TL;DR: Attackers rapidly weaponised Fortinet CVE-2026-24858, an Office zero-day, and an eScan supply chain compromise within a single week, showing how exposed perimeter systems, phishing, and trusted update channels can be turned into entry points within hours, according to FireCompass. The lesson is that speed, trust, and administrative access now define the blast radius more than vulnerability volume.
NHIMG editorial — based on content published by FireCompass: Weekly Cybersecurity Intelligence Report Cyber Threats and Breaches, 27 Jan to 2 Feb 2026
By the numbers:
- The supply chain attack compromised more than 200 systems and possibly as many as 500.
- APT28 targeted more than 60 government email addresses with spear-phishing.
Questions worth separating out
Q: What breaks when a perimeter appliance has an authentication bypass?
A: The main failure is that the control plane stops being a reliable gatekeeper.
Q: Why do fresh exploits become so dangerous when patching and review cycles are slow?
A: Because attackers can weaponise public vulnerabilities faster than many teams can deploy fixes or complete manual validation.
Q: What are the signs that a weaponised attachment has moved from email to endpoint compromise?
A: Look for document applications spawning script interpreters or command shells, unusual child processes, and registry or autorun changes appearing after message delivery.
Practitioner guidance
- Disable or constrain FortiCloud SSO on exposed perimeter appliances Review all FortiOS, FortiAnalyzer, FortiManager, and FortiProxy appliances for device-level authentication exposure, then apply the vendor's disablement guidance where business use does not require it.
- Hunt for document-to-process execution patterns across endpoint telemetry Search for Word spawning PowerShell, cmd.exe, or other unusual child processes, then correlate those events with new logons, registry run keys, and suspicious attachments sent to executive or government users.
- Treat security-software updates as privileged supply chain events Require cryptographic validation for all endpoint protection updates, verify file sizes and hashes against approved baselines, and monitor for post-update persistence mechanisms such as scheduled tasks, registry exclusions, and domain blocking entries.
What's in the full article
FireCompass's full report covers the incident-level detail this post intentionally leaves for the source:
- Exact CVE and detection details for the Fortinet appliance exploitation path, including affected versions and immediate remediation guidance
- The full Office zero-day technical chain, including payload behaviour, persistence indicators, and patch references
- IOC-level details for the eScan supply chain compromise, including file names, hashes, HOSTS modifications, and registry changes
- Week-by-week incident summaries that let responders map these events into their own threat hunting and response timelines
👉 Read FireCompass's weekly cybersecurity intelligence report on recent attacks and breaches →
Fresh exploits and supply chain compromise: what should defenders do?
Explore further
Speed is now the primary control variable in exposure management. The report shows attackers weaponising fresh vulnerabilities within 72 hours, which means patch queues and manual review cycles are increasingly out of phase with real adversary tempo. NIST CSF and MITRE ATT&CK both point toward continuous detection and response, not periodic reassurance. Practitioners need exposure workflows that assume same-week exploitation is normal.
A few things that frame the scale:
- From our research: Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging (37%) and over-privileged accounts (37%), according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
A: Treat software provenance as necessary but not sufficient. Verify update signatures, monitor unusual network connections, and watch for abnormal process behavior after patching. Supply chain compromise often succeeds because teams trust the source and stop checking the payload. Defensive controls should assume that a legitimate update channel can be abused, especially when access persists quietly and only selected targets are touched.
👉 Read our full editorial: Fresh exploits, zero-day weaponisation and supply chain risk