Daylila

Cybersecurity · Friday, 31 July 2026

01 · Briefing · what happened

Your password reset, your MFA prompt - and why attackers walk right past both

Cybersecurity 4 min 20 sources

Phishing that hijacks a live login session is now the top way into companies, and the reassuring rituals - a real login page, an MFA tap, a fresh password - no longer stop it. Plus a 607,000-record UK breach, a 23-million-person dental leak, fresh zero-days, and North Korea inside the code supply chain.

Key takeaways

  • Phishing that hijacks a live login session is now the top way into companies, and it walks straight past the MFA prompt and the password reset that make people feel safe.
  • A brutal breach week: 607,000 UK education records, 23 million+ at a US dental firm, and a record $4.99 million average breach cost.
  • Fresh zero-days in Cisco, Arista, VMware, Chrome and Adobe need patching now, while North Korea keeps poisoning the open-source code developers build on.

Multi-factor authentication - the second check beyond a password, usually a code or a tap on your phone - is now everywhere. It is also being walked past. Phishing was the way in for just over half of all serious incidents from March to June, up from a third the previous quarter, according to Cisco’s Talos incident responders [1]. The reason is a shift in how the trap is built.

The login page that is real

The classic phishing warning was “check for a fake login page.” Attackers have made that advice obsolete. In one campaign that ran from late June into July, researchers at Check Point found attackers abusing Microsoft’s own genuine login system rather than cloning it - lures dressed as a Teams notification from HR, hitting users at 120 organizations [3]. A separate phishing kit, LogoKit, now builds a fresh page for each target in real time, pulling a live screenshot of the victim’s own company website to use as the background [4].

The dangerous part is a technique called adversary-in-the-middle, where the attacker sits invisibly between you and the real site and relays everything through. You type your password on the real page. You approve the real MFA prompt. Both work exactly as designed - and the attacker quietly copies the session token, the small pass your browser keeps so it does not ask you to log in again. In the legal sector, this method is now the single most common way in, 28.6% of all break-ins, even though MFA is nearly universal there [2].

Here is why it matters for anyone with an account: the advice we all trust - “if something looks off, change your password” - does little once the token is stolen [5]. Resetting a password does not cancel a session that is already open. The account still looks locked; the intruder is already inside. The defensive move, for firms and individuals, is phishing-resistant sign-in - passkeys or hardware keys that refuse to work on a site pretending to be your bank - and, after any scare, ending active sessions, not just swapping the password.

The bill for getting this wrong keeps climbing. IBM’s annual breach study, out this week, put the global average cost of a data breach at a record $4.99 million, up 12% in a year [6].

A heavy week for breaches

Britain’s Department for Education confirmed hackers took about 607,000 records - phone numbers and email addresses, no bank details - in an attack it says was contained quickly [7]. Days earlier, a parliamentary inquiry called an earlier UK breach, which exposed thousands of Afghans who had applied to flee the Taliban, a “foreseeable” failure, finding the Ministry of Defence used secrecy as a “shield” against accountability [8].

The scale elsewhere was larger. DentaQuest, a US dental-benefits firm, said a May intrusion may have exposed personal and dental-health data on more than 23 million people [9]. Chipmaker Analog Devices disclosed that intruders detected in June had stolen files [10]. Coca-Cola confirmed a breach at its Fairlife unit after the Anubis extortion group threatened to leak data [11]. And South Korea fined its largest telecom, KT, about $39 million after an investigation found a breach exposed 16,647 subscribers and led to fraudulent mobile payments for hundreds of them [12].

Zero-days to patch now

Several flaws are being exploited before fixes could be widely applied - the definition of a zero-day, a hole the vendor is racing to close while attackers already use it. Cisco warned that a flaw in its Secure Firewall Management Center, tracked as CVE-2026-20316, lets a remote attacker with no login access sign straight into affected devices [13]. Arista disclosed a command-injection zero-day in its VeloCloud Orchestrator [14]. VMware patched a critical “VM escape” bug in ESXi, the kind that lets code break out of one virtual machine into the host running many [15]. Google shipped Chrome 151 with fixes for 370 flaws, seven of them critical [16]. And Adobe’s Acrobat and Reader are under active attack through an unpatched flaw; the interim defense is to turn off JavaScript in the reader [17].

North Korea, inside the code you build on

Amazon researchers tied a North Korea-linked group to four separate poisonings of open-source JavaScript packages - the free building blocks developers pull into apps [18]. The operation hit widely used packages including axios, downloaded tens of millions of times a week, meaning one compromise can ripple into countless downstream apps. In response, GitHub and PyPI - the main homes for open-source code - added time-based defenses that slow how fast a newly published or altered package spreads [19].

