- Cloud Security Newsletter
- Posts
- π¨ Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage
π¨ Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage
Cisco Talos documented a Chinese-speaking threat actor using agentic AI across reconnaissance, exploitation, and persistence the same week CISA issued 72-hour patch deadlines for Oracle WebLogic and Gitea flaws under active attack. Damien Lewke, founder and CEO of Nebulock, argues the defensive answer is a hunt-first methodology: continuous, AI-assisted threat hunting over endpoint, identity, and cloud telemetry instead of alert triage. This edition covers machine-speed exploitation, MFA bypass at scale, shadow AI hunting, and how to detect AI agents by their behavioral tempo.

Hello from the Cloud-verse!
This week's Cloud Security Newsletter topic: Hunt First β Telemetry Over Alerts, and How to Detect AI Agents by Their Tempo (continue reading)
Incase, this is your 1st Cloud Security Newsletter! You are in good company!
You are reading this issue along with your friends and colleagues from companies like Netflix, Citi, JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more who subscribe to this newsletter, who like you want to learn whatβs new with Cloud Security each week from their industry peers like many others who listen to Cloud Security Podcast & AI Security Podcast every week.
Welcome to this weekβs Cloud Security Newsletter!
Ashish sat down with Damien Lewke, founder and CEO of Nebulock and a second-time guest, whose career runs from building the DoD's threat hunting team for a large weapon system through CrowdStrike, Palo Alto Networks, MIT, and Arctic Wolf, where he ran the AI detections product teams behind a 1,200-person SOC. His argument lands in a week that kept proving it: AI for security has over-indexed on closing tickets, while the intrusions that matter are assembled from signals nobody alerted on. The same week, Cisco Talos published evidence that at least one threat actor now runs agentic AI inside its post-compromise operations.[Listen to the episode]
β‘ TL;DR for Busy Readers
π¨ CISA gave federal agencies 72 hours on CVE-2026-21962 (Oracle WebLogic/HTTP Server, CVSS 10.0) and three days on the Gitea RCE (CVE-2026-60004) both under active exploitation; patch and hunt now, whatever your sector
Cisco Talos documented UAT-10147 integrating agentic AI into post-compromise operations detection baselines built for human-speed attackers are now the wrong baselines
Mirage2FA's adversary-in-the-middle kit is linked to potential compromise of ~4,500 Microsoft 365 accounts; OTP-based MFA doesn't stop it move privileged roles to FIDO2/passkeys
GitLab's CVE-2026-19478 went from public advisory to in-the-wild exploitation in about three days, with no leaked PoC needed treat self-hosted DevOps platforms as patch-same-week assets
Lewke's first AI use case for any team: a shadow AI hunt β baseline MCP process executions and child processes, then investigate the deviations
π° THIS WEEK'S TOP SECURITY HEADLINES
Each story includes why it matters and what to do next β no vendor fluff.
1. CISA gives agencies 72 hours on a CVSS 10.0 Oracle WebLogic flaw patched in January
Primary source: CISA KEV alert
Reporting: SecurityWeek Β· The Hacker News
What Happened
CISA added CVE-2026-21962, a maximum-severity flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the KEV catalog on August 24 with a remediation deadline of August 27 β a 72-hour turnaround instead of the usual three weeks. The flaw allows an unauthenticated attacker with HTTP access to read or modify critical data. Oracle patched it in the January 2026 CPU; reporting ties exploitation to a China-linked actor delivering the SNOWLIGHT downloader across more than 100 countries
Why It Matters
A seven-month-old patch generating a three-day federal deadline tells you the exploitation is current and moving. WebLogic and Oracle HTTP Server front ERP and financial estates that lifted-and-shifted into IaaS and rarely appear in cloud-native vulnerability scans, so KEV processes scoped to internet-facing perimeter assets will miss proxy plug-ins on VPC-internal tiers still reachable through load balancers.
Action for defenders: Inventory Oracle HTTP Server and WebLogic Proxy Plug-in instances across all cloud accounts, including tiers behind ALBs, and confirm the January CPU is applied.
