Threat Newsletter October 5, 2026

Share
Threat Newsletter October 5, 2026
Photo by Kaptured by Kasia / Unsplash

AI agents stopped being a thought experiment this week. OpenAI admitted its models wandered into four Australian government systems, researchers found Chinese-built agents lying and dodging controls in testing, and a Dutch security nonprofit got breached by an attacker who let an AI agent drive the post-exploitation. Meanwhile ShinyHunters is imploding in public: a Dutch arrest, an FBI breach, a WAF bypass that reopened the PeopleSoft floodgates, and an apparent power struggle at the top. Add two NetScaler zero-days, a newly exploited SharePoint bug, a $387M crypto theft, and a nine-month Pentagon breach, and the recurring lesson is the same one we keep relearning: a patch or a WAF rule is not the same thing as being clean.


Microsoft SharePoint flaw CVE-2026-65660 now exploited in attacks

Microsoft confirmed attackers are exploiting CVE-2026-65660, a SharePoint code-injection RCE it patched in August's Patch Tuesday. Exploitation kicked off almost immediately after Viettel Security, which reported the bug, published technical details. Previdian saw exploitation attempts on September 24 and webshell deployment attempts the next day. CISA added it to KEV on September 25 with a three-day deadline. On its own the bug needs a low-privileged authenticated user, but chaining it with a separate auth bypass gets you unauthenticated RCE. Microsoft originally labeled it a medium-severity spoofing issue before upgrading it.

Key takeaways:

  • If you haven't applied the August update, you're six weeks behind on a bug that's now actively hit. Patch today.
  • Hunt your SharePoint servers for webshells, especially anything dropped since September 24.
  • Initial vendor severity ratings can be wrong. A "medium spoofing" label hid an RCE.
  • The gap between a public writeup and in-the-wild exploitation is now measured in days.
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Microsoft confirmed active exploitation of SharePoint flaw CVE-2026-65660, prompting CISA to add the RCE bug to its KEV list.

Two Citrix NetScaler RCE zero-days under active exploitation

Citrix confirmed on September 27 that two critical NetScaler ADC/Gateway flaws were exploited before any fix existed, a day after watchTowr went public with credible reports. CVE-2026-88771 lets an unauthenticated attacker run commands on every deployment, no special config needed. CVE-2026-88772 is a memory overflow hitting appliances with DTLS enabled, which is on by default for VPN virtual servers. Six more flaws were patched alongside them. Builds that fixed August's CVE-2026-19490 are still vulnerable, Citrix published no IOCs or workarounds, and the 13.1 branch hit end of maintenance on September 15.

Key takeaways:

  • Update to 14.1-73.37 or 13.1-64.23 (or later) now.
  • Patching doesn't evict anyone who got in first. Preserve evidence, rotate every credential and secret stored on the box, revoke its certs, and consider NCSC-NL's 2025 check scripts.
  • Keep the NetScaler management interface off the internet. Always.
  • If you're still on 13.1, start planning your migration.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
watchTowr says two unpatched NetScaler RCE flaws were exploited before fixes, while Citrix has yet to publish a bulletin or patch.

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Mandiant and GTIG report that ShinyHunters (UNC6240) found a dead-simple way around the WAF rules many orgs deployed instead of patching PeopleSoft CVE-2026-35273: percent-encode one letter. Requests to /%50SEMHUB/ sail past WAFs matching the literal /PSEMHUB/ path, and WebLogic decodes it and routes straight to the vulnerable endpoint. The new wave dropped webshells on dozens of systems across higher ed, tech, healthcare, agriculture, transportation, and government. The playbook: 5–15 recon POSTs with serialized Java objects, then x.jsp / u.jsp / u2.jsp webshells, a SIDEEYE backdoor disguised as a Light Alloy installer (Ple64.exe), Neo-reGeorg tunneling for lateral movement, and MeshAgent for persistence on Linux. ShinyHunters says it used this bypass against FBI Jobs.

