The attacks logged on this beat in recent weeks point to a single uncomfortable pattern: attackers are not breaking into US networks so much as being let in. A former-service-member turned BEC fraudster, a zero-day in an appliance defenders already trusted, and a Pentagon breach measured in millions of personnel records all describe the same failure mode. The perimeter is not being stormed; it is being used.
Access Is the Product
The most striking story of the three, in terms of scale, is the breach at the U.S. Department of Defense's information systems. As Tom's Hardware reported, hackers breached the department's systems and the records of nearly three million military and civilian personnel are now in the wild. The Pentagon says it has secured the source of the leak. That framing matters. Securing a source of a leak is not the same as recovering the data, and it is not the same as preventing the next one. Once personnel records are exfiltrated, the damage is a long tail of identity exposure and targeting risk that no patch cycle can unwind.
What the Pentagon incident shares with the other two is that the intruders did not need to invent anything. They needed access, and access is abundant.
The Insider Is the Cheapest Exploit
The second logged story is the most direct illustration. Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise scams and phishing campaigns, as BleepingComputer reported. This is not a story about sophisticated tradecraft. It is a story about people who understood the systems, understood the vocabulary, and understood which emails get opened.
That is the pattern worth naming. BEC attacks succeed because they imitate trust, and former insiders have more trust to imitate than any outside actor.
The Appliance You Already Trusted
The third story closes the loop. According to BleepingComputer, attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. The important word in that sentence is not "zero-day." It is "credentials." The zero-day got the attackers in the door. Credential theft is what let them walk around inside.
NetScaler sits at the edge of a lot of US enterprise and government networks. It is the kind of infrastructure that is assumed to be hardened because it is assumed to be boring. When an edge appliance becomes a credential-harvesting platform, the attacker inherits the trust the appliance already had.


