{"id":11397,"date":"2026-08-10T09:34:50","date_gmt":"2026-08-10T08:34:50","guid":{"rendered":"https:\/\/www.gpsj.co.uk\/?p=11397"},"modified":"2026-08-10T09:42:57","modified_gmt":"2026-08-10T08:42:57","slug":"the-death-of-the-perimeter-how-shinyhunters-and-zero-day-saas-exploits-weaponised-the-cloud-supply-chain","status":"publish","type":"post","link":"https:\/\/www.gpsj.co.uk\/?p=11397","title":{"rendered":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em><strong>By Graham Jarvis \u2013 Freelance Business and Technology Journalist<\/strong><\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"457\" height=\"600\" src=\"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg\" alt=\"\" class=\"wp-image-11398\" style=\"width:208px;height:auto\" srcset=\"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg 457w, https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024-229x300.jpg 229w, https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024-114x150.jpg 114w, https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024-400x525.jpg 400w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><figcaption class=\"wp-element-caption\"><em>Graham Jarvis<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">One thing is worth remembering: nobody is immune to either fraud or data breaches. Each and every one of us &#8211; including our organisations &#8211; could be successfully cyber-attacked; and this is exactly what happened recently in late May and early June 2026 to the Council of Europe. Attacks often begin with an emotional hook because when we as individuals become emotional, we think irrationally. This leads to mistakes begin made. In this case, the alleged emotional and structural hook was the 297GB exfiltration of the organisation\u2019s payroll and medical records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It reveals a terrifying reality: The very institutions tasked with governing privacy and human rights are helpless against modern cloud extortion \u2013 not even from hacking group ShinyHunters. This group executed the compromise via a sophisticated zero-day supply chain exploitation, rather than via a traditional perimeter hack. This poses a systemic threat because it emphasises the risk that, potentially, many organisations can no longer sit comfortably thinking that they can still protect their border.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Zero-day exploit<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This culminated in the Oracle PeopleSoft zero-day, whereby the hackers exploited vulnerabilities, such as being able to create a Server-Side Request Forgery (SSRF), an unauthenticated Remote Code Execution (RCE) flaw in the Environment Management component of PeopleSoft PeopleTools, versions 8.61 and 8.62.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This impacted at least 100 organisations globally \u2013 including the Council of Europe, with a heavy focus on the higher education sector (such as the University of Nottingham) and corporate networks. For remediation, Oracle issued an emergency security alert with mitigation and patching instructions on 10th June 2026. Five days later, and The Register confirmed in an article that the ShinyHunters extortion group had added the international organisation to its dark web leak site. Therefore, the Council of Europe fell victim to the very same CVE-2026-35273 PeopleSoft heist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eventually, ShinyHunters got to a point where they were able to safely pull data from the Council of Europe\u2019s servers, and list it on their Tor leak site over the weekend of 13th and 14th June 2026. It was at this point they put forward a demand for a hard ransom negotiation deadline of 16th June 2026. The Council of Europe refused to negotiate an undisclosed amount as part of a ransom, and so they leaked 4.7 GB of compressed data dump on 18 June 2026 to prove the validity of their haul. Despite this being part of a multi-stage release of the stolen data, the Council has continued to refuse to pay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Technical turning point<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The hack has nevertheless highlighted a technical turning point \u2013 and much because it caught so many organisations off-guard. Subsequently, it demonstrates that the traditional patch and pray approach to cyber-security defence models are completely fractured. To this end, there is a massive and unfolding cyber-security crisis that needs to be immediately challenged and tackled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organisations need to avoid this chaos. In another incident, ShinyHunters defaced Canvas login portals during the final exams at 330 schools \u2013 illustrating how digital extortion is in this case about inflicting immediate real-world disruption on millions of students and educators. While this is likely to cause much emotional stress on all of them, sometimes these events are about causing stress to push an organisation or an individual to make a mistake for financial gain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thankfully, Canadian firm Telus Digital did not pay the $65m demanded by the group. However, it