The data theft campaign that ran through the year stayed active in the period, with an attack on a major pharmaceutical company added to the list of affected organisations.
The pattern of these campaigns is economic before it is technical. Rather than attacking each company separately, the group targets widely adopted corporate platforms, because compromising one point yields access to many clients at once.
That shifts the problem somewhere uncomfortable. A company's security posture stops depending only on what it does and starts depending on what its suppliers do, in an arrangement where it has neither visibility nor control.
The available defence is less glamorous than the tooling conversation: reduce what each integration can see, review permissions granted to connected applications, and require prompt notification in contracts.
The coincidence in the period is worth noting: the same week recorded an incident at a healthcare software supplier with thousands of clients and an attack that reached an industrial production environment. Three views of the same movement, which is attacking the link many share.
