ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-06-19
▶The Wire — Daily Briefing

The Wire — Friday, June 19, 2026

When Your Vendors Become Your Vulnerabilities

47 stories analyzed

When Your Vendors Become Your Vulnerabilities

The security industry's dirty secret is now impossible to hide: the companies charged with protecting enterprise data are themselves becoming the weakest link in their customers' security posture. This week's cascade of supply chain compromises—beginning with Klue's OAuth breach that exposed Salesforce data from security firms Huntress and Recorded Future—reveals a structural problem far more damaging than any individual zero-day vulnerability. We are witnessing the collapse of trust-based security models, replaced by a harsh reality: every third-party integration is a potential foothold for attackers, and the vendors themselves are often the last to know they've been compromised.

The Klue incident cuts deeper than typical vendor breaches. Here, attackers weaponized a single compromised OAuth credential to harvest customer relationship management data directly from the firms that should be most paranoid about such exposures. The security vendors themselves were the victims, yet the attack succeeded because their trust in Klue's integrity—and their reliance on OAuth for seamless integrations—overrode basic defensive assumptions. This isn't a failure of individual companies; it's a systemic breakdown of the assumption that "trusted" vendors can be integrated without friction. The moment Salesforce disabled the Klue integration, thousands of other SaaS-dependent organizations faced an uncomfortable question: which of our integrations are silently compromised right now?

The pattern repeated throughout the week confirms this is no aberration. ShapedPlugin's premium WordPress plugins were compromised via supply chain attack, infecting paying customers through ostensibly legitimate updates. The Nintendo breach via TinyPulse shows that even consumer-facing tech companies operate with surprising vendor fragility. What unites these incidents is a common thread: attackers are no longer breaking into networks through code flaws—they're walking in through the front door using vendor credentials and trusted update channels.

Yet beneath every supply chain compromise lies an even more fundamental failure: broken identity and access hygiene. The FortiBleed leak exposed 74,000 Fortinet credentials in a single dataset, yet CISA's urgency suggests most organizations won't patch for weeks. The Novo Nordisk breach was catalyzed by an exposed GitHub token left unprotected in a compromised development environment. FIFA's World Cup streaming infrastructure faced potential hijacking due to an Entra ID access control misconfiguration—one of the most heavily resourced organizations on the planet, vulnerable to basics.

This week's quiet commentary from the field—captured eloquently in "No Exploits Required"—finally names what the industry has known for years: exploits rarely cause breaches. Weak credentials, absent monitoring, inadequate segmentation, and orphaned access do. The discovery of orphaned AI agents left behind by departed employees with persistent credentials illustrates just how broken access governance has become. As enterprises automate everything, they're accumulating persistent service accounts, API keys, and agent identities at exponential rates—with virtually no oversight mechanism.

On the operational side, defenders face an escalating crisis in critical infrastructure. Mitsubishi Electric disclosed critical remote DoS flaws in industrial controllers while Schneider Electric's path traversal vulnerability threatens power grid systems worldwide. Most alarmingly, Apollo's glucose monitors contain critical Bluetooth flaws that expose medical device data—a vulnerability that directly endangers patients dependent on these systems. These aren't theoretical risks; they're active threats to operational systems that may never receive patches. Defenders in manufacturing, healthcare, and utilities face the grim calculus of living with known critical flaws indefinitely.

The offensive side has evolved in tandem. Gentlemen ransomware now deploys GentleKiller, an EDR killer targeting 48+ security vendors, while Backdoor.Turn tunnels command-and-control traffic through Microsoft Teams to hide from perimeter monitoring. These aren't just incremental improvements—they represent attackers systematizing defenses-evasion as a core capability. The SocGholish takedown, which removed 15,000 infected WordPress sites, showed law enforcement's ability to act at scale, yet INC ransomware continues to emerge as a top-4 RaaS threat with 830+ victims.

The capital markets are speaking clearly: the future of cybersecurity belongs to whoever controls identity and AI-driven response. Accenture's $4.1 billion acquisition of Dragos, runZero, and NetRise consolidates industrial cybersecurity around asset discovery and threat correlation. Cisco's acquisition of WideField for Splunk's agentic SOC signals a bet on automation and AI-driven investigation. SailPoint's $200 million acquisition of Entro pivots the industry toward non-human identity—the realization that service accounts, API credentials, and autonomous agents are now the primary attack surface.

As we look ahead, three inflection points demand attention from security professionals. First, the shift from perimeter-to-identity defense is accelerating faster than most organizations can adapt. Third-party integrations will remain a liability until vendors implement zero-trust models with runtime attestation. Second, industrial and medical device security is entering a phase where vendors cannot keep pace with vulnerability disclosure; defenders must assume permanent compromise and build resilience strategies accordingly. Third, the consolidation of AI and identity as the center of gravity means that investment decisions made today will determine defensive posture for years to come. Organizations that haven't begun treating identity as a distinct security domain—rather than a component of access management—are running out of time.

The security industry spent decades perfecting perimeter defense. But perimeters no longer exist. We now live in a world where your vendor's compromise is your compromise, where your service accounts matter more than your firewalls, and where identity governance has become the critical infrastructure of cybersecurity itself.

Key Takeaways

  • Supply chain trust is collapsing. Klue, ShapedPlugin, and TinyPulse show that attackers now target vendors to reach customers. Every third-party integration is a potential compromise vector; assume compromise and enforce runtime verification.
  • Identity and access failures drive most breaches. FortiBleed, GitHub tokens, and Entra ID misconfigurations confirm that exploits rarely matter—weak credentials and orphaned access do. Audit service accounts and non-human identities with the same rigor as user accounts.
  • Industrial systems are permanently vulnerable. Critical flaws in manufacturing, power grid, and medical device controllers lack patches. Build resilience strategies and network segmentation rather than waiting for vendor fixes.
  • The vendor consolidation wave points to the future. Accenture, Cisco, and SailPoint's $4+ billion in M&A signals that AI-driven response and identity-centric defense will define the next generation of security infrastructure.

The Wire is HackWire's daily editorial briefing, published every morning.