On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- FortiClient EMSCVE-2026-35616EKZ Infostealer
FortiClient EMS CVE-2026-35616: when the security vendor's management plane ships the malware
The EKZ infostealer arrived on managed endpoints disguised as a Fortinet patch — pushed through the FortiClient EMS API after an unauthenticated bypass. Two months between disclosure and active campaign, and Fortinet still hasn't published IOCs.
8 min read - AI Agent AttacksMarimo CVE-2026-39987Cloud Credential Theft
AI Agent Post-Exploitation Is Real: Marimo CVE-2026-39987 and the 60-Minute Pivot Chain
On May 10, 2026 Sysdig recorded what looks like the first AI-agent-driven post-exploitation in the wild — Marimo CVE-2026-39987 to PostgreSQL exfiltration in under an hour, across 11 egress IPs. What it changes for defenders.
8 min read - Supply Chain AttackBotnetAI Traffic Analysis
Glassworm Takedown: When C2 Hides in Solana, BitTorrent, and Google Calendar
On 2026-05-26 CrowdStrike, Google, and Shadowserver coordinated the takedown of Glassworm, a developer-targeting supply-chain botnet that ran command-and-control over Solana memo fields, BitTorrent DHT, and Google Calendar event titles.
8 min read - CVE-2026-48172LiteSpeedShared Hosting
LiteSpeed cPanel CVE-2026-48172: when one tenant becomes root across every site you host
CVSS 10.0, actively exploited as a zero-day, added to CISA KEV on May 26 with a federal deadline of May 29. The shared-hosting blast radius is the real story — and quarterly pentest cycles cannot see it coming.
8 min read - NIS2Known VulnerabilitiesENISA Threat Landscape
NIS2's First Audit Deadline Is June 30. The 21.3% Known-CVE Gap Will Be the First Finding
On 30 June 2026 the first NIS2 compliance audit cycle closes. ENISA's 21.3% known-CVE intrusion rate stops being a slide and starts being an audit finding.
7 min read - Cisco SD-WANCVE-2026-20182UAT-8616
Cisco SD-WAN CVE-2026-20182: the downgrade-and-revert chain a quarterly pentest cannot catch
CVSS 10.0 auth bypass on Cisco Catalyst SD-WAN Controller, UAT-8616 active since 2023, and a downgrade-then-revert kill chain that erases the version trail point-in-time audits depend on.
8 min read - ClickFixWatering HoleTraffic Analysis
Ghost CMS, ClickFix and the Watering Hole That Wears Harvard's Hostname
CVE-2026-26980 turned 700+ Ghost CMS sites into ClickFix watering holes — Harvard, Oxford and DuckDuckGo among them. The host you trusted is now the distributor.
9 min read - EDRCISA KEVEndpoint Security
EDR as Attack Surface: Defender and Apex One Zero-Days in 48 Hours
In a 48h window CISA added Microsoft Defender and Trend Micro Apex One zero-days to KEV. When the endpoint security stack itself is the entry point, continuous external validation is the only check that holds.
8 min read - Dwell TimeHealthcareMTTD
Mandiant Says Dwell Time Is 14 Days. UNMC's Was 858.
The Mandiant M-Trends 2026 median dwell time is 14 days. The University of Nebraska Medical Center just disclosed an unauthorized-access window of 858 days. The gap is not a median problem — it's a detection-blind-spot problem the wire can fix and the host cannot.
6 min read