The quiet one: water

The story with the least coverage may matter most. CISA, the US cyber-defense agency, urged water and wastewater utilities on July 30 to protect their operational controls, days after a coordinated attack disrupted automated systems at dozens of Minnesota water utilities [20]. The agency’s blunt advice: take the internet-facing control devices offline. These are the systems that dose chemicals and run pumps - a reminder that the least glamorous infrastructure is often the least defended.

02 · Lesson · why it matters

The lock that only has to look locked

A measure can make everyone feel safer while making no one safer - and the feeling is exactly why it survives.

This week, the rituals we trust to protect us worked perfectly and protected no one. People typed their real passwords on the real login page. They approved the real code on their phones. The little padlock in the browser sat there, reassuring. And the attackers walked in anyway, because they were relaying the whole performance to the real site and copying the pass it handed back.

Then came the second ritual. Told to reset their passwords, people did - and it changed nothing, because the intruder already held an open session. Two acts of security. Both felt protective. Neither reduced the risk that was actually there.

The name for this

There is a term for a measure adopted because it looks protective, not because it works: security theater. The security expert Bruce Schneier coined it for the airport kind - the rituals that make a line of travelers feel watched over while stopping almost nothing.

But it lives everywhere. The password box that demands a symbol and a capital letter. The annual “we take your privacy seriously” email. The compliance checkbox ticked so an auditor sees a tick. The badge on a website that says “secure.” Each is visible. Each is reassuring. And each can be completely hollow.

The tell is simple. Ask of any safety measure: does it stop the actual attack, or does it stop me from worrying about it? Those are different questions, and the answers come apart more often than we would like.

Why the show wins

Real security is mostly invisible and boring. It is a system quietly ending stale login sessions. It is a key that refuses to work on a fake site. It is a control device taken off the public internet. Nobody feels protected by these, because there is nothing to feel. The work happens where you cannot see it.

Theater is the opposite. It is built to be seen. The padlock, the reset prompt, the code on your phone - their whole job is to be noticed and to soothe. So organizations, and people, drift toward the visible. You get credit for the thing customers can point at. You get little for the invisible thing that actually holds.

That is the trap. Attention flows to the show, and the show is not where the safety is.

The opposite it hides behind

Security theater is easy to confuse with something real, because they look alike from the outside. The real thing is a costly signal.

A costly signal proves something precisely because it is expensive to fake. A company that pays for a genuine independent audit, or opens its code to public inspection, has spent something hard. Money, exposure, the risk of looking bad. The cost is the proof. You cannot cheaply pretend to have done it.

Security theater is the cheap cousin. It borrows the look of the costly signal - a badge, a certificate, a stern email - without paying the price behind it. A padlock icon costs nothing to display. A real audit costs a great deal to pass. Same reassuring surface; opposite substance. Learning to tell them apart is most of the skill.

You are already inside this

It is tempting to file this under someone else’s problem - the IT department’s, the company’s. It is not. Every account you hold sits on measures you were told to trust. You were told MFA keeps you safe, so you stopped worrying about your login. You were told to reset your password, so you felt you had acted. The reassurance did its job on you.

That is the quiet cost. Theater does not just fail to protect - it spends down your attention. Feeling handled, you stop asking the harder question. The measure that makes you comfortable is often the one that makes you careless. The break-ins this week did not defeat vigilant people. They defeated reassured ones.

Why it keeps getting built

Nobody sits down to build a hollow defense. The show gets built because the incentives all point at it. A regulator needs to see a control in place. A customer needs to see a badge. An auditor needs a box to tick. A budget holder needs something to show for the money. Every one of them is satisfied by the appearance of safety, and the appearance is cheap.

So the arrangement serves its makers. The company looks compliant, the vendor sells the badge, everyone can say they acted. And it can still leave the people underneath exposed. Both things are true at once. The theater is not a lie someone told. It is what a system produces when the reward is for looking safe rather than being safe.

What is left when the show ends

None of this means the measures are worthless. MFA does stop the ordinary password thief; a reset does help in plenty of cases. The danger is not the measure. It is the feeling it leaves behind - the quiet certainty that, because something was done, we are safe.

The humbler view holds those apart. The feeling of security and the fact of it are two different things, and no padlock icon can tell you which one you are holding. The people best defended this week were not the ones who felt safest. They were the ones who kept asking whether the lock was actually locked - or only looked it.

03 · Lab · your turn

Buy The Show Or The Safety

Spend a fixed security budget across measures, then face a real attack and see whether you bought reassurance or protection.

04 · Hope · carry this

The gap between feeling safe and being safe is not a trap we are stuck in - it is a question anyone can learn to ask. And the more of us who ask it, the harder the hollow version becomes to sell.

Across the beats