Third-Party Tools Became the Breach Entry Point
Article

Third-Party Tools Became the Breach Entry Point

Bitget, DIVD and the agentic security debate point to one pattern: attackers now breach US firms through the trusted vendors and agents already inside the perimeter.

NagiSeptember 30, 20264 min read

Photo: BleepingComputer

The Thread

The common thread in the recent breach log is not the target, but the entry point. Bitget lost $387.5 million after a zero-day in third-party security products, the Dutch Institute for Vulnerability Disclosure was breached by an automated AI agent, and analysts are warning that agentic security itself is shrinking the window defenders have to react. In each case the attacker did not defeat the victim's own defenses; the attacker used the victim's trusted tools, agents or credentials to walk through them.

The Perimeter Moved Into the Supply Chain

Bitget's disclosure, as BleepingComputer reported, is the clearest example. The exchange lost $387.5 million last week, and the attackers got in by exploiting a zero-day flaw in third-party security products. That detail matters more than the dollar figure. Security vendors sell themselves as the layer that catches what everything else misses, which is why their software is granted privileged access across customer environments. A zero-day in that layer converts a defensive purchase into an offensive foothold, and it does so across every customer running the vulnerable product at once.

For US technology companies, the practical consequence is that vendor risk is no longer a procurement formality. A single upstream flaw can compromise an entire customer base before any individual security team has a signature or a patch. The exposure is not proportional to how well a company hardens its own network; it is proportional to how much privileged software it has installed from someone else.

The Attacker Is Now Automated

DIVD's experience, also reported by BleepingComputer, adds a second dimension. The nonprofit described the AI-driven attack as "loud and very, very messy," which is a useful description because it inverts the usual assumption that sophisticated intrusions are quiet. An automated agent does not need to be stealthy to succeed. It needs to be fast, persistent and cheap enough to run repeatedly.

That changes the economics of defense. Human attackers scale with headcount and patience. Automated agents scale with compute. A small organization like DIVD, which exists to disclose vulnerabilities in the public interest, has neither the budget nor the staff to absorb a high-volume, low-finesse assault that never tires. The same asymmetry applies to any US company whose security operations center is staffed for human-paced threats.

Agents Act on Legitimate Instructions

SiliconANGLE's analysis of agentic security strategy supplies the third piece. The point there is not that agents are malicious, but that they can act on legitimate instructions in unexpected ways. An agent with credentials can call tools and choose its own route toward a goal, and that expands the number of paths security teams must monitor. The risk materializes even when nobody instructs the agent to cause harm.

This is where the breach beat and the emerging agentic conversation converge. Bitget was breached through a product, DIVD through an automated agent, and both illustrate the same structural weakness: the systems inside the perimeter are increasingly capable of independent action, and independent action is hard to constrain with controls designed for deterministic software.

Why the Breach Window Is Closing

Traditional controls assume a sequence: a threat appears, defenders detect it, investigate, and respond. Mobile devices, cloud infrastructure and remote work already compressed that sequence. Agentic systems compress it further, because an agent can complete a task chain in the time a human analyst spends opening a ticket. SiliconANGLE's framing is that the breach window is shrinking, and the Bitget and DIVD incidents show what it looks like when the window is effectively already closed.

The uncomfortable implication for US enterprises is that detection-and-response postures built around human review cycles may no longer be sufficient on their own. If an automated agent can move from initial access to action faster than a response team can triage an alert, then the value of the alert depends on whether anything downstream can act on it automatically and safely.

What This Means in the US Market

US technology companies sit at an intersection of these pressures. They buy heavily from third-party security vendors, they are among the earliest adopters of agentic tooling, and their customers expect both speed and accountability. Bitget's loss, reported by BleepingComputer, is a reminder that breach costs on crypto platforms translate into customer losses directly, and US exchanges and fintechs face the same structural exposure when they depend on upstream security software.

DIVD's case is a reminder that automated attacks do not discriminate by size. The nonprofit was targeted precisely because it does vulnerability disclosure work, which is public-interest infrastructure that many US firms rely on indirectly. When a disclosure body is disrupted, the downstream effect is slower patching across the entire ecosystem, including for American companies that never interacted with DIVD directly.

And SiliconANGLE's point about agents using credentials and calling tools is a warning about the next wave of internal risk. As US enterprises deploy agents to handle security operations, procurement, and infrastructure tasks, each deployment adds a set of legitimate capabilities that can be turned toward illegitimate ends by an attacker who gains control of the agent or manipulates its instructions. The breach surface grows with the autonomy granted.

What to Watch

Three things, all grounded in what the stories actually say. First, watch for details on the third-party security product implicated in the Bitget breach, since the identity of an upstream vendor determines how many other US firms share the exposure. Second, watch how DIVD describes the automated agent that hit it, because the mechanics of that attack will indicate whether similar tooling is being reused against other targets. Third, watch whether agentic security strategies in the US market begin to include explicit controls on credential use and tool invocation, since SiliconANGLE's analysis identifies those as the paths that expand the breach surface. Until those controls are standard, the pattern is likely to repeat: the breach will arrive through something the victim already trusted.

More on this beat: Cybersecurity on TechManNews.

#data breaches#supply chain security#agentic AI#cryptocurrency exchanges#vulnerability disclosure#US enterprise security

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.

Third-Party Tools Became the Breach Entry Point | TechManNews