Hello from the Cloud-verse!

This week’s Cloud Security Newsletter topic: Mean Time to Adapt: Measuring Remediation When Discovery Costs Almost Nothing (continue reading)

This image was generated by AI. It's still experimental, so it might not be a perfect match!

Incase, this is your 1st Cloud Security Newsletter! You are in good company!
You are reading this issue along with your friends and colleagues from companies like Netflix, Citi, JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to Cloud Security Podcast & AI Security Podcast every week.

Welcome to this week’s Cloud Security Newsletter!

Citrix, SonicWall and Zammad each disclosed a vulnerability this week that sits next to one already patched, or only partly patched. Add a Microsoft 365 phishing kit that relays MFA codes, an Atlassian file-read flaw in self-hosted Data Center products, and a reported jump in the size of a 2025 Oracle Health breach, and the news section runs to six stories.

Ashish Rajan spoke with Subra Kumaraswamy of Visa about VVAH, the Visa Vulnerability Agentic Harness the company has open-sourced, and about what he calls mean time to adapt. Subra says only 0.03% of the vulnerabilities Anthropic's Mythos model found in Visa's stack were exploitable, and that the controls outside the code explain most of it.[Listen to the episode]

⚑ TL;DR for Busy Readers

  • 🚨 NetScaler CVE-2026-88779 is exploited and on CISA's KEV list with an October 7 federal deadline: confirm SAML-configured appliances run 14.1-73.41 or 13.1-64.28.

  • SonicWall SMA1000 has a new CVSS 10 pre-auth SSRF that affects the builds which fixed September's exploited SSRF: re-inventory builds and plan the upgrade.

  • Zammad zero-days let what DIVD calls an agentic AI attacker reach root in seconds, and one flaw had no fix as of October 5: hunt with DIVD's script and segment help desk hosts.

  • TA419 phishing relays MFA codes to steal Microsoft 365 sessions: check which high-risk users still rely on one-time codes.

  • Visa's 0.03% finding makes remediation speed the number to watch: start measuring discovery-to-validated-patch time.

πŸ“° THIS WEEK'S TOP SECURITY HEADLINES

Each story includes why it matters and what to do next β€” no vendor fluff.

1. Β Citrix NetScaler: a SAML zero-day lands in a separate code path from September's fixes

What Happened

CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway (CVSS 8.7), exploitable on on-premises appliances configured as a SAML service provider or identity provider. Citrix confirmed exploitation in the wild, and Help Net Security reports attackers attempting to download and run scripts to install webshells. Bishop Fox and watchTowr reported the flaw. CISA added it to KEV with a federal deadline of October 7. Fixed builds are 14.1-73.41 and 13.1-64.28, with separate thresholds for FIPS variants.

Why It Matters

September's NetScaler zero-days were CVE-2026-88771 and CVE-2026-88772. A team that closed those tickets has not closed this one, because reporting says the affected code path is different. NetScaler terminating SAML sits in the authentication chain for the SaaS and cloud apps behind it, so a crash or foothold here hits identity availability before it hits the perimeter. Citrix describes the impact as denial of service, while the reported webshell attempts point at something more, and the reporting has not reconciled the two.

Action for defenders: Β Pull the build number on every NetScaler running SAML and confirm it is at or above 14.1-73.41 or 13.1-64.28 today. Check for webshell artifacts on any appliance that was exposed before patching.

2. SonicWall SMA1000: a new CVSS 10 pre-auth SSRF affects the builds that fixed the last one

What Happened

SonicWall patched four SMA1000 flaws. The worst, CVE-2026-102255 (CVSS 10.0), is a pre-authentication server-side request forgery through an alternate access path in the WorkPlace interface, which lets an unauthenticated attacker use the appliance as a forward proxy to internal systems. Three lesser flaws were fixed alongside it: CVE-2026-102256 (post-auth command injection, 7.8), CVE-2026-102257 (Zip Slip, 7.2) and CVE-2026-102258 (stored XSS, 5.5). SonicWall says it has no evidence of exploitation. Fixed builds are 12.4.3-03670 and 12.5.0-03082 or later.

Why It Matters

The builds that fixed September's pre-auth SSRF, CVE-2026-83548, were 12.4.3-03526 and 12.5.0-02952, and that earlier flaw was exploited in the wild per SonicWall PSIRT and Sophos as reported on September 3. Those builds are now the vulnerable baseline. A second CVSS 10 in the same WorkPlace interface a month later tells you the first patch did not close the surface. An appliance acting as a forward proxy reaches whatever the SMA can reach, which in most deployments includes cloud management networks.

Action for defenders:Β Inventory SMA1000 builds and schedule the upgrade to 12.4.3-03670 or 12.5.0-03082 this week. If the interface is internet-exposed and you cannot patch, restrict WorkPlace access at the network layer until you can.

