ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-09-03
▶The Wire — Daily Briefing

The Wire — Thursday, September 3, 2026

The Year Trust Became the Attack Surface

20 stories analyzed

The Year Trust Became the Attack Surface

Today's threat landscape tells a story about the exhaustion of perimeter security. For decades, defenders have patched edge appliances, hardened VPN endpoints, and monitored network boundaries. But the past 24 hours reveal a coordinated erosion of every trust assumption that supported that model. Attackers are no longer trying to break through defenses—they're weaponizing the infrastructure defenders rely on most: software updates, vendor relationships, email systems, and routing protocols. And they're doing it with increasing sophistication, enabled partly by the very AI tools security companies are racing to deploy.

The scale is staggering. CISA flagged seven actively exploited flaws, led by a perfect-10 SSRF vulnerability in SonicWall's edge appliances. The attack sequence is textbook modern compromise: SSRF access chains into reverse shells and crypto miners, turning unpatched edge appliances into monetized footholds. But SonicWall is just one example. SonicWall separately warned of actively exploited SMA1000 zero-day flaws, while Sangoma Switchvox suffered unauthenticated SQL injection enabling RCE that is already in active use. These aren't theoretical risks. Attackers are in the wild, right now, controlling perimeter access for enterprises that thought their edge appliances were secure.

What makes this wave different is the sophistication of the supply chain weaponization. In one attack, malicious BGP hijackers intercepted Virtualizor VPS management updates, redirecting traffic to malicious servers and delivering backdoors as legitimate patches. This routing-layer attack required no repository compromise, no vendor infiltration—just enough control of internet routing to intercept update traffic. The implications are chilling: if attackers can corrupt software distribution at the routing layer, they can compromise any organization updating any software from anywhere on the internet.

The git attack vector cuts even deeper. Malicious .git config files can force Claude, Codex, Cursor, and other AI agents to execute arbitrary commands when agents interact with untrusted repositories. Four of eight discovered vulnerabilities remain unpatched. This is not a minor flaw—it's a structural vulnerability in the entire AI-assisted development ecosystem. Developers using AI coding agents are now exposed to command execution risks they don't know they have, via configuration files they're trained to trust.

Meanwhile, legitimate trust channels are being impersonated. Hackers phished victims to deploy ScreenConnect through Faronics Deploy—both tools pre-approved by IT departments. The attacker didn't need to compromise either tool; they just needed victims to install a backdoor using a tool that bypasses security controls by definition. Similarly, attackers deployed malicious software installers targeting multinational companies, disabling Windows security to establish persistence in environments where IT teams abroad couldn't monitor endpoints operating under Chinese network conditions.

The software supply chain is burning on multiple fronts. A critical SQL injection in All-in-One WP Migration—installed on 5 million WordPress sites—allows unauthenticated site takeover. JFrog Artifactory suffers a flaw enabling attackers to forge admin tokens, letting them inject backdoors into packages and compromise CI/CD pipelines at scale. Every dependency has become a potential attack vector.

The real dagger, though, is in what these attacks reveal about the human and organizational weak points. Attackers compromised 80,000 freelancers via TVRAT/DarkVNC malware to infiltrate their client networks. Freelancers work across multiple organizations without corporate security controls—they're structural weak links that no amount of perimeter hardening can fix. MSPs, meanwhile, remain ransomware's most efficient targets, with one compromise unlocking hundreds of clients. The fatal flaw: most haven't tested defenses during real incidents, so capabilities fail when needed most.

Trust boundaries are collapsing elsewhere too. Attackers exploited a Lenovo email verification flaw to hijack email addresses, then reset Dropbox accounts. Neither company fully controlled the vulnerability, yet both were compromised. The inter-vendor trust that enables convenience has become the inter-vendor trust that enables compromise.

Here's where the paradox deepens: even as these vulnerabilities proliferate, Google, Anthropic, and OpenAI unveiled AI security tools within a week. Google integrated Gemini into threat intelligence, Anthropic positioned Claude for compliance, OpenAI launched a cybersecurity grant program. Yet researchers demonstrated that Claude can adapt ICS exploits across different PLC models, dramatically lowering the technical barrier for weaponizing critical infrastructure attacks. We're deploying AI to defend systems while simultaneously proving that the same AI can weaponize those systems. The tech giants are racing to own enterprise legitimacy, but the velocity of exploit adaptation should give everyone pause.

On the enforcement side, there's reason for cautious optimism. Law enforcement weaponized Sality's own P2P network against itself, finally taking down the 23-year-old botnet. A Russian hacker was charged for the freelancer campaign. These are real wins—but they're corrections to yesterday's threats, not preventions of today's.

The consistent pattern across all of this is that attackers have shifted from trying to break defenses to weaponizing the infrastructure that supports them. Edge appliances meant to protect networks. Software updates meant to patch vulnerabilities. Routing protocols meant to distribute traffic. Email verification meant to secure accounts. AI coding agents meant to accelerate development. Each layer of defensive infrastructure has become a potential attack vector.

Key Takeaways

  • Edge appliances are no longer safe assumptions: SonicWall, SMA1000, and Switchvox are all under active exploitation. If you haven't patched these systems or are running unsupported versions, your perimeter is actively compromised right now.
  • Defend the supply chain layer, not just the applications: BGP hijacking, malicious git configs, and compromised software updates bypass traditional defenses. Air-gapped updates, cryptographic verification, and supply chain monitoring are now critical.
  • Structural weak links (freelancers, MSPs, unpatched endpoints) are the new fault lines: One compromised freelancer exposes 10+ clients. One compromised MSP affects hundreds. Test your defenses now, not during an incident.
  • Trust assumptions are being weaponized faster than they can be patched: Vendor relationships, email verification, software distribution, and routing protocols are all attack surfaces. Assume nothing is isolated; design for compromise.

The Wire is HackWire's daily editorial briefing, published every morning.