Daylila

Cybersecurity · Thursday, 13 August 2026

01 · Briefing · what happened

This week's breaches became takeovers - too many accounts could reach too much

Cybersecurity 4 min 16 sources

A year-long data theft through over-wide guest access, ransomware crews hunting the accounts with the broadest reach, and a firewall gang seizing wide access - all one lesson: a break-in's harm is capped by what the broken-in account can already reach.

351

victims in one ransomware campaign

across 334 organizations; 62% held a manager title or higher

$10M+

typical Gunra ransom demand

with five to seven days to pay

421

flaws in Microsoft's August patch

one already exploited before the fix existed

~2 yrs

UK records office breaches went unseen

three intrusions, thousands of people exposed

At a glance

  • Attackers stole data from Salesforce and ServiceNow sites left with guest access set too wide - no password needed.
  • Researchers named the year-long campaign 'City-Forum'; it hit telecom, finance, and public-sector organizations worldwide since March 2025.
  • Zscaler found ransomware crews now hunt managers, not CEOs: 62% of one campaign's 351 targets held a manager title or higher.
  • The prize is 'business privilege' - accounts that can approve payments and open HR, contracts, and customer records.
  • The FBI, CISA, and South Korea warned about Gunra, a gang using Fortinet firewall flaws to seize wide access and demand over $10 million.
  • Microsoft's August patch fixed 421 flaws, one already being exploited before a fix existed.
  • The common thread: a break-in's damage is capped by what the broken-in account, role, or tool could already reach.

Forces in play

Over-wide access High

guest roles, manager accounts, and admin consoles reaching far past their job

Targeted extortion Building

crews study org charts to phish the account with the widest reach

Narrow-access defence Building

splitting access so one break-in stays in one room - spreading slowly

Patch backlog High

421 Microsoft flaws in a month, plus gangs using flaws already known

In play City-Forum attacker — stole data via over-wide guest access on Salesforce and ServiceNow Zscaler ThreatLabz — research showing crews now target managers' broad business access Gunra ransomware gang — used Fortinet firewall flaws to seize wide access; $10M+ demands FBI, CISA, South Korea — joint advisory warning critical-infrastructure operators Microsoft — patched 421 flaws; warned of a China-linked crew abusing an IT console

How it unfolded

  1. Aug 11 FBI, CISA, and South Korea warn about Gunra ransomware
  2. Aug 11 Microsoft's August patch fixes 421 flaws, one exploited
  3. Aug 12 researchers detail the year-long City-Forum guest-access data theft
  4. This week Zscaler research: managers, not CEOs, are the prime ransomware targets

Where this points

Watch whether more companies audit what their guest roles and manager accounts can actually reach - the fix for all of this is narrower access, and it spreads slowly.

Full briefing

The account that could read everything

On Tuesday, security researchers detailed a data-theft campaign that ran for more than a year, which they call “City-Forum” [1]. An unknown attacker built custom tools to probe Salesforce and ServiceNow - two systems companies use to hold customer records and support tickets. It hunted for sites with “overly permissive guest access” [1].

Guest access is what an anonymous visitor is allowed to see. On many of these sites it was set too wide. So the attacker pulled real records without stealing a single password [1]. Active since at least March 2025, the campaign hit telecom, finance, enterprise-software, security, and public-sector organizations worldwide [1].

The tooling isn’t the point. A setting meant for the public could reach data meant for staff. Nobody picked a lock. The lock was set to “open for guests.”

Attackers hunt for the widest door, not the strongest one

A separate piece of research this week, from Zscaler’s ThreatLabz team, maps who ransomware crews - gangs that lock a victim’s files and demand payment - now go after [2]. Across one month-long campaign they tracked 351 victims at 334 organizations [2]. Nearly two-thirds held a manager title or higher, and the average target was 46 years old [2][3].