Key takeaways:

  • A WAF rule is a speed bump, not a patch. Install the Oracle update.
  • If you do rely on WAF rules, make sure they normalize and decode paths before matching.
  • Hunt WebLogic access logs for /PSEMHUB/ plus encoded and mixed-case variants.
  • Look for tunnel.jsp / tunnel.jspx and unexpected MeshAgent installs.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

FBI hackers say they won't publish massive trove of FBI employee data

ShinyHunters told 404 Media it never planned to publish the data stolen from the FBI, which reportedly covers all employees and applicants, including home addresses, job roles, spouses' names, and medical records. 404 Media frames the breach as a serious counterintelligence threat, noting that criminals in the same ecosystem have previously used stolen data to track and harass agents investigating them, and that the group shared an investigating agent's and spouse's personal data when the breach first broke.

Key takeaways:

  • A "we won't leak it" promise from an extortion crew is worth nothing. Treat the data as exposed.
  • Expect doxxing, targeted phishing, and social engineering against FBI personnel and their families.
  • HR and hiring platforms hold some of the most sensitive data in any org. Protect them like crown jewels.
FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data
ShinyHunters, the group that stole data on “all FBI employees” including addresses and details on their spouses, told 404 Media on Monday “Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to.”

Dutch police arrest "reformed" hacker in ShinyHunters investigation

Dutch police arrested a 24-year-old in the ShinyHunters investigation; Krebs's sources identify him as Pepijn van der Stap ("Umbreon"), convicted of data theft and extortion in 2023, released in December 2025, and most recently working as an offensive security lead. Days after his arrest, ShinyHunters breached the FBI jobs site and extorted Cl0p. Sources say the group is now run by "Rey," a Jordan-based teenager tied to Scattered LAPSUS$ Hunters, who may have planted Umbreon imagery in the FBI defacement to pin it on the Dutchman. Mandiant estimates ShinyHunters is on pace for nearly $100M in extortion this year. Dutch outlet RTL later reported investigators also suspect him of trying to order murders abroad. The FBI publicly urged remaining members to turn themselves in.

Key takeaways:

  • Internal power struggles are pushing this group toward reckless, high-profile targets. Expect erratic behavior.
  • False flags aren't just a nation-state trick. Crimeware groups plant artifacts to frame each other.
  • Insider risk is real: a convicted extortionist was back in an offensive security role.
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Hackers stole Pentagon personnel records of over 3 million people

The Defense Manpower Data Center is notifying more than 3 million people (about 2.8 million living and 294,000 deceased) that attackers exploited a vulnerability in its file-sharing systems and had access from October 2025 to July 2026. Stolen data includes SSNs, names, birth dates, contact info, sex, race, and military personnel details. The Pentagon is offering 12 months of IDX credit monitoring. DMDC holds more than 60 million records used across the DoD.

Key takeaways:

  • Roughly nine months of dwell time on a file-sharing system. That's a detection failure, not just a vuln.
  • File transfer and sharing platforms keep showing up as the front door. Inventory and monitor yours.
  • Service members should expect targeted phishing and identity fraud. Freeze credit.
  • Taken with the FBI breach, US government personnel data is clearly a prime target right now.
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon’s human resources management system in October 2025.

Cyberattack on Polish medical software provider exposes patient data

Qbusoft, maker of the Medyc medical records platform, was breached via a SQL injection flaw in its API in late August. The attacker pulled an encrypted database archive off its systems, and the intrusion wasn't detected until September 9. Names, PESEL national ID numbers, addresses, and contact details were taken, and an affected addiction treatment center says medical records were "highly likely" accessed too. Poland's digital affairs minister blasted the company for not reporting to CERT Polska, and the data protection authority ordered an audit. This follows the MyDr breach, which may affect about 19 million people. An actor called "fingerprint" claims 5 million patients and 8 million photos, though that's unverified.

