ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-05-05
▶The Wire — Daily Briefing

The Wire — Tuesday, May 5, 2026

The Enterprise Software Reckoning: When Legitimate Tools Become Weapons

32 stories analyzed

The Enterprise Software Reckoning: When Legitimate Tools Become Weapons

The attack surface just got a lot bigger, and it's not happening in dark corners of the internet. Over the past 24 hours, we've watched the security industry grapple with a pattern that should trouble every operations team: legitimate enterprise software—the kind your company depends on—has become the primary vector for widespread compromise. From accounting platforms to file transfer systems to remote management tools, attackers are trading zero-days and exploit chains for something far more reliable: the simple fact that nobody expects the mundane software to kill them.

The numbers tell the story. Over 40,000 servers have been compromised in ongoing cPanel exploitation, with the attack likely targeting a recently patched zero-day that grants administrative access. Hosting providers, government agencies, and MSPs across multiple continents are falling to the same vulnerability. Meanwhile, a separate critical flaw in Weaver E-cology—an office automation platform used by enterprise deployments across Asia—has been under active exploitation since March. The vulnerability, CVE-2026-22679, scores a catastrophic 9.8 on the CVSS scale and requires no authentication. It's the kind of flaw that should make security teams lose sleep.

But here's what should concern you even more: Progress has just disclosed a critical authentication bypass in MOVEit Automation, a managed file transfer solution trusted by thousands of organizations. Attackers don't need to break in anymore—they just need to walk through the front door that your legitimate enterprise software left unlocked.

The supply chain has become a carousel of compromise. We've now seen Trellix—a cybersecurity vendor that should know better—fall victim to a source code repository breach that resulted in a data breach affecting customer data. More troubling is the realization that compromised source repositories aren't just about stolen code; they're preparation for deeper attacks. Meanwhile, a backdoored version of PyTorch Lightning appeared on PyPI, stealing credentials from developers who believed they were installing a legitimate machine learning library. And DigiCert's customer support portal was breached through a simple social engineering attack—a malware-laden chat message to a support analyst opened the entire kingdom.

The supply chain isn't failing because of sophisticated zero-days in obscure dependencies. It's failing because the human elements—developer trust, support processes, update mechanisms—remain fundamentally broken.

Phishing, meanwhile, has evolved from a volume game into a precision weapon. Microsoft disclosed a campaign targeting 35,000 users across 26 countries, using code of conduct-themed lures to steal authentication tokens at scale. But the campaign that deserves your attention is the one targeting 80+ organizations with legitimate RMM tools. This isn't phishing in the traditional sense—it's weaponization of normal business tools. Attackers establish persistent access through SimpleHelp and ScreenConnect, tools your IT team probably uses to support your infrastructure. And Amazon SES is being increasingly abused to bypass security filters, turning one of the cloud's most trusted email services into a phishing platform.

The Silver Fox APT group has deployed a new malware family called ABCDoor across tax-themed campaigns targeting India and Russia, with over 1,600 socially engineered messages. Meanwhile, North Korea's APT37 has been pushing an Android backdoor called BirdCall through a compromised video game platform. These aren't isolated incidents—they're the opening moves of a year where AI-assisted attacks are moving from theory to practice. The story "2026: The Year of AI-Assisted Attacks" isn't prognostication; it's happening now.

There's a lurking second-order failure that most organizations haven't fully appreciated yet. Microsoft's April security updates are causing backup failures for third-party backup applications. This isn't just an inconvenience—it's a catastrophic vulnerability in the very systems designed to recover from the attacks we're discussing. Your organization is getting compromised, your updates are breaking your recovery mechanism, and the attackers know it. It's the security equivalent of discovering your fire suppression system is broken right after the arsonist leaves.

On the defensive side, there are small victories worth noting. A teenager alleged to be part of the Scattered Spider hacker group was arrested in Finland, and apparently couldn't resist bragging on Snapchat about it—a reminder that not all threat actors are operational security geniuses. OpenAI has rolled out advanced security features for ChatGPT accounts, and Cisco is moving to acquire Astrix Security to address the emerging problem of non-human identity risks, a category of threat that barely existed two years ago.

What we're seeing is a fundamental shift in the threat landscape. The fortress model of security—strong perimeter, trusted insiders, vetted software—is dead. We're now operating in an environment where the perimeter is dissolved, legitimate enterprise software is weaponized faster than it can be patched, and defenders are fighting an asymmetric war where they must be right 100 percent of the time while attackers only need to find one unlocked door.

The question for your organization isn't whether you'll be targeted by these attacks. The question is whether your backup strategy is actually resilient, whether your RMM tools are being monitored for suspicious activity, whether you're patching enterprise software as aggressively as you patch operating systems, and whether you're treating every supply chain dependency as a potential compromise vector. Because if today's threat landscape has taught us anything, it's that the next breach won't come through the sophisticated attack you've been preparing for. It'll come through the legitimate software everyone's using.

Key Takeaways

  • Enterprise software is the new primary attack surface: Over 40,000 servers compromised via cPanel, plus critical RCE flaws in Weaver E-cology and Progress MOVEit Automation. Patch enterprise platforms with the same urgency you apply to OS updates.
  • Supply chain compromise is pre-attack reconnaissance: Source code breaches at Trellix, backdoored PyTorch packages on PyPI, and DigiCert portal compromise indicate attackers are laying groundwork for deeper infiltration. Verify integrity of dependencies and vendor security posture continuously.
  • RMM tools and legitimate infrastructure are new attack vectors: 80+ organizations targeted via SimpleHelp and ScreenConnect; Amazon SES abused at scale. Monitor your own legitimate tools for anomalous administrative activity and unexpected remote sessions.
  • Backup systems are failing when you need them most: Microsoft April updates breaking backup applications creates a critical gap in disaster recovery exactly when ransomware and supply chain attacks are at their peak. Test your recovery procedures now, before an incident proves they don't work.

The Wire is HackWire's daily editorial briefing, published every morning.