"The FBI is out with a report that says we should not let AI security concerns distract from using basic cybersecurity hygiene. I agree, and it's a conversation I've had with many customers over the last few months. The basics matter more than ever. It doesn't matter if malware was created by a person or AI, it executes the same, and allowlisting stops both." - Danny Jenkins
From the ThreatLocker blog
The patching window is also the attack window
When a vulnerability is disclosed, defenders are not the only ones paying attention.
Weaponization of a CVE often follows a recognizable pattern. Attackers monitor new disclosures, compare vulnerable and patched code, and attempt to reproduce flaws before organizations can finish patching. In some cases, the patch itself can provide clues about how the vulnerability works.
Patching is essential, but it can't be relied upon alone.
How compromising one pipeline can open multiple paths to sensitive systems
CI/CD pipelines connect source code, build systems, credentials, cloud infrastructure, and production environments, making pipelines a valuable target for attackers. A compromised pipeline can expose deployment credentials and source code or provide a path into production.
From there, attackers may be able to modify code, inject malware into builds, distribute compromised packages downstream, or establish persistence.
Phishing remains the leading initial access vector
And AI is giving attackers more ways to make it work
Phishing is so much more than emails. Attackers now use malicious QR codes, text messages, SEO poisoning, and deepfake voices and videos to trick users. Despite years of awareness training and expensive security tooling, phishing remains effective because it targets people rather than software vulnerabilities.
Defenders can't eliminate every phishing attempt, making prevention and containment critical.
Malicious npm package poses as Twilio bug-bounty probe
The package was first published in August with 11 versions published in quick succession
What's happening: Researchers discovered a malicious npm package, tw-pkgprobe-7731, posing as an authorized Twilio bug-bounty research tool. Certain versions targeted Twilio developer environments, collected system information and environment variables, and could exfiltrate Twilio account SIDs and authentication tokens, potentially giving attackers access to victim accounts.
What defenders need to know: Organizations should scrutinize third-party packages before use, restrict access to secrets and environment variables, and rotate credentials if a potentially malicious package has been executed.
cPanel fixes three newly disclosed vulnerabilities
A hosting account could be enough to escalate to root
What's happening: cPanel disclosed CVE-2026-87899 which allows an authenticated hosting account to execute code as root and potentially take full control of a shared server. They disclosed two additional flaws affecting the WP Toolkit and WHM version 120 or later that could allow users to modify databases belonging to other accounts or access other users’ calendar and contact data. cPanel has released fixes for all three vulnerabilities.
What defenders need to know: Organizations using cPanel should update cPanel & WHM and WP Toolkit to patched versions as soon as possible. Because the most severe flaw only requires access to a hosting account, a compromised customer credential could potentially become a path to root-level control of the entire server.
Meet ThreatLocker near you next week
Dublin·Orlando· London · Denver· Manchester · Vancouver