The Perfect Storm: Legacy Cliffs, Zero-Days in the Wild, and AI Breaking the Rules
The threat landscape just shifted. We're watching four simultaneous crises converge in ways our security playbooks weren't built to handle: mission-critical systems running out of support deadlines within ninety days, industrial infrastructure under sustained ransomware assault, artificial intelligence systems escaping traditional security controls, and coordinated exploitation of zero-days across the entire stack—all happening right now.
Today's story count tells the story. We're tracking at least seven critical vulnerabilities under active exploitation, two major infrastructure attacks, three distinct malware frameworks targeting enterprises, and two separate operating system support deadlines looming this October. The thread connecting them isn't just severity—it's that each represents a fundamental failure of legacy defense assumptions. The defenses we built for last decade's threats don't detect or stop what's happening today.
Start with the patch avalanche. SharePoint's critical RCE didn't sit in disclosure purgatory—it went from announced to actively exploited within seventy-two hours. That's not a surprise anymore; it's the baseline. Fortinet's unauthenticated RCE and auth bypass in FortiGate firewalls is being weaponized against enterprise perimeters right now. Oracle's critical EBS flaw is so trivial to exploit—minimal technical effort, HTTP-only—that CISA just gave federal agencies forty-eight hours to patch. Zoom's account takeover vulnerability requires no user interaction at all. F5's NGINX heap overflow enables RCE on non-ASLR systems. And lurking beneath it all, legacy UEFI shims signed by Microsoft years ago can still bypass Secure Boot entirely, letting attackers inject code at firmware level before any operating system protection activates.
Most organizations won't patch all of these in time. That's not pessimism—it's mathematics applied to enterprise scale.
But the patch tidal wave is almost secondary to what's happening in operational technology and critical infrastructure. Nichirei, Japan's largest frozen food producer, got hit and had to take systems offline nationwide. Coca-Cola's Fairlife dairy unit got ransomware-encrypted and halted US milk production. These aren't theoretical incidents—they're real supply chain disruption affecting millions of people. Then look at Anubis ransomware, which doesn't just encrypt your data and hold it ransom—it permanently wipes files too, converting ransomware from a negotiation problem into irreversible data loss. That changes the game for attackers. Encryption was always recoverable if you had backups or refused to pay. Permanent destruction on an industrial scale? That's psychological warfare. And it's working on healthcare and critical infrastructure operators who face the choice between losing everything or paying everything.
Then there's Spirals, the Rust-based ransomware that breached a South Asian IT firm and encrypted the entire network in under twenty-four hours after systematically disabling antivirus, Veeam, VMware, and twenty-three other critical services. Fast. Precise. Practiced. This isn't script-kiddie ransomware—this is industrial-grade infrastructure takeover.
Industrial control systems themselves are under direct attack. Rockwell Automation's communication modules contain a critical DoS flaw allowing unauthenticated network attackers to disrupt connections repeatedly. Their PLC controllers have three critical DoS vulnerabilities triggered by malicious files. Siemens SICAM 8 has four critical flaws enabling authentication bypass and firmware compromise on power grids and manufacturing worldwide. These are the systems controlling electricity, manufacturing, and infrastructure. They were designed decades ago without security in mind, and as one piece today noted, restarting them to patch is often more dangerous than leaving them vulnerable. You can't security-theater your way out of that contradiction.
Now layer in artificial intelligence, and traditional security frameworks collapse entirely. Agentic AI systems are untamable by design—they operate at machine velocity making autonomous decisions that existing threat detection can't predict or control. Agent data injection corrupts the trusted data fed to AI agents rather than hijacking their instructions, letting attackers redirect shopping agents, trick coding assistants, and inject malicious code into production while evading modern defenses. A critical vulnerability in Claude for Chrome lets malicious extensions hijack AI operations and access Gmail, Drive, Calendar, and Salesforce without any user interaction. Meanwhile, over one million phishing emails now use text salting to confuse AI security filters, and attackers are using LLMs to generate retail scams at scale. The one bright spot here is OpenAI's GPT-Red—an autonomous red-team system that reduced prompt injection vulnerabilities sixfold in GPT-5.6 Sol by automating vulnerability discovery. At least someone's building defenses as fast as new attack surfaces emerge.
On the endpoint front, the threats are getting more sophisticated and more aggressive. ClickLock, a new macOS stealer, doesn't politely ask for your password—it crashes applications every two hundred and ten milliseconds until you surrender it. TELEPUZ spreads via ClickFix lures on compromised websites, stealing data and executing commands. OkoBot deploys twenty-plus payloads to steal crypto keys and financial credentials. Russian threat actors are trojanizing Webex and Zoom installers to deploy Starland RAT across the US, Europe, and Latin America.
Then comes the calendar cliff. Windows Server 2022 mainstream support ends October 13. Windows 11 24H2 Home and Pro editions lose support on the same date. Ninety days. Millions of devices will stop receiving patches, becoming targets for every unpatched exploit, ransomware variant, and credential theft campaign in circulation. Organizations haven't finished planning Windows Server 2025 upgrades yet. This isn't coming—it's here.
There are some wins worth noting. Two Scattered Spider members got five and a half years for orchestrating the Transport for London attack that compromised critical infrastructure and affected nine million commuters. 23andMe paid eighteen million dollars settling with forty-three states over a credential-stuffing breach. Spanish police disrupted a €140 million cyber fraud ring spanning multiple European countries. And on the vendor side, Risk Ledger raised thirty-two million in Series B to expand supply chain risk assessment, while Oak emerged from stealth with sixty million to consolidate fractured identity governance across human, machine, and AI identities. The defense ecosystem is accelerating too.
But acceleration isn't enough if it's still building for last decade's threat model. We need fundamentally different thinking about industrial systems that can't safely restart, about AI systems that operate at machine speed, about the fact that legacy support cliffs and zero-day exploitation timelines are now synchronized. Watch what happens in October. Watch whether organizations actually complete those OS upgrades before support ends. Watch whether the next Spirals variant learns from this one and goes faster. The question isn't whether the security industry is moving fast enough—it's whether it's moving differently enough.
Key Takeaways
- Patch velocity has inverted: Exploits now appear faster than organizations can deploy patches. Plan for persistent risk acceptance rather than "patch and move on." SharePoint went live to exploitation in 72 hours, and CISA gave feds 48 hours for Oracle—your organization won't beat either timeline.
- Legacy support deadlines are killing dates, not upgrade timelines: Windows Server 2022 and Windows 11 24H2 lose support October 13—expect ransomware targeting unsupported systems to spike immediately after. Infrastructure teams need to accelerate OS upgrades or build compensating controls now.
- Industrial infrastructure is no longer secondary threat terrain: Ransomware encrypted an entire dairy producer's US operations, OT controller DoS vulnerabilities are actively exploitable, and power grid equipment has firmware-level compromise paths. OT systems need network isolation and anomaly detection, not traditional patch cadences.
- AI agent security has no playbook yet: Agentic AI breaks traditional security controls, data injection evades modern defenses, and even trusted vendor Chrome extensions can be weaponized. Your threat model doesn't include AI-assisted attacks yet, but it should.
The Wire is HackWire's daily editorial briefing, published every morning.