The recent run of breach-beat stories shares one thread: attackers are winning less by breaking in and more by holding on. The FBI says FortiBleed attacks are still ongoing against exposed Fortinet FortiGate firewalls and SSL VPN gateways, and the operational effect is that legitimate administrators are locked out of their own equipment. Meanwhile, an analysis of the Klue breach, reported by BleepingComputer, describes forgotten OAuth grants used to reach corporate data, and The Verge's review of The Social Reckoning reminds readers that the modern leak era began with documents and access moving quietly through trusted insiders. Read together, the pattern is not exotic exploitation. It is durable, forgotten, or hijacked access surviving longer than the systems and people that created it.

Breaches Are Becoming Access Disputes

A decade ago, the standard breach narrative ended with data leaving the building. Today it ends with a fight over who controls the account. In the FortiBleed warning, the FBI describes attackers targeting FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. The breach is not over when the first file is copied; it continues as an availability problem for the defenders. That distinction matters for US technology companies because it turns a security incident into an operational outage. Network teams lose the console they need to restore service, and incident response has to begin with identity recovery rather than forensics. The breach stops being a privacy event and becomes a business continuity event.

OAuth Grants Are the Quietest Credential in the Room

BleepingComputer's piece on OAuth grants explains the second half of the pattern. OAuth grants create standing data highways between SaaS applications, AI agents, and other tools, and they multiply faster than security teams can review them. The Klue breach is the lived example: attackers took advantage of forgotten OAuth grants to reach corporate data. That is the same structural weakness as the FortiBleed lockouts, expressed in a different layer. In one case the credential is an administrator session on network gear; in the other it is a token that a business user approved months or years ago and never revisited. Both are forms of access that outlived the moment of their creation, and both are hard to see because they are working as designed.

For US technology companies, the OAuth problem is particularly awkward because it sits inside the productivity stack. A marketing team connects an analytics tool, an AI agent gets scoped access to a document store, and a contractor adds a project management integration. Each grant is a business decision made by someone who is not a security professional and who may not remember making it. The grant does not show up as a vulnerability, because it is not one. It shows up as a breach only after an attacker uses it.

The Social Reckoning Reminds Us Access Is a Human Story

The Verge's assessment of Aaron Sorkin's The Social Reckoning is a film review, but it belongs on the breach beat for one reason: it depicts how Frances Haugen, a Facebook civic integrity product manager, leaked a large trove of internal documents to Wall Street Journal investigative reporter Jeff Horwitz. That is not a firewall bypass or a forgotten token. It is a person with legitimate access choosing to move material out. The film's relevance to the current pattern is that it normalizes a lesson that security teams keep having to relearn: the most consequential access is often the access that was granted deliberately and never fully revoked or monitored.

It would be a mistake to treat the film as a guide to breach prevention, and The Verge notes that it mixes cinematic flair with details that hew closely to real life. The useful takeaway for US companies is narrower. Insider-driven document leaks and outsider-driven token abuse are not opposites. They are two ends of the same continuum of standing access that was never designed to expire. When a company reviews its breach exposure, the question is rarely whether an attacker can guess a password. It is how many people, tools, and tokens can already reach the data, and how many of those the organization can actually name.

Why This Pattern Is Getting Worse, Not Better

Three forces are pushing in the same direction, and all three are visible in the stories above. First, exposed network appliances remain a durable target. The FBI's warning that FortiBleed is still ongoing indicates that even well-known classes of attack against internet-facing Fortinet equipment have not been fully remediated across the installed base. Second, SaaS and AI tooling have multiplied the number of standing integrations inside the average US enterprise. BleepingComputer's framing is blunt: OAuth grants are multiplying faster than any security team can review them. Third, insiders with legitimate access continue to be a significant part of the breach story, which the Haugen narrative in The Social Reckoning illustrates plainly.

Each of these is manageable on its own. The combination is what creates the pattern. Attackers can enter through an appliance, pivot through an overlooked token, or simply collect documents from someone who already has the right permissions. In all three cases, the defender's problem is the same: access exists that nobody is actively watching, and the inventory of that access is incomplete. US consumers feel this through the companies that hold their data. A breach that starts as an administrative lockout or an unused integration can still end with personal information exposed, because the access that mattered was never the access anyone was monitoring.

What Changes for US Technology Companies

The practical shift is from detection to governance. If the dominant risk is standing access, then the controls that matter are the ones that inventory, scope, and expire that access. For network gear, that means not just patching but knowing which appliances are reachable and which administrator accounts depend on them. For SaaS and AI tools, it means treating OAuth grants as a security inventory rather than an IT convenience. BleepingComputer's point is that review is hard because the volume is high, not because the concept is complicated. The Klue breach shows what happens when review falls behind.

For US consumers, the implication is that the breach notices they receive may increasingly trace back to access that was legitimate at the moment it was granted. That is a harder story to explain than a stolen password, and it is harder for companies to prevent with the familiar playbook of perimeter defense and endpoint detection. The film at the center of The Verge's piece is a reminder that document leaks are not a technical anomaly. They are a governance failure with a human face, and the OAuth and appliance stories are the same failure expressed in code and configuration.

What to Watch

The concrete signals worth tracking are the ones the stories themselves put on the table. Watch whether the FBI's warning about ongoing FortiBleed attacks produces broader remediation of exposed FortiGate and SSL VPN deployments, and whether administrator lockouts become a standing feature of incident response planning. Watch whether the Klue breach prompts more US enterprises to audit forgotten OAuth grants, particularly those involving AI agents, which BleepingComputer singles out as a contributing factor in the volume problem. And watch how The Social Reckoning shapes public understanding of insider leaks, because the film's reception may affect how quickly companies move to restrict and log the access that insiders already hold. None of these are predictions. They are the places where the pattern will either be addressed or allowed to continue.

More on this beat: Cybersecurity on TechManNews.

#data breaches#OAuth#Fortinet#insider threat#access management#cybersecurity

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.