The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Why your vendors are failing you

The Perimeter Desk
2026-09-10
# Why your vendors are failing you My inbox is packed with people wondering if they're doing enough. Most of them are watching the wire and seeing a volume of failure that feels personal; when 438 data breach stories hit in one week, it doesn't feel like a few random accidents. It feels like a leak in the hull of the ship we're all on. The malware isn't usually the real problem. The incentive structure is. We reward vendors for feature richness and seamless integration, which is just corporate talk for keeping as much data as possible in as many places as possible. Look at IDScan. They've confirmed a breach of 153 million driver's licenses; let that number sink in. That isn't some leak; it's a library of identities, and who decided it was okay to store 153 million government IDs in a way that they could be stolen all at once? To make identity verification frictionless for their clients, they built a goldmine for attackers. Watch the wording when companies announce these things, and they start by saying they take security seriously as an explanation and end by saying they're working with third party experts as an excuse. The shift happens once they realize they can't explain why that much data was just sitting there. Here is a look at some of the questions hitting my desk this afternoon. *** **Gary, Des Moines: "I’ve spent all morning pushing updates to every server we own. As long as I stay on top of the patches, I can keep the bad guys out, right?"** Gary, I get the hustle. I really do. But you're fighting two different wars and only one of them is actually your job; you could be the best admin in Iowa and you'd still be tied to every vendor you trust. Take AdaptHealth. They weren't hit because some admin forgot a patch. A threat actor used social engineering on a third party contractor and that mistake exposed over 4.1 million people; what's the point of locking your doors if the guy cleaning the office leaves the back gate open? Patching is necessary. It isn't a shield against a compromised partner. **Marcus, London: "I'm seeing these reports about AI agents being used to hit PaperCut instances. Is this some kind of sentient malware we have to worry about now?"** It isn't sentient. It's just efficient. A Russian speaking actor likely used AI agents to compromise 440 instances across 395 organizations. The AI doesn't think. It simply automates the dull parts of an attack, specifically reconnaissance and initial exploit delivery. The danger is the speed, and humans have a biological bottleneck but attackers now use an API. They can hit hundreds of targets before you finish your first coffee; does that sound fast enough? We're seeing a shift where the window of opportunity between a public vulnerability and its exploitation has shrunk to almost nothing. **Sarah, Singapore: "We use several ID verification and health data tools to meet regulatory requirements. Are we actually increasing our risk by trying to be compliant?"** In short: yes. Executives usually miss the second order effect here, and you don't actually transfer risk when you outsource your health records or KYC to a giant like Veradigm. They just had patient data and Social Security numbers stolen through a compromised vendor API; you've simply shifted the danger to a spot where you can't see what's happening. What happens if IDScan loses 153 million licenses? Every company that used them for verification suddenly has a liability problem they can't fix. The data is gone. You can't patch a stolen driver's license, and people treat compliance like a checkbox, but attackers see those compliant hubs as high value targets. *** Resilience is a buzzword. Without reduction, it's just waiting for the next big hit, and CISA gave federal agencies until September 12 to patch Cisco, Citrix, and Fortinet flaws. That deadline arrives in two days. If you are still betting on vendors deleting unnecessary data, you're buying a miracle. Most won't move until regulators or lawsuits force their hand. Data is an asset on a balance sheet, and it is also a liability in the database. Who is actually auditing the deletion schedules of your most "trusted" partners?
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws BleepingComputer
  2. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances The Hacker News
  3. ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen - TechCrunch Google News Security
  4. Electronic health record company says customer data stolen in breach The Record
  5. Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks SecurityWeek
  6. Nightmare-Eclipse Strikes Again with 'ShieldCrash' Windows Exploit Dark Reading
  7. IDScan Confirms Data Breach, 150 Million Driver’s Licences Potentially Exposed - Firstpost Google News Security
  8. Critical NetScaler Vulnerability Exploited in Attacks SecurityWeek

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.