Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Late September breach wave: what IAM and security teams should act on


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Late September 2025 saw a concentrated breach pattern across aviation, retail, manufacturing, and local government, with spear-phishing, compromised OAuth tokens, third-party access, and exploited vulnerabilities driving outages and data theft, according to FireCompass. The pattern shows that identity controls, supplier governance, and detection speed now shape incident blast radius more than perimeter defenses.

NHIMG editorial — based on content published by FireCompass: Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 23 Sep to 29 Sep, 2025

By the numbers:

Questions worth separating out

Q: How should security teams reduce the blast radius of privileged identities?

A: Security teams should define a small set of tightly governed admin identities, give them the minimum authority needed, and make elevation time bound.

Q: Why do OAuth sessions create more risk than traditional login events?

A: OAuth sessions can carry trust forward after the initial authentication step, which means one successful approval can unlock access across multiple services.

Q: What are the warning signs that third-party access has become a security problem?

A: Watch for integrations that were created quickly, rarely reviewed, or granted broad data export rights.

Practitioner guidance

  • Harden entry paths against credential theft Prioritise phishing-resistant authentication, tighten mailbox and attachment filtering, and review where password-based login still grants access to critical systems.
  • Inventory and restrict delegated API access Map every OAuth integration, service connection, and API token that can reach customer data or production workflows, then remove excessive scopes and unused connections.
  • Test privileged access containment Identify where privileged credentials can still reach lateral systems, then segment those pathways and verify that break-glass access cannot spread beyond its intended scope.

What's in the full article

FireCompass's full report covers the operational detail this post intentionally leaves for the source:

  • Incident-by-incident technical indicators, including attacker methods, IOCs, and timeline details for each breach.
  • The specific MITRE ATT&CK mappings and exploitation notes that support the weekly intelligence summary.
  • FireCompass's response recommendations for attack surface testing, vulnerability discovery, and penetration-testing workflows.
  • Operational context around how the reported incidents affected aviation, retail, manufacturing, and public-sector environments.

👉 Read FireCompass's weekly cybersecurity intelligence report on late-September breaches →

Late September breach wave: what IAM and security teams should act on?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Identity compromise is now an enterprise intrusion path, not just a credential problem. The report spans phishing, OAuth abuse, supplier compromise, and privileged access failure, which are different entry methods but the same governance weakness. Once a trusted identity path is abused, the attacker inherits the trust that normal operations depend on. For IAM and PAM teams, that means access governance must be treated as an operational control plane, not a back-office policy function.

A question worth separating out:

Q: Should organisations treat ransomware, supplier compromise, and token abuse as one governance issue?

A: Yes, because all three usually exploit trust that was granted for business operations. The control question is not which attack arrived first, but whether the identity or integration behind it had more access than it needed. Unified governance across human identity, NHI, and recovery planning reduces the chance that one incident becomes enterprise-wide disruption.

👉 Read our full editorial: Supply chain, OAuth and OT failures defined the late September breach wave



   
ReplyQuote
Share: