AI Weakly #11 - "Patch the flaw. Verify the trust. Defend the identity"
AI Weakly is the weekly newsletter for those who make decisions on AI and security without time to waste. Every Tuesday: the facts that matter without the noise.
Issue #11
Top Story —
Week 29 reveals a convergence of critical threats: SonicWall SMA appliances are under active zero-day exploitation enabling root-level VPN compromise, Fortinet FortiSandbox flaws trigger CISA federal directives, and compromised DigiCert code-signing certificates amplify supply chain risk across enterprise software distribution. Simultaneously, identity attacks have overtaken exploits as the primary ransomware vector—a tactical shift that renders traditional vulnerability management insufficient. CISOs must treat this week as a forcing function: patch SonicWall/Fortinet immediately, audit certificate trust chains, and fundamentally reassess identity security beyond MFA.
Weakly Digest —
01 —
Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root-Level Remote Access Compromise
🔴 Critical / Active Exploitation
Inc ransomware group actively exploits two chained zero-day vulnerabilities in SonicWall SMA mobile access appliances to achieve root-level control. Compromised SMA devices grant attackers direct enterprise network access, representing immediate operational continuity risk.
EDITOR’S NOTE
Treat as perimeter breach scenario. Audit all SonicWall SMA deployments immediately for exploitation indicators (unexpected admin sessions, SSH key additions). If you use SMA 1000 series, prioritize patching over all other remediation activities this week. Assume compromise until proven otherwise.
02 —
CISA Issues Federal Patch Directive on Actively Exploited Fortinet FortiSandbox Critical Flaws
🔴 Critical / Active Exploitation
CISA mandates immediate patching of two actively exploited vulnerabilities in Fortinet FortiSandbox with federal agency compliance deadline. Active exploitation of a major threat detection platform creates cascading risk across dependent security infrastructure.
EDITOR’S NOTE
This is a compliance+security forcing function for federal contractors and agencies. Non-federal organizations should treat the CISA mandate as urgency guidance—threat actors exploit compliance gaps at other organizations. Patch FortiSandbox before end of business today. Verify patch deployment across all instances.
03 —
GoldenEyeDog Subgroup Attributed to DigiCert Breach; Stolen Code-Signing Certificates Enable Enterprise Supply Chain Attack
🟣 Supply Chain / APT Activity
CylindricalCanine, a subgroup of Chinese APT GoldenEyeDog, is attributed to the April 2026 DigiCert breach resulting in stolen code-signing certificates. Compromised certificates enable malware distribution with trusted signatures across thousands of organizations.
EDITOR’S NOTE
Escalate to application security and supply chain teams immediately. Audit software signatures from DigiCert-signed executables in your environment for anomalies (unexpected publishers, changed hashes). Consider certificate pinning policies for critical software vendors. This attack vector persists for months unless actively monitored.
04 —
Identity Attacks Overtake Exploits as Top Ransomware Infection Vector; MFA Deployed Yet Failing
🟣 Identity Security / Ransomware
Email-based identity attacks have surpassed software exploits as the primary ransomware entry point, with MFA deployed in 97% of compromised credentials yet unable to prevent breach. This represents a fundamental tactical shift by ransomware operators toward human-centric compromise.
EDITOR’S NOTE
Your MFA deployment is table-stakes, not a ransomware defense. Implement conditional access policies tied to behavioral anomaly detection, not just factor verification. Audit email gateway rules for phishing/credential harvesting—this is now your primary ransomware perimeter. Consider passwordless authentication for critical roles.
05 —
Over 1 Million Emails Use Text Salting to Evade AI-Powered Security Filters; LLM-Based Detection Compromised
🔴 Critical / Email Security Evasion
Research reveals 1M+ emails exploit text salting techniques to bypass AI-powered email security filters, exposing fundamental vulnerability in LLM-based threat detection. Adversarial text manipulation renders machine learning defenses ineffective at scale.
EDITOR’S NOTE
If your email security relies primarily on AI/ML classifiers, you have a detection gap. Layer in rule-based detection for text salting indicators (invisible Unicode, extreme whitespace patterns). Validate email gateway logs for bypassed phishing—assume some volume escaped detection this month. Test human-in-the-loop review workflows for flagged edge cases.
Also worth reading —
Claude Web Fetch Vulnerability Enables Data Exfiltration Through Nested URL Redirects — Audit Claude deployments with web_fetch enabled; restrict tool access to non-sensitive workflows and implement API-level rate limiting.
xAI's Grok Build CLI Automatically Uploads User Directories Including SSH Keys and Credentials — Review all AI development tools in your environment for default-enabled cloud uploads; require explicit user consent and audit cloud retention policies.
Forgotten UEFI Bootloaders Remain Trusted, Exposing Secure Boot to Pre-OS Malware Bypass — Audit bootloader revocation status across enterprise endpoints; implement firmware scanning and supply chain verification in device onboarding workflows.
Cursor IDE Allows Automatic Execution of Malicious Code From Poisoned Repositories (Unpatched) — If using Cursor for development, disable auto-execution features and implement repository scanning; consider sandboxed environments for AI-assisted coding.
