ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-08-23
▶The Wire — Daily Briefing

The Wire — Sunday, August 23, 2026

When Defenses Fail in Parallel: AI Exploits, Supply Chain Decay, and the Credibility Crisis in Security

16 stories analyzed

When Defenses Fail in Parallel: AI Exploits, Supply Chain Decay, and the Credibility Crisis in Security

We're watching the security apparatus crack along multiple fault lines at once. Today's 16 stories don't describe isolated incidents—they describe a coordinated system failure, where every layer of defense simultaneously shows critical weaknesses. And AI is the common thread.

Start with the supply chain. Hackers infect Android car head units with proxy botnet malware reveals a particularly insidious pattern: threat group MoYu compromised firmware update mechanisms to deliver the DoFun malware, transforming millions of vehicles into residential proxy nodes. That's not just an attack on cars—it's infrastructure-level compromise hiding in the legitimate update chain. The same week, 14 trojanized npm packages drop RedC2 4.0 Linux backdoor with AI-assisted C2 shows the same playbook working against software supply chains. Both attacks exploit what defenders have consistently underinvested in: validating the chain itself rather than just the endpoints.

Then there's the Siemens story. Five federal agencies warn of active exploitation of internet-exposed Siemens S7 Series PLCs using AI-generated exploit scripts. Not custom, hand-crafted attacks—machine-generated. Attackers are now using AI to lower the technical floor for targeting critical manufacturing, energy, water, and chemical infrastructure. This isn't a vulnerability; it's a tactic shift. And it's working.

These supply chain stories share a grim insight: traditional patching doesn't work when the attack vector is the patch. Defenders assumed updates mean safety. That assumption is dead.

Authentication is the next casualty. New phishing toolkit uses passkeys to maintain access after password resets should terrify security teams that bet their infrastructure on passkeys. iAuthFlow V2 doesn't break passkey cryptography—it exploits the enrollment process itself. During a phishing attack, the attacker registers their own passkey on the victim's account. Even if the victim detects the breach and resets their password, the attacker's passkey survives. It's the perfect persistent backdoor: attackers retain access through the very security mechanism designed to eliminate them.

Meanwhile, encrypted prompts bypass AI safety guardrails in Grok and Gemini. The breakthrough is almost laughably simple: encode instructions in Base64 or ROT13, and safety filters see gibberish. The model decodes the real instructions. This isn't exploiting a bug; it's exposing a structural design flaw: safety guardrails operate on the representation of user input, not the semantics. Any encoding defeats them. And smashing security podcast #481: never say this to a robot dog shows the attack generalizes. Researchers jailbroke a $9,000 robot by claiming it was a Pokémon. AI safety constraints aren't robust—they're fragile.

The Windows security story is subtler but just as damaging. Named pipes under attack: securing Windows interprocess communication describes how attackers register named pipes before legitimate services and impersonate them to escalate privilege. It's a beautiful attack because defenders treat named pipes as infrastructure, not an attack surface. The pattern repeats across today's coverage: every layer of the stack has a assumption that's now broken.

The enforcement chapter is the darkest. TikTok agrees to $400 million settlement in U.S. child privacy lawsuit follows a $5.7 million settlement in 2019. The math is clear: TikTok's fines are now just friction, not deterrence. They're the cost of doing business. Banking trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight shows law enforcement's same crisis. Grandoreiro was "taken down" in 2024—now it operates as a franchised malware-as-a-service network across multiple countries. Arresting operators doesn't dismantle the infrastructure. The business model survives. Prison for data analyst who tried to extort $2.5 million from his employer hints at another enforcement gap: analysts have sweeping access to company data but get minimal monitoring. The breach wasn't technical—it was a staffing oversight that prosecutors had to catch.

Critical infrastructure teams face convergent pressure. Cisco patches nine Crosswork and secure workload flaws, five scoring CVSS 10.0 means that network operators are now patching maximum-severity flaws built on hardcoded credentials. These aren't sophisticated—they're sloppy. But they're in the core of network orchestration systems. Critical isolated-vm vulnerability leads to RCE on host is the mirror: sandbox escape through race condition on platforms designed to safely run untrusted code. The isolation model fails under adversarial conditions.

The surveillance angle cuts differently. An invisible car? Researcher uses machine learning to hide vehicles from Flock cameras proves that the nation's largest vehicle surveillance network can be defeated by adversarial patterns. Flock Safety's license plate readers, trusted by law enforcement nationwide, become unreliable when attackers know they're being watched. This isn't a bug—it's a fundamental limitation of ML-based detection when adversaries have time to adapt.

The closing piece, OWASP flags top AI skill risks in new security blueprint, is the most forward-looking. Agentic systems executing real-world actions—sending emails, querying databases—introduce a new risk category that security teams don't yet have playbooks for. OWASP is right to flag this, but the warning arrives as enterprises are already deploying these systems at scale. We're building the parachute after jumping.

What we're watching unfold is not a series of separate incidents. It's a convergence: AI is lowering the technical barrier for exploitation while simultaneously breaking traditional defenses (authentication, isolation, safety guardrails, surveillance). Supply chains are compromised at scale. Law enforcement's deterrence model is broken when crime is decentralized and fines are just expenses. And defenders are still playing a game that assumes the rules they built—patches work, passwords matter, AI systems respect guidelines, insider threats are rare, surveillance deters—still hold.

The credibility crisis is already here. Fines don't deter. Passkeys don't defeat phishing. Isolation can be breached. Patches become weapons. And the people who should be stopping this—law enforcement, regulators—are 18 months behind the pace of change.

Key Takeaways

  • Supply chain attacks are now the default vector: Firmware updates, npm packages, and PLCs are compromised at scale. Assume the patch is the threat.
  • AI is weaponizing security infrastructure: AI-generated exploits lower the barrier for attacking critical systems; AI jailbreaks defeat safety guardrails through encoding; AI-powered C2 evades detection. The technology you built security around is now the attack.
  • Authentication and isolation assumptions are broken: Passkey phishing persists through password resets; named pipes enable privilege escalation; sandbox escapes are race conditions away. Your layers don't decouple.
  • Deterrence models have failed: Fines are business expenses; decentralized malware networks survive takedowns; insider monitoring stays insufficient. Enforcement can't keep pace with the professionalization of crime.

The Wire is HackWire's daily editorial briefing, published every morning.