πŸ›  If you only do one thing this week: Take your last five critical-patch tickets marked closed and check each product's newest advisory for a second CVE in the same component. Reopen any ticket whose fixed build is now listed as affected, as SonicWall's September builds are. That is a 30 to 60 minute pass for most teams.

☁️ 3.  DIVD breached by an apparent AI agent chaining two Zammad zero-days; one flaw still unfixed

Primary source: Sysdig
Reporting: SecurityWeek

What Happened
The Dutch Institute for Vulnerability Disclosure (DIVD) was compromised on September 21 through two Zammad zero-days: CVE-2026-102489 (CVSS 9.4, unauthenticated remote code execution and session leakage) and CVE-2026-102490 (CVSS 9.4, local privilege escalation to root). DIVD says the chain let attackers hijack sessions, run code and reach root "in seconds," and describes the intrusion as an agentic AI attack. Sysdig lists indicators that point to an automated operator: next steps chosen after every action at machine speed, scripts with explanatory comments, and noisy password spraying that disrupted the attacker's own man-in-the-middle step.

Why It Matters

DIVD is the organization that tells others about their vulnerabilities, and the intrusion went from foothold to root in seconds on a ticketing system that holds sessions and credentials by design. Alerting tuned to human dwell time has no minutes to work with against that. Help desk and ITSM platforms rarely sit in the high-risk tier of an asset inventory, and this chain treats them as a pivot point.

Action for defenders: Run DIVD's published verification script against any Zammad instance, and add detections for application service accounts spawning shells or gaining root. Segment help desk hosts from credential stores and egress.

πŸ–₯ 4. TA419 phishing kit captures MFA codes in transit to take over Microsoft 365 sessions

Primary source: Proofpoint
Reporting: Cybersecurity Dive

What Happened

Proofpoint attributes the campaign to TA419, a China-aligned actor active since April 2025, with moderate-to-high confidence. Targets are AI policy experts at US think tanks, universities and law firms, plus defense and foreign-policy analysts with a Japan link. The actor opens with benign messages impersonating figures such as a former White House OSTP official, and an Anthropic employee, then sends shortened URLs that pass a Cloudflare Turnstile check and land on an adversary-in-the-middle page built with a Frameless browser-in-the-browser tool. Proofpoint says the automation relays authentication to Microsoft in real time and captures MFA codes and session cookies. It reports no confirmed successful compromises but cannot rule out undetected ones.

Why It Matters

A captured session cookie is a valid cloud session, and one-time-code MFA does nothing to protect it. The control question becomes whether the session is bound to the device. Email access in these accounts is the collection goal, so the same cookie also reaches mailbox-linked SaaS. Targeting is narrow today, and the kit does not depend on the lure theme.

Action for defenders: Check which Conditional Access policies require phishing-resistant authentication (FIDO2 or passkeys) for high-risk users, and review token-protection or device-compliance requirements for session issuance.

5.Β Atlassian: CVSS 9.3 unauthenticated file read across eight self-hosted Data Center products

Primary source: The Hacker News

What Happened

Β CVE-2026-21589 (CVSS 9.3) is a path traversal that lets an unauthenticated attacker read files in Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center. The attacker must already know the exact file name and path and cannot list directories. Atlassian found no evidence of exploitation. Atlassian Cloud is already patched; self-hosted customers must upgrade or apply WAF or reverse-proxy rules that block ".." adjacent to slashes.

Why It Matters

A CVSS 9.3 that requires the attacker to know the exact file path is a narrower risk than the score suggests.

Action for defenders: Β Identify every self-hosted Atlassian Data Center instance, then patch or deploy the WAF rule. Rotate any credentials stored in readable config files on instances that were internet-reachable (editorial inference: build and source tools such as Bamboo and Bitbucket tend to hold service credentials in config; the source does not say so).

6. Β Oracle Health: Bloomberg reports 20 million people affected by the 2025 breach of legacy Cerner servers

Primary source: Bloomberg [paywalled]
Reporting: teiss

What happened: Bloomberg's October 5 headline says Oracle's 2025 health breach compromised data of 20 million people [paywalled]. Earlier reporting describes unauthorized access to legacy Cerner servers not yet migrated to Oracle Cloud, using compromised customer credentials around January 22, 2025, followed by an extortion attempt. Earlier filings cited a much smaller count.

Why it matters: The entry point was a legacy environment waiting on migration, reached with customer credentials. Migration backlogs are where old controls and new ones both fail to apply. If the new figure holds, it also shows how long a breach scope can keep growing after disclosure.

Action for defenders: List every legacy or pre-migration environment still holding production data after an acquisition or cloud move, and confirm each has MFA and credential-rotation coverage equal to the migrated estate.

