ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-05-20
▶The Wire — Daily Briefing

The Wire — Wednesday, May 20, 2026

When Vulnerability Becomes the Default Attack Vector

43 stories analyzed

When Vulnerability Becomes the Default Attack Vector

The year 2026 will be remembered not for any single breach, but for the moment the entire threat model flipped. This week, Verizon's Data Breach Investigations Report confirmed what we've suspected: vulnerability exploitation has overtaken credential theft as the leading breach vector. We are not watching this shift happen in theory. We are watching it cascade in real time across supply chains, platforms, and developer tools with a coordinated intensity that demands our immediate attention.

The evidence is stacking up faster than patches can be released. GitHub's internal repositories—the code vaults of a global platform trusted by millions—have now been breached through at least three separate vectors in as many days. An unnamed malicious VSCode extension compromised roughly 3,800 internal repositories. Simultaneously, threat actor group TeamPCP claimed access to approximately 4,000 repositories. Then Grafana's breach exposed source code through a compromised TanStack npm package—a third supply chain collapse in the developer ecosystem in days. These are not isolated incidents. They are the pattern.

What makes this moment instructive is not the breaches themselves, but what they expose: the brittleness of the supply chain when vulnerability density meets exploitation velocity. Attackers are no longer hoping to steal credentials or social-engineer their way past MFA. They are finding unpatched systems, exploiting them before patches even exist, and moving laterally through codebases that developers themselves depend on. The math is simple: why invest in credential theft when a max-severity flaw in ChromaDB allows unauthenticated server takeover, when Drupal will patch a critical flaw so urgent it could be exploited within hours, when Linux kernel vulnerabilities have proof-of-concept exploits within days?

The vulnerability barrage is relentless and distributed. Windows zero-days continue to arrive in waves. Industrial control systems are all exposed: ZKTeco CCTV cameras, ABB building controllers, ScadaBR SCADA systems, and Kieback & Peter DDC building controllers all carry critical flaws. SEPPMail email gateways face remote code execution vulnerabilities. Microsoft's critical vulnerability count has doubled year-over-year according to analysts reviewing privilege escalation and identity abuse patterns. The vulnerability supply is not merely high—it is becoming the default attack surface.

Yet beneath this wave of technical vulnerabilities runs a second current: the economic incentive driving attackers to exploit them faster. The FBI's warning that ShinyHunters may continue targeting students and staff after receiving a ransom payment for the Canvas breach signals a hard truth. Ransom works. This week, 7-Eleven confirmed the ShinyHunters attack that was claimed last month. When extortion gangs are paid, they scale. Microsoft disrupted the Fox Tempest malware-signing service distributing ransomware as legitimate software, but the economic model simply migrates. The B1ack's Stash marketplace giving away 4.6 million stolen credit cards signals a shift in how cybercrime ecosystems value data—when reputation or volume matters more than individual transaction profit, free releases become a tool for market dominance.

Developer tooling has become the new front line of this economic warfare. A malware wave compromised over 600 npm packages in the Shai-Hulud campaign. The Nx Console extension, used by thousands of developers, was compromised to steal credentials. Popular GitHub Actions tags were redirected to attacker-controlled repositories to harvest CI/CD credentials. The logic is obvious: compromise one developer tool and you gain access to thousands of downstream environments. It is leverage at scale. And it is working.

Authentication itself is becoming a weaker defense as attackers exploit the human factor in identity consent. EvilTokens, a phishing-as-a-service platform, compromised over 340 Microsoft 365 organizations in five weeks by spoofing OAuth consent prompts. The attack bypasses MFA entirely because the victim is willingly granting permission. Similarly, Microsoft Self-Service Password Reset is being abused in Azure data theft attacks. The pattern is inescapable: when technical controls fail, attackers move to social engineering and consent-based identity theft. And when identity is compromised, MFA becomes irrelevant.

There are glimmers of progress. Discord has rolled out end-to-end encryption on all voice and video calls. Law enforcement collaboration is expanding, with Interpol's Operation Ramz bringing together 13 countries in the MENA region to fight cybercrime. But these moves feel incremental against the scale of the problem.

What we are witnessing is the maturation of a new attack paradigm: attackers no longer need to target the strongest link in the chain. They can exploit the weakest. They can distribute the attack surface across thousands of npm packages, VSCode extensions, GitHub Actions, and unpatched industrial control systems. The Verizon DBIR validates what the week's headlines make visceral: vulnerability has become the default attack vector not because it is new, but because it is abundant, accessible, and faster to exploit than ever before. For security teams, the question is no longer whether vulnerabilities exist in your infrastructure. They do. The question is where in your supply chain the exploit will land first, and what you will do when it does.

Key Takeaways

  • Vulnerability exploitation has replaced credential theft as the #1 breach vector. The shift from identity-based attacks to vulnerability-based attacks is now systemic. Patch velocity, not prevention, is the competitive advantage.
  • Developer tools and supply chains are under coordinated siege. 600+ npm packages, compromised extensions, and CI/CD credential theft demonstrate attackers targeting leverage points—not endpoints, but pipelines.
  • Extortion economics create reinforcing feedback loops. When ShinyHunters are paid, more attacks follow. The economic incentive amplifies the technical opportunity.
  • Identity consent-based attacks have made MFA obsolete as a standalone defense. OAuth phishing and SSPR abuse bypass second factors entirely. Human authorization matters more than technical authentication.

The Wire is HackWire's daily editorial briefing, published every morning.