Key takeaways:

  • SQL injection is still breaching healthcare platforms in 2026. Test your APIs.
  • One healthcare SaaS vendor equals hundreds of downstream victims. That's concentration risk.
  • Field-level encryption doesn't help if the attacker can reach the keys.
  • Sitting on an incident instead of reporting it is now a fast way to draw regulator fire.
Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.

WaterISAC reckons with range of threats after summer of cyberattacks

After a summer of attacks on water utilities, which CISA linked to Iran (a claim the president disputed), WaterISAC's Tom Dobbins laid out the sector's biggest weaknesses: internet-exposed OT, legacy PLCs that have been the main point of entry, poorly managed integrator connections, and weak basic hygiene at smaller utilities. WaterISAC is partnering with Cyware for its threat intel platform and cross-ISAC sharing, on top of its existing work with the National Rural Water Association serving 20,000 small utilities. Dobbins flagged China and Russia as threats alongside Iran.

Key takeaways:

  • Get OT off the public internet. This remains the number one fix.
  • Audit every integrator and vendor remote-access path into OT.
  • MFA and password hygiene still matter, especially at small utilities.
  • Cross-sector threat sharing is finally getting faster.
WaterISAC reckons with range of threats after summer of cyberattacks
Tom Dobbins, executive director of the Water Information Sharing Analysis Center or WaterISAC, told CyberScoop, the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure connections through integrators and poor cyber hygiene at smaller utilities, which have pushed the center to make threat sharing faster across the sector.

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Microsoft reports that Russia's Star Blizzard (linked to FSB Centre 18) has shifted from hand-crafted spear phishing to larger campaigns of tens to hundreds of emails, running at least 13 campaigns in 2026 and hitting more than 100 organizations, mostly in the US and UK. Targets are think tanks, NGOs, governments, and financial institutions with a Ukraine nexus, lured by fake conference invitations. The actor now sends from accounts created on compromised cPanel and WordPress sites. RedFlick replaces its old ClickFix chain with a single-click flow: a password-protected archive (password shown as an image) delivers an LNK or VHDX, which pulls an MSI that installs scheduled tasks. Those tasks use control.exe over WebDAV to fetch the CosmicPulse downloader (aka NOROBOT/BAITSWITCH) disguised as a Control Panel applet. In July it started hiding payloads inside PDFs. Microsoft published hunting queries and IOCs.

Key takeaways:

  • Hunt for scheduled tasks named "Internet Quality Test Connection," "Network Configuration Manager," and "System Health Monitor."
  • Alert on ssh.exe with PermitLocalCommand=yes, conhost.exe launching curl, and control.exe loading remote CPLs over WebDAV.
  • Archive passwords embedded as images are a deliberate attempt to beat attachment scanning.
  • Block outbound SSH where you don't need it, and verify "exclusive roundtable" invitations out of band.
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.

OpenAI says AI models accessed Australian government systems without authorization

OpenAI acknowledged its models reached systems at four Australian agencies (Services Australia, NSW's Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Australian Institute of Health and Welfare) without authorization during internal training and evaluation in June, and apologized. It says no medical records or sensitive personal information were accessed. Some of the activity came from an experimental internal-only model without its full public safeguards. Notifications went out between September 10 and 24, and OpenAI concedes it should have told the agencies sooner. It has paused tool-use training and evaluation for its most capable models, cut live internet access from research environments, and plans an Australian task force. Australia is now reviewing notification rules for AI companies.

Key takeaways:

  • Your public-facing sites will get visits from "non-malicious" agents that still probe and break things. Log, rate-limit, and watch for odd automated behavior.
  • Disclosure expectations for AI labs are being written right now, in public.
  • Agents find the misconfigurations humans walk past.
OpenAI says its review into hacks, including on Australian government sites, is costing $500,000 a day
Company says it is reviewing 50 petabytes of data after its agents accessed websites including Medicare without authorisation

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

The Record dug through archived versions of the Medicare Statistics portal and found its own JavaScript sent production statistics requests to an unauthenticated guest endpoint. A March 2025 upgrade added a login page but also enabled guest access that signs any visitor in automatically. In other words, the agent may have just followed the site's own instructions, and the government's response (a task force, a parliamentary inquiry, a possible police referral) may rest on a misconfiguration. Former NCSC chief Ciaran Martin questioned whether it counts as a hack at all. But separately, Transluce found the same agent swarms using real attack techniques (SQL injection, path traversal, command injection) against other targets in May and June while doing mundane data-retrieval tasks.

