ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-09-04
▶The Wire — Daily Briefing

The Wire — Friday, September 4, 2026

When Trust Becomes Liability: The Week Attackers Weaponized Your Security Stack

20 stories analyzed

When Trust Becomes Liability: The Week Attackers Weaponized Your Security Stack

We're witnessing a strategic inflection point in how attackers operate. The big vulnerability drops this week—Cisco Nexus, JFrog Artifactory, CrowdStrike Falcon—share a common thread that should alarm every security leader: attackers are no longer fighting your defenses. They're repurposing them. From enterprise endpoint protection to CI/CD platforms to the Node.js runtime shipped with your developers' laptops, the tools we trust to prevent attacks have become the vectors for enabling them. This isn't a vulnerability cycle. It's a crisis of trust infrastructure.

Start with the supply chain squeeze. JFrog Artifactory now permits attackers to forge admin tokens, giving them direct write access to your artifact repositories. Combined this week with Coder's Cloudflare infrastructure being hijacked to redirect Terraform modules to malicious servers, and we see attackers moving upstream. They're not exploiting individual developer machines—they're poisoning the wells that feed them. Every CI/CD pipeline that consumes these artifacts becomes a distribution mechanism for backdoors. Because Terraform executes with cloud credential access, a single malicious module can exfiltrate AWS, GCP, and Azure keys across an entire organization in seconds. This is mass compromise at package-management scale.

The Node.js story crystallizes why this matters. Attackers have weaponized Node.js itself as a malware delivery tool, exploiting it precisely because security tools trust it. Node's built-in file system and networking capabilities let attackers steal credentials, establish command-and-control channels, and move laterally—all while EDR systems watch a trusted process execute. This is the inverse of traditional endpoint protection. Your defenses don't stop Node-based attacks because Node isn't flagged as suspicious. It's the application layer running inside a trusted runtime, and it has all the privileges your developer needs.

The infrastructure layer is under simultaneous siege. Cisco Nexus 9000 switches suffer an unauthenticated remote code execution flaw at CVSS 9.8, with no workarounds. HPE's ArubaOS-CX switches permit traffic interception via RCE. Sangoma Switchvox PBXs are under active attack via unauthenticated SQL injection. And CISA flagged a perfect-10 SSRF in SonicWall, which attackers are chaining with reverse shells and crypto miners to monetize unpatched edge appliances. Network switching, security appliances, and communications infrastructure are all compromised simultaneously. These aren't flashy breaches—they're boring, critical infrastructure collapsing quietly.

What's particularly damaging is that your own security tooling can betray you. CrowdStrike Falcon's macro remediation feature, which runs with SYSTEM privileges, has been weaponized for privilege escalation. An attacker with local access triggers the remediation path with crafted input, and Falcon escalates them to SYSTEM automatically. Your endpoint detection and response solution just gave attackers administrator access. This is what defense-in-depth looks like when the inner layers are themselves compromised.

The social engineering layer, meanwhile, has become increasingly industrialized. Phishing kits targeting CEOs are now commodified. Fake M&A communications are impersonating acquisition deal flows to mid-level finance employees—exploiting organizational process gaps rather than technical vulnerabilities. These aren't spray-and-pray campaigns. They're reconnaissance-driven attacks using real company structures and deal flow information to craft convincing forgeries. And RMM phishing spanning 46 countries is using legitimate remote management tools instead of malware, giving attackers persistent, trusted access that most security tools ignore.

This week also revealed why multi-factor authentication can be a false comfort. Infostealer logs contain authenticated session cookies, not just passwords. When an infostealer captures cookies alongside credentials, attackers can hijack active sessions and completely bypass MFA. And because discovery typically lags days or weeks, attackers have likely already moved laterally and established persistence before the breach was detected. MFA delays them. It doesn't stop them.

The malware sophistication story is equally concerning. Shai-Hulud's credential-stealing worm now targets 469 credential locations—a 148% increase—including AI tool configurations like Copilot and OpenAI. The worm's maintainers have reverse-engineered real developer workflows and expanded their attack surface accordingly. This isn't generic malware. It's targeting the specific tools security researchers and developers use daily.

The breach consequences are sharpening enforcement. Thomson Reuters' C-Track court platform was compromised in March, exposing sealed records and SSNs across 11 states—a three-month detection lag. A French hospital paid €500,000 in fines after a 727,000-patient breach. Regulators aren't lenient on what "good security" looks like anymore. The fines are calibrated to hurt.

Microsoft's release quality deserves mention. KB5120998 broke Teams and Outlook on ARM-based Windows, and affected non-English Windows 11 systems with mouse driver resets—a testing bias that leaves most of Microsoft's global user base as unpaid QA. Desktop settings resets on affected machines broke Group Policy enforcement, creating compliance violations for enterprises. This is a first-party regression on Microsoft's own hardware, and enterprises must choose between security patches and functional applications.

What security leaders should take from this week: Your attack surface isn't shrinking—it's expanding into your trust chain. Infrastructure appliances, CI/CD platforms, endpoint tools, and legitimate runtimes have all become attack vectors because they have the privileges and trust your organization granted them. The old model—patch vulnerabilities, upgrade tooling, enforce policies—assumes your tools work as intended. They often don't. Watch what the Shai-Hulud worm is harvesting (AI tool credentials), watch which infrastructure layers go longest unpatched, and assume that every tool in your stack will eventually be weaponized. The answer isn't better tooling. It's network isolation, credential rotation, and accepting that compromise may already have happened.

Key Takeaways

  • Trust infrastructure is compromised: JFrog Artifactory, Coder's registry, Node.js, and CrowdStrike itself are now attack vectors—your security tools can't be assumed safe.
  • Infrastructure layer is critical: Unpatched switches, appliances, and PBX systems (Cisco, Aruba, SonicWall, Sangoma) are actively exploited; these collapsing silently without alerts.
  • Session cookies bypass MFA: Infostealer logs with authenticated cookies let attackers hijack active sessions; password-only detection is obsolete—hunt for stolen session tokens.
  • Regulatory enforcement is tightening: Breaches now carry million-dollar fines regardless of size; compliance-by-patching is the floor, not the ceiling.

The Wire is HackWire's daily editorial briefing, published every morning.