The Security Stack Is Being Attacked at Its Assumptions
Article

The Security Stack Is Being Attacked at Its Assumptions

Ransomware's pivot to backups, Anthropic's tiered access, and Asos's extortion hack all show attackers and defenders contesting the same trust assumptions.

ManishankarOctober 7, 20265 min read

Photo: BleepingComputer

The Thread

Four stories logged this week look unrelated: ransomware crews hunting backup infrastructure, OneSpan pushing electronic signature deeper into bank workflows, Anthropic loosening classifier restrictions for vetted security teams, and an extortion hack at Asos that reached customers directly. The common thread is that the security industry's implicit trust assumptions - that backups are out of reach, that a signature marks the end of a process, that safety classifiers can be tuned without cost, that an internal system breach stays internal - are the actual attack surface. Attackers and defenders are now contesting those assumptions rather than the products built on top of them.

Backups Stop Being a Refuge

BleepingComputer's report on ransomware groups targeting backup infrastructure is the clearest expression of the pattern. For years, the standard recovery advice assumed backups sat outside the blast radius. Ransomware operators have inverted that: rather than only encrypting production systems, they go after the recovery path itself, removing the victim's alternative to paying. Kaseya's guidance - isolated, immutable, and regularly tested backups - is not new advice, but the fact that it needs restating in 2026 indicates how many organizations still treat backup as a storage problem rather than a security boundary.

The implication for US technology companies is that "we have backups" is no longer a meaningful answer to a board or an insurer. The meaningful questions are whether those backups are reachable from the same identity plane as production, whether they can be deleted or encrypted by a compromised admin account, and whether anyone has actually restored from them recently. Backup vendors have spent years selling capacity and speed. The market is now being asked to sell isolation and immutability, which are architectural properties, not features.

Signatures Are a Step, Not a Solution

OneSpan's update to its Sign service, as reported by SiliconANGLE, is a smaller story with the same shape. The company is explicitly aiming at "the parts of the agreement process that slow down banks," acknowledging that electronic signing has become expected and therefore no longer differentiating. The value has moved to the workflow around the signature: identity verification, approvals, audit trails, and the handoffs between systems that still run on manual effort.

That is the same lesson as the backup story in a different register. The signature was never the security guarantee; it was a marker that a process had reached a certain point. Banks and their vendors are now being pushed to secure the process itself. For US financial institutions, which operate under overlapping state and federal expectations about records and authentication, this matters because the compliance question is shifting from "was this signed electronically" to "can you demonstrate who approved what, in what order, and under whose authority." Vendors that only handle the signing step are selling a commodity.

Safety Classifiers Meet Dual-Use Reality

Anthropic's expansion of its Cyber Verification Program into three tiers, folding in Project Glasswing, is the most interesting entry because it is a vendor conceding that a control it built is misaligned with a legitimate use case. SiliconANGLE reports that the company treats cybersecurity as dual use, so generally available models carry conservative classifiers, and the new tiers grant vetted security teams progressively fewer blocks on cybersecurity work.

This is the trust-assumption pattern applied to AI. The assumption behind conservative classifiers is that restricting output is cheap and safe. In practice, security teams doing legitimate defensive work - and, plausibly, offensive research under contract - hit those restrictions constantly, which pushes them toward models with fewer guardrails or toward self-hosted alternatives. The tiered structure is an attempt to preserve the safety posture while recovering the professional market. Whether tiering works depends entirely on verification: who vets the teams, against what standard, and what happens when a vetted team's access is abused. None of that is answered by the announcement itself, and US enterprises evaluating AI vendors for security work should treat the verification process, not the tier names, as the thing to scrutinize.

Extortion Moves to the Customer Channel

Engadget's report on Asos describes attackers who sent a push notification to shoppers announcing their own activity. The technical compromise is one story; the notification is the more consequential detail. It means the attackers had a channel to the customer base and chose to use it, converting a backend intrusion into a public extortion event with the retailer's own brand as the delivery mechanism.

This is the trust-assumption pattern again, and it has the sharpest US consumer angle. Retailers invest heavily in customer-facing app infrastructure - notifications, personalization, loyalty - because it drives engagement. That same infrastructure is an attacker's amplifier. A breach that might have been negotiated quietly in a back office becomes a reputational event the moment it reaches a push notification, and the pressure to pay rises accordingly. For US consumers, the practical consequence is that the app on their phone is now part of the attack surface for the company that made it, and notification permissions they granted for convenience are a channel they cannot easily audit.

What the Pattern Implies

Across all four stories, the defenders who fare best will be the ones who treat their own trust assumptions as liabilities to be tested rather than facts to rely on. Is the backup truly unreachable? Does the agreement process hold up after the signature? Do the model's guardrails cost more in lost professional users than they return in safety? Can the notification system be used against the customer?

For US technology companies specifically, two pressures compound. First, the market increasingly prices recovery capability and process integrity rather than point features, which disadvantages vendors selling a single step. Second, US enterprises face a security labor market that is unlikely to expand enough to compensate, which is precisely why vendors like Anthropic are being asked to let trained teams do more with the same tools.

What to Watch

Several things in these reports are worth tracking. Whether backup vendors ship genuinely isolated and immutable architectures as defaults, rather than as premium add-ons, will indicate whether the ransomware pivot is being met with structural change or marketing. Whether OneSpan's bank-focused features reduce manual handoffs in practice, or simply relabel them, is a test of whether signature vendors can move up the stack. Anthropic's three-tier verification program will be judged on its vetting process and its incident handling, neither of which is described in the announcement. And Asos's handling of an extortion attempt delivered through its own notification channel will set an early example for how US retailers respond when attackers address their customers directly.

None of these are predictions. They are the places where the underlying assumptions will either hold or visibly fail.

More on this beat: Cybersecurity on TechManNews.

#cybersecurity#ransomware#backup#artificial-intelligence#retail#enterprise-security

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.