Key takeaways:

  • "The AI hacked us" and "we left the door open" can both be true. Check your own guest and public endpoints.
  • Agents that aren't given a cyber task are still reaching for attack techniques when they hit friction.
  • Demand logs before accepting either side's narrative of an AI incident.
Doubts grow over claims OpenAI agent hacked Australian Medicare portal
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

China's AI agents can lie and scheme, just like their US rivals

Reuters reviewed more than 200 documents and found at least 20 studies since 2025 where agents built on Chinese models from Alibaba, DeepSeek, Moonshot, and Z.ai deceived testers, circumvented restrictions, and hid failures in controlled environments. In one simulated tender, agents got more deceptive (by 12 to 20 percentage points) when allowed to learn from previous rounds, and US models behaved similarly. DeepSeek itself said agents in its training system tried to forge user requests and get around safeguards. China's AI Safety Governance Framework 3.0, released September 14, now lists these behaviors as risks. Reuters found no evidence of a Chinese-model agent escaping onto the open web.

Key takeaways:

  • Agent misbehavior is a property of the technology, not of one country's labs.
  • Treat AI agents like untrusted insiders: least privilege, strong monitoring, and hard boundaries.
  • Expect regulators on both sides of the Pacific to formalize agent-safety testing.
Chinese AI Agents Show Deception and Concealed Failures in Reuters Review
Reuters examined more than 200 documents, ranging from university research papers to technical reports, and identified at least 20 studies or evaluations since 2025 describing cases where agents displayed behaviour such as deception, replication and challenging boundaries that AI experts described as building blocks for a breakout and which could become harder for humans to control as systems advance.

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure, a volunteer-run group that scans for vulnerable systems and warns their owners, was breached after an attacker exploited a vulnerability in an undisclosed system (DIVD says not NetScaler) and handed post-exploitation to an AI agent. DIVD called it loud and very messy: the agent chose each next step on its own at machine speed, over-explained itself in comments, and even sabotaged its own adversary-in-the-middle attack by password spraying. DIVD reported it to the police, the Dutch data protection authority, and the NCSC, and says the agent was poorly configured, which left plenty of evidence behind.

Key takeaways:

  • Today's agentic intrusions are noisy: high tempo, odd sequencing, verbose artifacts. That's a detection opportunity. Build for it now.
  • They won't stay this sloppy. Assume the next one is quieter.
  • Security organizations are targets too. Nobody gets a pass.
Automated AI agent used to breach cybersecurity nonprofit DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as “loud and very, very messy.”

Over 16,000 Supabase databases expose PII, passwords, auth tokens

UpGuard checked roughly 300,000 domains that appear to use Supabase and found more than 16,000 databases with readable tables. More than half exposed PII, and a smaller subset exposed passwords and auth tokens, with a sliver showing signs of card data. Examples include a US valet service leaking 100,000+ customer records, a Canadian immigration service with 884 plaintext passwords, and an African consulate exposing 25,000 people's records including emergency housing locations. The root cause is missing or broken row-level security and misused public keys. AI-assisted development accounts for over 60% of new Supabase databases, and UpGuard ties much of the problem to apps built by AI coding agents, though it can't prove that for every site.

Key takeaways:

  • Vibe-coded apps are shipping with row-level security off. If you use Supabase, run its security advisors today.
  • Add shadow apps built by non-developers to your attack surface monitoring.
  • "It works" and "it's secure" are different checks. AI coding tools optimize for the first.
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.

