ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-05-22
▶The Wire — Daily Briefing

The Wire — Friday, May 22, 2026

When the Offensive Meets the Defensive: A Week of Takedowns, Supply Chain Reckoning, and a Shifting Threat Landscape

38 stories analyzed

When the Offensive Meets the Defensive: A Week of Takedowns, Supply Chain Reckoning, and a Shifting Threat Landscape

We're witnessing a rare convergence this week. On one side, international law enforcement has achieved a string of victories that matter: a cybercrime VPN service dismantled, a prolific botnet operator in custody, and ransomware infrastructure crumbling. On the other side, attackers are moving faster than defenders can patch, supply chains are hemorrhaging secrets, and the fundamental nature of how organizations get breached is changing faster than our incident response playbooks can keep up.

The week's opening act belongs to law enforcement. First VPN, a service used by dozens of ransomware gangs for network reconnaissance and staging attacks, has been seized in a joint international operation, and a 23-year-old Canadian man operating the Kimwolf DDoS botnet—which infected nearly two million devices worldwide—has been arrested and charged. These aren't niche operations. First VPN was instrumental in major data theft campaigns. Kimwolf alone generated months of coordinated DDoS attacks across critical infrastructure. When infrastructure this large falls, it matters. It signals that the cost of conducting business as a cybercriminal is increasing, and that international coordination—particularly between the U.S., Canada, and European authorities—is becoming more effective.

But here's the uncomfortable truth: these victories are tactical wins in a strategic rearguard action. The same week that law enforcement takes down Kimwolf, attackers are successfully exploiting fresh supply chain vulnerabilities that will live in production environments for months. The TanStack npm package compromise wasn't just an isolated incident. It compromised Grafana's codebase and internal repositories. It gave attackers access to 3,800 GitHub repositories via a backdoored Nx Console VS Code extension. The fact that Grafana—a company of security engineers—didn't rotate tokens after the initial compromise tells us something critical: even fortress organizations with mature security programs are failing basic credential hygiene. This is the cost of complexity. Every team manages dozens of external packages, tokens, and access points. Rotation becomes reactive, not preventive.

What's instructive is the market response. Socket just raised $60 million to address supply chain security, and they're not alone. The capital flowing into supply chain security tools reflects an industry-wide acknowledgment: we've lost visibility into our dependencies, and the time between discovery and exploitation is collapsing. Yet even as companies throw money at the problem, the fundamentals remain: too many vulnerabilities, too little time, and not enough visibility.

This brings us to the critical patch cascade. Multiple CVSS 10.0 and highly critical vulnerabilities demand action this week. Cisco's Secure Workload REST API vulnerability—with no authentication required—grants Site Admin privileges. Drupal released a critical patch for CVE-2026-9082 enabling unauthenticated remote code execution. Trend Micro's Apex One zero-day is already being exploited in the wild, and CISA has added it to the Known Exploited Vulnerabilities catalog. Microsoft disclosed two Defender vulnerabilities under active exploitation. And in a reminder that old code can become suddenly dangerous, researchers disclosed a nine-year-old Linux kernel vulnerability that enables root execution across major distributions. This is the triage nightmare security teams are living: patch prioritization has become impossible when every vendor releases maximum-severity flaws simultaneously.

Beneath these individual vulnerabilities runs a deeper current. Sophisticated nation-states are operating with the assumption that perimeter defense is already compromised. China's Webworm APT is hacking EU government entities by abusing Discord and Microsoft Graph, converting legitimate productivity tools into command-and-control channels. Chinese attackers are targeting telecommunications providers in Central Asia with new Linux and Windows malware, specifically Showboat and JFMBackdoor, designed to establish persistent backdoors. These aren't flashy operations. They're patient, they're using tools we already trust, and they're designed to stay undetected for years.

But perhaps the most consequential shift this week came quietly: Verizon's Data Breach Investigations Report shows that stolen credentials are no longer the primary entry point for attackers. For nearly twenty years, "use the creds" was the attack script. Now the landscape has fractured. Attackers are pivoting to identity-based approaches, abusing cached AWS keys on Windows machines and legitimate API tokens. Crypto drainers don't steal wallets—they trick users into approving malicious transactions. Fake Android apps are doing carrier billing fraud. The common thread isn't one technique—it's social engineering at scale, automation, and the weaponization of user trust in systems they interact with daily.

The industry's response to this shift is worth watching. CISO budgets are being redrawn around agentic AI security, and companies like Ocean are raising $28 million to deploy specialized AI agents that inspect every incoming email. There's an implicit acknowledgment here: human-paced detection is dead. If attackers are using automation and social engineering at scale, defenders need agentic systems that can operate at comparable speed and sophistication.

We're entering a period where the old playbook—patch faster, use stronger credentials, deploy endpoint detection—is necessary but no longer sufficient. Law enforcement victories are welcome, but they're asymptotic gains against a fundamentally asymmetric problem. The economics of offense remain heavily weighted toward attackers. The patch avalanche will continue. Supply chains will remain brittle. Nation-states will keep operating with patient sophistication.

What we should be watching: whether the budgetary shift toward agentic security actually changes the detection timeline. Whether organizations can absorb the current patch load without creating new vulnerabilities. And whether supply chain tools can move from detection to real-time prevention before the next TanStack event.

Key Takeaways

  • Law enforcement is winning battles but losing the war: Major cybercrime infrastructure takedowns (First VPN, Kimwolf) demonstrate effective international coordination, but attackers are moving to supply chain compromises that bypass traditional defenses—and they're not rotating stolen credentials.
  • Patch velocity is now a risk vector: The coincidence of CVSS 10.0 flaws (Cisco, Drupal, Trend Micro) plus actively exploited zero-days across Apex One and Defender means triage is broken; prioritize by exposure surface first, severity second.
  • Identity is the new perimeter: Credentials no longer lead breaches—cached tokens, API keys, and user-approved transactions do. Defenders must shift from "defend the password" to "defend the trust decision."
  • AI agents are no longer theoretical: With Ocean's $28M funding and CISO budgets reshuffling toward agentic email security, the industry is betting that human-speed incident response is obsolete; watch whether agentic detection actually closes the attack timeline.

The Wire is HackWire's daily editorial briefing, published every morning.