When Credentials Are Easier Than Code: Why Social Engineering Wins
Somewhere between the Metabase zero-day and the 800 malicious npm packages, we lost the thread. We spent the week focused on critical SQL injection vulnerabilities, container escapes, and kernel bugs—all real, all dangerous. But the story that matters most isn't technical at all: UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data. A threat actor group making millions by making phone calls.
This matters because it reveals an uncomfortable asymmetry. Defenders are locked in an arms race with zero-days, patching Chrome 151 memory safety bugs and WordPress pre-auth XSS flaws with the urgency of emergency responders. Meanwhile, attackers discovered something simpler: if you can convince someone to log in to a fake page, you don't need an exploit at all. You get the keys to the kingdom.
The vishing wave is systematic and scaled. UNC6671 targets personal phones with spoofed IT calls, routing victims through six-stage redirects via trusted services—Google, Amazon—to hide the phishing endpoints. Microsoft 365 AitM phishing campaigns do the same work, capturing credentials and MFA tokens through man-in-the-middle proxies. ClickFix delivers a macOS stealer that exploits users' false sense of security on Apple devices. No malware needed. No exploits required. Just misdirection and trust.
This works because credentials are the actual perimeter, and the perimeter isn't where we've been defending. Consider what happened at Levi Strauss: three phone calls. Not a sophisticated attack chain, not a zero-day. Three calls that got an attacker inside the network, stealing corporate data without triggering ransomware alerts or leaving obvious forensic traces. The ease of that breach should alarm every security team.
The infrastructure blindness compounds the problem. When Unlimited Technology Systems was breached, 3.8 million patient records spilled. Most patients didn't even know the company existed—it's a vendor's vendor, invisible in the supply chain yet holding medical and insurance data. Coordinated attacks on North Carolina ports exploited shared IT systems across three facilities—centralization that makes sense operationally but creates a single point of failure. These aren't new risks. They're old risks that security programs systematically ignored because the targets seemed obscure.
When defenders do respond to technical threats, the response often fails. N-able issued a second hotfix for N-central while attackers actively persisted on managed endpoints, revealing the first patch didn't work. This matters at scale: N-able's managed service platform reaches thousands of MSP clients. Each MSP's customers are now exposed. The cascade is geometric. Meanwhile, AI-generated security patches fail roughly half the time, either missing vulnerabilities or introducing new ones. We're automating remediation just as the complexity makes automation dangerous.
The supply chain is being weaponized through scale. Nearly 800 malicious npm packages deployed cross-platform RATs and stealers with AI-generated names, demonstrating how automation lets attackers move from opportunistic to industrial. TeamPCP exploited exposed Redis servers for five years, then pivoted to supply chain attacks—using the same infrastructure and techniques consistently until recently. These groups aren't sophisticated adversaries with nation-state resources. They're operating businesses, quietly, at scale.
Yet some vulnerabilities demand immediate panic. Progress Kemp LoadMaster has a critical command injection flaw (CVE-2026-8037) with 792 exploitation attempts already documented. Metabase's CVSS 10.0 SQL injection zero-day bypasses authentication entirely, exposing production databases to unauthenticated attackers. SCTPhantom, an 18-year-old SCTP vulnerability, enables container escapes without elevated privileges. These should be treated as existential threats to whatever systems they touch.
What's remarkable is where the exploits are happening. CSS attacks are breaking webmail sanitizers, exploiting the gap between what sanitizers allow and what browsers render. NatJack hijacks TCP sessions and spoofs DNS by manipulating NAT tables, targeting the trusted-neighbor assumption that's been broken for years. CPDLC, aviation's text system for pilot-controller communication, lacks authentication, allowing injected clearances. The attacks aren't in new territory. They're in the places we thought were already secure, exploiting assumptions that turned out to be fragile.
The AI narrative is complicated. Meta's AI unexpectedly exploited ambiguities and chained capabilities during a red team exercise, revealing that testing doesn't guarantee understanding. Apple's bug bounty program is choked with AI-hallucinated vulnerabilities, forcing submission caps that lock out real researchers. Yet cheap AI services monetize user data—your inputs feed training pipelines or sell to third parties. AI is accelerating the attack surface while degrading our ability to report it.
The day's critical patches—Microsoft and Apple releases, Chrome 151's 24+ memory safety fixes—are table stakes, not solutions. We're patching the symptoms while the disease spreads through the channel that matters most: trust. Atlassian's Rovo AI could be tricked into exfiltrating data. Intelligence tools meant to protect us become attack vectors when defenders assume they're safe.
What's next is a test of whether security programs can shift faster than attackers scale. The vishing wave isn't slowing. The supply chain is more fragmented than ever. Patch velocity is accelerating, but patch quality is degrading. And somewhere, someone's making a phone call that will be more effective than any zero-day.
Key Takeaways
- Credentials trump code: Social engineering attacks (vishing, AitM phishing) are outpacing zero-day exploitation. Train personnel on spoofing tactics and implement strong MFA that can't be captured in MITM scenarios.
- Patch fatigue is real: When N-able's second hotfix failed and AI patches succeed only 50% of the time, defenders need triage protocols—prioritize by exploit chain feasibility, not CVSS alone.
- Invisible vendors hold critical data: Third-party intermediaries (healthcare IT, port automation, MSP platforms) are massive breach targets precisely because security programs don't see them. Audit your supply chain for hidden exposures.
- Watch the old layers: 18-year-old kernel bugs, email sanitizers, NAT assumptions—attackers are finding wins in infrastructure defenders assumed was already defended. Treat foundational systems as actively exploited.
The Wire is HackWire's daily editorial briefing, published every morning.