AI Weakly #07 - Your visibility stack is their entry point.
AI Weakly is the weekly newsletter for those who make decisions on AI and security without time to waste. Every Tuesday: the facts that matter without the noise.
Issue #7
Top Story —
This week exposed a coordinated escalation across three attack surfaces: North Korean threat actors compromised 140+ npm packages targeting AI development pipelines, China-nexus APT conducted year-long espionage against US researchers via credential theft, and Russian-speaking groups exploited 86,000+ Fortinet devices to breach enterprise network perimeters. Meanwhile, active exploitation campaigns against Splunk, Palo Alto GlobalProtect, and critical VPN infrastructure demonstrate attackers are weaponizing the tools CISOs depend on for visibility and access control. The common thread: credential compromise and supply chain contamination are now the primary vectors for nation-state intrusion into AI systems and sensitive research environments.
Weakly Digest —
01 —
Microsoft Links Mastra AI Supply Chain Attack to North Korean Sapphire Sleet—140+ npm Packages Compromised
🟣 Supply Chain / AI Infrastructure
North Korean threat actor Sapphire Sleet compromised 140+ npm packages targeting AI development infrastructure in a coordinated supply chain attack. This represents the first state-sponsored assault on AI software supply chains at scale.
EDITOR’S NOTE
Immediate action: audit npm dependencies in your development pipeline and implement SCA tooling with real-time alerts for compromised packages. Escalate to engineering leadership—this is not a 'nice to have' control. Consider air-gapping AI development environments from production networks and implementing strict code review gates for dependencies introduced in the past 12 months.
02 —
China-Nexus APT Spies on US Researchers Undetected for One Year via Stolen RedCAP Credentials
🟣 Credential Theft / Espionage
A China-nexus threat actor conducted year-long espionage against US research institutions using stolen RedCAP credentials, exfiltrating sensitive data before Google disrupted the operation. The campaign demonstrates sophisticated persistence and highlights credential compromise as the primary attack vector against high-value research targets.
EDITOR’S NOTE
Action required: implement continuous credential monitoring and anomaly detection for research and sensitive data environments. Enforce hardware-backed MFA across all research institutions and implement session-based access controls with behavioral analytics. This signals the need for enhanced threat hunting in research-adjacent systems—activate your IR team for forensic reviews of any credential-based access in the past 18 months.
03 —
CISA Issues Critical Patch Deadline for Splunk Enterprise—Active Exploitation Confirmed
🔴 Critical / Active Exploitation
CISA mandated urgent patching of a critical Splunk Enterprise vulnerability being actively exploited in the wild, with patch deadline for federal agencies by Sunday. The flaw directly impacts organizations' ability to detect and respond to security incidents.
EDITOR’S NOTE
This is a drop-everything priority: patch Splunk Enterprise immediately in all environments. Splunk is part of your detection infrastructure—compromise here blinds your SOC and enables attackers to evade logging. Run threat hunts for any suspicious Splunk activity, API access anomalies, or forwarder configuration changes in the past 30 days. If patching delays are unavoidable, isolate Splunk instances and reduce data flows to critical-only ingestion.
04 —
Sweeping FortiBleed Campaign Compromises 86,644 Fortinet Devices—CISA Urgent Alert
🔴 Critical / Perimeter Security
Russian-speaking threat actors have actively compromised credentials from 86,644 internet-exposed FortiGate devices across 200+ countries in an ongoing campaign. CISA issued urgent warnings to all Fortinet customers as the incident represents a systemic breach of enterprise network perimeter security.
EDITOR’S NOTE
Immediate mandatory actions: inventory all FortiGate appliances and verify they are patched to the latest firmware. Reset all administrative and service account credentials on FortiGate devices immediately—assume all existing credentials are compromised. Implement network segmentation to limit blast radius if perimeter devices are breached, and deploy out-of-band monitoring for FortiGate admin activity. This is a perimeter-at-scale compromise; treat with the urgency of a network-wide breach.
05 —
Palo Alto Confirms Active Exploitation of PAN-OS GlobalProtect VPN Authentication Bypass—CVE-2026-0257
🔴 Critical / Active Exploitation
Unknown threat actors are actively exploiting CVE-2026-0257, a critical authentication bypass in PAN-OS GlobalProtect VPN (CVSS 7.8), to gain unauthorized access to enterprise VPN portals. This directly threatens remote workforce access controls.
EDITOR’S NOTE
Urgent: patch all PAN-OS GlobalProtect instances immediately. VPN access is the gateway to your network—compromise here gives attackers immediate internal access. While patching, implement secondary authentication (hardware MFA) for VPN logins, monitor VPN logs for impossible travel and credential anomalies, and consider temporary IP whitelisting for VPN access if patches delay. Review VPN session logs for the past 30 days for any suspicious authentication patterns.
Also worth reading —
Copilot 'SearchLeak' Prompt-Injection Attack Enables 1-Click Data Theft from AI Systems — Assess AI assistant deployments for prompt-injection vectors and implement output filtering before data reaches end users.
Novo Nordisk Breach: Leaked GitHub Token Compromises Software Development Pipeline — Implement secrets scanning, rotate all developer credentials, and enforce hardware-backed MFA for git access immediately.
Klue OAuth Breach Exposes Customer Salesforce Access—Icarus Extortion Group Expanding Victim List — Audit all SaaS OAuth integrations and revoke tokens preemptively; implement app-layer monitoring for abnormal CRM access patterns.
Most CISOs Report Pressure to Bury Bad Security News—Governance Risk Escalates — Establish clear incident disclosure protocols with legal and board visibility; document pressures to suppress disclosures for regulatory protection.
