The common failure across these incidents is not the headline mechanism but the trust decision that followed it. In Microsoft 365, MFA itself was not defeated; stolen bearer sessions were accepted after authentication. A matched domain or username indicates possible exposure, while completed-login data strengthens evidence of session capture—but tenant compromise still requires correlation with Entra sign-in, audit, device, and activity records. Immediate containment therefore means preserving logs, disabling confirmed accounts, revoking Entra and application sessions, reviewing OAuth grants and account changes, and separately terminating upstream federation sessions where applicable.
The Liquid incident likewise remains unresolved despite the return of roughly 3,400 of the approximately 4,000 BTC withdrawn. About 598.5 BTC remains unrecovered, and restitution alone does not establish that reserves, L-BTC liabilities, functionary state, and affected outputs have been reconciled. Nor does the actor’s self-description establish authorized white-hat activity. Containment needs verifiable transaction and UTXO evidence, reserve-to-liability reconciliation, reproducible patch material, and signed functionary attestations. For the malicious HAProxy build, the mechanics are firmer than the attribution: prior host compromise, binary replacement, a known hash, custom command behavior, file transfer, and shell execution are observed; DPRK sponsorship remains moderate-confidence, and the two identified South Korean victims are a sample rather than a proven limit.
Shai-Hulud sharpens a different distinction. The strongest classification is a registry-control failure because a known malicious hash was republished byte-for-byte in four versions through one npm account after 111 days. The evidence does not establish whether that account path reflected token theft, endpoint compromise, or intentional abuse. Resolving, downloading, caching, or locking an affected dependency proves exposure—not execution. Compromise requires evidence that the preinstall path ran or that malicious follow-on activity occurred, so defenders should block the versions and hash, freeze affected builds, preserve artifacts and runner logs, and search direct and transitive dependencies.
We now turn from technically grounded incidents to claims whose exploitation and impact evidence may be weaker: N-able N-central and the reported Oracle E-Business Suite breach at Bimbo Bakeries USA. The next test is whether the available sourcing supports those labels—or only warrants a narrower risk statement.