shows that cybercrime has gone way beyond being an operational nuisance. It is a material threat to corporate solvency and, particularly when data breaches are involved. In some jurisdictions, such as in the EU and in the UK, it can lead to heavy fines in line with GDPR regulatory breaches. So, their exploits still pose a threat to global infrastructure, education and governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Entirely in the Cloud<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"600\" src=\"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/David_Trossell_Bridgeworks.jpg\" alt=\"\" class=\"wp-image-11399\" style=\"width:358px;height:auto\" srcset=\"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/David_Trossell_Bridgeworks.jpg 400w, https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/David_Trossell_Bridgeworks-200x300.jpg 200w, https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/David_Trossell_Bridgeworks-100x150.jpg 100w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption class=\"wp-element-caption\"><em>David Trossell<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">As David Trossell, CEO and CTO of WAN Acceleration company Bridgeworks, says, \u201cThe World operates entirely in the Cloud in mid-2026, and this makes the software supply chain the ultimate vulnerability for any organisation; this allows for hackers to cause an intersection of sophisticated state-level disruption, corporate liability and to exploit the vulnerabilities of everyday public, civic and educational institutions inasmuch as those of corporate entities.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given that the threat from groups such as ShinyHunters comes from SaaS exploits and from cloud supply chain breaches, there is a role for WAN Acceleration to either eliminate or reduce the disruption caused by data breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cRather than acting after the fact, it\u2019s important to store data in at least 3 far-off, disparate locations to minimise any disruption and to maintain uptime by focusing on service continuity,\u201d he advises. This is because prevention is always cheaper than a cure \u2013 or than moving the corporate battle towards containment, rapid detection and post-datum recovery.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trossell argues that it\u2019s no good accepting the death of any permitter when it comes to cyber-security and preventing data breaches. The goal is to protect data, and even if a breach is exfiltrated it must still be highly encrypted. Unlike WAN Optimisation, WAN Acceleration, data is encrypted in transit. There is no need, unlike with WAN Optimisation, to unlock the data before it can be sent over a Wide Area Network (WAN). In contrast, WAN Acceleration with PORTrockIT deploys a no-touch approach and its use of artificial intelligence and machine learning can accelerate the transfer of data, while obfuscating cyber-criminals by making it harder to divert and access data in transit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Maintain continuous, automated offsite replication<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By mitigating latency and maximising bandwidth utilisation by up to 98%, enterprises can maintain continuous, automated offsite replication. They can frequently push immutably isolated or air-gapped data to distant, secure facilities. If a breach happens, recovery could \u2013 for example &#8211; be achieved in two hours old rather than two days because WAN Acceleration achieves up to 50\u00d7 faster data recovery performance by dramatically shortening the recovery window.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organisations should nevertheless treat the events caused by cybercriminals, such as ShinyHunters, as a warning that resilience can no longer depend on perimeter security, delayed patching or a reactive incident response. They need to be far more proactive to prevent and curtail any form of cyber-disruption. This begins with assuming that SaaS platforms, cloud services and third-party software supply chains may be at any point compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mihai Popa, CISO at Bridgeworks, explains: \u201cThe lesson from these incidents is that organisations can no longer plan for a world where the perimeter holds. SaaS, cloud platforms and software supply chains are now part of the attack surface, which means resilience has to be engineered into the way data is protected, replicated and recovered. At Bridgeworks, our focus is on helping organisations to keep encrypted data moving securely and rapidly across distance, so that even when disruption occurs, recovery is measured in hours rather than days.