 million in losses. Federal investigators say 119 defendants have now been charged in the broader operation.

That is worth remembering on Monday morning.

Cybercrime may be scalable, international, and frustratingly persistent, but criminal infrastructure leaves evidence and operators eventually make mistakes. Defenders, investigators, and law enforcement only need to keep making those mistakes expensive.

This week’s lesson: attackers are attacking the systems that decide who you are, what code you trust, and what access you receive.

When identity and DevOps become the perimeter, “internal system” stops being a meaningful comfort.

J.W.

(P.S. Check out our partners! It goes a long way to support this newsletter!)

Nobody actually knows how AI gets used.

AI tool sprawl happened fast, and visibility never caught up. Employees paste contracts into ChatGPT, run code through Copilot, and build workflows in apps security never approved.

Harmonic Security classifies every AI interaction by task, tool, and team, so you can see what’s actually happening across approved and unapproved apps alike.