Cybersecurity Watch: Industrialized Identity Attacks, Blockchain Exploits, and the Rising Ransomware Tide

Written by Erwin Castro — Founder & Editor, The CODEW
The CODEW Cybersecurity Watch | September 8, 2026

BigBear MFA Bypass, Liquid $320M Exploit, Ransomware Surge & Critical Patches

The CODEW Cybersecurity Watch cover

Executive Brief

Industrialized Identity Attacks, Blockchain Exploits, and the Rising Ransomware Tide

The week crystallized three converging pressures: industrialized identity attacks that neutralize MFA at scale, a high-profile blockchain infrastructure exploit resolved largely through public negotiation, and sustained ransomware volume at new 2026 highs. BigBear 2.0 demonstrated mature phishing-as-a-service capable of session hijacking across hundreds of Microsoft 365 tenants. Liquid Network's $320 million federation-wallet drain exposed validation flaws in sidechain software. August ransomware claims hit 964 victims.

Critical patches from SAP (CVSS 10.0 memory corruption) and Microsoft early updates targeting Entra ID, Azure AI Language, and related cloud identity services underscored the need for rapid prioritization of internet-facing and identity-adjacent systems. The through-line: identity has become the primary battlefield, and attackers' tooling has industrialized faster than many defenders' adoption of phishing-resistant controls.

Cybersecurity at a Glance — Biggest Developments

  • BigBear 2.0 demonstrated mature phishing-as-a-service capable of session hijacking across hundreds of Microsoft 365 tenants, compromising 5,000+ credentials across 258 organizations.
  • Liquid Network suffered a $320 million federation-wallet drain (mostly returned), exposing validation flaws in Elements sidechain software.
  • August ransomware claims hit 964 victims—a 2026 monthly high.
  • SAP issued critical patches including CVE-2026-44756 (CVSS 10.0) memory corruption in Extended Passport processing.
  • Microsoft released early September updates covering 11 CVEs, including CVSS 10.0 issues in Azure AI Language and Azure Active Directory B2C.

Threat Watch — Attacks, Campaigns and Emerging Threats

BigBear 2.0, an Evilginx2-based adversary-in-the-middle PhaaS, compromised more than 5,000 Microsoft 365 credentials and session cookies across 258 organizations. Operators used geo-matched residential proxies, custom JavaScript to disable FIDO2/WebAuthn, and automated cookie replay, bypassing MFA after victims completed legitimate authentication. CloudSEK researchers obtained admin-panel access, documenting 42 VPS nodes and ongoing activity spanning 40+ countries.

Additional notable activity included a 220-million-record APIS (Advance Passenger Information System) exposure linked to a Vietnam-associated system accessed via default credentials, Mathspace's breach of an unpatched Metabase instance affecting over 1 million users in Australia and New Zealand, and operational disruptions such as Springfield Public Schools closing after a cyber incident.

Supply-chain and registry risks also surfaced, including malicious Terraform modules on the Coder registry designed to steal cloud credentials.

Vulnerability Watch — Critical Vulnerabilities and Exploitation

SAP's September 8 Security Patch Day delivered 19 new notes, led by CVE-2026-44756 (CVSS 10.0) memory corruption in Extended Passport processing and CVE-2026-58240 (CVSS 9.8) missing authentication on NetWeaver Message Server. Additional critical issues affected CAP multitenant credential handling and SAP GUI for Java.

Microsoft released early September updates covering 11 CVEs, including CVSS 10.0 issues in Azure AI Language and Azure Active Directory B2C, plus high-severity Entra ID and Copilot Studio flaws. Chrome and other browser engines continued to see critical disclosures.

Trackers flagged active exploitation against SonicWall SMA1000, PaperCut, JFrog Artifactory, and selected Python/web-stack components. Organizations should treat identity, edge, and ERP/message-server exposures as immediate patch priorities.

Ransomware Watch — Major Ransomware Developments

August produced a 2026 monthly high of 964 claimed victims across 83 groups (up ~19% from July), putting the year on pace well ahead of 2025. Qilin led with 157 victims; TheGentlemen followed at 127. Newer or returning names (Orova, DireWolf, CL0P, Storm) filled much of the top 10, illustrating continued splintering and affiliate churn.

Healthcare, construction, finance, and technology remained heavily targeted; the United States accounted for roughly 43% of claims.

Double-extortion and pure data-leak models persist. Defenders report growing use of ESXi-focused encryption and blockchain-based C2 or leak infrastructure to complicate takedowns. Negotiation itself is increasingly treated as a structured process by both sides.

AI Security Watch — AI Threats, Defenses and Governance

Shadow AI continues to draw official attention: national cyber authorities warned that unapproved generative tools create uncontrolled data-exfiltration and compliance pathways. Attackers are using AI agents to scale phishing decoys (e.g., Kimsuky LNK campaigns) and to automate infrastructure.

On the defensive side, platforms are embedding AI into detection engineering and identity risk scoring, while vendors accelerate acquisitions of agent-security and observability capabilities. Governance focus is shifting from model safety alone to runtime controls over autonomous agents that hold credentials or can modify production systems.

Cloud & Infrastructure Security — Emerging Infrastructure Risks

The Liquid Network incident highlighted validation and range-proof weaknesses in Elements (the open-source sidechain software). Attackers generated unbacked L-BTC that passed federation peg-out checks, draining ~4,000 BTC (~$320M) from the 11-of-15 multisig wallet without compromising private keys. Self-described white-hats returned 3,400 BTC after patches were confirmed, retaining ~598 BTC as a claimed bounty; the network remains paused pending full restart.

