ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-07-15
▶The Wire — Daily Briefing

The Wire — Wednesday, July 15, 2026

The System is Overwhelming Itself: Patch Triage Meets Supply Chain Chaos

55 stories analyzed

The System is Overwhelming Itself: Patch Triage Meets Supply Chain Chaos

We're reaching an inflection point in information security, and it's not pretty. Yesterday's Patch Tuesday wasn't just another monthly update cycle—it was a seismic moment that exposes how the industry's defenses are fundamentally breaking under their own weight. Microsoft released a record 622 vulnerabilities, including two actively exploited zero-days that are already compromising enterprises worldwide. But that staggering number isn't the worst part. The worst part is that we know with absolute certainty that most organizations won't patch them all, and attackers know it too.

The volume is so extreme that it forces a grim calculus: security teams must now choose which vulnerabilities to ignore, betting that their risk profile will make them less attractive targets than someone else's. This isn't theory anymore. It's happening today. And while patch Tuesday dominated headlines, a cascade of other critical vulnerabilities hit simultaneously—SonicWall's actively exploited zero-days, industrial control systems from Siemens and Schneider, SAP's CVSS 9.9 NetWeaver flaw—all dropping simultaneously and all demanding immediate attention. Security leaders are no longer managing risk. They're managing triage failure.

The supply chain is telling us why this matters with brutal clarity. Over the past 24 hours, we've seen ~300 counterfeit GitHub repositories designed to slip credential-stealing malware into developer build pipelines. Jscrambler packages were poisoned with preinstall hooks targeting 1,479 developers. 148 npm packages disguised as student proxies converted browsers into a botnet. And in perhaps the most alarming discovery, xAI's Grok Build uploaded entire Git repositories—not just the files it needed—to storage without user consent, meaning proprietary code and credentials were transmitted at a 27,800x multiplier of what was necessary. These aren't sophisticated attacks. They're industrial-scale exploitation of the fact that nobody has visibility into their dependencies anymore. The open-source ecosystem has become a delivery mechanism for compromise, and patching individual projects doesn't solve the problem when the entire supply chain is compromised at source.

Critical infrastructure is in the crosshairs this week in ways that demand escalation above typical vulnerability discussion. Siemens released patches for perfect-score CVSS 10.0 authentication bypass vulnerabilities in their control center software. ABB disclosed four critical flaws in T-MAC Plus affecting manufacturing systems with a CVSS of 9.9. SharePoint is being actively exploited by attackers chaining multiple CVEs to establish persistence and steal credentials across organizations. VMware Avi Load Balancer has seven critical authentication bypasses and RCE vulnerabilities. These aren't edge cases or niche deployments. These are systems that literally control the flow of data, power, and money through enterprises and infrastructure operators worldwide. CISA is begging organizations to harden SharePoint. The Pentagon is so concerned about contractor readiness that it suspended CMMC Phase 2 to rethink the entire framework. This isn't bureaucratic shuffling—it's a signal that the security posture the DoD expected contractors to achieve is effectively impossible.

Identity and authentication systems are failing in multiple directions simultaneously. Microsoft Entra ID—the authentication backbone for millions of enterprises—is under attack via OAuth client ID spoofing that allows attackers to validate stolen credentials without triggering detection. Two separate attack groups have already compromised millions of accounts this way since December. New phishing kits are bypassing Microsoft 365 MFA using reverse proxy and token interception, letting attackers hijack authenticated sessions without the user ever knowing they've been compromised. Meanwhile, a critical flaw in Claude for Chrome survives eight patches, allowing malicious browser extensions to access Gmail and Calendar without user consent by pivoting through Claude's pre-authorized connections. The industry's response? Microsoft is making passkeys the default authentication method starting September—a necessary hardening, but also an admission that password-based authentication has so thoroughly failed that regulatory-scale enforcement is the only solution left.

Perhaps the most damning story of the week is buried in the ransomware coverage: a ransomware negotiation firm was caught sharing victims' insurance details and negotiation strategies with criminal gangs to maximize ransom payouts. This reveals institutional corruption in the third-party ecosystem that should terrify organizations. Meanwhile, the US is sanctioning VPN services and malware providers that enable ransomware attacks, and Spanish authorities dismantled a €140M cyber fraud operation. Law enforcement is scaling up. But so are the criminals. The ransomware ecosystem isn't shrinking—it's just reorganizing. When enforcement targets infrastructure providers instead of the attackers themselves, it forces the criminal economy to evolve. That's what we're watching. D1R claimed breaches of Synopsys and Bosch with no actual evidence—pure extortion theater. That's the new normal.

Looking forward, this week serves as a wake-up call that the security industry is trying to solve multiplication problems with addition. We're patching faster, but we're also discovering vulnerabilities faster than we can ever hope to patch them. We're building more security tools, but we're also depending on more third-party code, more browser extensions, more cloud connections, more identity providers—all expanding the attack surface. We're sanctioning more bad actors, but the economic incentives for cybercrime keep growing. The real reckoning will come when organizations realize that traditional risk management—patching, monitoring, hardening—can't scale to the threat volume we're facing. The path forward isn't better patches or faster detection. It's architectural rethinking: zero-trust networks, immutable deployments, supply chain isolation, identity verification that doesn't rely on shared OAuth infrastructure, and accepting that some critical systems need to be segmented entirely. The system is overwhelming itself. Monday's briefing will tell us if we're finally ready to admit it.

Key Takeaways

  • Patch Triage Has Become Triage Failure: Microsoft's 622 vulnerabilities including two actively exploited zero-days, combined with simultaneous critical flaws in SonicWall, SAP, Siemens, and VMware, forces organizations to choose which vulnerabilities to ignore—a choice they will lose.
  • Supply Chain Compromise Is Now Industrial Scale: Counterfeit GitHub repos, poisoned npm packages, xAI uploading entire repositories without consent, and LabubaRAT masquerading as NVIDIA show that the open-source ecosystem and software distribution channels are delivery mechanisms for compromise, not isolated incidents.
  • Authentication Systems Are Breaking Under Attack: OAuth client ID spoofing validates stolen credentials at scale, MFA bypasses are commoditized in phishing kits, and browser extensions leak Gmail/Calendar access. Microsoft's pivot to mandatory passkeys is a necessary hardening but also an admission of systemic failure.
  • Critical Infrastructure and Enterprise Backbone Systems Are Actively Exploited: SharePoint RCE, VMware Avi authentication bypass, industrial control vulnerabilities in Siemens/ABB/Schneider, and SonicWall zero-days hitting in the wild mean attackers aren't waiting for patches—they're already inside infrastructure operators' networks.

The Wire is HackWire's daily editorial briefing, published every morning.