The New Attack Stack
Look past the separate targets and the different payloads, and the three incidents logged on this desk in the last two days describe a single, uncomfortable reality about cybersecurity in September 2026: the barriers that once defined a successful attack - multi-factor authentication, patched software, and even the threat of total loss - are all eroding at once. One attack quietly walks past MFA at hundreds of organizations. Another exploits a flaw that affects every version of a dominant commerce platform, with no patch available at the time of exploitation. A third steals hundreds of millions in bitcoin, then returns most of it after a fix, keeping a ransom paid in cryptocurrency for the privilege of a resolution. For US technology companies and consumers, these are not isolated stories. They are three data points on the same curve.
The common thread is that each attack weaponizes a trust assumption. BigBear 2.0 trusted that a second factor makes phishing useless. The Magento vulnerability trusted that the platform, however old, was not carrying a universal backdoor. The Liquid Network hackers trusted that once funds were moved, they were gone - until the network patched the flaw, proving that even cryptocurrency settlements can be undone by code. In every case, the defender’s assumption was not merely weak; it was inverted by the attacker.
The Authentication Assumption Falls
The BigBear 2.0 phishing service, as BleepingComputer reported, has bypassed multi-factor authentication at 258 organizations and stolen more than 5,000 Microsoft 365 credentials. MFA was sold to American enterprise as the near-absolute stopgap after password sprays and credential stuffing became routine. The service does not break MFA cryptographically; it likely uses adversary-in-the-middle techniques that capture a one-time code or push approval in real time, then replay it. That is not a novel exploit but a process failure: the user, not the token, is the weakest link. For US companies, the implication is blunt - MFA is now a speed bump, not a wall. Every vendor dashboard that counts MFA adoption as a security metric is measuring the wrong thing. The credential theft at 258 organizations suggests that the tooling for this bypass is commoditized, cheap, and available to anyone willing to rent a service. The effect on the US market is a recalibration of what "phishing-resistant" means. Microsoft 365 is the backbone of most American mid-market and enterprise productivity; 5,000 stolen accounts are not a rounding error but a dataset for lateral movement, invoicing fraud, and supply-chain impersonation.
The Zero-Day Without a Patch
The Magento and Adobe Commerce "StyleSmuggler" zero-day, as BleepingComputer reported, affects all versions of the platform and has been used to deploy a Linux backdoor. That last detail matters. A backdoor on Linux - not the typical web shell on a shared Windows host - indicates a deep foothold, likely at the OS level, and one that persists beyond a simple file cleanup. For the US e-commerce market, Magento and Adobe Commerce power a significant share of online storefronts, including many mid-sized retailers that lack dedicated security teams. A zero-day affecting all versions means there is no safe upgrade path in the interim. Merchants are left with two bad options: take the store offline or monitor for indicators of compromise they may not know how to see. The exploitation was active in the wild before any disclosure, meaning that the attackers had a window of complete invisibility. For US consumers, the threat is indirect but real: a compromised commerce platform can inject skimming code into the payment page, capturing card details and personal data without any visible failure. The attack does not need to be sophisticated after the initial breach - it just needs to be quiet. The Linux backdoor suggests the attackers intended to stay, collecting data over weeks or months, not a smash-and-grab.


