Cybersecurity · Sunday, 26 July 2026
01 · Briefing · what happened
The lock everyone trusts turned out to have a spare key this week
Attackers spent the week walking straight past the defences we lean on most - a password, a second code, a fresh patch. What stopped them was never one wall. It was having more than one.
Most weeks in security have a single big breach. This one had a theme. Nearly every defence people trust on its own got walked past somewhere - and the places that held were the ones with a second line behind the first.
The second code stopped being a wall
For years the advice has been simple and good: turn on two-factor authentication, so a stolen password alone can’t get in. This week showed the limit of that advice.
German police and Frankfurt’s cybercrime unit took down Kratos, one of the most widely used criminal phishing kits, pulling more than 200 servers offline. Indonesian authorities arrested the man they say built it
The trick has a name: adversary-in-the-middle. The fake login page quietly relays what you type to the real Microsoft in real time, catches the resulting session, and hands the attacker a logged-in seat
A separate campaign made the same point from another angle. On Thursday the NSA, CISA - the US cyber-defence agency - and partner agencies issued a joint warning
The patch is only a wall once it exists
The other half of the week was defences that had not been built yet.
A zero-day is a flaw the maker does not yet know about. There is no patch and no warning, so attackers using it have a clear run until it is found. Several landed at once. From late June, a group tracked as UTA0533 quietly exploited two flaws in SonicWall’s remote-access VPN boxes as zero-days, chaining them to seize full control
That last detail is the sharp one. A patch closes a hole, but it does not undo what came through while the hole was open.
Where it lands on you
None of this means turn off two-factor. The opposite. This week also brought a plain reminder of why it exists.
Chick-fil-A told customers their loyalty accounts were broken into by credential stuffing: attackers took username-and-password pairs leaked from other companies and tried them here, betting that people reuse passwords
The rest of the week filled in the picture. A Proofpoint report published July 22 found two-thirds of ransomware victims believed AI made the attack more effective, mostly by writing sharper lures
No single fix on that list would have stopped all of it. That is the whole point - and the lesson underneath it.
02 · Lesson · why it matters
Why safety is layers, not a wall
No single guard is reliable, so we stack many imperfect ones - and trouble comes only on the rare day the holes in all of them happen to line up.
The cheese with holes in it
Picture a slice of Swiss cheese. It has holes, so on its own it stops nothing - hold it up and you can see straight through. Now stack a second slice behind it, and a third. Each still has holes, but the holes sit in different places. To see through the whole stack, you would need a spot where a hole in every slice lines up at once. Each slice you add makes that rarer.
That is the whole idea behind keeping things safe, and it has a plain name: defence in depth. You stop hunting for one perfect wall, because there isn’t one. You accept that every guard has holes. Then you put enough of them in a row that an attacker has to get lucky through all of them at once.
Every guard broke somewhere this week
Read this week as a list of failures and it sounds hopeless. A password is a slice, and its hole is obvious: people reuse it, so a leak somewhere else becomes a key here. So we added a second slice, the login code, meant to catch the stolen password. But that slice has holes too - steal the session token after login, or copy the recovery codes, and you walk right through it. Add a third slice, a fresh patch, and it has the widest hole of all, because for a while it simply does not exist. On a zero-day, that slice is missing entirely.
Every one of those guards was walked past somewhere in the past seven days. Not one of them is a wall.
Read as slices, it is the opposite of hopeless
Now read the same week as a stack. The password stops the lazy attacker working from an old leak. The login code stops the one who has only your password. The quiet monitoring behind them both stops the one who got past the first two. No single slice does the whole job, and none of them has to. Together they turn “one mistake and you are in” into “you need every hole to line up on the same day.”
That is why the people who did not get fully breached this week were rarely the ones with the strongest single lock. They were the ones with a second slice waiting when the first one failed.
The real danger is two slices sharing a hole
Here is the catch, and it is the sharp edge of the whole idea. Defence in depth only works if the layers are genuinely independent - if they fail for different reasons. The moment two of them share a weakness, the stack quietly collapses back into a single slice.
That is exactly what the adversary-in-the-middle trick does. It defeats the password and the login code in one move, because it steals them both at the same instant, from the same fake page. Two layers, one hole. They looked like separate guards, but they were checked at the same door - so one breach took both. A stack of slices is only as deep as the holes it does not share.
The better question
So the useful question is never “is this defence strong?” No defence is strong enough on its own, and asking it invites the false comfort that got the reused-password crowd breached. Two better questions replace it. What stands behind this guard when it fails? And, quieter but sharper - do my layers share a weakness?
A house with a lock and an alarm is safer than one with two locks, because the alarm fails for different reasons than the lock. Two locks share a hole. A lock and an alarm mostly do not.
We are inside the stack
This is not only a computer idea, and that is the point of noticing it. A pilot’s checklist, a second doctor reading the same scan, the co-signer on a large payment - each is another slice, each imperfect. Each is there because the one in front of it will someday show a hole. We reach for the single reassuring wall - the strong password, the one trusted person, the rule that settles it. We do it because one wall is easy to picture and easy to trust. The world rarely offers one; it offers slices.
The humbler move is to stop hunting for the guard that cannot fail and start asking what waits behind the one that will. And to remember that we are not standing above this arrangement, inspecting it. We are inside it - one slice among the others, checked at our own door. And our own certainty that we are covered is often the widest hole in the stack.
03 · Lab · your turn
Stack the layers
Rehearse defence in depth - stack independent security layers and watch a breach only get through when the holes line up.
04 · Hope · carry this
No single guard held this week, and yet the sky did not fall - because safety was never one flawless wall, but the quiet habit of putting a second line behind the first for the day it gives way. The same days that exposed the holes also saw police pull 1,800 criminals' tools offline in a single raid, a reminder that the people closing the gaps are gaining ground too.
More from Cybersecurity