ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-09-08
▶The Wire — Daily Briefing

The Wire — Tuesday, September 8, 2026

When Trust Infrastructure Becomes the Attack Surface

18 stories analyzed

When Trust Infrastructure Becomes the Attack Surface

The infrastructure we've built to keep remote work secure is systematically failing us. Over the past 24 hours, a coordinated pattern has emerged: the very tools enterprises depend on for visibility, access, and management—remote access clients, load balancers, routers, RMM platforms—have become weapons in attackers' hands. And they're not doing this opportunistically. They're doing it at scale, with precision, and with the confidence that patches won't arrive in time to matter.

Start with the ScreenConnect crisis. We've now documented at least two distinct campaigns where attackers compromised ScreenConnect servers to inject malware into legitimate clients—turning a trusted remote-access tool into a self-propagating worm that spreads through enterprise networks automatically. The sophistication here matters: attackers didn't just plant a backdoor. They weaponized ScreenConnect's own file-distribution functions to spread multi-stage VBScript chains to every newly connected host. This is worm-like behavior in a tool designed for legitimate administration. Worse, ConnectWise has now disclosed a new ScreenConnect vulnerability with workarounds but no patch yet—creating a dangerous window where prior flaws were weaponized within 24 hours.

The problem extends far beyond ScreenConnect. N-able's N-Central platform, used by thousands of MSPs, was hit with a critical CVSS 10.0 RCE vulnerability. This is already under active exploitation, and every MSP customer represents dozens or hundreds of downstream client networks now at immediate risk. We're watching a supply-chain attack in slow motion. And while we're focused on the cloud, attackers are chaining together MikroTik router vulnerabilities to fully compromise unpatched devices with exposed SSH—a reminder that the attack surface includes every network perimeter in the installed base.

This weaponization of trust infrastructure reflects a strategic shift. Attackers have moved past the perimeter. They're now targeting the tools that give administrators sight and control over networks. Compromise a load balancer—as North Korean hackers did with HAProxy to intercept web traffic and spy on South Korean firms—and you have a privileged vantage point to every request, every session, every secret. These aren't smash-and-grab breaches. They're persistent espionage operations.

Meanwhile, the human element remains remarkably resilient as an attack vector. Threat actors are impersonating IT staff directly, using personalized details to vishing executives and stealing Microsoft 365 sessions. These aren't high-tech attacks—they're social engineering, but executed with enough precision to hit the C-suite. And if vishing feels quaint compared to automated malware, consider that BigBear 2.0 bypassed MFA for 5,000+ Microsoft 365 accounts using phishing proxies that capture authenticated session cookies. MFA is failing us not because it's technically weak, but because it's being bypassed by adversary-in-the-middle attacks that steal the authenticated session before MFA even enters the conversation.

Then there's the AI acceleration. OpenAI is rolling out ChatGPT Astra—nation-state-grade AI capability at $20 per month. For security professionals, this is sobering. Threat actors now have access to advanced models that can customize malware, generate convincing phishing content, and automate social engineering at scale. And OpenAI just added a Writing Style feature that learns to mimic your voice from connected documents—which means AI-generated phishing emails will soon eliminate the telltale mismatch that currently makes them detectable. Attackers have already figured this out: thieves are using AI-generated voice calls to impersonate Apple support and trick victims into revealing Apple ID credentials, allowing them to bypass Activation Lock and resell stolen iPhones.

The data breaches we're seeing reflect the real-world consequences of these convergences. Trezor's logistics partner exposed 81,000 crypto customers' names, addresses, and order histories—making them prime targets for spear-phishing and SIM-swap attacks despite the hardware wallet security model. And Mathspace's breach of 1M+ users happened through an unsecured Metabase analytics tool—a textbook failure to secure internal tools while hardening customer-facing systems.

Critical zero-days aren't helping. A Chrome V8 zero-day, router hijacks, and developer supply chain attacks are converging simultaneously on browsers, network perimeters, and development environments. And Magento's StyleSmuggler zero-day enables CSS injection to execute server code and plant persistent Linux backdoors—with no patch yet and active exploits already compromising e-commerce platforms.

There's one more insight that cuts across today's news: security frameworks don't translate across platforms. Your AWS security checklist won't protect you on Azure or GCP because each platform has distinct vulnerabilities rooted in different design philosophies. Organizations that assume unified security strategies will work across multiple clouds are about to learn an expensive lesson.

What should concern us most is the convergence. Attackers are hitting trusted infrastructure simultaneously. They're bypassing MFA. They're using AI to automate sophisticated attacks. And patches are arriving too slowly. We're in a window where the traditional defense-in-depth model—lock the perimeter, secure access tools, use MFA, patch regularly—isn't holding. The perimeter is compromised. Access tools have become weapons. MFA is being bypassed. And patches take weeks, while exploits take hours.

Key Takeaways

  • Supply-chain attacks are systemic: ScreenConnect, N-Central, MikroTik, and HAProxy shows that remote access tools, RMM platforms, load balancers, and routers are prime targets. If you manage these tools, patch immediately and assume they've been compromised until proven otherwise.
  • MFA is no longer sufficient defense: BigBear's session-cookie theft and vishing attacks show that traditional MFA bypasses are working at scale. Layer in anomaly detection, secure session handling, and consider Zero Trust principles beyond just multi-factor authentication.
  • AI is lowering barriers to sophisticated attacks: ChatGPT Astra at $20/month plus Writing Style mimicry means attackers now have tools to customize phishing, malware, and social engineering at scale. Your users will see more convincing AI-generated attacks.
  • Patch windows are killing us: New ScreenConnect, Magento, and N-Central vulnerabilities with days or weeks before patches arrive create open attack windows. Organizations need incident response plans that assume zero-day compromise is inevitable.

The Wire is HackWire's daily editorial briefing, published every morning.