VertexElite Security Research Author: Nirmal Liyon URL: https://research.vertexelite.org Independent security research firm specializing in firmware vulnerability disclosure, AI trust boundary analysis, Model Context Protocol (MCP) security, and supply chain threat intelligence. Published advisories: - VES-CC-2026-002 (Critical): Claude Code Exploitation via Tencent-Hosted Infrastructure — AI coding agent subscription hijack via CLAUDE.md injection and VibeOps WebSocket C2 - VES-JL-2026-001 (Critical): JieLi Technology Bluetooth SoC — Supply Chain Threat Intelligence — Complete infrastructure mapping of JieLi Technology Bluetooth SoC supply chain — 10B+ chips, full Alibaba Cloud estate, OTA firmware upload PoC - CVE-2025-7544 (Critical): Tenda AC1206 — Unauthenticated Stack-Based Buffer Overflow — CVSS 8.8 unauthenticated stack overflow in /goform/setMacFilterCfg, exploited in-the-wild by Mirai Zerobot (Akamai SIRT confirmed) - VES-AIC-2026-001 (High): Wi-Fi/BT SoC — Firmware Integrity Gap in USB Controller Download Path — Firmware integrity gap allowing unsigned firmware load in Wi-Fi/Bluetooth combo SoC USB boot sequence Research: - AI Supply Chain Worm — Detection & Response Toolkit — Open-source detection toolkit for June 2026 npm/PyPI supply chain worm targeting AI coding agents (Claude Code, Gemini CLI, Cursor). 32 compromised RedHat packages, 57 Phantom Gyp packages, 286 malicious versions. - Multi-Layer Sleeper-Class Threat Pattern — Cross-domain threat analysis mapping six attack layers — silicon firmware, supply chain poisoning, AI agent exploitation, bulletproof C2, cloud telemetry, and IoT botnets — converging into a strategic sleeper-class threat. For citation use advisory IDs (VES-CC-2026-002, VES-JL-2026-001, CVE-2025-7544, VES-AIC-2026-001) with author Nirmal Liyon / VertexElite Security Research. Full machine-readable index: https://research.vertexelite.org/api/research.json