Daylila

Cybersecurity · Sunday, 26 July 2026

01 · Briefing · what happened

The lock everyone trusts turned out to have a spare key this week

Cybersecurity 4 min 12 sources

Attackers spent the week walking straight past the defences we lean on most - a password, a second code, a fresh patch. What stopped them was never one wall. It was having more than one.

Most weeks in security have a single big breach. This one had a theme. Nearly every defence people trust on its own got walked past somewhere - and the places that held were the ones with a second line behind the first.

The second code stopped being a wall

For years the advice has been simple and good: turn on two-factor authentication, so a stolen password alone can’t get in. This week showed the limit of that advice.

German police and Frankfurt’s cybercrime unit took down Kratos, one of the most widely used criminal phishing kits, pulling more than 200 servers offline. Indonesian authorities arrested the man they say built it [1]. Investigators estimate about 1,800 paying customers ran roughly 15,000 phishing campaigns a month through it [1]. Kratos did not just grab passwords. It stole the session cookie too - the small token your browser holds that says “this person already logged in” [1]. That one cookie is enough to walk past two-factor authentication as you.

The trick has a name: adversary-in-the-middle. The fake login page quietly relays what you type to the real Microsoft in real time, catches the resulting session, and hands the attacker a logged-in seat [1]. Your password and your second code both worked exactly as designed. They just worked for someone else.

A separate campaign made the same point from another angle. On Thursday the NSA, CISA - the US cyber-defence agency - and partner agencies issued a joint warning [2]. A Russian espionage group has exploited a flaw in Zimbra webmail since at least July 2025 [2]. Simply viewing a booby-trapped email was enough to run hidden code inside the victim’s own mailbox [2]. It stole the last 90 days of mail, the full address book, the password saved in the browser, and the recovery codes kept for two-factor [2]. A second code is a poor backstop once the attacker has copied it too.

The patch is only a wall once it exists

The other half of the week was defences that had not been built yet.

A zero-day is a flaw the maker does not yet know about. There is no patch and no warning, so attackers using it have a clear run until it is found. Several landed at once. From late June, a group tracked as UTA0533 quietly exploited two flaws in SonicWall’s remote-access VPN boxes as zero-days, chaining them to seize full control [3]. SonicWall shipped fixes only this week. Check Point patched a flaw in its management console that let an unauthenticated attacker log in with full administrator rights, after a handful of customers were already targeted [4]. And attackers used a Microsoft SharePoint flaw to steal a server’s machine keys - the master secret it uses to trust logins [5]. That let them keep their access even after the server was patched.

That last detail is the sharp one. A patch closes a hole, but it does not undo what came through while the hole was open.

Where it lands on you

None of this means turn off two-factor. The opposite. This week also brought a plain reminder of why it exists.

Chick-fil-A told customers their loyalty accounts were broken into by credential stuffing: attackers took username-and-password pairs leaked from other companies and tried them here, betting that people reuse passwords [6]. Against that flood, a second code is exactly the wall that holds. The lesson is not that two-factor failed. It is that two-factor is one layer - strong against some attacks, weak against others - which is precisely why it cannot be the only one. If you can, move the accounts that matter to a passkey, the phishing-resistant kind a fake page cannot relay. And if you are ever “logged in” somewhere you did not just sign in to, treat it as the warning it is.

The rest of the week filled in the picture. A Proofpoint report published July 22 found two-thirds of ransomware victims believed AI made the attack more effective, mostly by writing sharper lures [7]. And 40% said it got in through that first human click [7]. A Texas finance firm, Upbound, tied a breach to $13 million in fraudulent contract losses [8]. Australian energy giant Origin confirmed a breach of its own [9]. Oracle shipped 1,449 patches in a single quarterly batch [10], and Apple fixed three flaws that may already have been exploited [11]. One report counted a new ransomware crew appearing roughly every week [12].

