The Perimeter Is Dead. Here's What's Replacing It.
The past 24 hours have given us a masterclass in how security boundaries collapse when defenders patch slower than adversaries exploit. And the pattern is unmistakable: we're not fighting isolated vulnerabilities anymore. We're watching coordinated infrastructure attacks that treat critical authentication systems, build tools, and network appliances as interchangeable entry points into the same supply chain.
Start with GitLab. CISA confirmed that CVE-2023-7028, a maximum severity flaw from January 2024, is now actively exploited in the wild. A CVSS 10.0 unauthenticated account takeover that exposes code, CI/CD credentials, and secrets. Eighteen months of patches, and significant portions of the internet still run vulnerable instances. But here's the thing: GitLab isn't unique. Check Point VPN vulnerabilities are facing imminent exploitation with similar scope. The Netherlands' NCSC didn't issue a warning lightly. What they're seeing suggests that the traditional perimeter—the VPN, the firewall, the identity layer—is no longer a meaningful boundary. It's a checkpoint in a supply chain, and when it falls, everything downstream goes with it.
The Lenovo story crystallizes this perfectly. A flaw in Lenovo's identity platform compromised 5,000 Dropbox accounts via OAuth hijacking. Users trusted Lenovo to vouch for their identity. Dropbox trusted Lenovo. But when Lenovo failed, that trust became a liability, not an asset. The cascade effect is the story now. When identity providers break, they don't just expose their own users—they expose every service that delegates authentication to them. This is the new surface area for attacks: not the applications themselves, but the credential systems they outsource to.
CISA's latest KEV addition makes this explicit. Five vulnerabilities in Artifactory, ScreenConnect, and RouterOS form a coherent attack chain: supply-chain poisoning through artifact repositories, lateral movement through managed service provider tools, and network control through compromised routers. These aren't random flaws. They're the infrastructure of modern software delivery, and they're all failing in ways that attackers are actively weaponizing. One compromised Artifactory instance doesn't just expose code—it poisons every build downstream. One ScreenConnect breach gives an MSP's attacker access to hundreds of client networks. The perimeter metaphor assumes a clear inside and outside. Today's attacks ignore that distinction entirely.
The AVEVA Pipeline Integrity Monitor vulnerabilities drive this home further. Four chained critical flaws—hard-coded cryptographic keys, weak password hashes, missing authorization, and XSS—create a complete attack path. This isn't a single flaw that requires months to weaponize. This is scaffolding for offline credential theft and privilege escalation built directly into the product. And it affects infrastructure monitoring systems in industrial environments. The threat model has shifted from "keep attackers out" to "assume they're already in, and make sure they can't move laterally."
But the speed at which exploitation follows disclosure is itself a story now. GitLab's path traversal flaw was exploited within 24 hours of disclosure. The traditional N-day window—the assumption that defenders get some time to patch after a vulnerability becomes public—is collapsing. Adversaries have incident response capabilities now. They have automation. They have scale. The moment a patch lands, some attacker group has automated exploitation and begun scanning for instances. The race between patch deployment and attack deployment is over. Attackers won.
What's striking is how adversaries are also adapting phishing to exploit MFA fatigue and trust in new security mechanisms. Passkey phishing compromised Microsoft 365 environments in summer campaigns using legitimate email infrastructure and CEO scams. Passkeys were supposed to be phishing-resistant. They're not—they're phishing-evolved. And then there's InjectEave, which uses invisible Unicode characters to make malicious URLs unrecognizable to security systems while appearing normal to users. The adversaries aren't abandoning social engineering. They're encoding it at the character level.
The tracking angle adds a darker dimension to all of this. The Pentagon disabled ad tracking after finding foreign adversaries using commercial location data to track troops. The infrastructure built to show you mattress ads can be weaponized to track military movements. And audio fingerprinting via the Web Audio API is silently creating stable device identifiers across sessions without permission. These aren't vulnerabilities in the technical sense—they're features. The attack surface isn't a bug; it's the business model.
Meanwhile, the threat landscape is expanding upward. Anthropic's CEO warned that AI could autonomously coordinate agent swarms to attack internet infrastructure at scale within a year, removing the human operational constraints that currently make such attacks detectable. We're not just defending against today's threats. We're watching the foundation for tomorrow's threats being poured in real time.
The question for security teams is no longer "Are we secure?" It's "Which of these active exploits are we vulnerable to right now?" The perimeter is dead. The supply chain is the battlefield. Identity systems are the weak link. And the time to detect and patch is measured in hours, not months.
Key Takeaways
- Patch immediately, not eventually: Exploitation windows have collapsed from days to hours. GitLab and ScreenConnect show active weaponization within 24 hours of disclosure. If you're not patching within 72 hours on critical flaws, assume you're compromised.
- Identity providers are the new perimeter: OAuth/SAML cascades mean one compromised IdP exposes thousands of downstream users to unrelated services. Audit your identity provider's security posture as if it were your own—because it is.
- Supply chain tools require air-gapped security: Artifactory, ScreenConnect, and RouterOS exploits prove that build infrastructure and MSP tools are now primary targets. These need the same hardening you'd apply to production systems, not just developer convenience.
- Social engineering is outpacing MFA: Passkey phishing and InjectEave show adversaries evolving faster than defenses. User training and threat detection matter more now than the specific MFA mechanism.
The Wire is HackWire's daily editorial briefing, published every morning.