THE DEEP TAKE

Nine enterprises, one stolen asset, nothing to patch

A threat actor calling itself TheHatman spent last week posting internal employee directories on crime forums. McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels, Kyndryl, Gap, Hexaware and Wyndham are all named. The claimed total is roughly 3.6 million records. Every one came out of an Azure tenant. None came out of an Azure vulnerability.

Look at what was actually taken. Names, employee IDs, job titles, departments. Manager and direct-report relationships. Group memberships. Service accounts. In some cases, the names of accounts holding Global Administrator rights. That is not a breach in the way your board understands the word. No customer records. No payment data. No source code. What left the building was the map.

The map is worth more than most of the data. Hudson Rock, which tracked the postings, points at the obvious use: spear-phishing and business email compromise that are accurate. An attacker who knows a VP's real direct reports does not have to guess. Neither does one calling your help desk. The directory turns a generic pretext into a specific one, and specificity is the whole game in social engineering. It also does something quieter. A list of Global Administrator account names tells an attacker which ten identities are worth a year of patience.

Here is the part that should change how you file this. Nobody needed privileges to take it. Entra ID grants every authenticated member directory read by default. The allowedToReadOtherUsers setting in the tenant authorization policy ships set to true. One stolen session token, from one infostealer infection on one unmanaged laptop, is enough to enumerate the whole organization. The attacker never escalates. They read what your own employees are already allowed to read.

So the standard response does not fit. There is no CVE. There is no patch cycle. There is no advisory to route. Three things do move. Set allowedToReadOtherUsers to false and grant directory read explicitly where the business needs it. Pull Global Administrator accounts out of the general directory and put them behind phishing-resistant MFA. Tell your service desk that knowing a manager's name is no longer evidence of anything. The first is one policy change. The third is one email.

The larger shift is worth naming. Enterprises spent a decade classifying data and building controls around the crown jewels. The org chart never made that list, because it is not sensitive on its own. It is only sensitive as an input to something else. That is the category attackers are now paying for.

Powered by the DoGood network

The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.

QUICK HITS

Two vendors patched. Attackers arrived within days.

SAP shipped the fix for CVE-2026-58231 on August 11. It is a CVSS 10.0 flaw in the SAP Commerce Cloud Data Hub Adapter. Unauthenticated, remote, arbitrary code execution. Honeypots recorded exploitation attempts on August 14. GitLab patched CVE-2026-19478 on August 17, a CVSS 9.4 GraphQL code injection that lets an unauthenticated attacker modify or delete public projects. WatchTowr reported exploitation roughly two days later. The number that matters is not the severity score. It is the gap between the vendor release note and the first attempt, and that gap is now shorter than most change advisory boards meet. Name your five most revenue-bearing platforms. Confirm each has an emergency change path that does not wait for the next scheduled window.

AI is hitting its ROI target and eating the hours anyway

New SolarWinds research on AI in IT service management, drawn from more than 800 IT professionals, found 84% saying AI has met or exceeded their ROI expectations. In the same survey, 52% said their overall workload has gone up since they adopted it. And 83% now spend three or more hours a week keeping the AI running. SolarWinds sells service management software, so weigh the framing accordingly. The numbers still describe something real. Those three hours are a standing operational tax, and nobody put it in a business case. Before the next agent goes live, ask who owns its upkeep and which work those hours displace.

Microsoft is about to charge you 5% for paying monthly

On August 12 Microsoft issued a corrected notice. Starting October 1, a 5% cost of capital uplift applies to CSP software subscriptions on annual-term commitments billed monthly. SQL Server, Windows Server, Client Access Licenses and System Center are named. Annual billing and month-to-month subscriptions are untouched. Existing annual-term subscriptions billed monthly pick up the uplift at renewal on or after October 1. The correction is the part to catch: an earlier notice carried the wrong effective date. Ask your reseller which subscriptions renew after October 1 on monthly billing, then price the annual-upfront alternative against the uplift.

THE NUMBER: $9.3 billion

Cisco's AI infrastructure orders for fiscal 2026, reported August 12, with $4 billion of that in the fourth quarter. The company guided investors to $7.5 billion of hyperscaler AI infrastructure revenue in fiscal 2027. Almost none of that is your budget, and that is the point. Your supplier has told the market where its capacity and its roadmap attention are going. The buyers ahead of you order in nine-figure blocks. When your campus or data center refresh goes out to quote this year, treat lead time as a term you negotiate rather than a number on the page. Get it in the contract.

Every story here starts with something already inside the environment. Something already known to somebody else. That is close to what IT leaders in the DoGood network describe when they talk about what they buy next. Not new capability. Control over what they already run.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.