ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-09-01
▶The Wire — Daily Briefing

The Wire — Tuesday, September 1, 2026

Trust is the Real Perimeter—And We're Teaching Users to Ignore It

16 stories analyzed

Trust is the Real Perimeter—And We're Teaching Users to Ignore It

This week, we watched the security industry accidentally train millions of people to dismiss their own defenses. Microsoft told Windows users to ignore critical alerts that their antivirus was off. But that's only the surface of a deeper crisis: attackers have stopped trying to break in. They've started walking in through doors we held open, wearing badges we signed, using tools we trust—and we're rewarding them with our indifference.

The throughline this week isn't technical sophistication alone. It's how trust has become the most exploitable resource in the enterprise, and how defenders are making it worse.

Start with Recently patched PaperCut zero-days used in data theft attacks. This isn't the first time. In 2023, critical PaperCut flaws were weaponized before patches existed, and More Details Emerge on Exploited PaperCut Vulnerabilities shows attackers bypassed even the second patch. Why? Because PaperCut is the universally trusted print management layer in hospitals, universities, and government networks. It sits at the perimeter of information flow, which makes it the perfect pivot point for lateral movement. It's not that the software is uniquely broken—it's that no one audits it, everyone needs it, and once you're inside, you own the supply chain.

That same trust architecture enables Chinese Fire Ant hackers turn Cisco routers into spying platforms. These attackers didn't discover a new vulnerability. They embedded hidden GRE tunnels that bypass audit logs entirely, creating persistent command channels that IOS XR forensics can't detect. The router already had legitimate access to all traffic. Fire Ant just weaponized that pre-existing trust. And in Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More, we learned attackers are distributing pre-backdoored routers through the supply chain itself—trusting that nobody checks the firmware against canonical hashes before deployment.

But the most revealing breakdown of trust happened on Microsoft asks users to ignore 'Antivirus is turned off' errors. A display bug falsely warned users their antivirus was disabled. Microsoft's response: ignore it. This is a security anti-pattern so profound it should be taught in every incident response program. You have just trained tens of millions of people that when their antivirus protection disappears, the correct response is to do nothing. That habit—that learned indifference to critical security signals—is now baked into user behavior. When a real attack silences Defender, users won't notice. We did that.

The attackers understood this immediately. ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions weaponizes this exact habit. Silver Fox distributed signed malware that flagged as a false positive, then banked on users adding it to their exclusion list themselves—effectively disabling their own defenses against the hidden ValleyRAT backdoor. The user became an unwitting accomplice in their own compromise.

Nation-states are exploiting this trust erosion at scale. North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales reveals a sophisticated shift: Pyongyang moved fake-employee operations from technical roles—where vetting is stricter—into sales, marketing, and healthcare, where background checks are lighter and insider knowledge is equally valuable. They're generating hundreds of millions annually by understanding that trust in hiring is weaker than technical access controls. It's more efficient than hacking; it's just fraud with a nation-state budget.

The AI inflection makes this worse. Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets proves Russian ransomware gangs have weaponized AI-powered code editors in live attacks against 10+ networks. This isn't a theoretical concern anymore—it's operational reality. Meanwhile, Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance highlights that even compliance logging doesn't solve the core problem: AI agents with unrestricted access to production credentials and SSH keys. And this week, OpenAI confirms ChatGPT outage as users report errors revealed how enterprises became dependent on consumer AI without formal SLAs or uptime guarantees, treating a public service as infrastructure. One service failure exposed how little redundancy we've built around these tools.

The infrastructure level is no better. File servers are here to stay. Heres how to manage them securely reminds us that file servers harbor years of unchecked permissions—forgotten shares, legacy groups, access that was never cleaned up. One compromised credential cascades across years of accumulated data. We've built permission inheritance and forgotten where it goes.

Other attacks this week hit closer to real harm. Cronos blockchain restarts after $74 million Tectonic exploit shows oracle price manipulation enabling borrowers to drain DeFi lending protocols of $74 million through inflated collateral. This is a four-year-old attack pattern still working. And in the physical world, Berlin confirms data theft after Rhysida ransomware attack claims shows that ransomware gangs don't just encrypt—they steal to extort, especially from high-profile targets holding sensitive citizen records.

The human cost surfaced too: Nigerians extradited to US for sextortion, deaths of two teens reminds us that behind infrastructure compromises are networks exploiting adolescents for explicit imagery, then blackmailing them into despair.

What does this add up to? The perimeter didn't fail—trust did. And we're making it worse by asking users to ignore security warnings, by deploying AI without friction-adding oversight, by letting attackers walk in through pre-compromised hardware, by hiring them as employees, by assuming file-server permissions are fine-grained when they're actually decades of sediment. Every layer that's supposed to catch intrusions is now either transparent or trained to ignore what it sees.

Key Takeaways

  • Patch timing is dead: Even critical zero-day patches no longer guarantee safety if attackers were in before the fix dropped. PaperCut, TerminalFix, and others show that detection of prior compromise is now more important than patching speed.
  • Trust infrastructure is your attack surface: Print servers, routers, authentication flows, and hiring processes are trusted because we have no choice—not because they're secure. Assume every trusted service has been backdoored at the supply-chain level and verify accordingly.
  • Stop training users to ignore warnings: One false-positive from Microsoft teaches millions that critical security alerts are noise. The cost of that training is irreversible. Audit alert fatigue immediately.
  • AI is weaponized: This isn't coming—it's here. Organizations deploying Claude Code, Cursor, or ChatGPT without access controls or session visibility are handing attackers the keys to production systems already inside the network.

The Wire is HackWire's daily editorial briefing, published every morning.