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This warrants, not just WAN Acceleration, but also the prioritisation of continuous monitoring, rapid and continuous vulnerability management, strong identity controls, heightened data encryption, immutable backups stored in geographically dispersed locations that are regularly tested for replication and recovery. At the very least, such plans have to be in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Essential: Act to disrupt hackers<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In terms of prevention, the goals should be to cut any cyber-attackers ability to disrupt operations before any such event can occur. It is also imperative to have processes in place to ensure that any pressure put on anyone by hackers, doesn\u2019t lead to a decision that could be costly financial and operationally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nobody should be given the tools to exploit any individual or organisation, and so they should be taken out of their hands. This is why WAN Acceleration is significant \u2013 supporting the practical side of resilience; this is by enabling organisations to move voluminous amounts of highly encrypted data fast across large distances without being impinged by the effects of latency and packet loss.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a threat landscape where downtime, data loss and delayed recovery can be as damaging as the breach itself. However, with this technology, organisations can shift from a purely defensive posture to one focused on continuity, prevention and, when a beach does occur, it can help with rapid recovery. This posture therefore revives the perimeter and it can prevent its ultimate death.<\/p>\n\n\n\n<p class=\"has-cyan-bluish-gray-color has-text-color has-link-color wp-elements-71bf03f68ec9a338d3cafda35df0ceb9 wp-block-paragraph\"><em>Graham Jarvis is the Freelance Lead Journalist, for Business and Technology, at Trudy Darwin Communications.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"\n<p class=\"wp-block-paragraph\">By Graham Jarvis \u2013 Freelance Business and Technology Journalist<\/p>\n<p> Graham Jarvis <\/p>\n<p class=\"wp-block-paragraph\">One thing is worth remembering: nobody is immune to either fraud or data breaches. Each and every one of us &#8211; including our organisations &#8211; could be successfully cyber-attacked; and this is exactly what happened recently in late May and early <\/p>\n<p>Continue reading <a href=\"https:\/\/www.gpsj.co.uk\/?p=11397\">The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"footnotes":""},"categories":[1],"tags":[2486,1069,25,417,26,264,739,310,416,422,1542],"class_list":["post-11397","post","type-post","status-publish","format-standard","hentry","category-it-it-security","tag-cyberattack","tag-data","tag-government-public-sector-journal","tag-government-journal","tag-gpsj","tag-gpsj-magazine","tag-hacking","tag-public-sector","tag-public-sector-journal","tag-public-sector-magazine","tag-wan","odd"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gpsj.co.uk\/?p=11397\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal\" \/>\n<meta property=\"og:description\" content=\"By Graham Jarvis \u2013 Freelance Business and Technology Journalist Graham Jarvis One thing is worth remembering: nobody is immune to either fraud or data breaches. Each and every one of us &#8211; including our organisations &#8211; could be successfully cyber-attacked; and this is exactly what happened recently in late May and early Continue reading The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gpsj.co.uk\/?p=11397\" \/>\n<meta property=\"og:site_name\" content=\"Government &amp; Public Sector Journal\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T08:34:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-10T08:42:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"457\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"The GPSJ Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"The GPSJ Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397\"},\"author\":{\"name\":\"The GPSJ Team\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/#\\\/schema\\\/person\\\/d54386f99736367ec2789825fed93b4a\"},\"headline\":\"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain\",\"datePublished\":\"2026-08-10T08:34:50+00:00\",\"dateModified\":\"2026-08-10T08:42:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397\"},\"wordCount\":1386,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gpsj.co.uk\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GrahamJarvis_TDC_BW_2024.jpg\",\"keywords\":[\"Cyberattack\",\"Data\",\"Government &amp; Public Sector Journal\",\"Government Journal\",\"GPSJ\",\"GPSJ Magazine\",\"Hacking\",\"public sector\",\"Public Sector Journal\",\"Public Sector Magazine\",\"WAN\"],\"articleSection\":[\"IT &amp; IT Security\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397\",\"url\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397\",\"name\":\"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gpsj.co.uk\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GrahamJarvis_TDC_BW_2024.jpg\",\"datePublished\":\"2026-08-10T08:34:50+00:00\",\"dateModified\":\"2026-08-10T08:42:57+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/#\\\/schema\\\/person\\\/d54386f99736367ec2789825fed93b4a\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#primaryimage\",\"url\":\"https:\\\/\\\/www.gpsj.co.uk\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GrahamJarvis_TDC_BW_2024.jpg\",\"contentUrl\":\"https:\\\/\\\/www.gpsj.co.uk\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GrahamJarvis_TDC_BW_2024.jpg\",\"width\":457,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?p=11397#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.gpsj.co.uk\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/#website\",\"url\":\"https:\\\/\\\/www.gpsj.co.uk\\\/\",\"name\":\"Government &amp; Public Sector Journal\",\"description\":\"Public Sector, Government, business, stories and news along with latest developments, research, thought leadership, strategy, policy and insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.gpsj.co.uk\\\/#\\\/schema\\\/person\\\/d54386f99736367ec2789825fed93b4a\",\"name\":\"The GPSJ Team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g\",\"caption\":\"The GPSJ Team\"},\"sameAs\":[\"http:\\\/\\\/gpsj.co.uk\"],\"url\":\"https:\\\/\\\/www.gpsj.co.uk\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gpsj.co.uk\/?p=11397","og_locale":"en_GB","og_type":"article","og_title":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal","og_description":"By Graham Jarvis \u2013 Freelance Business and Technology Journalist Graham Jarvis One thing is worth remembering: nobody is immune to either fraud or data breaches. Each and every one of us &#8211; including our organisations &#8211; could be successfully cyber-attacked; and this is exactly what happened recently in late May and early Continue reading The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain","og_url":"https:\/\/www.gpsj.co.uk\/?p=11397","og_site_name":"Government &amp; Public Sector Journal","article_published_time":"2026-08-10T08:34:50+00:00","article_modified_time":"2026-08-10T08:42:57+00:00","og_image":[{"width":457,"height":600,"url":"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg","type":"image\/jpeg"}],"author":"The GPSJ Team","twitter_card":"summary_large_image","twitter_misc":{"Written by":"The GPSJ Team","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gpsj.co.uk\/?p=11397#article","isPartOf":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397"},"author":{"name":"The GPSJ Team","@id":"https:\/\/www.gpsj.co.uk\/#\/schema\/person\/d54386f99736367ec2789825fed93b4a"},"headline":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain","datePublished":"2026-08-10T08:34:50+00:00","dateModified":"2026-08-10T08:42:57+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397"},"wordCount":1386,"commentCount":0,"image":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397#primaryimage"},"thumbnailUrl":"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg","keywords":["Cyberattack","Data","Government &amp; Public Sector Journal","Government Journal","GPSJ","GPSJ Magazine","Hacking","public sector","Public Sector Journal","Public Sector Magazine","WAN"],"articleSection":["IT &amp; IT Security"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.gpsj.co.uk\/?p=11397#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.gpsj.co.uk\/?p=11397","url":"https:\/\/www.gpsj.co.uk\/?p=11397","name":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain - Government &amp; Public Sector Journal","isPartOf":{"@id":"https:\/\/www.gpsj.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397#primaryimage"},"image":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397#primaryimage"},"thumbnailUrl":"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg","datePublished":"2026-08-10T08:34:50+00:00","dateModified":"2026-08-10T08:42:57+00:00","author":{"@id":"https:\/\/www.gpsj.co.uk\/#\/schema\/person\/d54386f99736367ec2789825fed93b4a"},"breadcrumb":{"@id":"https:\/\/www.gpsj.co.uk\/?p=11397#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gpsj.co.uk\/?p=11397"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gpsj.co.uk\/?p=11397#primaryimage","url":"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg","contentUrl":"https:\/\/www.gpsj.co.uk\/wp-content\/uploads\/2026\/08\/GrahamJarvis_TDC_BW_2024.jpg","width":457,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/www.gpsj.co.uk\/?p=11397#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gpsj.co.uk\/"},{"@type":"ListItem","position":2,"name":"The Death of the Perimeter: How ShinyHunters and Zero-Day SaaS Exploits Weaponised the Cloud Supply Chain"}]},{"@type":"WebSite","@id":"https:\/\/www.gpsj.co.uk\/#website","url":"https:\/\/www.gpsj.co.uk\/","name":"Government &amp; Public Sector Journal","description":"Public Sector, Government, business, stories and news along with latest developments, research, thought leadership, strategy, policy and insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gpsj.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.gpsj.co.uk\/#\/schema\/person\/d54386f99736367ec2789825fed93b4a","name":"The GPSJ Team","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/13cdd73dc4abbd6e05b80a0562c7c553a9104ad2e5e96ee20afca2c462894143?s=96&d=blank&r=g","caption":"The GPSJ Team"},"sameAs":["http:\/\/gpsj.co.uk"],"url":"https:\/\/www.gpsj.co.uk\/?author=3"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/11397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11397"}],"version-history":[{"count":7,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/11397\/revisions"}],"predecessor-version":[{"id":11407,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/11397\/revisions\/11407"}],"wp:attachment":[{"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gpsj.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}