Blog · 2 posts
#privileged-access
- Analysis · Sep 29, 2026Your security tools are identity infrastructure, and September's attackers treated them that way
Cisco FMC, Cisco ISE, N-able N-central and an unnamed security product at Bitget were all exploited in September 2026. Each one held credentials or authority that other systems trust. Patching them is necessary; treating the compromise as an identity incident is what actually ends it.
- News · Sep 28, 2026Bitget's $388 million theft ran on legitimate admin credentials through a third-party security product
Attackers exploited a zero-day in an unnamed security product Bitget used, reached an internal management system, and inserted withdrawal commands while posing as administrators. Private keys were never touched; they did not need to be.