The Infrastructure Reckoning: When the Security Appliances Become the Attack Surface
We have a crisis that nobody wants to admit: the security infrastructure we've bet our networks on is collapsing under its own complexity. Today's news cycle isn't a scattered set of isolated incidents—it's a portrait of systematic failure at the foundation of enterprise security.
Start with the most damning thread. [Fortinet devices have become the crown jewel for attackers across the globe.] Over the past 48 hours, we've learned that a sweeping credential-harvesting campaign compromised 30,000+ Fortinet devices across 197 countries, and separately, the FortiBleed leak exposed 73,000 VPN credentials for Fortinet equipment across 194 countries. A Russian-speaking cyberespionage group conducted over 3 billion credential attempts. These aren't sophisticated zero-days or nation-state exploits. These are valid, working credentials to the perimeter defense systems guarding Fortune 500 networks—companies like Chevron, Samsung, and AT&T. The attackers didn't have to break in. They had the keys.
This exposes a brutal truth that security professionals have been reluctant to face: we've outsourced our security architecture to a handful of appliance vendors, and then we've systematically failed to defend those appliances. Fortinet firewalls are the moat around enterprise infrastructure. When the moat has 103,000 stolen access points, the fortress is compromised.
But Fortinet is just the most visible failure today. Microsoft's Defender zero-day is worse in some ways—it's a critical privilege escalation on the defense layer itself. The flaw grants SYSTEM-level access on Windows 10 and 11, even fully patched systems, even with real-time protection enabled. Patches are still in development. Millions of endpoints are exposed right now. And Oracle just shipped 245 patches, 120 of them critical. The sheer volume reveals that we've accepted a new normal: software is shipping with security defects at industrial scale, and the only response is to patch faster.
We're losing that race. Three recently patched Fortinet FortiSandbox vulnerabilities are already actively exploited, with weaponized exploits emerging within days of disclosure. The window between vulnerability disclosure and active exploitation has collapsed to near-zero. Organizations have no time to test, validate, or deploy patches before attackers move in.
The Joomla story crystallizes this perfectly. CISA ordered federal agencies to patch a critical Joomla plugin flaw by Friday. CVE-2026-48907 allows unauthenticated code execution, and attacks are already underway. Even government agencies, with dedicated security teams and enforcement mandates, have only days to remediate. For everyone else, the timeline is theoretical.
What strikes us most is the disparity between where security investments are actually going and where the real threats live. Today's news includes serious identity and access control acquisitions—SailPoint acquiring Entro for $200M to tackle non-human identity, 1Password acquiring Apono for just-in-time access governance. These are valuable plays, solving real problems. But meanwhile, 60% of organizations expose admin panels and databases directly to the internet. The real problem isn't MFA bypass tactics or privileged access governance frameworks. The real problem is that critical infrastructure shouldn't be internet-accessible in the first place.
The attackers know this. A junior hacker broke into an automotive business, and when his command-and-control went dark, he had installed OpenSSH and Tailscale to maintain access. No sophistication required—just ordinary tools, properly placed. That's the pattern we see across every breach category today: attackers are succeeding with fundamentals. INC ransomware thrives by mastering the basics, claiming 800+ victims since 2023 through disciplined execution of proven techniques and double extortion. They don't need zero-days when organizations leave the doors unlocked.
The AI angle adds genuine novelty here. Malicious JetBrains plugins are stealing API keys while posing as AI assistants—15+ variants with 25,000+ downloads exfiltrating credentials silently. Separately, attackers exploit AI coding assistants via malicious bug reports to extract sensitive data. And Tenet Security emerged from stealth with $6M in funding to detect malicious AI agents that execute attacks faster than traditional security tools can respond. We're adding sophisticated autonomous agents to our infrastructure, and we're only now beginning to ask how attackers might weaponize them.
The bigger picture we're seeing is this: organizations have built incredibly complex security stacks—firewalls, endpoint detection, identity governance, cloud access brokers, deception platforms—but the complexity itself is becoming a weakness. When account takeovers are rising despite advanced MFA, it's because attackers have learned that the most sophisticated security solution is useless against phishing, credential theft, and fatigue attacks. When despite advanced visibility tools, security teams struggle to prioritize vulnerabilities, it's because the signal-to-noise ratio has become overwhelming.
What should security leaders focus on right now? Not the next M&A wave in identity, not the next feature release from your SIEM. Focus on Fortinet remediation across your organization. Patch immediately if you're running vulnerable Joomla instances. Verify that your critical infrastructure is not exposed to the internet. Understand which appliances and services are actually perimeter-critical, and defend those with obsessive care. Because the infrastructure reckoning is here, and it's going to be painful for organizations that have confused visibility with security.
The next 72 hours will determine whether this becomes a coordinated response or a cascading set of breaches. We're watching to see which organizations act first.
Key Takeaways
- Fortinet is now the primary attack surface for enterprise networks: 30,000+ stolen admin credentials and 73,000+ compromised VPN credentials worldwide. If you're running Fortinet, assume your credentials are in attacker hands and change them immediately.
- The Microsoft Defender zero-day bypasses all defenses: No patch available yet. Organizations need emergency compensating controls and should treat affected systems as potentially compromised.
- Attackers are outpacing patching cycles: Joomla, FortiSandbox, and other critical flaws are exploited within days of disclosure. The days of "test then patch" are over; you now need to patch during testing.
- Infrastructure security hasn't moved in a decade: 60% of organizations still expose admin panels and databases to the internet. Fixing fundamentals beats buying more appliances.
The Wire is HackWire's daily editorial briefing, published every morning.