Rather than emailing the CEO, the attackers research a company’s reporting lines and pick the employees whose accounts touch the most [2]. Zscaler calls the prize “business privilege” rather than technical privilege [2]. Security teams guard the admin accounts, the ones with the keys to the servers [3]. But a manager who approves payments, reviews contracts, and can open HR and customer records holds a different master key [2]. “The value of a compromised managerial account lies in the breadth of business access,” the researchers wrote [2].

Same pattern, bigger blast radius

Microsoft warned this weekend that a China-linked crew it tracks as Storm-1175 began deploying new ransomware, StormEncryptor, on August 2 [4]. The suspected way in is a flaw in N-central, a console that IT service firms use to run thousands of client machines at once [4]. Microsoft says the flaw hands attackers “god-mode” access - one console, every downstream network [4]. It has watched the group go from first entry to full encryption in under 24 hours [4].

The same word - privileged - sits at the center of this week’s biggest ransomware alert. On Monday the FBI, CISA (the US cyber-defence agency), and South Korea’s police warned about Gunra, a gang built from leaked Conti ransomware code [5][6]. Gunra exploits known flaws in Fortinet firewalls to “gain privileged access,” then steals and encrypts data, demanding over $10 million with five to seven days to pay [5][7]. It has hit healthcare, finance, and government sectors worldwide [5]. Ransomware is not slowing: one tracker this week found attacks climbing while attention drifts to AI [8].

Why narrow access is the whole defence

These stories look separate. They share a spine: a break-in’s damage is bounded by what the broken-into thing can reach. A guest role that could read staff records. A manager account that spanned the whole business. A console with god-mode over every client. When any one is compromised, its reach is the ceiling on the harm.

The defensive answer has a plain name: least privilege. Give every account, role, service, and tool only the access its job actually needs, and nothing more. The guest role reads what guests should read. The manager approves what that manager approves, not everything. The console reaches only the clients it must. Least privilege doesn’t stop the break-in - it traps the intruder in one room instead of handing over the building.

Two more this week show the cost of getting it wrong. A supply-chain attack means compromising one thing many others rely on. One this week poisoned a data feed used by WordPress plugin maker BdThemes to quietly create rogue admin accounts on affected sites [9]. And Britain’s data regulator reprimanded the ACRO criminal records office after three break-ins went undetected for nearly two years, exposing thousands of people including domestic-violence victims [13].

The patch pile, and the week’s other breaches

Microsoft’s August update was one of its largest ever: 421 flaws fixed, including one Windows flaw already being exploited before the patch existed [10][11]. CISA added three more actively-exploited flaws to its must-patch list for federal agencies [12]. Cisco patched a dozen flaws in its networking software, three near the top of the severity scale [14]. Adobe urged immediate patching of critical ColdFusion flaws [15].

Elsewhere, a cyberattack on freight giant Ceva Logistics disrupted European retailers and may have exposed data belonging to customers of the Steam gaming platform [16].

02 · Lesson · why it matters

Why a break-in becomes a takeover

The harm from a break-in isn't how the attacker got in - it's how far the account they broke into could reach.

How it works

  1. Every account, role, and tool is handed some access
  2. Handed more than the job needs, that extra just sits there
  3. Until a break-in - a phished login, a flaw, a poisoned update
  4. Then the intruder inherits everything that account could reach
  5. Narrow the access first, and the break-in stays trapped in one room

The twist

The damage from a break-in isn't set by how the attacker got in - it's set by how far the thing they broke into could already reach.

Where you've seen this

A house key

a cleaner needs the key to one door, not the master key to every room and the safe

A bank branch

a teller moves small sums; the vault needs two managers, so one bribed teller can't empty it

A ship's hull

watertight compartments mean one breach floods a section, not the whole vessel

A film studio

a day's extra gets a wristband for one lot, not the keys to the whole studio

The catch

Least privilege is friction - every extra check slows real work, so the pull is always to hand out broad access 'just to be safe,' which is how the reach creeps wide again.

