The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest
Fresh incidents show attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

Key points
- Attackers leaned on exposed internet services and unpatched software rather than novel techniques.
- VMware products, a Windows zero-day (a bug the maker did not know about) and Model Context Protocol tools used by AI assistants were all abused in live attacks.
- Supply-chain breaches, where a hack at one supplier spreads to its customers, kept widening past the first victim.
- Old vulnerabilities with patches already available are still being weaponised against organisations that never installed the fix.
- Defenders are being told the same thing they were told last year: shut the front door before worrying about the ceiling.
The expensive break-ins aren't always the clever ones. This week made that plain again.
Across the incidents summarised in a weekly roundup from The Hacker News, the pattern held. Attackers hit services already exposed to the open internet, dusted off bugs that vendors patched months or years ago, and rode into networks on browser sessions staff had left logged in. When one supplier got hit, the damage didn't stop at the supplier's door. It's a pattern we've tracked across eight VMware stories since 14 July, none of them surprising, all of them avoidable.
None of it was magic. Most of it was access already sitting there, waiting.
What actually went wrong this week?
Four themes ran through the incidents: exposed services, a Windows zero-day, hijacked browser sessions and supply-chain fallout. Each is unremarkable on its own. Together they explain most of the damage.
VMware makes software that lets companies run many virtual computers on one physical machine. Attackers exploited known VMware flaws to get inside networks; in several cases the fixes had been available for some time and the victims hadn't installed them.
Then there was a Windows zero-day. A zero-day is a flaw the maker didn't know about, meaning there was no patch when attacks began. Microsoft is now working through the fix cycle. Until every machine is updated, criminals with working code have the advantage.
How are browsers being turned into an attack path?
Browsers are being hijacked because staff stay signed in to work apps all day. Stealing a live session is easier than stealing a password; attackers don't need credentials if they can grab the cookie that proves you're already logged in.
Once inside, criminals can read email or pivot into cloud dashboards. Multi-factor authentication, the extra code you approve at login, doesn't always help because the session has already passed that check. We first reported on this technique on 17 August.
Separately, attacks were spotted against MCP, or Model Context Protocol, a newer standard that lets AI assistants plug into company tools and data. Poorly configured MCP servers gave attackers a shortcut into whatever systems the AI was allowed to touch.
Where the damage spread
| Attack path | What it hit | Why it worked |
|---|---|---|
| VMware exploits | Corporate data centres | Patches existed, were not applied |
| Windows zero-day | Windows endpoints | No fix available when attacks began |
| Browser session hijack | Staff cloud accounts | Live logins bypass MFA prompts |
| MCP tool abuse | AI assistant integrations | Weak configuration on new tech |
| Supply-chain compromise | Downstream customers | Trust inherited from supplier |
Should ordinary people worry?
Most readers won't be targeted directly, but they may be customers of a company that gets hit. If a service you use emails about a security incident, change that password, turn on multi-factor authentication and watch for follow-up phishing, where criminals send fake messages pretending to be the breached company.
If your employer asks you to sign back into work apps this week, do it promptly. That request isn't busywork. It's often the one step standing between a known bug and a very bad Monday.
The real story here isn't the zero-day or the AI angle. It's that the same unpatched VMware boxes and forgotten browser tabs keep showing up in incident reports, week after week. The ceiling's fine. It's the front door.