Broader cloud risks include registry poisoning (Terraform modules) and continued credential harvesting against edge appliances and SaaS admin consoles. Organizations running hybrid or multi-cloud workloads should re-validate federation, bridge, and secrets-management controls.

Identity & Network Security — Zero Trust, SASE and Access Security

BigBear's success against MFA reinforces that phishing-resistant authenticators (FIDO2/passkeys) and continuous session evaluation remain incomplete at many enterprises. Conditional Access and device posture checks are necessary but insufficient when session cookies can be replayed from residential IPs.

Zero-trust architectures that treat every session as potentially compromised, combined with just-in-time access and strong non-human identity controls, are moving from roadmap to operational requirement. SASE and SSE platforms continue to absorb identity threat detection capabilities through both organic development and acquisition.

Security Operations — Detection, Response and Resilience

SOC teams face rising volume of identity-driven alerts and the need to detect AiTM patterns (unexpected session locations, FIDO interference, rapid cookie reuse). Rapid isolation of Microsoft 365 tenants, revocation of refresh tokens, and monitoring for secondary lateral movement remain priority playbooks.

Ransomware response increasingly includes pre-negotiated legal and insurance workflows alongside technical recovery. Backup integrity and offline/immutable copies continue to differentiate organizations that recover quickly from those facing prolonged outages.

Vendor & Product Watch — Major Security-Company Developments

Platform vendors are doubling down on identity, AI-agent security, and exposure management. Recent product emphasis includes tighter integration of behavioral biometrics, non-human identity governance, and detection engineering for agentic workflows. Open-source and registry security (npm, Terraform, model hubs) is receiving heightened scrutiny after successive supply-chain incidents.

Cybersecurity M&A & Funding — Capital and Consolidation

August saw roughly $1.27B in disclosed funding across 20 rounds and 16 acquisitions. Large checks went to identity (Saviynt $255M, Socure) and adjacent AI/security categories. Strategic buyers (CrowdStrike/XM Cyber, Fortinet/Virtue AI, Visa/BioCatch, Munich Re/At-Bay) continued platform expansion.

Consolidation remains the dominant theme: pure-play specialists are being absorbed into broader security, payments, and insurance platforms rather than remaining independent.

Regulatory Watch — Important Policy and Compliance Developments

  • EU Cyber Resilience Act reporting obligations approach key milestones later in September.
  • G7 statements continue to press for accelerated post-quantum cryptography transition roadmaps.
  • National authorities are issuing sharper guidance on shadow AI and third-party risk.
  • Expect increased scrutiny of critical-infrastructure operators and of organizations that fail to apply high-severity patches promptly.

The Security Shift — The Structural Trend Behind the Week's News

Identity has become the primary battlefield, and the attackers' tooling has industrialized faster than many defenders' adoption of phishing-resistant controls. Simultaneously, infrastructure software (sidechains, message servers, ERP components, AI gateways) is revealing high-impact validation and authentication gaps that can be exploited without classic "hacking" of credentials. Ransomware volume is rising even as groups splinter, indicating a resilient affiliate economy. Capital is following the same logic: identity, agent security, and platform consolidation are where both risk and returns concentrate.

Strategic Takeaway

For CISOs / Security Leaders

  • Accelerate phishing-resistant MFA rollout and session-binding controls.
  • Treat Microsoft 365 and SAP/NetWeaver exposures as top-tier patch priorities this week.
  • Expand detection for AiTM and cookie-replay patterns.
  • Validate offline recovery paths against ESXi-style encryption.

For Enterprises

  • Map third-party and supply-chain dependencies (registries, logistics providers, sidechain or bridge services).
  • Test incident-response playbooks that include legal, insurance, and communication tracks.

For Investors

  • Identity, AI-agent security, and exposure-management pure-plays remain attractive targets for platform acquirers.
  • Ransomware resilience and post-quantum readiness are emerging secondary themes.
  • Watch for further consolidation among mid-tier vendors unable to reach independent scale.

What to Watch Next Week

  • Full Microsoft September Patch Tuesday volume and any newly disclosed zero-days.
  • Whether remaining Liquid Network funds are returned and the network restarts cleanly.
  • BigBear infrastructure disruption or copycat PhaaS activity.
  • Early September ransomware claim totals and any new high-profile industrial or healthcare victims.
  • Further CRA implementation guidance and national shadow-AI advisories.
  • Any acceleration in identity or AI-security M&A announcements.

The CODEW Stat

August 2026 produced 964 ransomware victims across 83 groups—a 2026 monthly high—while BigBear 2.0 compromised 5,000+ credentials across 258 organizations, demonstrating that identity attacks and ransomware have both reached industrial scale.





Editorial Note

Cybersecurity Watch is The CODEW's weekly security intelligence briefing, tracking threats, vulnerabilities, ransomware, AI security, cloud infrastructure, identity, M&A, and regulatory developments. This edition prioritizes impact and response over raw incident lists, focusing on exposure, defender actions, and structural signals for security leaders and capital allocators.


Cybersecurity Watch: Industrialized Identity Attacks, Blockchain Exploits, and the Rising Ransomware Tide Cybersecurity Watch: Industrialized Identity Attacks, Blockchain Exploits, and the Rising Ransomware Tide Reviewed by Erwin Castro on Tuesday, September 08, 2026 Rating: 5
CRM + marketing automation + payments in one integrated platform. Helps small businesses streamline sales and automate the follow-up work that falls through the cracks. Get Keap