Full lesson

Nobody picked the lock

This week, researchers described an attacker who spent more than a year quietly reading companies’ internal records. There was no clever break-in. The companies used systems - Salesforce, ServiceNow - that let anonymous visitors see a little. On many sites, “a little” was set too wide. The visitor’s pass opened doors meant for staff.

Think about what that means. The failure wasn’t the front door. It was how much a public setting could reach. The lock worked fine. It was just set to “open for guests.”

Attackers go for the widest door, not the strongest one

A second piece of research this week found something telling. Ransomware crews - gangs that lock your files and demand payment - have started skipping the CEO. They aim at managers instead.

Why a manager? Not because the account is powerful in a technical sense. Because it reaches far. A manager approves payments, reviews contracts, opens HR files, sees customer accounts. One login, and an attacker inherits all of it. The researchers gave it a name: business privilege. The value of an account, to someone who steals it, is simply the breadth of what it can touch.

The reach is the ceiling

Put these together and a pattern shows up, plain and hard.

A break-in’s damage is bounded by what the broken-into thing can reach. A guest setting that could read staff records. A manager account that spanned a whole company. A remote console with what one report called “god-mode” - one screen that ran thousands of client machines at once. In each, the harm wasn’t decided by how the attacker got in. It was decided, in advance, by how far that door already opened.

The reach is the ceiling on the harm. And most of the time, nobody chose that ceiling on purpose. It just drifted wide.

The defence has a plain name

The answer isn’t a taller wall. Walls fail; something always gets in. The answer is narrower doors.

Security people call it least privilege. Give every account, every role, every tool only the access its actual job needs - and nothing more. The guest reads what guests should read. The manager approves what that manager approves, not everything. The console reaches only the machines it must, split so one break-in can’t touch them all.

You already know the shape of this. A bank teller can move small sums; emptying the vault takes two managers and a second key. A cleaner gets the key to one office, not the master key to the building and the safe. A ship has watertight compartments, so one hole floods a section, not the whole hull. None of it stops the accident. All of it decides how big the accident gets.

Least privilege doesn’t stop the break-in. It traps the intruder in one room instead of handing over the building.

Why the doors keep drifting open

Here’s the honest catch. Narrow access is a nuisance.

Every extra check slows real work. Someone needs a file “just this once,” and it’s faster to grant broad access than to scope it and remember to take it back. Convenience and safety pull in opposite directions, and convenience wins the day-to-day. So access accretes. A permission granted for one project outlives it. A role built for five people ends up used by fifty. None of it is malice - it’s the path of least resistance, quietly widening, until a break-in finally cashes it in. The arrangement that made yesterday’s work smooth is the one that hands over the building today.

You are inside this

This isn’t only a problem for corporate IT departments. You live in the same shape.

Your email account is a master key. It can reset the password on nearly everything else you own - so whoever holds it holds all of you, not just your inbox. The app you let see “all your contacts” or track your location “always” is carrying more of you than its job needs. The single question that runs through all of it - does this really need to reach that? - is the whole defence, at every scale.

And the companies holding your records are answering that same question, quietly, on your behalf. When one of them leaves a guest setting too wide, you are the staff records on the other side of it.

What seeing this leaves you with

You can’t watch every door. Neither can the people who run the systems you depend on - the admins, the regulators, the app makers. That’s not their failure or yours; a system has more openings than any one seat can see.

So the safest system was never the one that keeps everyone out. It’s the one where a break-in stays small - where the reach was narrowed before anyone got in. The break-in is somewhere in the future, probably unavoidable. The reach is the part still up for grabs today. And none of us ever fully knows how far a single key opens until it’s turned.

03 · Lab · your turn

Set the reach

Rehearse how narrow access traps a break-in in one room, while broad access turns one stolen login into a takeover.

04 · Hope · carry this

The good news: the fix needs no new invention. Every time someone narrows what a thing can reach - a manager, an admin, you with an app - the next break-in gets smaller.

Across the beats