Saturday, and the day's theme wrote itself in systems you don't fully control. The thing putting you at risk this week isn't code you shipped — it's the firewall at your edge, the vendor holding your customer list, and attackers who no longer need a human in the loop. Three stories, one uncomfortable throughline: your attack surface keeps moving off your own balance sheet.
The firewall at your edge is the way in
Start with the box you bought precisely to keep attackers out. Attackers are actively exploiting a Remote Access SSL VPN vulnerability affecting Cisco ASA and FTD devices, and the flaw lets unauthenticated attackers restart vulnerable devices remotely, producing denial-of-service conditions. The mitigation picture is narrow: Cisco has released patches, and there is no workaround.
The operator's take: "no workaround" means the only lever is patching, and patching an internet-facing VPN concentrator is the kind of change control that gets deferred because downtime is visible and risk isn't — until it is. Edge security appliances are the highest-value target you own: they're exposed by design, they sit in the trust path for everyone, and a DoS on your VPN is a DoS on your whole remote workforce. If you run ASA or FTD, this is a same-day job, not a next-sprint ticket.
Your vendor got hacked, so you did too
The second story is the one that never shows up in your own logs. Hardware wallet maker Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping and logistics provider, ShipMonk, was hacked. The exposed data is exactly the set that fuels convincing phishing: attackers gained access to customer names, shipping addresses, email addresses, and phone numbers, hitting customers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026. It wasn't the only one: computer maker Framework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses.
The operator's take: neither Trezor nor Framework was breached at the front door — the loss walked in through a logistics partner and a customer-data store that a third party operated. Your vendor's breach is legally and reputationally your breach; the customer whose data leaked has never heard of ShipMonk. Map where your customer PII physically lives across every processor and fulfillment partner, put breach-notification and audit clauses in those contracts, and assume any data you hand a vendor is data you'll one day have to explain. Minimize what you share, because you can't patch a system you don't run.
Ransomware learned to run itself
The third story is why the first two matter more than they used to. Ransomware attacks against billion-dollar companies jumped 74% quarter-over-quarter in the first half of 2026, with total ransomware attacks worldwide up roughly 20% year-over-year. And the delivery mechanism is changing: the first fully AI-automated ransomware attack was recorded in July 2026. Researchers made the same point from the defensive side — work presented around DEF CON 34 and Black Hat 2026 showed how AI systems can expose data, compromise development workflows, accelerate exploit creation, and take damaging actions through vulnerable APIs.
The operator's take: the same automation making your engineers faster is compressing the attacker's cycle from initial access to encryption. When exploitation gets cheaper and faster, the economics flip toward volume — which is exactly why a 74% jump in attacks on large companies isn't noise. The defense isn't a shiny AI product; it's the boring fundamentals executed faster: MFA everywhere, tested and offline backups, tight identity, and a patch clock measured in hours for anything internet-facing. Assume the attacker automates. Make sure your response does too.
Also on my radar
- Vishing still beats your firewall. Abbott Laboratories, one of the world's largest healthcare companies, was breached after a single employee was tricked over the phone into handing over their login credentials — no zero-day required, so phishing-resistant MFA and a "verify the caller" reflex are still your cheapest controls.
- Distribution giants are targets too. Wesco, a global supply-chain and distribution company, has confirmed it is investigating a cybersecurity incident — the logistics layer everyone depends on is having a bad month, and its data touches a lot of downstream customers.
- Concentration is the quiet risk. Two of this week's headline breaches trace back to a single shared vendor pattern — a spike in attacks on shipping and logistics companies is likely to expose a lot of data — so know which providers sit behind more than one of your dependencies.
The throughline for a Saturday: your security posture is now the weighted average of every system you touch but don't own — the appliance at your edge, the vendor in your supply chain, and an attacker who automates. You can't audit your way out of that overnight, but you can patch the exposed box today, shrink what you hand your vendors, and run your incident playbook at the same speed the other side runs theirs. Control what's yours, contract for what isn't, and assume the breach starts somewhere you can't see. That's the Signal for today.
Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.