A Pattern of Attacks on the Supply Chain
This week's security news does not describe four unrelated incidents. It describes one pattern: attackers are increasingly targeting the trusted intermediaries - vendors, platforms, identity systems, and artificial intelligence models - that companies rely on rather than breaking in directly. The stories logged by TechCrunch, The Verge, BleepingComputer, and other outlets over the past two days show that the perimeter has shifted from the enterprise's own walls to the third parties it cannot operate without.
Breaches at the Edges of the Crypto Economy
TechCrunch reported that scammers are targeting hundreds of thousands of crypto owners after Trezor confirmed a data breach at an email provider it relies on. This was the second data breach at a company that the hardware crypto wallet maker depends on. The significance is not the breach itself - email service providers have been compromised before - but the cascading effect. Trezor's customers chose a hardware wallet specifically to avoid custodial risk, yet their exposure came through a marketing or communications vendor. For US crypto holders, that means the security posture of a wallet manufacturer is only as strong as the weakest vendor in its chain. The scammers are not attacking the device; they are attacking the relationship between the device maker and its users. That is a lower-cost, higher-yield approach.
The Tooling Layer Becomes the Target
BleepingComputer reported that threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. Artifactory is not a consumer product; it is enterprise infrastructure used to store and manage software artifacts. A compromise there does not just expose one company - it can poison the software that company builds and distributes to its own customers. This is the supply-chain attack in its purest form. The attackers are not breaking into a bank or a retailer; they are breaking into the factory that makes the tools those institutions use. For US technology companies, the lesson is that the build pipeline is now a primary attack surface, and self-hosted instances of widely used tools are often the softest entry point.
Identity as the New Battlefield
The passkey-themed phishing campaigns against Microsoft 365 accounts, reported by BleepingComputer, show how quickly attackers adapt to defensive innovation. Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. Passkeys were supposed to reduce reliance on passwords and make phishing harder. Instead, attackers are using the language of passkeys - the promise of passwordless security - as a lure. The compromise does not require breaking the cryptography; it requires convincing a user that they are enrolling in or recovering a passkey when they are actually handing over access. For US companies that have moved to Microsoft 365 and are beginning to adopt passkeys, this is a direct warning: the human layer remains the most reliable exploit, even when the technology beneath it is sound.

