ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-07-08
▶The Wire — Daily Briefing

The Wire — Wednesday, July 8, 2026

The Authentication Layer Is Breaking Down—And AI Can't Help

39 stories analyzed

The Authentication Layer Is Breaking Down—And AI Can't Help

Today's threat landscape reveals a troubling convergence: the authentication mechanisms we've relied on for years are failing simultaneously across multiple fronts, while AI systems are introducing entirely new attack surfaces before we've figured out how to secure them. Meanwhile, critical infrastructure is still running decade-old vulnerable code that's now being actively weaponized. It's a day that shows the industry is defending on multiple fronts and losing ground on several.

The most alarming signal comes from authentication itself. DEBULL tooling is abusing Microsoft's device-code flow to bypass MFA entirely—no password compromise needed, no traditional MFA defeat. Meanwhile, a critical flaw in Gitea allows authentication bypass via HTTP header manipulation, and this isn't theoretical—it's under active exploitation in the wild. The pattern is consistent: attackers are finding elegant ways to exploit the trust infrastructure itself. What's particularly striking is that these aren't zero-days in obscure corners—they're in mainstream tools and platforms that millions of organizations depend on. For teams managing self-hosted Gitea instances or those deploying Microsoft 365 at scale, today's threat level just changed materially.

The AI supply chain is showing its vulnerability earlier and more dramatically than many predicted. A critical flaw in Google Dialogflow CX, dubbed "Rogue Agent," allows attackers with basic update permissions to inject malicious code into chatbots, exfiltrating customer conversations and stealing credentials. Google has patched this, but the fundamental lesson is stark: permission validation in AI systems is broken. More troubling is GitLost, a prompt injection vulnerability in GitHub Agentic Workflows that lets unauthenticated attackers extract sensitive code from private repositories using crafted GitHub issues. An attacker doesn't need to compromise anything—they just need to inject instructions into normal-looking issues and trick the AI into doing the work. We're also seeing critical flaws in Langflow being exploited to steal LLM provider credentials and AWS keys. The pattern here is that AI agents are being deployed with broad access to sensitive systems before we've figured out how to defend against prompt injection at scale. The GitHub Actions attack pattern your CI security scanners miss shows us why: attackers are thinking in workflows and chains, not individual files. Traditional scanning catches the leaves but misses the tree.

Critical infrastructure is a bleeding wound. We're seeing exploitation of vulnerabilities that are over a decade old: GhostLock, a 15-year-old Linux kernel flaw, is being actively exploited to achieve root access in seconds. Januscape, a 16-year-old KVM vulnerability, enables VM escape on Intel and AMD clouds. These aren't novel attacks—they're old vulnerabilities that patch management has somehow failed to contain for a decade and a half. Meanwhile, hardware CAD tools aren't spared: Labcenter Proteus has three critical memory corruption flaws that could allow attackers to inject malicious code into hardware designs at the CAD stage. If your medical device, power grid component, or telecom equipment was designed with Proteus, an attacker could be sitting in your supply chain. Hitachi Energy's power grid management systems have critical NGINX buffer overflow and unencrypted credential exposure vulnerabilities, while Digi International's PortServer devices are wide open to unauthenticated access and XSS injection. And looming over all of this is the Tenda router backdoor—a hidden admin password in firmware that grants full access—affecting millions of home and small business networks.

The nation-state threat landscape is deepening. BusySnake infostealer, deployed by Armored Likho, is targeting critical infrastructure in Russia, Brazil, and Kazakhstan to steal credentials and maintain persistent access to electrical power networks. Chinese APT UAT-7810 is using LONGLEASH malware on Ruckus routers to build persistent C2 relay nodes, enabling network interception and lateral movement in North America and Europe. Iran-linked APT compromised Israeli targets through IT service providers using a modular C&C framework. These aren't campaigns aimed at quick data theft—they're infrastructure-level supply chain compromises designed for persistence and long-term access. The fact that Spain arrested a pro-Russian hacktivist member targeting US and European critical infrastructure suggests international enforcement is ramping up, but the operational pace of threat actors is still outpacing law enforcement.

What's actively being exploited right now matters most. CISA added four vulnerabilities with CVSS 10.0 to its Known Exploited Vulnerabilities list: Adobe ColdFusion, JoomShaper, Joomla, and WordPress are all being actively exploited with minimal delay after disclosure. Ubiquiti warned of seven critical UniFi OS flaws affecting over 100,000 devices, and BeyondTrust patched four vulnerabilities including two critical flaws that allow unauthenticated authentication bypass. These aren't theoretical—they're live campaigns. That's why CISA ordered federal agencies to patch the critical ColdFusion flaw by Friday.

The business impact is becoming visible in dollar terms. An Ohio county paid $1 million to prevent data leakage in a cyber extortion attack, and Accenture confirmed a breach where a threat actor publicly offered 35GB of stolen source code, keys, and credentials for sale. This is the third major breach at Accenture in five years. The ransom economics are working in favor of attackers.

What's worth watching: The convergence of old vulnerabilities with new attack vectors is creating a window of maximum vulnerability. Organizations are patching AI systems as fast as vendors can release patches, but we're still in the phase where defenders don't fully understand the attack surface. The authentication layer is being undermined through multiple paths simultaneously—device-code phishing, header manipulation, permission validation gaps in AI systems. And critical infrastructure is being targeted at the firmware and hardware level by nation-states that have no interest in quick payoffs. This is a marathon, not a sprint, and today shows we're falling behind on multiple vectors at once.

Key Takeaways

  • Patch authentication systems immediately: DEBULL and Gitea exploits are live. If you use self-hosted Gitea or Microsoft 365 at scale, treat these as critical. Device-code phishing is harder to detect and defeat than traditional MFA attacks.
  • Lock down AI agent permissions: GitLost, Rogue Agent, and Langflow exploits show that permission validation in AI systems is broken. Audit what access your AI agents have to sensitive data and networks. Treat prompt injection as a persistent threat category.
  • Inventory firmware and kernel versions across infrastructure: GhostLock and Januscape are 15+ years old but still being exploited. Legacy Linux systems, routers, and firmware are all at risk. Run a full inventory and prioritize patching.
  • Assume nation-states are in your supply chain: LONGLEASH, BusySnake, and modular C&C frameworks are targeting critical infrastructure through routers, service providers, and IT vendors. Supply chain defense is no longer optional.

The Wire is HackWire's daily editorial briefing, published every morning.