📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The New Attack Stack: MFA, Zero-Days, and Returned Ransoms

Photo: BleepingComputer

Article

The New Attack Stack: MFA, Zero-Days, and Returned Ransoms

Three unrelated attacks reveal a shift: cybercriminals now bypass authentication, exploit unpatched commerce platforms, and negotiate rather than hold data hostage.

Arjun NairSeptember 7, 20266 min read
📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The New Attack Stack

Look past the separate targets and the different payloads, and the three incidents logged on this desk in the last two days describe a single, uncomfortable reality about cybersecurity in September 2026: the barriers that once defined a successful attack - multi-factor authentication, patched software, and even the threat of total loss - are all eroding at once. One attack quietly walks past MFA at hundreds of organizations. Another exploits a flaw that affects every version of a dominant commerce platform, with no patch available at the time of exploitation. A third steals hundreds of millions in bitcoin, then returns most of it after a fix, keeping a ransom paid in cryptocurrency for the privilege of a resolution. For US technology companies and consumers, these are not isolated stories. They are three data points on the same curve.

The common thread is that each attack weaponizes a trust assumption. BigBear 2.0 trusted that a second factor makes phishing useless. The Magento vulnerability trusted that the platform, however old, was not carrying a universal backdoor. The Liquid Network hackers trusted that once funds were moved, they were gone - until the network patched the flaw, proving that even cryptocurrency settlements can be undone by code. In every case, the defender’s assumption was not merely weak; it was inverted by the attacker.

The Authentication Assumption Falls

The BigBear 2.0 phishing service, as BleepingComputer reported, has bypassed multi-factor authentication at 258 organizations and stolen more than 5,000 Microsoft 365 credentials. MFA was sold to American enterprise as the near-absolute stopgap after password sprays and credential stuffing became routine. The service does not break MFA cryptographically; it likely uses adversary-in-the-middle techniques that capture a one-time code or push approval in real time, then replay it. That is not a novel exploit but a process failure: the user, not the token, is the weakest link. For US companies, the implication is blunt - MFA is now a speed bump, not a wall. Every vendor dashboard that counts MFA adoption as a security metric is measuring the wrong thing. The credential theft at 258 organizations suggests that the tooling for this bypass is commoditized, cheap, and available to anyone willing to rent a service. The effect on the US market is a recalibration of what "phishing-resistant" means. Microsoft 365 is the backbone of most American mid-market and enterprise productivity; 5,000 stolen accounts are not a rounding error but a dataset for lateral movement, invoicing fraud, and supply-chain impersonation.

The Zero-Day Without a Patch

The Magento and Adobe Commerce "StyleSmuggler" zero-day, as BleepingComputer reported, affects all versions of the platform and has been used to deploy a Linux backdoor. That last detail matters. A backdoor on Linux - not the typical web shell on a shared Windows host - indicates a deep foothold, likely at the OS level, and one that persists beyond a simple file cleanup. For the US e-commerce market, Magento and Adobe Commerce power a significant share of online storefronts, including many mid-sized retailers that lack dedicated security teams. A zero-day affecting all versions means there is no safe upgrade path in the interim. Merchants are left with two bad options: take the store offline or monitor for indicators of compromise they may not know how to see. The exploitation was active in the wild before any disclosure, meaning that the attackers had a window of complete invisibility. For US consumers, the threat is indirect but real: a compromised commerce platform can inject skimming code into the payment page, capturing card details and personal data without any visible failure. The attack does not need to be sophisticated after the initial breach - it just needs to be quiet. The Linux backdoor suggests the attackers intended to stay, collecting data over weeks or months, not a smash-and-grab.

Advertisement

📣

728x90

MID_CONTENT_2

The Ransom That Came Back

The Liquid Network heist, as SiliconANGLE reported, involved about $320 million in stolen bitcoin, with the hackers returning most of it after the network patched the vulnerability. They kept 598 bitcoin, worth roughly $47 million, as a sort of negotiated fee. This is not a standard ransomware payment; it is closer to a bug bounty paid under duress. For the US cryptocurrency sector, the pattern is alarming and weirdly hopeful at the same time. The theft proves that even supposedly settlement-settled networks - those built to be immutable - can be reversed if the vulnerability is found early enough. The return proves that these attackers, despite the stereotype, are rational actors who understand that holding a poisoned asset is worse than returning it and keeping a portion. But the retained $47 million is not a rounding error. It is a price tag for a class of exploit, and it will be studied by other criminals as a template. The US market for digital assets, already under regulatory scrutiny, now faces a narrative problem: if a network can claw back stolen funds after the fact, the finality that makes blockchain attractive is conditional. Conversely, if attackers can steal $320M and walk away with $47M, the deterrent effect of "traceable on the ledger" is weaker than assumed.

The Business Model of Partial Theft

Across these three stories, the attackers are not seeking maximum destruction or maximum reputational damage. They are seeking a negotiated outcome. BigBear 2.0 sells a service, not a vendetta. The Magento backdoor operators likely monetize slowly by skimming or selling access. The Liquid Network hackers returned 85% of the loot in exchange for a sizable, yet smaller, guaranteed payout. This is a shift from the 2010s model of encrypt-and-demand. Now, the threat is not that your data will be destroyed; it is that your operations will be interrupted until you pay, or that your reputation will suffer a disclosure you cannot control. For US companies, the new ransomware is not necessarily about locking files - it is about creating enough chaos that the cost of remediation exceeds the cost of payment. The BigBear 2.0 victims did not lose data; they lost trust in their authentication. The Magento victims may not even know they are breached until a credit card database appears on a forum. The Liquid Network case adds a twist: the attackers themselves set a price for the return, and the network accepted it by patching first. That is a negotiation, not a heist. US legal frameworks, including sanctions and anti-racketeering laws, are not designed for this gray zone where attackers become quasi-contractors.

What the US Defender Must Watch

For American technology companies and their customers, the watch item is not a single vulnerability but the decay of edge assumptions. The next BigBear-style service will target not just Microsoft 365 but Google Workspace, AWS identity, and Okta. The next Magento zero-day could affect Shopify, Salesforce Commerce Cloud, or any PHP-based storefront. The next Liquid Network attack will not need to return the funds - it will simply find a newer, more obscure settlement layer. The practical takeaway from the three stories is that security teams must treat every layer as hostile: do not assume MFA works, do not assume a platform without a known CVE is safe, and do not assume blockchain finality is final. The only defense that survives these attacks is detection and response speed, not prevention. As the Liquid Network case showed, a fast patch can recover most of the value. As the Magento case showed, a fast detection can stop a backdoor before it spreads. And as the BigBear case showed, a fast credential reset after a suspicious login can prevent a single phish from becoming 5,000 stolen accounts. None of these are new ideas. The difference in 2026 is that attackers are now pricing them precisely, and the market is beginning to accept partial loss as the new norm. For US consumers, the cost of that norm is higher prices and weaker privacy. For US companies, the cost is a permanent state of assumed compromise. The thread is not doom, but it is a warning: the security perimeter is gone, and the only question left is how quickly you can shrink the blast radius.

More on this beat: Cybersecurity on TechManNews.

Advertisement

📣

728x90

IN_ARTICLE_5

#cybersecurity#phishing#zero-day#cryptocurrency#ransomware#MFA

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.