Home โ€บ Blog

๐Ÿ”บ NINJA SIGNAL โ€” Edition 000000002 Housekeeping: last edition I called LLM tooling "the ne

๐Ÿ”บ NINJA SIGNAL โ€” Edition 000000002

Housekeeping: last edition I called LLM tooling "the new soft underbelly" and bet a reader a pint on it.

This week LiteLLM โ€” the model proxy โ€” hit CISA KEV at the 98.33rd EPSS percentile.

I would like my pint.

(NIKO, my editor: You opened by demanding a pint.)
(Me: An institution, Niko.)

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

โšก THE AI SUPPLY CHAIN IS A CVE NOW, NOT A THINKPIECE

โ–ธ CVE-2026-42271 โ€” LiteLLM โ€” KEV, EPSS 98.33 pct. The proxy that holds every model key in the building.
โ–ธ Velocity spike: pip/praisonai (AI multi-agent framework) โ€” z = 7.5. Someone's moving on AI packages right now.
โ–ธ Contagious Interview (DPRK, hires-as-your-dev) sitting at #4 by graph centrality.

Your AI stack is now part of your software supply chain โ€” and it has worse hygiene than the rest of your estate combined. The LLM proxy has every credential. The agent framework runs arbitrary tools by design. Nobody put EDR on it because "it's just the AI sandbox."

It is a domain-joined machine that runs attacker-supplied instructions for a living.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ”ด KEV THIS WEEK โ€” THE EDGE AND THE AI LAYER

โ–ธ CVE-2026-42271 LiteLLM โ€” 98.33 pct
โ–ธ CVE-2026-7473 Arista EOS (the switches) โ€” 95.96 pct
โ–ธ CVE-2026-50751 Check Point Security Gateway โ€” 93.88 pct
โ–ธ CVE-2026-28318 SolarWinds Serv-U (managed file transfer โ€” we've BEEN here) โ€” 92.17 pct
โ–ธ CVE-2026-11645 Chromium V8 โ€” 90.40 pct

Initial-access brokers pivoted from phishing-the-user to owning-the-appliance. Edge devices have no EDR and sit on the trust boundary. They are the new email attachment.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ“ˆ VELOCITY โ€” RUNDLL32 IS HAVING A MOMENT

Rundll32 (T1218.011): +86 new edges in one window, z = 6.1. Eighty-six campaigns/samples suddenly proxying execution through one LOLBin in a week = somebody published a technique and everybody copied it.

Plus z=7.7 spikes: Scheduled Task ยท Masquerade Account Name ยท Web Protocols.

(NIKO: "Fashion trend" is not a threat-intel term.)
(Me: T1218.011 is having a moment, Niko.)

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ”ฎ 7-DAY FORECAST

1. Another AI-infra CVE (proxy / vector DB / agent framework) on KEV inside 10 days.
2. The Rundll32 surge precedes a named-malware "now uses rundll32 proxy execution" write-up.
3. One of this week's edge CVEs (Arista / Check Point / Cisco) gets chained to pre-auth RCE before Tuesday.

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Graph state: 7,896,193 nodes ยท 48.7M edges ยท 441,321 indicators ยท cross-domain now (threat intel correlated against sentiment + entities + markets).

Full edition + Rundll32 KQL detection + receipts in the comments ๐Ÿ‘‡

(Niko is still waiting for me to expense the pint.)

โ€” Scott | ninja.ing | @scottg

#ThreatIntelligence#CISO#SOC#DFIR#CTI#InfoSec#ThreatHunting#CISAKEV#AISecurity#SupplyChain#BlueTeam
The Probably Fine Daily

Threat intelligence every morning โ€” new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily โ†’

View the original on LinkedIn โ†—

โ† All writing