#audit-trail
-
Coder registry compromise: the origin pool was the identity
Attackers joined the Cloudflare pool behind Coder's module registry and served credential-stealing Terraform modules. TLS held. The trust behind it didn't.
-
The agent handed over its API key, and the logs looked normal
Attackers prompted a METR agent into revealing its API key, then spent about $600,000 in model credits over three weeks inside normal-looking evaluation traffic.
-
Three unauthenticated CVSS 10s in the system that approves access
ServiceNow patched three unauthenticated CVSS 10.0 flaws. When the platform that records approvals is writable before login, its records become claims to verify.
-
The forged SAML login your logs will call legitimate
Actively exploited miniOrange SAML bypasses (CVE-2026-15981, CVE-2026-61979) forge admin logins the IdP never saw and version scanners called patched.
-
The audit log will say the admin did it
CISA's Metasys advisory (CVE-2026-34491) describes low-privilege XSS that executes in admin sessions. Every action it takes will be logged as the admin.
-
The passkeys held. The signals around them didn't.
Three August research releases defeated passkeys without breaking the cryptography. Each broke the plumbing around the key: logging, binding, and the audit trail.