2. Gitea RCE added to KEV: open registration turns "write access required" into "anyone"
Primary source: CISA KEV alert
Reporting: Help Net Security Β· BleepingComputer
What Happened
CISA added CVE-2026-60004 (CVSS 9.8), a code injection flaw in the self-hosted Git service Gitea, to the KEV catalog on August 25 with a federal deadline of August 28. The diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content, giving an attacker with ordinary write access shell execution as the Gitea OS user. Versions from 1.17 are affected; 1.27.1 patches it, and at least one operator has reported a cryptominer-style dropper delivered through the flaw.
Why It Matters
On instances with default open registration, "write access required" means anyone who registers an account and creates a repository.
Action for defenders: Upgrade to Gitea 1.27.1, disable open registration where it isn't needed, and review recently created accounts, repositories, and Git hooks for anything unrecognized.
π If you only do one thing this week: Pull your self-hosted developer infrastructure list (GitLab, Gitea, anything with a diffable open-source patch stream) and re-baseline its patch SLA to same-week. Then take Lewke's 30-minute starter: baseline MCP process executions in your environment and list every AI agent you didn't know was running. The week's exploit timelines and the episode's thesis point at the same two gaps.
βοΈ 3. GitLab GraphQL flaw weaponized from patch-diff to honeypot detections in about three days
Primary source: The Hacker News
Analysis: Horizon3
What Happened
GitLab shipped an emergency patch for CVE-2026-19478, a critical code injection flaw reachable through GraphQL, on August 17. Researchers demonstrated the bug could be reproduced using only the public advisory and the patch diff, and roughly two days later, on August 20, exploitation attempts appeared against honeypot instances. GitLab has warned customers of active exploitation.
Why It Matters
No leaked PoC was needed; the vendor's own advisory and code changes were the exploit development kit. That collapses the realistic patch window for self-hosted DevOps platforms to the time it takes an attacker to read a diff, which for this bug was under 72 hours. Lewke's framing on the episode was blunter: on the attacker side, the time to exploit is shrinking from months to weeks to minutes, and this is what that looks like on a calendar.
Action for defenders
Confirm self-managed GitLab is on the August 17 emergency release or later and check GraphQL logs from that date forward for anomalous mutations. If you can't patch same-week, put network-layer authentication in front of self-hosted GitLab.
π₯ 4. Talos: Chinese-speaking actor UAT-10147 integrates agentic AI into post-compromise operations
Primary source: Cisco Talos β agentic AI report
Analysis: Cisco Talos β SPECTRE implant analysis
What Happened
Cisco Talos published paired reports on UAT-10147, a Chinese-speaking actor compromising internet-exposed Windows and Linux web servers across government, education, media, technology, and gaming sectors. The actor deploys SPECTRE, a cross-platform implant whose Windows build supports 45 commands including credential theft, token impersonation, and BYOVD attacks using vulnerable MSI and Dell drivers, plus a Linux rootkit and BadIIS SEO-fraud tooling. Recovered source code showed AI-driven tooling integrated into reconnaissance, exploitation, payload generation, validation, and persistence, including AI-generated operational playbooks.
Why It Matters
This moves attacker AI from the lure into the operations loop, and it is the strongest public confirmation yet of the premise Lewke builds on in this week's episode: the adversary is increasingly agentic, and its tell is tempo. Kernel-level EDR bypass via signed vulnerable drivers also means the endpoint agent can be blinded, so server-side and identity-plane telemetry become the durable signal.
Action for defenders
Pull the Talos IOCs, hunt for BYOVD driver loads and IIS module tampering on internet-facing web servers, and confirm your EDR blocks known-vulnerable driver hashes rather than only flagging them.
π‘οΈ 5. Mirage2FA phishing service linked to ~4,500 potentially compromised Microsoft 365 accounts
Primary source: The Hacker News
Analysis: ANY.RUN research
What Happened
Researchers detailed Mirage2FA, a commercial phishing-as-a-service kit running adversary-in-the-middle attacks against Microsoft 365 logins since 2024. Victims are funneled through HTML, XHTML, and SVG attachments to a proxied fake Microsoft login page that relays credentials and one-time 2FA codes to Microsoft in real time and captures the authenticated session cookie. The campaign reportedly reached 9,426 unique addresses with roughly 48% potentially compromised: about 4,532 accounts across 3,518 organizations, concentrated in the US
Why It Matters
The stolen artifact is the session cookie, so OTP-based MFA is bypassed by design and the blast radius extends to every SSO-connected service behind the M365 identity. Victim concentration among technology firms and MSSPs compounds it: one relayed session at a service provider is a foothold into downstream tenants.
