TL;DR: Cyber incidents this week show how quickly exposed credentials, phishing-exploited Office flaws, and supply-chain access can turn into broad data loss, with attackers now moving from disclosure to exploitation in minutes, according to FireCompass. The operational lesson is that identity, patching, and exfiltration controls must work as a single containment model, not separate programmes.
NHIMG editorial — based on content published by FireCompass: Weekly Cybersecurity Intelligence Report on cyber threats and breaches for 20 Jan to 26 Jan 2026
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams respond when credentials are exposed at massive scale?
A: Start with session invalidation, then rotate or revoke the affected secrets, tokens, and passwords.
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation.
Q: What are the warning signs that file-share exfiltration is already underway?
A: Look for large downloads from sensitive directories, unusual archive creation, access from non-standard accounts, and repeated activity outside normal business hours.
Practitioner guidance
- Rebuild revocation around minutes, not hours Define automated revocation triggers for exposed secrets, suspicious file-share activity, and impossible-travel access so teams can cut off access before an attacker has time to reuse it.
- Correlate email, endpoint, and identity telemetry Hunt for Office child-process abuse, suspicious file-open behaviour, and credential use that follows phishing delivery.
- Segment third-party access by reachable data Map vendor and partner identities to the file systems, repositories, and operational data they can reach, then remove broad access paths that do not have a clear business need.
What's in the full article
FireCompass's full report covers the operational detail this post intentionally leaves for the source:
- Incident-by-incident breakdowns for Nike, McDonald’s India, Fortinet, Microsoft Office, Cloudflare Wrangler, and the Pakistan-linked APT activity
- Detailed remediation guidance for phishing, zero-day exploitation, ransomware exfiltration, and CI/CD command injection
- Detection rule examples for SIEM, EDR, email security, and network monitoring
- The full weekly timeline of events between 20 Jan and 26 Jan 2026
AI-assisted attacks and the shrinking response window for IAM teams?
Explore further
Identity compromise is now an acceleration layer for every major intrusion path. This weekly report does not describe isolated incidents so much as a common operating model: once a secret, token, or administrative pathway is exposed, attackers turn it into immediate access and then widen the blast radius through file systems, collaboration tools, and remote access. For IAM and PAM teams, that means identity governance has to be measured in minutes, not review cycles. The practitioner conclusion is that standing access windows are now the attack surface.
A few things that frame the scale:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks. That pattern shows how quickly identity weakness becomes operational breach exposure.
A question worth separating out:
A: Neither should stand alone. Phishing and exploit chains often begin in email, execute on the endpoint, and finish in identity misuse or data theft, so the stronger approach is correlated control. Prioritise the identity response path for containment, while keeping endpoint telemetry tight enough to show how the attack started.
👉 Read our full editorial: AI-assisted attacks are compressing the window for credential defence