WRAITH Threat Report Bog image for August 2026

WRAITH Threat Report | Enterprise Edition | August 2026

Key Takeaways

  • The attack surface isn’t fixed. It changes in both directions: old assets nobody decommissioned, and new ones nobody has assessed yet.
  • A forgotten legacy server or an old, unrotated credential can matter more than any current vulnerability.
  • New tools adopted outside formal IT processes create real risk before anyone’s had the chance to test them.
  • A scoped assessment only covers what existed on the day it ran. Everything added or forgotten since is untested.
  • Continuous, credential-free exposure discovery is the only way to keep pace with an environment that never stops changing.

Nothing Stays Scoped: What This Month’s Attacks Reveal

Your last red team engagement was thorough. It covered every system you gave the testers access to. It found real issues, and your team fixed them.

But your environment didn’t stop there. A legacy server stayed online. An old integration credential was never rotated. A new AI tool went live without anyone logging it.

None of that was in scope. All of it was still part of your attack surface.

This month’s cases show what happens when attackers find the parts of your environment your last test never saw.

Case 1: Oracle Cloud Classic

Source: BleepingComputer, Security Boulevard, The Register

  • A legacy “Oracle Cloud Classic” server, old infrastructure rebadged from an earlier product generation, had gone unpatched for years
  • Attackers exploited a known Java vulnerability, one Oracle had patched back in 2022, that had simply never been applied to this older system
  • A web shell and malware were installed, giving persistent access to Oracle’s Identity Manager database
  • Usernames, hashed passwords, and single sign-on credentials were stolen, affecting more than 140,000 Oracle Cloud tenants
  • Oracle initially denied any breach had occurred, before confirming the incident weeks later

Implication: Nobody was actively testing this server. It wasn’t new, it wasn’t interesting, and it wasn’t in anyone’s current scope. That’s exactly why it was still vulnerable to a fix that shipped years earlier.

Case 2: The Klue Breach

Source: TechCrunch, SecurityWeek, TheHackerNews

  • Klue, a competitive intelligence platform, issued an integration credential in 2022 for a limited pilot project
  • The credential was never rotated, reviewed, or retired. It stayed active for four years
  • An extortion group found it and used it to generate access tokens linked to hundreds of customers’ Salesforce accounts
  • Roughly 200 companies had data exposed, including security vendors LastPass, BeyondTrust, Snyk, Tanium, and HackerOne
  • A near-identical pattern hit over 700 organisations the previous year through a different vendor’s integration, showing this is a repeating failure, not a one-off

Implication: A credential from a pilot project that ended years ago became the master key into hundreds of companies. No one was reviewing something that old, because nobody was still thinking about it.

Case 3: JadePuffer & The Langflow Server

Source: BleepingComputer, CSO Online, Dark Reading

  • A Langflow server, a popular tool for building AI applications, was exposed to the internet, likely without formal security review
  • Attackers exploited a known vulnerability in Langflow to gain code execution on the server
  • From there, an autonomous AI agent took over the intrusion, harvesting credentials and pivoting to a separate production database
  • The agent encrypted over 1,300 records before deleting the originals, adapting to failures along the way with no human direction

Implication: This wasn’t old, forgotten infrastructure. It was the opposite: a tool spun up recently enough that no assessment had ever touched it.

Key Patterns Across This Month’s Attacks

Three cases. Some assets were forgotten, others were brand new. Both were missed.

  • No environment stays fixed. Assets are added and forgotten constantly, in both directions.
  • Old assets fall out of scope over time. Legacy servers and stale credentials stop being reviewed long before they’re actually decommissioned.
  • New assets fall outside scope from the start. Tools adopted quickly, often outside formal IT processes, go live before any review cycle reaches them.
  • None of this was exotic. A known Java flaw. An unrotated access token. A documented Langflow bug. Nothing here needed a zero-day.
  • A snapshot cannot protect a moving target. All three of this month’s breaches happened in the gap between what was tested and what the environment had become.

Why This Matters for Enterprise Security Leaders

Most enterprise security programmes validate their environment through scoped, point-in-time assessments:

These are valuable, and they answer a clear question. How secure is the environment we tested, on the day we tested it?

They don’t answer a different, more important question. How secure is the environment right now, months after that test ended?

A scoped assessment can only test what it’s told about. If a legacy server isn’t flagged, it isn’t tested. If a credential from a 2022 pilot isn’t mentioned, it isn’t reviewed. If a new AI tool goes live the week after the engagement ends, it’s invisible to the report entirely.

Consider what that means against the cases above:

  • A network penetration test run against Oracle’s current production environment would likely have missed a rebadged legacy server nobody thought to include in scope.
  • A vendor risk review conducted when Klue was first onboarded in 2022 would have looked fine. It had no reason to catch a credential that was only forgotten years later.
  • Nothing about a fixed assessment window could have caught a Langflow server that didn’t exist yet when the last web application penetration test ran.

The result is a blind spot that grows with time. The longer it’s been since your last assessment, the bigger the gap between what was tested and what’s there.

How WRAITH Addresses This

The answer isn’t testing more often. It’s testing continuously, without needing to be told what to test.

WRAITH includes WISPr, a capability that continuously discovers what’s externally exposed across an organisation, without requiring input, credentials, or a defined scope from the customer. It looks for exactly the kind of asset a scoped assessment would miss: cloud resources, exposed services, forgotten domains, and misconfigurations that appeared after the last formal review.

Because WISPr runs continuously rather than at a fixed point in time, any new exposure it identifies can be folded straight into a live campaign. A legacy server coming back online, a new AI tool appearing on the perimeter, or a forgotten integration nobody remembers configuring all become visible as they appear, not months later at the next scheduled test.

This is the same problem all three of this month’s cases share. Old assets don’t announce that they’re still there. New ones don’t wait for permission. WRAITH is built to catch both, continuously, rather than relying on someone remembering to mention them.

A scoped assessment tests what you tell it about. WRAITH tests what’s actually there.

Picture of Jennifer Goulbourne

Jennifer Goulbourne

Jennifer is a Digital Marketing Executive at OmniCyber Security, where she's responsible for engaging the company's existing customer base across digital channels and creating helpful resources on threat intelligence and security operations for cybersecurity professionals and business leaders.

Contact us..

Related Articles

Blog image for how to scope a penetration test

How to Scope a Penetration Test

Key Takeaways Start with your business objectives before deciding what type of penetration test you need. Internal and external penetration testing answer different security questions.

Find Out More