Litany Of The Hacked: August 2026 Wrap-Up
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.
Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes:
GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities)...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens...
We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly.
Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is that the bad guys are increasingly narrowing the margin of error for error and negligence. You're now in the always-on SOC era. Moreover, managers have traditionally been responsible for monitoring people-based threats, but now leaders are also on the hook for corporate policies and procedures that because of their inadequacy can lead to cyber-attacks.
As we frequently note, what was good enough before from a talent perspective is not good enough now. You need to know what talent the new CISO or cyber-defender brings to the role.
Ask us how you can avoid joining the litany.
(image credit: ESA/Hubble & NASA, A. Sarajedini, G. Piotto)
Comments
Post a Comment