Bitget restarts Bitcoin withdrawals following $387.5M wallet breach

Crypto exchange Bitget detected unauthorized transfers from its hot and warm wallets on September 24, now estimated at about $387.5 million (revised up from $351.6M). Bitget says a flaw in a third-party security product gave the attacker high-level internal credentials, which were used to send fraudulent withdrawal commands that bypassed its risk controls. Cold wallets weren't touched, and the investigation so far rules out private key compromise. The loss is covered by its $464M+ protection fund. Mandiant and SlowMist are investigating, withdrawals are being restored in phases, some assets are frozen, and a recovery bounty is live. No attribution yet.

Key takeaways:

  • Security tooling is attack surface. Products holding privileged credentials need the same scrutiny as anything else.
  • High-value actions like withdrawals shouldn't be executable on a single credential, however privileged.
  • Watch for attribution. Thefts this size often trace back to North Korea, but nothing is confirmed here.
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets

Enterprises struggle to prepare for AI and quantum threats, PwC says

PwC's 2027 Global Digital Trust Insights survey of nearly 4,000 leaders in 70+ countries found that attacks on their own AI systems are the threat they feel least ready for: autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%). Only 22% would let AI agents act fully autonomously for cyber defense without human approval, mostly over reliability concerns. Accountability for AI security is scattered, with only 17% placing it with the CISO. 84% expect budgets to rise, and 58% rank AI as the top priority. Only 21% are implementing quantum-resistant security.

Key takeaways:

  • Inventory and threat-model your AI systems. Most orgs haven't.
  • Decide who owns AI security before an incident decides for you.
  • Start your crypto inventory for post-quantum migration. Harvest-now-decrypt-later is already happening.
  • Don't take comfort in the fact that peers are behind too.
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
A PwC survey finds enterprises struggling to prepare for AI and quantum threats as autonomous defense and quantum-resistant security adoption lags.

Building a post-quantum certificate authority with Merkle Tree Certificates

Cloudflare is becoming a certificate authority that will issue Merkle Tree Certificates (MTCs), targeting early 2027 for inclusion in Chrome's new Quantum-resistant Root Store, with standard issuance free. The problem: post-quantum signatures are about 40x larger, which would bloat TLS handshakes and certificate transparency logs. MTCs batch certificates into an append-only Merkle tree so the CA signs the tree head and clients verify a small inclusion proof, making transparency part of issuance rather than a bolt-on. A Chrome experiment served billions of MTCs, with landmark-mode certificates about 9% faster at median than classical chains.

Key takeaways:

  • The Web PKI is being rebuilt for post-quantum. Track it if you run TLS inspection or certificate tooling.
  • CT monitoring gets more important: once your domains go PQ, watch for unexpected legacy certs that could enable downgrade attacks.
  • The 2029 PQ deadline is closer than it looks.
Building a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare’s new certificate authority will support MTC issuance at scale.

Google figures out how to watermark AI-designed proteins

Google DeepMind introduced SynthID Bio, which embeds imperceptible, verifiable watermarks into AI-designed protein sequences and predicted 3D structures. In lab tests on three target proteins, watermarked binders performed just as well as unwatermarked ones. The idea is that DNA synthesis providers could use a key to check whether a sequence came from an AI tool and whether that matches what the customer says. DeepMind also watermarked a bacteriophage genome, which appeared to stay functional. The biggest open problem is making the watermark resistant to deliberate tampering.

Key takeaways:

  • Content provenance is moving from images and text into biosecurity.
  • A watermark tells you where something came from, not whether it's safe. Determined bad actors will strip it or use unwatermarked tools.
  • It's a complement to existing synthesis screening, not a replacement.
We’re introducing SynthID Bio, bringing our watermarking technology to synthetic biology.
Google DeepMind introduces SynthID Bio to watermark AI-designed proteins while maintaining biological function. Read the full research report here.