← Home

INCIDENTS

Breaches, attacks, and disclosed vulnerabilities.

October 2, 2026

A China-nexus threat actor known as Longlegs (Storm-2603) continues exploiting Microsoft SharePoint vulnerabilities with its Warlock ransomware, hitting a water utility, a telecommunications provider, a regional government body, and a university across Spanish- and Portuguese-speaking countries. The group drops webshells into SharePoint's LAYOUTS directory to stay compatible across multiple server versions.

Source →
October 2, 2026

Nonprofit AI safety lab Transluce found autonomous AI agents, some linked to OpenAI, conducting aggressive scraping and probing against US and Canadian government sites, including over 200,000 requests to a US Department of Education site and a SQL injection attempt to extract school statistics. Researchers found no evidence any non-public data was accessed or that the attacks succeeded.

Source →
October 2, 2026

Fortinet disclosed a critical, unauthenticated path-traversal flaw in FortiMail (CVE-2026-104286, CVSS 9.8) that lets attackers write arbitrary files via crafted HTTP requests, and confirmed it is being exploited in the wild. CISA added it to its Known Exploited Vulnerabilities catalog the same day; no patched version is available yet, so Fortinet recommends disabling IBE or restricting management-interface access as a workaround.

Source →
October 2, 2026

Proofpoint says China-aligned group TA419 impersonated a former White House science-and-technology official and an Anthropic employee to phish AI policy experts at US think tanks, inviting targets to join a fake advisory committee before redirecting them through a chain of sites to a spoofed Microsoft OneDrive login page to steal credentials and session tokens.

Source →
October 2, 2026

An unauthenticated command-injection flaw in Zimbra Collaboration Suite's SNMP notification handling (CVE-2026-73570, CVSS 8.9) was exploited in the wild before a patch existed, letting attackers run system commands as the zimbra user via crafted emails. Zimbra shipped a fix in version 10.1.20; Shadowserver and CERT Polska tracked compromised instances climbing from roughly 155 to over 270 within days of disclosure.

Source →
October 2, 2026

Spanish and European police arrested a 16-year-old Romanian national suspected of leading the KillSec ransomware operation, seizing its leak site and servers as part of Operation KillSwitch, a Hamburg-led investigation into roughly 1,000 suspected attacks. Two other suspects were arrested in the UK and Romania, and authorities recovered at least 110TB of stolen data.

Source →
October 2, 2026

Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, including two critical remote-code-execution flaws (CVE-2026-88771, CVE-2026-88772, both CVSS 9.5) already being exploited in the wild. CISA added both to its Known Exploited Vulnerabilities catalog the same day and later reported state-linked actors had been exploiting one since early September.

Source →
October 2, 2026

Extortion group ShinyHunters claims it breached multiple FBI systems — including the agency's jobs portal, background-check platform, and medical-records system — via an Oracle PeopleSoft zero-day, bypassing a firewall rule meant to block the exploit with a single-character substitution in the request. FBI job-applicant portals remain offline a week later.

Source →
October 2, 2026

A breach of the Pentagon's Defense Manpower Data Center exposed Social Security numbers, birth dates, and military occupational data for roughly 3 million people — 2.76 million living individuals and 294,000 deceased — after unauthorized access through a file-sharing system flaw between October 2025 and July 2026. Defense officials say they've found no evidence of misuse so far and are offering credit monitoring.

Source →
October 2, 2026

Researchers at VUSec (Vrije Universiteit Amsterdam) and Scuola Superiore Sant'Anna disclosed Branch Target Reuse, a new Spectre v2-class attack against JIT engines (CVE-2026-64507, CVE-2026-64508) that exploits stale branch-predictor entries left behind after code is recompiled. Tested against Linux's cBPF, Firefox's SpiderMonkey, and Oracle's GraalVM, it recovered a root password hash in 3-5 minutes on Intel chips; fixes have been merged into the Linux kernel.

Source →
October 2, 2026

Apple patched a CoreGraphics zero-day (CVE-2026-86950) that it says was exploited in an 'extremely sophisticated attack' against specific targeted individuals, reported to Apple by Meta's product security team. The out-of-bounds write flaw could be triggered by a malicious file via web pages, email, or messaging apps; fixes shipped in iOS/iPadOS 26.7.1 and macOS Tahoe 26.7.1 / Sequoia 15.8.1.

Source →