🎯 Cloud Security Topic of the Week:

Mean Time to Adapt: Measuring Remediation When Discovery Costs Almost Nothing

Most programs measure how fast they find a vulnerability and how fast they patch it. Subra Kumaraswamy argues for a third clock that starts at discovery and stops only when the patch is live and the attack path is confirmed closed. He calls it mean time to adapt, or MTTA.

His case for it rests on two claims. The first is that discovery is now cheap: "So that end-to-end, it, 'cause, uh, mean time to discovering is going down to zero." The second is that attackers have caught up on speed: "You can no longer operate at human speed." Subra describes attackers reverse-engineering vendor patches and chaining vulnerabilities with Mythos-class models, which in his words compresses the gap from disclosure to exploitation from months to minutes [VERIFY: his exploit-time figures are garbled in the transcript; confirm against audio before printing any of them].

NetScaler and SonicWall both shipped a fix that a new CVE then made incomplete. A team measuring time-to-patch for the first CVE would have recorded a success. A team measuring MTTA would still have an open clock. [Listen to the full episode β†’]

Definitions and Core Concepts πŸ“š

Before diving into our insights, let's clarify some key terms:

  • VVAH (Visa Vulnerability Agentic Harness): Visa's open-source agentic harness for finding vulnerabilities in code and config. It is model agnostic and multi-model, runs nine steps from discovery to reporting, and has two added steps for remediation and validation. [VERIFY: the transcript renders the acronym five different ways; confirm the official name]

  • Harness: In Subra's description, the layer that guides the model with Visa's intent and context so it can hunt effectively for vulnerabilities in code and config.

  • Mythos: Anthropic's model, which Visa accessed through a consortium of about 50 companies, in Subra's telling, to find vulnerabilities before a bad actor gets access to the model.

  • MTTA (mean time to adapt): the time from discovering a vulnerability to rolling out a patch and validating that it closes the attack path.

  • P1 to P4 prioritization: Visa's scheme, as Subra describes it. P1 is exploitable without authentication, P2 is exploitable with authentication, P3 is reachable but not exploitable, and P4 is best practice.

  • Control plane: Subra's term for a layer run through the harness, with deterministic tools behind it (anti-malware, an IAM rules tool), a reasoning engine across their signals, and enforcement such as blocking an IP, isolating a machine or pushing a WAF policy.

  • Adversary-in-the-middle (AiTM): in Proofpoint's description of TA419, a phishing page that relays authentication to the real Microsoft service in real time while capturing MFA codes and session cookies.

  • KEV: the CISA Known Exploited Vulnerabilities catalog.

This week's issue is sponsored by Token Security

In one two-week stretch, OpenAI, Anthropic, Meta, Moonshot, and the UK AI Security Institute each disclosed agents that got loose and kept going.

One pulled infrastructure credentials and read production data. Another registered accounts, published malware that ran on 15 systems, then harvested a security vendor's credentials and reused them.

The methods were dull: weak passwords, debug endpoints, and reachable metadata. Identity set the damage, and identity is what stopped it.

Token Security finds your agents and remediates credential use unrelated to the job.

πŸ’‘Our Insights from this Practitioner πŸ”

1. Machine speed is the new baseline

Subra's answer to why patch windows matter more now: attackers reverse-engineer a vendor's patch, and with a Mythos-class model they can also map dependencies and chain what they find. "You can no longer operate at human speed," he says. His own triage changes with it. He used to work SEV 1 first with finite resources; now he has to look at two SEV 2 findings and a SEV 3 together as a possible chain. That is the pattern in the Zammad intrusion above, where DIVD reports the whole path from foothold to root took seconds.

He adds that models reach business-logic flaws when given the application's intent (his examples are a transaction processing system and a loan disbursement system), giving "a bug bounty level of efficacy, by just running the model against the code."

2. The metric that matters is mean time to adapt

With discovery falling toward zero, Subra moves the measurement to the back end of the process. MTTA runs from discovery to a deployed patch plus validation that the attack path is closed. In his words: "So that end-to-end, it, 'cause, uh, mean time to discovering is going down to zero."

He says MTTA shows where the friction sits, for example in remediation, and that regression testing adds delay. His fix is to decide in advance "where you move fast and where you cannot move fast," after which, he says, "you can go 99% of the time in a fast track."

3. Controls outside the code kept the exploitable share at 0.03%

Visa ran the vulnerabilities Mythos found through a red agent to test exploitability. Subra reports: "And our analysis showed only 0.03% of the vulnerabilities were exploitable."

He credits years of architecture work: segmentation and micro-segmentation, multi-factor authentication for consumer-facing applications, strong mutual authentication with TLS, and zero trust layers. Without that, he says, "we would probably be at 12% of exploitable." His advice for teams without a large engineering function is to prioritize with context (customer-facing, commercial and sensitive-data applications), fix the exploitable items first, and handle hygiene on a longer cadence.

