📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The Security Stack Is Fraying at Every Layer at Once

Photo: BleepingComputer

Article

The Security Stack Is Fraying at Every Layer at Once

Arjun NairSeptember 9, 20266 min read
📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The Thread

The three stories that crossed the cybersecurity desk this week are not three separate incidents. They are three symptoms of a single structural condition: the security assumptions baked into every layer of the technology stack are eroding at the same time, and the tools we have built to defend that stack are themselves becoming part of the problem. Whether it is a healthcare vendor leaking patient data, a kernel vulnerability in enterprise software, or an AI agent breaching consumer gadgets, the common pattern is that trust is no longer a property of any single component - it is a fragile, distributed fiction that fails upward and outward.

The Vendor Layer: Trust by Contract, Not by Evidence

The Veradigm disclosure, as reported by BleepingComputer, is a textbook case of third-party risk that has become first-party liability. Veradigm, a healthcare technology company, disclosed a data breach after an incident at one of its third-party vendors exposed patients' personal data. The phrasing matters: the attacker hit the vendor, but the breach is Veradigm's. The company warned patients, presumably because the data held by that vendor belonged to them.

This is not an anomaly in the supply chain; it is the supply chain's default state. American healthcare companies, in particular, have spent years consolidating services into a handful of cloud and data-processing partners, often without auditing those partners' security postures beyond contractual clauses. When a ransomware gang claims an attack, as happened here, the entire chain - vendor, primary company, and patient - discovers that the contract did not include a clause for shared responsibility in a crisis. The result is that US consumers, already wary of healthcare data handling, now face a situation where their personal data can be exposed by a company they never directly dealt with. The pattern is not that vendors are malicious; it is that the security of the weakest link is treated as a legal problem rather than an engineering one.

The Kernel Layer: The Floor Is Not Solid

The second story, from BleepingComputer, is about SAP addressing 20 vulnerabilities in its September 2026 updates, including a maximum-severity memory corruption flaw in the SAP Kernel code, dubbed 'OVERPASS.' This is the layer that most enterprises assume is unbreakable - the kernel of the software that runs their core business processes. When a kernel flaw is rated maximum severity, it is not a nuisance; it is a hole in the floor.

The 'OVERPASS' naming is instructive. It suggests a path that bypasses the usual security controls, and in kernel code, there is no higher privilege to escalate to. For US companies running SAP for finance, HR, or supply chain, this is not an abstract concern. An attacker who exploits a kernel memory corruption flaw can often read or write anything in memory, which means they can steal credentials, alter transactions, or move laterally with impunity. The fact that SAP has issued a patch is good, but the pattern is troubling: the foundational software layer, maintained by one of the largest enterprise software vendors in the world, still ships with flaws that allow full compromise. And the time between a patch being available and an exploit being developed is shrinking, as cybersecurity professionals have noted for years.

The Consumer Layer: Automation as an Attack Surface

The third story, from Wired, is the most forward-looking and the most alarming. An AI agent, after safety guardrails were removed from a powerful open-source model, found vulnerabilities in household devices and hacked into a PC. The author then used the same agent to tell them how to fix everything. This is a mirror image of the first two stories: while vendors and kernel developers are trying to patch their own flaws, the attack surface has moved to the edge - to routers, smart speakers, cameras, and other internet-of-things devices that American consumers have installed by the dozen, often without changing default passwords or updating firmware.

Advertisement

📣

728x90

MID_CONTENT_2

The Wired narrative is not a cautionary tale about rogue AI; it is a demonstration that the security tools of the near future are dual-use. The same agent that found vulnerabilities could be directed by a malicious actor with the same open-source model and the same removed guardrails. Remove the safety rail, and the agent becomes a penetration tester for hire, but at machine speed. For US consumers, this means the gap between what a skilled human hacker could do to a home network and what a patient AI agent can do is narrowing dramatically. The author's conclusion - that the exercise made everything more secure - is optimistic, but only because the agent was on the author's side.

The Common Thread: Nobody Is Watching the Watchers

Put the three stories together, and the pattern is clear: no layer of the stack can be trusted to police itself. The vendor layer fails because oversight of third parties is contractual, not technical. The kernel layer fails because even the most critical software is written by humans and tested imperfectly. The consumer layer fails because devices are deployed without maintenance, and now autonomous agents can discover and exploit that neglect at scale.

There is a deeper irony here. The AI agent in the Wired story was used to find vulnerabilities and fix them, but the same agent class is what attackers will increasingly use to find vulnerabilities in the other two layers. A kernel bug like 'OVERPASS' is exactly the kind of thing an AI agent could hunt for in source code or probe for in memory, given the right access and no guardrails. A third-party vendor breach like the one Veradigm suffered could have been discovered by an agent that reads breach forums or scans exposed databases. The security industry's own tools - vulnerability scanners, penetration testers, automated detection - are all being augmented by AI, and the line between defense and offense is blurring.

What This Means for US Technology Companies and Consumers

For US technology companies, the implication is that security cannot be an afterthought at the perimeter. It must be a property of the entire stack, from the kernel to the third-party vendor to the consumer device. That is not a new insight, but these three stories show that the industry is still not acting on it. Veradigm's breach shows that vendor management is still a box-checking exercise. SAP's patch shows that even the most mature vendors ship critical flaws. The Wired experiment shows that consumers are now the last line of defense - and they are not equipped for that role.

For US consumers, the pattern means that the data they entrust to healthcare companies, the software their employers run, and the devices in their homes are all vulnerable in ways that are increasingly automated to exploit. The advice from the AI agent in the Wired story - change default passwords, update firmware, segment networks - is sound, but it is also a burden that most consumers cannot bear alone. And when a healthcare vendor is breached, it is not the consumer who has a choice about whether to trust them; it is a mandatory relationship based on insurance, employment, or medical necessity.

What to Watch

What the next chapter will look like is grounded in these three stories. First, watch whether regulatory pressure forces companies like Veradigm to disclose not just the breach but the exact contractual and technical controls they had in place with the third-party vendor. If such disclosures become standard, the market will start to price in vendor risk more accurately. Second, watch how enterprises respond to the 'OVERPASS' patch: the speed of adoption, not the fix itself, will determine how many US companies get hit by exploits of this kernel flaw. Third, watch how the open-source AI community handles guardrails. The Wired experiment removed them deliberately; an attacker will not need to. If those models are not hardened by default, the consumer threat surface will expand faster than it can be patched. The thread running through all three stories is that security is not a product to be bought but a discipline to be practiced across every layer, every day - and the current practice is failing.

More on this beat: Cybersecurity on TechManNews.

Advertisement

📣

728x90

IN_ARTICLE_5

#cybersecurity#supply chain#kernel vulnerabilities#AI agents#healthcare data#consumer IoT

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.