When Encryption Isn't the Target: How Attackers Are Shifting to Infrastructure, Sessions, and Availability
We witnessed something telling in the past 24 hours. A critical vulnerability in enterprise software got exploited in 72 hours. A major AI platform went offline. An encrypted messaging app was knocked offline by distributed attacks. And a crypto exchange's customer data is being sold to enable physical robbery. None of these stories were about breaking encryption. All of them were about something harder to defend: the brittleness of infrastructure itself.
The headline that should worry every security leader today is Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure. CVE-2026-58231 is not novel cryptanalysis or a zero-day in an obscure library. It's a straightforward remote code execution flaw in a platform that powers commerce for thousands of enterprises. And it was weaponized in 72 hours. For most organizations, that's simply not enough time for standard patch management—not enough time to test in staging, schedule maintenance windows, or even discover you're running the vulnerable version. By the time defenders could respond, attackers had already moved laterally. This is our new reality: the speed of exploitation now exceeds the speed of response.
This pattern repeats across today's threat landscape. The Fortune 500 Companies Hit in Azure Data Theft Campaign is a reminder that cloud infrastructure is now the primary target. Someone stole credentials or exploited a misconfigured identity service, gaining access to customer data for McDonald's, TCS, Vodafone, and others. The attacker isn't breaking Azure's encryption—they're exploiting trust boundaries, access control weaknesses, and the speed of response. For organizations storing sensitive data across hundreds of cloud resources, the challenge isn't cryptography anymore. It's visibility and rapid response.
That speed problem became visceral when Anthropic confirms Claude is down in major outage affecting multiple services. Within hours, thousands of organizations discovered that AI has become infrastructure. When Claude went offline, workflows stopped. Developers couldn't debug. Security teams couldn't analyze logs. The outage exposed a hidden dependency: we've built a layer of critical tools on top of a single API provider with no graceful fallback. This isn't a breach or a vulnerability in the traditional sense. It's a reliability failure at a layer we haven't yet learned to architect defensively around.
The New AmnesiaStealer macOS malware hijacks browser sessions via remote control fits perfectly into this theme. Why steal passwords when you can steal active browser sessions? AmnesiaStealer doesn't crack authentication—it hijacks it. An attacker with a compromised session operates as you in real time, sidestepping two-factor authentication, security questions, and everything else protecting the account. The malware represents a fundamental shift: from password security to session security. Your credentials are almost useless if your live session is already owned.
The targeting data angle becomes clear with the SafePal data breach impacts 39,798 customers, stolen info for sale. Forty thousand records—names, addresses, purchase dates—don't sound catastrophic on the scale of enterprise attacks. But these records identify crypto holders to thieves. That stolen data becomes a targeting list for physical robbery, SIM-swap attacks, and phishing. The SafePal breach isn't dangerous because it exposed passwords. It's dangerous because it created a map of wealthy targets. Your security posture is no longer just about what you protect—it's about whether attackers can identify and profile you before the attack even starts.
There's a counterintuitive lesson in Large-scale DDoS attacks disrupted Threema secure messaging service. Threema is end-to-end encrypted. The protocol is sound. The cryptography is solid. And none of that mattered when attackers simply knocked it offline with distributed traffic. When encryption can't be broken, availability becomes the vector. This is especially damaging for platforms like Threema, which are popular with journalists and activists who depend on messaging for safety. An attacker doesn't need to read their messages—ensuring they can't send them at all is a complete victory.
Finally, there's Metas Ray-Bans are being banned from pubs, restaurants, and theatres. This story feels different because it's not an attack—it's a consumer device that blurs the line between convenience and covert surveillance. Unlike a visible phone with a camera, Ray-Bans look like normal glasses. They can record audio and video without consent or awareness. Venues are banning them because there's no way to enforce privacy. The asymmetry is the vulnerability: recordable, but undetectable. Regulators are stalling, manufacturers are pushing adoption, and we don't yet have policy frameworks for devices that look innocent while functioning as comprehensive surveillance tools.
The through-line connecting these stories is this: we've overinvested in encryption and underinvested in resilience, visibility, and response speed. SAP's vulnerability sits unpatched for three days. Azure's access controls can't prevent misconfiguration at scale. Claude's outage has no redundant architecture. Threema has no DDoS mitigation layered behind encryption. AmnesiaStealer bypasses authentication entirely. SafePal's data becomes a targeting list for physical attacks. Ray-Bans become surveillance with plausible deniability.
Security professionals need to shift their mental model now. The question isn't "can attackers read our data?" It's "can they compromise our sessions before we notice? Can they exploit our infrastructure faster than we can patch? Can they knock us offline? Can they identify our high-value targets and attack before defenses engage?" These are availability, velocity, visibility, and targeting problems—not encryption problems.
The next wave of security will be measured not by encryption strength, but by patch velocity, session resilience, infrastructure redundancy, and the speed of incident response. Organizations that can patch in hours, not weeks; detect compromised sessions in minutes, not months; and architect without single points of failure will survive. The others won't have encryption to hide behind anymore.
Key Takeaways
- Infrastructure speed is now a security control. Organizations have 72 hours or less to patch critical vulnerabilities. If your patch pipeline takes longer, you're operating as if systems are already compromised.
- Sessions are the new credentials. AmnesiaStealer hijacks authenticated sessions, bypassing passwords and MFA. Session anomaly detection and continuous authentication are now defensive table-stakes.
- Stolen targeting data enables follow-on attacks. SafePal's breach becomes dangerous not through credential compromise, but through targeting—creating profiles for robbery, SIM-swap, and phishing. Privacy breaches are now physical security problems.
- Availability is a vulnerability. When encryption can't be broken (Threema), attackers target availability. Infrastructure redundancy and DDoS mitigation are no longer optional—they're foundational.
The Wire is HackWire's daily editorial briefing, published every morning.