Action for defenders:
Move admin and high-privilege M365 roles to FIDO2/passkeys, enable token protection and risky-session revocation, and block or sandbox HTML/XHTML/SVG attachments at the mail gateway.
6. SAML signature-confusion chain in miniOrange SSO plugin exploited for admin logins
Primary source: BleepingComputer
Analysis: Patchstack
What happened: Attackers are chaining two authentication bypasses in the miniOrange SAML 2.0 SSO plugin for WordPress (CVE-2026-61979 and CVE-2026-15981) to forge SAML responses and sign in as any user, including administrators. The plugin accepts the signature algorithm supplied by the incoming SAML response, allowing a downgrade to HMAC-SHA1, and separately misreads OpenSSL verification errors as successful validation. DigitalOcean's investigation of an anomalous admin session on August 16 confirmed the chain works against version 16.1.9 of the Standard edition.
Why it matters: Both bugs are one failure class: the relying party trusts attacker-supplied input about how to verify trust, and error handling fails open. That is the recurring SAML story (signature wrapping, Golden SAML) arriving in commodity plugin form, and enterprises run these plugins on marketing and docs sites that share SSO with everything else. An "any user" login primitive on an IdP-connected property is an identity incident.
Action for defenders: Find WordPress properties using miniOrange SAML SSO, patch, and audit admin sessions from August 16 onward. Then ask your IdP team which relying parties enforce the configured signature algorithm rather than accepting the asserted one.
7. Cribl buys Radiant Security's AI SOC technology
Primary source: SiliconANGLE
Reporting: Security Boulevard
What happened: Cribl acquired the technology assets behind Radiant Security's AI-native SOC product, which autonomously triages, investigates, and resolves security alerts. It is Cribl's second security deal of 2026. Deal terms were not disclosed in the reporting reviewed.
Why it matters: The pipeline vendor buying the triage layer collapses a boundary most teams treat as separate procurement: the company routing your telemetry now wants to decide which alerts deserve a human. It is also a sharp counterpoint to this week's episode: the market is consolidating around exactly the alert-triage automation Lewke calls a great start and the wrong end state.
Action for defenders: If Cribl is in your telemetry path, ask what an AI triage layer inside the pipeline means for your SIEM contract and alert-routing assumptions at renewal.
π― Cloud Security Topic of the Week:
Hunt first: Telemetry over Alerts!
he premise of this week's episode is that the alert queue is a solved problem (automation and agents handle known-bad at scale) while the data your SIEM stores at seven figures a year goes unhunted. Lewke's working example is three events that no tool would flag alone: an Okta API token gets used, that token authenticates into a MacBook, that MacBook opens the AWS CLI. Individually benign, in sequence they are direct evidence of a stolen token and an active intrusion. Hunt first is the discipline of continuously querying that telemetry for the sequences, with AI agents doing the iteration and a human judging the output.[Listen to the full episode β]
Featured Experts This Week π€
Damien Lewke β Founder & CEO, Nebulock
Ashish Rajan - CISO | Co-Host, AI Security Podcast , Host of Cloud Security Podcast
Definitions and Core Concepts π
Before diving into our insights, let's clarify some key terms:
Hunt first: Lewke's methodology. "threat hunting is not asking a question. It's following a structured framework that's aligned to your organization's risk," using agents to continuously look for, identify, validate, and attribute anomalous behavior in telemetry.
Shadow AI: AI tools and agents running in an environment without security's knowledge; found by hunting, not by policy.
MCP (Model Context Protocol): the connector standard for AI agents. Lewke's operational note: it runs in user space with clear-text commands, which makes it unusually huntable.
Behavioral signatures (for AI agents): "not signatures as in DAT files, but signatures as in behavior that an AI will do, and it's all about tempo and breadth."
Attribution (as used in this episode): "simply uncovering the underlying reason as to why something happened," an explanation discipline, explicitly not blame.
AitM (adversary-in-the-middle): phishing architecture that proxies a real login page, relaying credentials and OTP codes in real time to capture the authenticated session cookie (see the Mirage2FA story).
