Q3 2026 Lookback: Trust Was the Attack Surface
If Q3 2026 had a theme, it was this: the attackers stopped needing us to make a mistake, and started inheriting trust we had already handed out.
Supply chain, for months, not days. TeamPCP ran the longest software supply chain spree on record. Trivy, LiteLLM, Telnyx, SAP’s npm packages and TanStack all got poisoned, and the downstream list included the European Commission, Mistral, OpenAI and GitHub. The Australian Federal Police put it at 1,000+ organizations, 500,000+ stolen credentials and 300GB of data, all from a small number of trusted components. Two arrests on August 26 don’t un-poison anything. Teams I work with spent weeks rotating secrets and asking where their build pipelines pull from. If your scanner and your CI tokens live in the same blast radius, your scanner is now an attack path. Pin versions, delay new releases by a few days, and know which secrets your pipeline can reach.
Autonomous agents moved from demo to incident. In mid-July Hugging Face disclosed a breach run by an autonomous AI agent: a malicious dataset, two code-execution flaws in the processing pipeline, then lateral movement across clusters through thousands of actions in short-lived sandboxes. JadePuffer reportedly automated an entire ransomware chain, and Spain’s data protection agency took its first report of an AI-driven breach that altered personal data. What stuck with me is how Hugging Face caught it: their own anomaly detection and AI-assisted timeline reconstruction (17,000+ events). Speed is the variable now. Your detection and containment playbooks assume a human operator who sleeps. Also, inventory the agents inside your own environment, because they’re privileged identities nobody is reviewing.
Edge and enterprise app zero-days, with a disclosure gap. ShinyHunters hit Oracle PeopleSoft (CVE-2026-35273) from late May, over 100 organizations, with exploitation ahead of Oracle’s June 10 advisory and a WAF bypass that made “we have a WAF” a weak answer. Then September brought Citrix NetScaler (CVE-2026-88771/88772, CVSS 9.5, 50,000+ exposed instances) and a Cisco Catalyst SD-WAN Manager authentication bypass (CVE-2026-76504). The NetScaler story wasn’t just the bug. Exploitation was visible on September 24, and Citrix’s advisory didn’t land until the 27th. Defenders learned from insurers, threat intel shops and LinkedIn posts. Build your process to act on credible third-party signal within hours, including pulling management interfaces off the internet before the vendor confirms anything.
The extortion ecosystem is eating itself, and your data is still out there. ShinyHunters defaced Cl0p’s leak site in September, the EY third-party incident got attributed to them in July, and a Dutch arrest followed in late September. A soldier got 70 months for the AT&T and Verizon extortions. Law enforcement is landing blows, but the stolen data doesn’t expire when a crew falls over. Victims of the old Cl0p campaigns are now exposed to a second round of extortion from someone else. Assume previously breached data gets re-sold and re-used, and keep monitoring for it.
Takeaway for Q4: Trust is the attack surface. Every package, vendor appliance, third-party platform and now every AI agent holds credentials and access somebody granted once and never revisited. Before you buy another tool, audit what you’ve already authorized, and make sure you can revoke it in an hour, not a week.