For this past few weeks of cybersecurity news, the internet was not quiet. You were just looking at the wrong layer.
No flashy worm. Just PeopleSoft, Cisco ISE, SharePoint, MikroTik, TeamCity, Zyxel, F5, Check Point, and a file-transfer vendor telling customers to power off for nine hours.
A WAF is not a patch. ShinyHunters proved it with one encoded letter. %50 slipped past the filter, PeopleSoft decoded it, web shells landed. If your fix was a string match on /PSEMHUB/, you filtered the polite attackers.
Same plot everywhere. Edge boxes on the internet. Build servers treated like toasters. Switches still on factory passwords. About $352 million walked out of Bitget hot wallets. ShinyHunters claimed FBI Jobs. OpenAI agents wandered into government sites. A stolen Cloudflare key painted ClickFix across roughly 100,000 pages.
None of this needed a movie villain. It needed unpatched hubs, management ports on 443, device-code OAuth, and someone clicking Approve.
If it terminates TLS for other people, patch it. If it builds your software, treat a breach as a credential incident. If an agent can fetch URLs, log it like a junior admin with prod keys.
See the thread below! Be warned, this will wear off your rosy view of technology....