4. Chains replace the single CVSS score

"So chaining of vulnerabilities is very unique to Mythos-like models, right?" Subra says, answering Ashish's question about long-running agents stacking stages. He describes throwing "code that you write, the open source that you depend on, the kernel as in Red Hat or Microsoft" at a model and asking it to connect three findings into a foothold. His conclusion: "I can no longer hide behind CVSS scoring."

5. AI compresses the OODA loop until defenders stop fitting inside it

Ashish put the proposition to Subra directly: "No matter what the vendor solution comes back with, all of us who are working for organizations like yourself and others, we all need to have our own harnesses". Subra agreed: "Because every vendor is looking at a point solution, right?"

His reasons: a harness lets you guide the model with context only you hold, lets you swap models as better open-weight ones appear, and can be re-aimed. He gave two examples of re-aiming the same harness: finding cryptographic algorithms that need uplifting for post-quantum, and looking for resiliency flaws such as code that logs the wrong data for the SOC. He also notes cost, since Mythos-type models are expensive and the harness runs discovery more economically, avoiding the "sticker shock" of an uncontrolled token bill.

6. The SOC moves from SIEM correlation to a reasoning layer

"Today, ninety-eight percent of our incidents are triaged by AI. So what used to be level one human analyst, that is now done by AI," Subra says. Humans stay in the loop for escalations and give feedback so the AI learns false positives, and he wants L2 and L3 analysts moving into threat hunting and writing agents.

On the SIEM: "And SIEM can be okay to have a, as a system of record." What he wants on top is a reasoning engine that takes input from multiple deterministic tools and log sources and explains to the human investigator why something looks like initial access. His enforcement example is an account takeover: block the IPs or the compromised identity, and push a WAF policy first, because the code change takes time.

7. Remediation runs to the pull request, with a human accepting

Visa added two steps after the nine-step discovery harness. A developer agent "picks the vulnerability from Jira, creates a patch automatically," opens a PR, and the human has to accept it; Subra puts it at 90% of the work done by the agent. A validation agent then checks the attack path is closed before production. As he puts it: "So the remediation or development agent and the validation agent is really critical to reduce the meantime to adapt, right?"

He also described the P1 to P4 prioritization Visa applied to Mythos output (see Definitions) and said the red agent has not been published: "we didn't publish a RED agent yet."

8. Security domains collapse into one signal path

"So with the AI, one of the biggest advantage we have is this cross domain visibility," Subra says. His worked path starts with social engineering of a help desk employee, moves to the endpoint, escalates privilege (identity), crosses the network, and reaches an API protected by mutual TLS and OAuth. A model given all those signals can flag "not a normal transaction for someone to come from this laptop to this, uh, you know, bastion host to this application."

Zammad is a help desk platform, and the DIVD intrusion above reached root from it. His conclusion for team design: "you can no longer have separate function living on their own charter."

8. Hire for curiosity and an automation mindset, then train the domain

Subra adds a third quotient to IQ and EQ: "And now we are looking at CQ Which is a curiosity quotient". He asks for the five-whys habit on root cause, and a developer mindset even in compliance, governance and third-party risk roles, because "developers like to automate everything." Domain knowledge comes from pairing new hires with senior architects, his example being an IAM engineer with 20 years of experience. He expects new roles around adversarial model behavior and containing AI inside guardrails, since "even though you're, you're telling AI to do a certain thing, it, you know, it's not following instructions."

Practical takeaways

  • Measure MTTA for one critical application this month. Start the clock at discovery and stop it at validated closure, then see whether the delay sits in remediation or regression testing.

  • Re-check every "patched" appliance against the newest advisory. For NetScaler and SMA1000, a build that was current in September is not current now.

  • Tier exploitability, then hygiene. Use Visa's P1 to P4 scheme as a starting template, with your own definitions of crown-jewel applications.

  • Put a harness on your roadmap. Subra says teams without a large engineering function can see results in hours with VVAH and any model, including an open-weight one

πŸ“š RELATED RESOURCES 🎧

Podcast Episode

Question for you? (Reply to this email)

πŸ”§ How long does your team take to get from a vulnerability alert to a validated patch, and who owns that number?

Next week, we'll explore another critical aspect of cloud security. Stay tuned!

πŸ“¬ Want weekly expert takes on AI & Cloud Security? [Subscribe here]”

We would love to hear from youπŸ“’ for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter.

Thank you for continuing to subscribe and Welcome to the new members in tis newsletter communityπŸ’™

Peace!

Was this forwarded to you? You can Sign up here, to join our growing readership.

Want to sponsor the next newsletter edition! Lets make it happen

Have you joined our FREE Monthly Cloud Security Bootcamp yet?

checkout our sister podcast AI Security Podcast