A guest diarist over at the SANS Internet Storm Center spent this week explaining something most teams would rather not hear: the security tool you trust to block malicious traffic may be waving a chunk of it right through. The browser is the blind spot. Your endpoint agent sees process activity, your firewall sees packets, and somewhere in between, encrypted browser sessions carry payloads neither one was ever configured to inspect. The dashboard stays green. The thing you bought to stop the attack quietly isn’t in the path.
That gap, the distance between what your stack is assumed to cover and what it actually covers, is the most underrated problem in cybersecurity right now. It doesn’t show up in a breach report as a flashy zero-day. It shows up as “we thought that was handled.”
The basics aren’t basic if nobody checks them
Dark Reading ran a piece this week on INC Ransomware, and the headline tells the whole story: the crew thrives by mastering the basics. No novel exploit chain. No nation-state toolkit. They go after sectors like healthcare where downtime creates immediate pressure to pay, and they get in through the same tired doors everyone swears they’ve locked. Exposed remote access. Weak or reused credentials. Unpatched edge boxes that someone meant to retire two budget cycles ago.
Here’s the uncomfortable part. “Mastering the basics” is only a viable business model because so many defenders have quietly stopped verifying their own basics. You deployed MFA in 2022. Is it actually enforced on every account, or are there service accounts and legacy protocols still riding on a password? You turned on brute-force protection at the edge. Does it actually trip, or did a config change six months ago set the threshold so high it never fires? Nobody knows, because nobody tested it. The control exists on paper. Attackers test it for you, in production, for free.
MFA you assumed was protecting you
SecurityWeek is hosting a session this week on how modern breaches bypass MFA and slip past detection, and the framing is worth sitting with: legacy MFA alone is no longer sufficient. Read that again, because the operative word is “alone.” Plenty of teams checked the MFA box years ago and mentally filed identity as done. Meanwhile attackers moved on to session token theft, MFA fatigue, adversary-in-the-middle phishing kits, and OAuth consent abuse, none of which a one-time push prompt slows down.

The pattern repeats across every layer. You bought threat-protection for email, but the malicious link resolves cleanly at scan time and weaponizes after delivery. You stood up threat detection in the SOC, but the rule that should catch lateral movement was tuned down to silence false positives and never tuned back up. Each control was real on the day it shipped. Drift did the rest. Cyber security tooling decays in place, quietly, until the day something walks straight through it.
Why this is about to get worse
The UK’s NCSC chief, Richard Horne, warned this week that hostile states sit behind roughly three-quarters of attacks on Britain’s critical infrastructure, and that adversaries are “prepositioning” inside those networks. His line is the one that should keep operators up at night: “kinetic targeting in any conflict tomorrow will be based on intelligence gathered today.”
Prepositioning depends entirely on blind spots. An attacker who plans to sit quietly for months isn’t tripping your loudest alarms on purpose. They’re living in the gap, the encrypted channel nobody inspects, the dormant account nobody reviews, the logging source that stopped reporting and never got noticed. The state-sponsored playbook and the INC ransomware playbook converge on the same real estate: the parts of your environment you assume are covered and never confirm. One wants money this week. The other wants a foothold for a conflict that hasn’t started. Both rely on you not looking.
Stop buying. Start verifying.
The good news is that closing the assumed-versus-actual gap costs mostly attention, not budget. You almost certainly own the tools already. You just haven’t proven they work where you think they work. Here’s where to point that attention first:
- Run an actual control test, not a config review. Generate a failed-login storm against a non-production account and confirm your brute-force throttling fires and alerts. Drop a known benign test payload through an encrypted browser session and see whether anything notices. If the control doesn’t trip, it doesn’t exist.
- Inventory your auth paths, all of them. Find every legacy protocol, service account, and API token that can authenticate without MFA. Those are the doors INC-style crews walk through. Kill them or wrap them in phishing-resistant MFA.
- Map your detection coverage against the kill chain. List the techniques you can actually detect today versus the ones you assume you cover. The honest version of that list is usually shorter than the marketing version.
- Watch your telemetry for silence. A log source that stops reporting is a blind spot in the making. Alert on the absence of expected data, not just the presence of bad data.
- Treat the browser as in-scope. Confirm whether your stack inspects encrypted web sessions at all, and where that traffic goes uninspected, layer browser isolation or DNS-level filtering so it isn’t a free lane.
None of this is glamorous. It’s security hardening in the most literal sense: taking the controls you already paid for and making sure they hold weight. This is what defense in depth actually means in practice, not stacking five products, but confirming that when one layer fails, the next one is genuinely standing there and not just listed in an architecture diagram.
Then rehearse the failure. Your incident response plan should assume at least one control you trusted didn’t fire, because eventually one won’t. Run a tabletop where the MFA was bypassed and the EDR stayed quiet. If the team’s first reaction is “that can’t happen,” you’ve found your next blind spot.
Attackers aren’t getting more clever this quarter. They’re getting more disciplined about exploiting the difference between what you bought and what you verified. Close that gap and the basics stop being a business model for the people trying to ransom your hospital.
Sources
- The browser blind spot: Why your security tool may not be blocking what you think it is
- INC Ransomware Thrives by Mastering the Basics
- Webinar Today: How Modern Breaches Bypass MFA and Evade Detection
- Hostile states behind three-quarters of attacks on Britain’s critical infrastructure, cyber chief warns
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
