The recent run of breach-beat stories shares one thread: attackers are winning less by breaking in and more by holding on. The FBI says FortiBleed attacks are still ongoing against exposed Fortinet FortiGate firewalls and SSL VPN gateways, and the operational effect is that legitimate administrators are locked out of their own equipment. Meanwhile, an analysis of the Klue breach, reported by BleepingComputer, describes forgotten OAuth grants used to reach corporate data, and The Verge's review of The Social Reckoning reminds readers that the modern leak era began with documents and access moving quietly through trusted insiders. Read together, the pattern is not exotic exploitation. It is durable, forgotten, or hijacked access surviving longer than the systems and people that created it.
Breaches Are Becoming Access Disputes
A decade ago, the standard breach narrative ended with data leaving the building. Today it ends with a fight over who controls the account. In the FortiBleed warning, the FBI describes attackers targeting FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. The breach is not over when the first file is copied; it continues as an availability problem for the defenders. That distinction matters for US technology companies because it turns a security incident into an operational outage. Network teams lose the console they need to restore service, and incident response has to begin with identity recovery rather than forensics. The breach stops being a privacy event and becomes a business continuity event.
OAuth Grants Are the Quietest Credential in the Room
BleepingComputer's piece on OAuth grants explains the second half of the pattern. OAuth grants create standing data highways between SaaS applications, AI agents, and other tools, and they multiply faster than security teams can review them. The Klue breach is the lived example: attackers took advantage of forgotten OAuth grants to reach corporate data. That is the same structural weakness as the FortiBleed lockouts, expressed in a different layer. In one case the credential is an administrator session on network gear; in the other it is a token that a business user approved months or years ago and never revisited. Both are forms of access that outlived the moment of their creation, and both are hard to see because they are working as designed.
For US technology companies, the OAuth problem is particularly awkward because it sits inside the productivity stack. A marketing team connects an analytics tool, an AI agent gets scoped access to a document store, and a contractor adds a project management integration. Each grant is a business decision made by someone who is not a security professional and who may not remember making it. The grant does not show up as a vulnerability, because it is not one. It shows up as a breach only after an attacker uses it.
The Social Reckoning Reminds Us Access Is a Human Story
The Verge's assessment of Aaron Sorkin's The Social Reckoning is a film review, but it belongs on the breach beat for one reason: it depicts how Frances Haugen, a Facebook civic integrity product manager, leaked a large trove of internal documents to Wall Street Journal investigative reporter Jeff Horwitz. That is not a firewall bypass or a forgotten token. It is a person with legitimate access choosing to move material out. The film's relevance to the current pattern is that it normalizes a lesson that security teams keep having to relearn: the most consequential access is often the access that was granted deliberately and never fully revoked or monitored.
It would be a mistake to treat the film as a guide to breach prevention, and The Verge notes that it mixes cinematic flair with details that hew closely to real life. The useful takeaway for US companies is narrower. Insider-driven document leaks and outsider-driven token abuse are not opposites. They are two ends of the same continuum of standing access that was never designed to expire. When a company reviews its breach exposure, the question is rarely whether an attacker can guess a password. It is how many people, tools, and tokens can already reach the data, and how many of those the organization can actually name.