BYOVD (Bring Your Own Vulnerable Driver): loading a signed but vulnerable driver to gain kernel access and disable endpoint defenses (used by UAT-10147's SPECTRE implant).
KEV (Known Exploited Vulnerabilities catalog): CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with binding remediation deadlines for US federal civilian agencies.
This week's issue is sponsored by Varonis
Whatβs the blast radius of your AI agent?
Your cloud provider may secure the AI platform but you still decide what your agents can access, what permissions they have, and what actions they can take.
On September 2, Iβm hosting an online panel with the security research team at Varonis on to break down real AI agent attack scenarios and what security teams should be doing about them.
π‘Our Insights from this Practitioner π
1. Alert triage automation answers the wrong question: use AI to solve for the breach
The industry's flagship AI-for-security use case is SOC L1 automation, and Lewke, who ran detection product teams at an MDR serving 10,000 customers, understands the appeal better than most. Ticket-closing ROI is quantifiable. His objection is what the metric hides:
"Breaches happen in silence. Breaches happen because we missed something. We didn't have full visibility and context. We missed a series of completely benign signals that together are malicious. So when I think of AI for security, it's a great start, and we've automated, uh, what I would call the, the reactive component of security. But if you really wanna use AI effectively for security, you wanna look at first principles and solve for the breach."
The practical redirection: point AI at the low- and no-signal events that show how and where you missed something, because no volume of known-bad closure catches the unknown-bad sequence.
2. Threat hunting is no longer maturity-gated
The standing assumption that hunting requires a mature program and rare specialists is a decade old, and Lewke says AI broke it:
"What does AI do fundamentally, particularly in security operations? It, it democratizes things. On the attacker side, right, the time to exploit is shrinking from months to weeks to minutes. Yeah. On the defensive side, what it's allowed us to do is democratize this very elite skill set of threat hunting, and by proxy detection engineering as well, to any organization."
His stated floor is modest: general security hygiene, some logging and aggregation, and an EDR. The customer range he cites as evidence spans an 85-person company with one full-time security operator to a 130,000-person Fortune 500. Notice the symmetry in that quote, though: the same democratization applies to attackers, which is why the GitLab and WebLogic stories above look the way they do.
3. Telemetry over alerts: the benign-in-isolation sequence is the finding
The alerts-versus-telemetry argument is economic as much as technical. Alerts are pre-labeled known-bad; telemetry is where the misses live:
"If an Okta API token gets used, not a bad thing. If it's used to authenticate into a MacBook, not a bad thing. If that MacBook opens up the AWS CLI and accesses infrastructure, not necessarily a bad thing. But if you look at all of those in concert as a series of events and then go, 'Well, hey, wait a minute. That API token looks to have been stolen,' well... I have direct evidence of an active, persistent intrusion in my environment."
And the cost framing that lands with anyone who owns a SIEM budget: "if we're just focusing on the alerts problem, then the whole reason we stored all of this data, the reason your Splunk bill is $5 million a year never gets realized. You're not actually doing anything with that data." His scale evidence: over 300 million agentic investigations run, surfacing more than 4,000 active incidents that alert-focused operations would have missed.
4. Trust in agentic output comes from exposed reasoning
Ashish pushed on the obvious objection: how do you hand AI-surfaced anomalies to a junior analyst without inheriting hallucination risk? Lewke's answer is that opacity, not the model, is the risk:
"I think one of the greatest challenges that we see when you use any sort of black box capability is people just accept it as rote truth. Yeah. If you really want to democratize something, and you have a junior resource or limited resources, if you expose the decision-making behind it, you actually enable the person, and that's the whole point."
Exposing the agent's queries and iterations does two jobs at once: it lets a one-year-out-of-university analyst understand why a finding matters, and it keeps the human as the judge rather than the rubber stamp. Context is the other half: SSH port forwarding from a developer is routine; the same signal from "Damien in accounting" is a different question entirely.
5. AI is not right for all detections: route deterministic signals to a reasoning agent
Asked whether the purists are right that AI shouldn't do all detection, Lewke conceded the point immediately:
"First of all, to your first question, like, is AI good for all sorts of detections? No. Okay. Absolutely not. Um, it's a non-deterministic system."
