The Strondex Blog
Recent security incidents in plain English, what happened, and the specific controls that would have changed the outcome. Written for the people who have to answer for it.
Want the at-a-glance view? See the Cyber Breach Tracker, recent breaches mapped to the exact control that would have stopped each one.
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Attackers exploited CVE-2026-18577, a bypass of N-able's own patch for CVE-2026-18556, to gain administrative control of on-premises N-central servers and then pivot to downstream managed endpoints. The incident shows how an incomplete patch can be more dangerous than no patch at all, because it creates a false sense of remediation.
August 3, 2026 Read the analysis →Microsoft Teams Vishing Campaign STAC4749 Delivers Chaos Ransomware in Under 17 Hours
A vishing campaign tracked as STAC4749 targeted dozens of North American organizations between February and June 2026, using Microsoft Teams calls to impersonate IT helpdesk staff and trick employees into granting remote access. At least three intrusions ended with Chaos ransomware deployed in as little as 17 hours.
July 31, 2026 Read the analysis →Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
A critical authentication bypass in Check Point SmartConsole was actively exploited before patches shipped on July 22, 2026. A public proof-of-concept followed two days later, compressing the patch window for every organization running an exposed Management Server.
July 29, 2026 Read the analysis →OnTrac Data Breach Exposes SSNs and Medical Data for 40,000 Individuals
Lasership Inc., doing business as OnTrac Final Mile, disclosed a network intrusion that exposed sensitive personal and medical information for over 40,000 individuals. The breach is a textbook case of what happens when network access controls fail to contain an intruder once they are inside.
July 27, 2026 Read the analysis →Russian Espionage Group Exploited a Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group tracked as LAUNDRY BEAR exploited a stored XSS zero-day in Zimbra Collaboration Suite to silently steal email, credentials, and 2FA codes. The flaw required no user interaction beyond viewing a message.
July 24, 2026 Read the analysis →Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US authorities dismantled Kratos, a Phishing-as-a-Service platform that targeted Microsoft 365 accounts across 35 countries using session-cookie theft to bypass MFA. The July 2026 takedown seized more than 200 servers and led to the arrest of the alleged developer in Indonesia.
July 22, 2026 Read the analysis →Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors exploited CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect, to gain unauthorized VPN access and deploy Qilin ransomware across multiple organizations in June 2026. Arctic Wolf Labs traced the full attack chain from perimeter compromise to domain-wide encryption.
July 21, 2026 Read the analysis →Forg365: A New Phishing-as-a-Service Platform Using AI to Compromise Microsoft 365 Accounts
Researchers at ZeroBEC have uncovered Forg365, a phishing-as-a-service platform that combines adversary-in-the-middle and device-code phishing with AI-generated lures to steal Microsoft 365 credentials and session tokens. The platform is purpose-built to bypass standard MFA and maintain persistent access to compromised accounts.
July 10, 2026 Read the analysis →Accenture Confirms Breach After Hacker Offers Stolen Data for Sale
A threat actor operating as '888' claimed to have stolen 35 GB of Accenture data including source code, Azure credentials, and SSH keys, and listed it for sale on a cybercrime forum on July 6, 2026. Accenture confirmed the breach but disclosed little about scope or method.
July 8, 2026 Read the analysis →AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
A threat operator named JADEPUFFER used an AI agent to carry out what Sysdig researchers describe as the first fully autonomous, end-to-end ransomware operation, exploiting a critical Langflow vulnerability to encrypt production database records without meaningful human involvement. The attack succeeded largely because of foundational hygiene failures that most organizations share.
July 3, 2026 Read the analysis →FBI: Russian Hackers Now Target Signal Backup Recovery Keys
The FBI and CISA warn that Russian Intelligence Services are phishing Signal users for their Backup Recovery Keys — giving attackers persistent access to full message histories even after victims change accounts. Here is what changed, who is at risk, and the one control that matters most.
June 29, 2026 Read the analysis →Polymarket Customers Lose $3 Million in Supply-Chain Attack
On June 25, 2025, a compromised third-party frontend dependency injected malicious JavaScript into Polymarket's website, tricking users into approving fraudulent transactions and draining approximately $3 million in pUSD from more than 11 wallets. Polymarket's own servers and smart contracts were untouched — the entire breach ran through a vendor's code.
June 27, 2026 Read the analysis →CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
CISA added CVE-2026-12569, a critical (CVSS 9.3) unauthenticated RCE flaw in PTC Windchill and FlexPLM, to its Known Exploited Vulnerabilities catalog after attackers began deploying persistent JSP web shells. Manufacturing and retail supply-chain organizations running unpatched Windchill instances face active risk right now.
June 26, 2026 Read the analysis →Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Threat actors are actively exploiting CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM and Unified CM SME that lets unauthenticated remote attackers write arbitrary files and escalate to root. Cisco patched on June 3, 2026; organizations on Release 14.x must upgrade to 14SU6 immediately or disable the WebDialer service as an interim workaround.
June 24, 2026 Read the analysis →LastPass Confirms Data Breach in Klue Supply Chain Attack
A threat actor compromised Klue's integration infrastructure using a legacy credential, stole OAuth tokens, and accessed LastPass customer data inside Salesforce, exposing names, emails, addresses, and support records. At least ten other enterprise organizations were also confirmed victims.
June 23, 2026 Read the analysis →Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Three typosquatting npm packages impersonating a PostCSS utility delivered a Windows RAT with Chrome credential theft. The lesson: govern the third-party code flowing into your build pipeline.
June 23, 2026 Read the analysis →“Apple Files Leaked on the Dark Web” Was a Supplier Breach: Tata, World Leaks, and Third-Party Risk
Confidential Apple files hit the dark web, but Apple was never breached. The data came from contract manufacturer Tata Electronics. The lesson: your IP is only as safe as the weakest vendor holding a copy of it.
June 23, 2026 Read the analysis →The Surveillance System Became the Breach: MSG, ShinyHunters, and the Data You Shouldn't Keep
ShinyHunters published Madison Square Garden's facial-recognition logs, secret risk dossiers, and SSNs. The entry point is undisclosed, so the real lesson is data minimization: you can't lose what you didn't keep.
June 21, 2026 Read the analysis →FortiBleed: 75,000 Firewalls, and the One Control That Stops It
A credential-harvesting campaign exposed admin and VPN logins on tens of thousands of Fortinet firewalls across 194 countries. Here's how it worked, and why your cyber insurer asks about MFA on remote access.
June 19, 2026 Read the analysis →The Canvas Breach: When Your Vendor Gets Hacked, You're Still on the Hook
ShinyHunters breached the Canvas learning platform twice in two weeks, hitting thousands of schools. The lesson for every business: your data lives in vendors you don't control, and your insurer knows it.
June 19, 2026 Read the analysis →Charter, a Phone Call, and the ShinyHunters Extortion: The Vishing Playbook
No malware, no zero-day, just a phone call and missing phishing-resistant MFA. How ShinyHunters walked into a telecom giant, and what underwriters now expect you to have in place.
June 19, 2026 Read the analysis →