ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-06-14
▶The Wire — Daily Briefing

The Wire — Sunday, June 14, 2026

When Access is Everything: A Day Where Threats Span Decades, Supply Chains, and Policy

6 stories analyzed

When Access is Everything: A Day Where Threats Span Decades, Supply Chains, and Policy

The security landscape shifted noticeably this week, and not in the direction we hoped. Today's news cycle reveals a hard truth: attackers—whether acting as scorned insiders, nation-states, or exploiting unpatched systems—understand that persistence matters far more than noise. And increasingly, they're willing to stay invisible for years to prove it.

The most sobering story of the day comes from federal investigators who uncovered Chinese hackers hijacking auth flow, spying on isolated network for a decade. A decade. Operation Highland maintained undetected access to critical infrastructure by compromising the authentication layer itself—the very system designed to keep them out. The attackers bypassed air-gap protections, collected administrative credentials, and maintained complete visibility into network operations. For ten years. The implications are staggering: if this happened to one critical infrastructure target, how many others remain undiscovered? This isn't about a missing patch or a forgotten password. This is about an entire class of sophisticated threats that understand that remaining invisible is worth more than any immediate destructive attack.

That same logic explains why an ex-school district employee jailed for hacks on former employer stayed active for a full year after losing legitimate access. Ezekiel Potter's year-long campaign destroyed accounts, disabled educational platforms, and caused tens of thousands in damage—but more importantly, it demonstrates the organizational blind spot that haunts most enterprises: credential lifecycle management. He had access. He left. He kept using it. The difference between Potter's 21-month sentence and the apparent freedom of the Highland operators is merely jurisdiction and discovery, not sophistication. Both understood that retained credentials are an asset worth exploiting methodically.

These two stories—one domestic, one geopolitical—underscore why the ecosystem is finally moving. NPM 12 will change script execution behavior to prevent supply chain attacks, marking a significant inflection in how we manage trust at the dependency level. The JavaScript ecosystem has been the canary in the coal mine for supply chain compromise. Malware like Shai-Hulud and TeamPCP exploited automatic script execution to bootstrap installations into hostile environments. NPM 12's shift to disable automatic scripts by default is a rational response to a clear threat pattern. It's not perfect—it will break workflows and require developer discipline—but it reflects a maturation: we're finally asking "should we run this automatically?" instead of assuming we should.

That same question applies to critical infrastructure monitoring. The critical Splunk Enterprise flaw allowing unauthenticated remote code execution (CVE-2026-20253, CVSS 9.8) is precisely the kind of vulnerability that Operation Highland would have weaponized had they found it first. Splunk runs in thousands of enterprise deployments, often in high-security environments where it serves as the single source of truth for system and security events. An attacker gaining RCE on Splunk doesn't just get access to the system—they get access to the visibility layer, the ability to see what defenders are seeing, and the power to corrupt the historical record. This isn't a hypothetical. This is an active threat against every organization that hasn't patched yet. The urgency here cannot be overstated.

But perhaps the story that will reshape the industry most directly isn't a breach or a vulnerability—it's policy. This week, the US government ordered Anthropic to disable Fable 5 and Mythos 5 on the grounds of export controls affecting foreign nationals. Anthropic complied, taking the models offline globally just three days into their free rollout. This is a watershed moment in how we think about security and sovereignty. The immediate impact is commercial disruption—Anthropic's business plans upended, developer workflows interrupted, competitive positioning damaged. But the deeper impact is on the nature of "security threat." For the first time, an entire class of technology has been removed from the public internet not because it was found to be malicious, but because policymakers determined that its capabilities in the wrong hands constitute a national security risk. Whether you agree with the specific policy, the precedent is now set: government agencies will intervene directly in product launches to prevent capability transfer.

This creates a new category of risk that security teams must monitor: not just technical vulnerabilities or operational compromises, but regulatory disruption. Your critical dependencies could be taken offline tomorrow if policy winds shift. Your vendor relationships now include a geopolitical vector you cannot control.

Our analysis shows that these six stories aren't disconnected incidents—they're indicators of an evolving threat environment where access is the ultimate asset, whether you're an insider with retained credentials, a nation-state with decade-long patience, a supply chain attacker seeking automation, or a policymaker seeking to restrict capability. The common thread is control: whoever controls access controls the outcome. The question for security professionals isn't just "how do we prevent breaches?" anymore. It's "how do we manage access across technical, organizational, and now geopolitical dimensions?"

Watch this space. The converging pressures—escalating insider threats, nation-state persistence, supply chain vulnerability, critical infrastructure exposure, and now direct regulatory intervention—are reshaping how we think about defense. The winners will be organizations that treat access control not as an IT function but as a core business strategy.

Key Takeaways

  • Credential lifecycle is now a critical infrastructure issue. The decade-long Operation Highland and the Potter case show that retained or poorly-managed credentials are the most dangerous asset in your environment. Audit your access control procedures today.
  • Supply chain discipline is moving from "nice to have" to "required." NPM 12's shift reflects industry acceptance that automation without verification is now a liability vector. Plan for tools and workflows that require explicit consent.
  • Critical infrastructure monitoring systems are high-value targets. Splunk's RCE vulnerability (CVSS 9.8) affects your visibility layer. Treating observability tools as security-critical, not utility-grade, is now essential.
  • Regulatory risk is a security risk. The Anthropic policy enforcement shows that government can reshape your technology stack overnight. Diversify dependencies, monitor policy shifts in your sector, and assume your critical tools could be disrupted for reasons outside your control.

The Wire is HackWire's daily editorial briefing, published every morning.