"Technology alone will not win in cybersecurity. Dedicated professionals who challenge assumptions, share knowledge, and never stop looking for better ways to defend their organizations will make the real difference." - Danny Jenkins
What's happening: MFA, identity and access management (IAM), and single sign-on (SSO) have made credential theft more difficult, but they can't be the only protections in place. Identity security has moved beyond them. Attackers are directly targeting authentication tokens, abusing trusted identities after login, and intercepting authentication flows. This means organizations need to start verifying devices along with users and implementing controls over access privileges and application behavior to enforce strict identity security. If identity security is only asking who should be allowed access, it could be missing threat actors using stolen credentials, malicious insiders, and adversary-in-the-middle attacks. Identity needs to be verified throughout a session, not just at login.
Why it matters: If identity security is only asking who should be allowed access, it could be missing threat actors using stolen credentials, malicious insiders, and adversary-in-the-middle attacks. Identity needs to be verified throughout a session, not just at login.
The big picture: A valid login is no longer enough to establish trust. To authenticate a user session, the device must also be verified followed by least privilege access controls and behavioral monitoring to detect unusual requests or activity and stop incidents quickly.
What's happening: Romania's land registry went offline, along with internal email, effectively shutting down the country's real-estate market as sales could not be authenticated and citizens could not access proof of ownership. The attack itself was ordinary and preventable. The attacker(s) reportedly used known, unpatched vulnerabilities and stolen credentials that had been leaked online. Some data was exfiltrated, and reachable backups were reportedly wiped.
Why it matters: Detection tools monitoring for zero-day behavior or malware had little effect in this incident because the initial access was through a legitimate login and a bug that should have been patched previously.
The big picture: This was not a complex attack. It succeeded, and quickly, because of a lack of basic controls. Known vulnerabilities, exposed credentials, too much internal reach, and reachable backups turned a simple breach into a national outage. Organizations that address these fundamentals are far better positioned to stop similar attacks before they escalate.
SOC teams need more time to adjust to faster attacks
What's happening: As we've addressed in recent weeks, AI isn't creating new cyberattacks; it's increasing the speed and scale of them. To combat the increased burden on Security Operations Center (SOC) teams, incident response plans need to incorporate preventive controls and focus not only on who logged in but on what actions are attempted, which processes are executed, and what communications are initiated.
Why it matters:With so many tools, workflows, and systems to monitor, time is critical in incident response. Preventive controls that block unknown applications or scripts from running and unapproved actions from occurring reduces the number of alerts and allows SOC teams the time they need to investigate a request before it becomes an incident.
The big picture: Effective incident response starts long before an incident occurs. Zero Trust doesn't replace incident response plans; it ensures that when an incident occurs, there is far less damage because the SOC team is able to address it quickly.
Your security stack may detect the initial compromise. But what happens next?
Privilege escalation: The attack path most security tools overlook
Tuesday, August 11
11 a.m. EDT
Hosted by ThreatLocker CEO Danny Jenkins and CPO Rob Allen
What's happening: CVE-2026-50522 and CVE-2026-58644 are critical deserialization vulnerabilities in on-premises SharePoint, allowing for remote code execution. The former has a CVE of 9.8 and is under active exploitation. The flaw was patched by Microsoft last week as part of Patch Tuesday. Successful exploitation can lead to web shell deployment, credential theft, data exfiltration, and lateral movement throughout an environment. Researchers also warn that attackers may steal SharePoint machine keys, allowing them to maintain access even after the initial vulnerabilities have been patched.
Why it matters: Privileges of at least Site Owner are required for these exploits. Although there are several levels of privilege above Site Owner, this exploit would allow execution on the local server under the context held by the SharePoint process. Mitigation emphasis should be placed on theft of machine keys. Patching is crucial, but it will not remove the persistence mechanism if the keys were already compromised.
The big picture: Vulnerabilities provide initial access, but excessive trust is what allows attackers to succeed. Restricting access to SharePoint servers, limiting lateral movement, and continuous verification of users, devices, and applications helps reduce the impact of vulnerabilities, before and after patching.
Claude Cowork sandbox escape vulnerability in Linux VMs
More access means a larger attack surface
What's happening: Researchers discovered a sandbox escape vulnerability in Claude Cowork that could allow an AI agent running inside a Linux virtual machine to escape its restrictions and read or write files elsewhere on the host Mac. The flaw, codenamed SharedRoot, affected approximately 500,000 macOS users before being patched. From inside the VM, researchers said the agent could read and write files far outside the connected folder with no permission prompts.
Why it matters: As organizations adopt more AI agents with increasing autonomy, it's vital to review the permissions they're afforded. If an AI agent can access sensitive files, applications, or internal systems, a compromise of the agent can effectively compromise everything it is allowed to reach.
The big picture: AI agents should be treated no differently from users when it comes to enforcing least privilege access and application control policies. Limiting what AI agents are able to do in your environment reduces your attack surface in case of a compromise or unintended behavior.
ThreatLocker events
Meet the Cyber Hero Team in person at these upcoming events
Room blocks are now open for ZTW27 in Orlando, February 17–19, 2027.
Learn the skills cybercriminals don't want you to know directly from leading industry voices like Marcus Hutchins, Leo Laporte, Steve Gibson, and more.
Use code ZTWWEEKLY27 to save $200 on your registration: