Arcanum Cyber Threat Advisory – Identity, OT, Autonomous Systems, Social Engineering and Supply Chains

Arcanum Cyber Threat Advisory – Identity, OT, Autonomous Systems, Social Engineering and Supply Chains

This week’s threat landscape highlights a continued shift away from traditional malware-centric attacks towards the exploitation of trusted identities, legitimate business processes and increasingly autonomous digital systems.  Identity providers, operational technology environments, software development pipelines, AI agents and engineering repositories are all being targeted through methods that abuse normal functionality rather than breaking security controls.

Key Threat Themes This Week

1. Identity remains the primary attack surface, with adversaries increasingly bypassing multi-factor authentication through session theft rather than credential compromise.
2. Operational Technology and Critical Infrastructure continue to face elevated threat activity, including attacks affecting power generation and water-sector operations.
3. AI systems are becoming both targets and attack platforms, creating new governance and assurance challenges.
4. Software supply chains, engineering systems and development repositories remain attractive targets, often resulting in data theft and extortion rather than encryption-based ransomware.
5. Social engineering continues to outperform purely technical attacks, succeeding even against mature organisations and cyber security professionals.  The common thread is clear: attackers are increasingly exploiting trusted pathways that organisations already depend upon for day-to-day operations.

Immediate Actions for Security Leaders

Organisations should prioritise:

  • Reviewing Microsoft 365 session security and privileged identity protections.
  • Identifying internet-exposed OT, PLC and industrial-control assets.
  • Inventorying AI agents, automation platforms and connected workflows.
  • Auditing software development pipelines, CI/CD workflows and code repositories.
  • Validating manual operational fallback procedures for essential services.
  • Reviewing monitoring coverage for engineering, document, backup and archive repositories.

Arcanum View

The threat landscape is increasingly defined by the convergence of identity, operational technology, software supply chains and autonomous systems.  Organisations that can demonstrate control over trusted pathways, evidence effective monitoring and maintain resilient recovery arrangements will be significantly better positioned to withstand the next generation of cyber threats.  The challenge is no longer simply preventing compromise; it is assuring that critical systems remain governable, observable and recoverable when compromise inevitably occurs.

 

Key Threat 1: Identity Attack Techniques Continue to Evolve

Recent campaigns demonstrate attackers increasingly bypassing traditional multi-factor authentication by stealing authenticated sessions rather than passwords.  A phishing framework targeting Microsoft 365 environments reportedly compromised thousands of accounts through session theft techniques.

Separately, another incident involved a cyber security employee being successfully socially engineered into revealing credentials, illustrating that even mature organisations remain vulnerable to people-focused attacks.

Why This Matters

Identity has become the modern enterprise perimeter.  Adversaries increasingly target:

  • Session cookies
  • OAuth permissions
  • Access tokens
  • Password-reset workflows
  • Federated authentication systems

The result is that successful authentication can become the beginning rather than the end of an attack.

Recommended Actions
  • Monitor session anomalies rather than focusing solely on failed logins.
  • Review privileged account protections.
  • Strengthen phishing-resistant authentication for high-risk users.
  • Test password-reset and identity-recovery processes.
  • Regularly review application consent and delegated permissions.

Key Threat 2: Critical Infrastructure Remains Under Sustained Pressure

Reports this week highlight continuing attacks affecting operational environments.  A UK power generator reportedly experienced disruption following a cyber incident involving an exposed PLC.  Separately, multiple community water systems reportedly lost computerised operational controls during a coordinated incident, requiring manual operation and emergency procedures.

Why This Matters

Cyber incidents affecting OT environments can directly impact:

  • Service availability
  • Safety
  • Environmental protection
  • Regulatory compliance
  • Public confidence

Unlike traditional IT breaches, the consequences may extend into the physical world.

Recommended Actions
  • Review exposure of industrial-control systems.
  • Validate separation between IT and OT environments.
  • Test manual fallback arrangements.
  • Review third-party remote-access arrangements.
  • Verify OT monitoring and incident-response capabilities.

Key Threat 3: AI Systems Are Emerging as a Strategic Cyber Risk

One reported intrusion allegedly enabled an autonomous AI agent to perform approximately 17,600 actions over several days after exploiting weaknesses in a data-processing workflow.  At the same time, security commentators are increasingly questioning accountability when autonomous agents operate outside their intended scope.

Why This Matters

AI agents increasingly possess:

  • Access to enterprise data
  • Workflow automation privileges
  • Integration with business systems
  • Ability to trigger real-world actions

The key security question is no longer simply “Is the model secure?” but rather:

“What authority does the agent have and how is that authority governed?”

Recommended Actions
  • Maintain a register of AI agents and automation workflows.
  • Apply least-privilege access principles.
  • Introduce approval gates for high-impact actions.
  • Enable detailed audit logging.
  • Include AI-enabled systems within incident-response exercises.

Key Threat 4: High-Risk Vulnerabilities Continue to Affect Core Enterprise Platforms

A critical vulnerability affecting Red Hat Keycloak reportedly enables account takeover through weaknesses within password-reset functionality.  Vendor fixes are available.

Separately, recent reporting highlights significant growth in the number of actively exploited vulnerabilities and continued exploitation of enterprise software platforms.

Why This Matters

Identity systems increasingly represent a single point of failure.  Where compromise of an identity platform occurs, attackers may quickly gain access to:

  • Enterprise applications
  • Cloud services
  • Administrative accounts
  • Privileged workflows
Recommended Actions
  • Identify affected identity-management systems.
  • Review patch status.
  • Monitor password-reset activity.
  • Validate administrative access controls.
  • Confirm emergency patching processes remain effective.

Key Threat 5: Software Supply Chains and Engineering Systems Continue to Be Exploited

Recent incidents demonstrate continuing exploitation of:

  • Development environments
  • Product Lifecycle Management platforms
  • Source-code repositories
  • Software dependencies
  • CI/CD pipelines

One campaign exploited engineering-management platforms to steal intellectual property and conduct extortion without deploying ransomware encryption.  Separately, exposed Git repositories reportedly revealed credentials, API keys and sensitive organisational information.  Earlier reports also highlighted compromises involving open-source supply chains and build-time malware insertion.

Why This Matters

The objective is increasingly data theft and extortion rather than operational disruption.  Engineering repositories often contain:

  • Design information
  • Intellectual property
  • Architecture details
  • Credentials
  • Supplier information
Recommended Actions
  • Treat engineering repositories as critical assets.
  • Perform credential scanning across current and historical code.
  • Review CI/CD execution permissions.
  • Rotate potentially exposed secrets.
  • Monitor for abnormal repository access patterns.

Key Threat 6: Data Breaches Continue to Affect Regulated Sectors

Recent incidents affecting healthcare and financial organisations demonstrate the continuing impact of unauthorised access and data exfiltration.  Reported breaches involved sensitive healthcare, employee, financial and personal information.

Why This Matters

For many organisations, the greatest consequence is now:

  • Regulatory exposure
  • Reputational damage
  • Extortion risk
  • Loss of trust

rather than operational downtime.

Recommended Actions
  • Review access to sensitive file repositories.
  • Monitor for large-scale data movement.
  • Strengthen privileged-access management.
  • Exercise breach-notification procedures.
  • Verify investigation and forensic-retention capabilities.

Strategic Assessment

Across all incidents reviewed this week, attackers repeatedly succeeded through the abuse of trusted pathways:

  • Authenticated sessions
  • Password-reset processes
  • Engineering protocols
  • AI workflows
  • Build pipelines
  • Repository access
  • Support interactions
  • Operational management systems

In many cases, systems behaved exactly as designed.  The security failure arose because attackers successfully obtained access to a trusted process, identity or workflow.

Assurance Considerations

For organisations using CAF, GovAssure, NIS or related assurance frameworks, this week’s incidents reinforce the importance of:

  • Identity and access management outcomes.
  • Monitoring and detection capabilities.
  • Supply-chain risk management.
  • Operational resilience and recovery.
  • Asset management and configuration control.
  • Governance of AI-enabled technologies.
  • Protection of OT and industrial systems.
  • Assurance over third-party access.

Questions for Boards and Senior Leaders

  1. Do we know which AI agents and automation tools can act on our behalf?
  2. Can we rapidly revoke those permissions during an incident?
  3. Would we detect theft of an authenticated user session?
  4. Are any OT systems accessible directly from the internet?
  5. Could essential services continue operating safely without automated control?
  6. Are engineering repositories and development pipelines monitored as critical assets?
  7. Have newly disclosed vulnerabilities been assessed against our technology estate?
  8. Are backup, archive and document-management platforms treated as production systems?
  9. Who owns enterprise-wide identity risk?
  10. Are we measuring cyber resilience outcomes or only compliance with controls?

If you would like help answering the questions raised, get in touch today and our expert team can advise on the best approach for your organisation.