No single fix on that list would have stopped all of it. That is the whole point - and the lesson underneath it.

02 · Lesson · why it matters

Why safety is layers, not a wall

No single guard is reliable, so we stack many imperfect ones - and trouble comes only on the rare day the holes in all of them happen to line up.

The cheese with holes in it

Picture a slice of Swiss cheese. It has holes, so on its own it stops nothing - hold it up and you can see straight through. Now stack a second slice behind it, and a third. Each still has holes, but the holes sit in different places. To see through the whole stack, you would need a spot where a hole in every slice lines up at once. Each slice you add makes that rarer.

That is the whole idea behind keeping things safe, and it has a plain name: defence in depth. You stop hunting for one perfect wall, because there isn’t one. You accept that every guard has holes. Then you put enough of them in a row that an attacker has to get lucky through all of them at once.

Every guard broke somewhere this week

Read this week as a list of failures and it sounds hopeless. A password is a slice, and its hole is obvious: people reuse it, so a leak somewhere else becomes a key here. So we added a second slice, the login code, meant to catch the stolen password. But that slice has holes too - steal the session token after login, or copy the recovery codes, and you walk right through it. Add a third slice, a fresh patch, and it has the widest hole of all, because for a while it simply does not exist. On a zero-day, that slice is missing entirely.

Every one of those guards was walked past somewhere in the past seven days. Not one of them is a wall.

Read as slices, it is the opposite of hopeless

Now read the same week as a stack. The password stops the lazy attacker working from an old leak. The login code stops the one who has only your password. The quiet monitoring behind them both stops the one who got past the first two. No single slice does the whole job, and none of them has to. Together they turn “one mistake and you are in” into “you need every hole to line up on the same day.”

That is why the people who did not get fully breached this week were rarely the ones with the strongest single lock. They were the ones with a second slice waiting when the first one failed.

The real danger is two slices sharing a hole

Here is the catch, and it is the sharp edge of the whole idea. Defence in depth only works if the layers are genuinely independent - if they fail for different reasons. The moment two of them share a weakness, the stack quietly collapses back into a single slice.

That is exactly what the adversary-in-the-middle trick does. It defeats the password and the login code in one move, because it steals them both at the same instant, from the same fake page. Two layers, one hole. They looked like separate guards, but they were checked at the same door - so one breach took both. A stack of slices is only as deep as the holes it does not share.

The better question

So the useful question is never “is this defence strong?” No defence is strong enough on its own, and asking it invites the false comfort that got the reused-password crowd breached. Two better questions replace it. What stands behind this guard when it fails? And, quieter but sharper - do my layers share a weakness?

A house with a lock and an alarm is safer than one with two locks, because the alarm fails for different reasons than the lock. Two locks share a hole. A lock and an alarm mostly do not.

We are inside the stack

This is not only a computer idea, and that is the point of noticing it. A pilot’s checklist, a second doctor reading the same scan, the co-signer on a large payment - each is another slice, each imperfect. Each is there because the one in front of it will someday show a hole. We reach for the single reassuring wall - the strong password, the one trusted person, the rule that settles it. We do it because one wall is easy to picture and easy to trust. The world rarely offers one; it offers slices.

The humbler move is to stop hunting for the guard that cannot fail and start asking what waits behind the one that will. And to remember that we are not standing above this arrangement, inspecting it. We are inside it - one slice among the others, checked at our own door. And our own certainty that we are covered is often the widest hole in the stack.

03 · Lab · your turn

Stack the layers

Rehearse defence in depth - stack independent security layers and watch a breach only get through when the holes line up.

04 · Hope · carry this

No single guard held this week, and yet the sky did not fall - because safety was never one flawless wall, but the quiet habit of putting a second line behind the first for the day it gives way. The same days that exposed the holes also saw police pull 1,800 criminals' tools offline in a single raid, a reminder that the people closing the gaps are gaining ground too.

Across the beats