When the defences are the target: security tools exploited, a supply-chain worm, and the patching gap
Two security products actively exploited in the same week. A self-replicating npm worm rips through GitHub and a major observability vendor. A municipal health system loses 1.8 million people's biometrics through a third party. And the DBIR confirms it: exploitation has overtaken stolen credentials as the number-one way in.
Executive summary
- The security stack itself was exploited. CISA confirmed in-the-wild exploitation of flaws in two endpoint-protection products in the same week, with hands-on-keyboard attackers chaining one to SYSTEM in live incidents.
- Supply-chain compromise went wormable. A self-replicating npm worm stole CI/CD credentials and auto-published infected packages, cascading into source-code theft at GitHub (3,800 internal repositories) and a major observability vendor.
- The data confirmed the shift. The Verizon DBIR 2026, published in-window, recorded vulnerability exploitation overtaking stolen credentials as the top breach entry point for the first time in 19 years, while KEV remediation rates fell to 26% and median patch time stretched to 43 days.
Key findings
Microsoft Defender and Trend Micro Apex One flaws actively exploited
CISA added two Microsoft Defender flaws (privilege escalation and denial of service) and a Trend Micro Apex One directory-traversal zero-day to KEV in the same week. Incident responders reported hands-on-keyboard actors abusing the Defender chain to reach SYSTEM in multiple live cases. When the endpoint protection layer is the exploited surface, defence needs telemetry the endpoint agent does not own.
'Mini Shai-Hulud' npm worm cascades into GitHub and Grafana source-code theft
A self-replicating supply-chain worm seeded via a compromised npm package stole CI/CD credentials and used them to publish further infected packages automatically. Fallout confirmed in the window: 3,800 GitHub internal repositories compromised, and Grafana Labs' code downloaded via a stolen token, with the vendor publicly refusing the ransom demand.
1.8 million people's medical records and biometrics stolen via a health system's third party
The largest US municipal health system confirmed attackers had months of access via an unnamed third-party vendor, copying diagnoses, billing data, identity documents, precise geolocation and fingerprint and palm-print biometrics, credentials that can never be reissued.
Ransomware disrupts a critical injectable-medicine component maker
A supplier of stoppers, seals and syringe components for injectable drugs filed a material-incident disclosure after attackers stole data and encrypted systems, temporarily disrupting manufacturing and shipping across its global sites. Pharmaceutical supply chains inherit the cyber posture of their component makers.
Franchise-owner data leaked after a misconfigured Salesforce instance is mined
A global convenience-store chain confirmed criminals accessed franchisee documents, with the extortion crew claiming over 600,000 CRM records taken through a misconfigured customer-community instance found with an open-source auditing tool. When payment was refused, a 9.4 GB archive was published.
The broader pattern
- Exploitation is now the front door, and the patching gap is the widest it has been. The DBIR's 43-day median patch time collides with KEV deadlines measured in days.
- Your security tooling deserves its own threat model. Two exploited endpoint-protection products in one week means single-vendor visibility is a single point of failure.
- Third parties carried the worst losses again. A vendor breach exposed biometrics; a package registry carried a worm into blue-chip engineering orgs. DBIR data shows third-party involvement in breaches up 60% year on year.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch the exploited Defender and Apex One flaws and hunt for SYSTEM-escalation chains. Both are on KEV with federal deadlines; assume adversaries read the same list.
Rotate CI/CD and package-registry tokens; alert on unexpected publish events. The fortnight's worm spread on stolen automation credentials, not human logins.
Ask your critical vendors which third parties hold your regulated data. The biggest healthcare loss of the fortnight travelled through an unnamed vendor.
Scan your own SaaS communities and portals for misconfigured sharing. Attackers used an open-source auditor to find exposed CRM instances; run it before they do.
Benchmark your median patch time against the DBIR's 43 days, then halve it for KEV entries. Exploitation is now the #1 entry point; KEV-listed flaws are the priority queue.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Blacklight does not depend on the endpoint agent being trustworthy: it correlates identity, SaaS, network and cloud telemetry independently, so an exploited security tool, a token quietly publishing packages, or a vendor account touching data it never touches gets investigated on behaviour. KEV entries are matched to your estate the day they land, closing the gap the DBIR says attackers now walk through.
Sources & methodology
Primary public sources this issue: Verizon Data Breach Investigations Report 2026 · CISA Known Exploited Vulnerabilities catalog and alerts (20 and 21 May 2026) · Microsoft May 2026 Patch Tuesday release notes · public disclosures and filings (West Pharmaceutical Services 8-K, Grafana Labs, NYC Health + Hospitals, 7-Eleven) · Help Net Security, The Record, TechCrunch, BleepingComputer and Krebs on Security reporting · MITRE ATT&CK v15 for technique mapping. Attacker-claimed figures are labelled as claims.