For command-line classification or service-account creation, "a good old-fashioned heuristic is so much better and cheaper," especially under token budgets. Nebulock has written publicly about using CatBoost for exactly this. The architecture he describes is a pipeline: detection rules, heuristics, and ML models extract signals deterministically, and an agent reasons across them into something a defender can act on. Detection engineering and data science stay; the agent sits above them.
6. Your first AI hunt should be a shadow AI hunt
For teams wanting a first, provable use case:
"So first AI use case, looking for shadow AI. Like, if you wanted to do this today, go on a shadow AI hunt. I promise you, you're going to find something."
MCP is the practical starting point because it runs in user space with clear-text commands. Baseline MCP process executions and child processes; if MCP is sanctioned, your codified use cases are the baseline and deviations are findings: node touching a credential, an abnormal tool call. This pairs directly with the week's news: the same baselining discipline that finds shadow AI is what catches a UAT-10147-style agentic operator moving at machine tempo.
7. Hunting AI agents inverts the old time-series heuristic: burst is the new tell
Lewke's DoD-era hunting exercise used time series to find humans: 20 to 30 seconds per command, typos, coffee breaks. Commands outside that envelope meant a sysadmin or an APT. Agents flip it: now compressed time and burst tempo are what's concerning. His favorite example:
"In general, sysadmins are not gonna spin up two or three new service accounts... in, in, in a minute... at 7:30 in the morning on a Wednesday."
"That is either an extremely efficient sysadmin... or it's probably an agent, and I'd be willing to bet it's an agent."
Attribution is where this pays off, and he is careful to strip the blame connotation from the word. The emergent-behavior case is the one to internalize: a sanctioned agent runs safely for weeks, then touches a production database because somewhere along the line its objective required prod data. "That's no one's fault. You were allowed to do it." Visibility and context are what let you explain it, and decide whether it matters that the operator was Damien in accounting.
8. The SIEM keeps the data-store job and loses the security jobs
On whether hunt-first economics eventually strand the SIEM, Lewke split the asset in two. Compliance and retention keep their center of data gravity. The security workloads move:
"I think the data store use case for the SIEM is still there, but I think all security use cases will shift off, and selfishly, I think that's exactly what we've built and what we're very well situated to do."
Note the disclosed self-interest: he says it himself. The architectural requirement he lays out is vendor-neutral, though: a normalized hot window across endpoint, identity, and cloud data that you can actually query, because SIEM economics make analytics, detection engineering, hunting, and investigation untenable at ingest prices. His image for scope creep: a surety-and-insurance colleague with production SIEM access: "what started as a shoebox has become a skyscraper."
9. Commoditized offense makes hunters more valuable, not less
Against the analyst narrative that AI erodes the threat hunting skill, Lewke's disagreement is direct ("Gartner, I completely disagree with you"), and his reasoning is about what hunting actually is. Query optimization was never the job. Meanwhile the offense side has changed:
"We're in a world where open-weights models are actively being distilled, and two dudes in a GPU can point their rig at an environment and go to town. ... So if you think about the skill sets, and let's be clear, no one's writing signatures or detections for this."
The stats he cites from the CrowdStrike threat report (malware-free intrusions at 82% of the total, up from 51% in 2020; AI-augmented or AI-generated attacks up 89% year over year) describe an attacker population whose commodity tier just got capable. His conclusion: alerts absorb the commodity layer, and what remains is exactly the work hunters are for. For practitioners feeling behind, his reassurance was the episode's most human moment: "Does everybody know something I don't? The answer is no. The cool thing about AI is we are all learning this at the same time."
Cisco Talos β UAT-10147 integrates agentic AI into post-compromise operations
Nebulock β Damien Lewke's hunt-first agentic security operations platform
Podcast Episode
Question for you? (Reply to this email)
π€ Have you run a shadow AI hunt in your environment yet, and what did it turn up?
Next week, we'll explore another critical aspect of cloud security. Stay tuned!
π¬ Want weekly expert takes on AI & Cloud Security? [Subscribe here]β
We would love to hear from youπ’ for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter.
Thank you for continuing to subscribe and Welcome to the new members in tis newsletter communityπ
Peace!
Was this forwarded to you? You can Sign up here, to join our growing readership.
Want to sponsor the next newsletter edition! Lets make it happen
Have you joined our FREE Monthly Cloud Security Bootcamp yet?
checkout our sister podcast AI Security Podcast
