Cyber Security Week in Review: October 2, 2026

 

Cyber Security Week in Review: October 2, 2026

Cisco has released security updates for a critical zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, which attackers are actively exploiting to gain admin privileges. The vulnerability affects all deployments regardless of configuration.

In a separate report, Microsoft has warned that threat actors are exploiting a patched Zimbra Collaboration Suite vulnerability (CVE-2026-73570) to remotely execute commands, deploy web shells, and access email and authentication data. The flaw affects exposed servers with SNMP enabled and was patched in Zimbra 10.1.20 in July 2026. Attackers have been observed using persistence and privilege-escalation techniques.

The US Cybersecurity and Infrastructure Security Agency (CISA) has released an unrelated warning detailing a vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition (CVE-2026-84411). The vulnerability is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling. CISA says that currently there’s no indication that the flaw is being exploited in the wild.

Attackers are exploiting two Citrix NetScaler zero-day vulnerabilities to gain root access, install web shells and tunneling malware, steal credentials, and move into internal networks. The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. The first is an unauthenticated remote code execution flaw affecting NetScaler ADC and Gateway deployments. The second is a memory overflow vulnerability that can enable remote code execution or denial of service when DTLS is enabled.

Fortinet has warned of an actively exploited security vulnerability (CVE-2026-104286) in its FortyMail product, which allows a remote non-authenticated attacker to execute arbitrary code. The vulnerability exists due to improper input validation when handling URLs within the IBE feature in the FortiMail management interface. A remote non-authenticated attacker can write arbitrary files on the underlying system via specially crafted HTTP requests, which may result in full system compromise. Until a patch is available, the company recommends users to apply the provided workarounds.

Apple has released security updates to fix a zero-day vulnerability that was exploited in highly targeted attacks against iPhone users. The flaw, tracked as CVE-2026-20700, affects CoreGraphics, a system framework used for graphics, images, and text. Apple said the vulnerability could allow a specially crafted file to execute malicious code.

The ShinyHunters extortion group is using a URL-encoding trick to bypass web application firewalls (WAFs) and exploit a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273. It allows unauthenticated remote code execution on vulnerable servers. The attackers are targeting PeopleSoft servers that have not installed Oracle’s security update. Organizations that tried to block the vulnerable /PSEMHUB/ endpoint with WAF rules may still be exposed.

Russian state-linked threat actor, tracked as Star Blizzard, has changed its phishing and malware delivery tactics in 2026, using larger campaigns and a new technique Microsoft calls RedFlick. Since January, Microsoft has observed Star Blizzard targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial organizations involved in supporting Ukraine. More than 100 organizations, mainly in the US and UK, have been affected.

Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials, according to a new report from CERT-UA. Threat actors use malicious apps and advanced attacks against both Android and iPhone devices. For example, a tool, called DarkSword, can exploit iPhones through hacked news and government websites. After infecting a phone, hackers may steal messages, contacts, passwords, and call history.

The Dutch Institute for Vulnerability Disclosure (DIVD) said that its network was breached through two zero-day vulnerabilities in the open-source Zammad ticketing system (CVE-2026-102489 and CVE-2026-102490). The vulnerabilities allowed attackers to hijack sessions, execute code remotely, and escalate privileges to root. AI automation enabled the attacker to exploit the vulnerabilities and access, read, and exfiltrate data within seconds. 

Belnet, the Belgian National Research and Education Network (NREN), disclosed a security incident involving a zero-day vulnerability in technology from an external supplier. Between 22 July and 25 September 2026, attackers accessed and copied certain incoming emails, including attachments, and may have accessed files shared through FileSender and FedSender. Password-protected or authenticated file transfers remain protected unless the password was included in the upload comments.

TeamViewer has warned about five high-severity vulnerabilities in its Full Client and Host software. One of the flaws (CVE-2026-92370) could allow remote attackers to bypass access controls and execute code on affected systems. The other vulnerabilities are CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, and CVE-2026-92371, which could enable attackers to execute code or escalate privileges. The flaws affect Windows, Linux, and macOS versions of the software.

Vulnerability disclosures doubled from January to August 2026, reaching a record 10,740 in August, Google’s GTIG says. So far this year, 141 vulnerabilities have been exploited, already exceeding 2025’s total of 127. Google says AI is helping attackers find and exploit high-risk vulnerabilities faster, especially vulnerabilities that have already been patched and disclosed.

A threat actor known as JADEPUFFER carried out a destructive attack against a Microsoft Azure environment in June 2026, using compromised service principals to access and delete cloud resources. Two compromised service principals were used in the attack, one of which was mainly leveraged to explore the Azure environment. The other one carried out destructive actions and searched for credentials. The attackers performed more than 300 discovery operations before beginning the destructive activity. They later made more than 100 attempts to delete Azure Storage accounts and most of the storage accounts were wiped.

Cryptocurrency exchange Bitget said attackers behind last week’s theft of $387.5 million gained access to its systems by exploiting zero-day flaws in third-party security products. Preliminary investigations found that the attackers compromised two security appliances used by Bitget. The attackers then installed a web shell on one device and moved into a production wallet server, where they deployed malware and a custom withdrawal tool.

Fortinet’s FortiGuard Incident Response team discovered an attack that used SectopRAT, a remote access trojan that can remotely control a victim’s device, steal sensitive information, capture screens, and manage files and processes. In the analyzed case, the malware was hidden inside a legitimate audio workstation program developed by an Italian company.

Microsoft has warned about phishing campaigns that trick users into installing MSP360 remote-management software. Attackers use fake meeting invitations, PDFs, and software-update messages to gain remote access to devices. Threat actors then install ConnectWise ScreenConnect to maintain another way to access the systems and use the access to steal information and credentials.

Attackers are abusing ChatGPT Custom GPTs to impersonate real products and send victims to malicious websites. The attack tricks users into running PowerShell, which installs malware through several hidden stages. The malware uses techniques like DLL sideloading and multiple persistence methods to stay on infected systems. Huntress found at least 40 related incidents, including two linked directly to the fake Custom GPTs.

OpenAI said it blocked a coordinated effort to copy protected reasoning from its AI models. The activity was linked to people associated with Chinese AI company Moonshot AI, according to OpenAI, although the company did not provide technical evidence. The campaign began on July 1, 2026 and involved thousands of users. OpenAI said it disrupted the activity completely on July 28.

European law enforcement targeted the KillSec ransomware group in an international operation called Operation KillSwitch. Three people were provisionally arrested, and eight searches were carried out in Greece, Romania, Spain, and the UK. Authorities believe a 16-year-old was the group’s main administrator. KillSec is suspected of carrying out around 1,000 cyberattacks worldwide, with about 500 believed to have been successful. The group stole sensitive data and threatened to publish it unless victims paid a ransom. Police also seized servers, domains, data, and other assets connected to the group, including at least 110 terabytes of stolen information.

Former US soldier Cameron John Wagenius was sentenced to 70 months (5 years and 10 months) in prison for hacking several US technology and telecommunications companies. He and others stole login information, accessed company systems, and demanded money in exchange for not releasing the stolen data. He was also ordered to pay $294,978 in restitution.

Ardit Kutleshi pleaded guilty for helping run Rydox, an illegal online marketplace used by criminals to buy and sell stolen personal information and hacking tools. The marketplace carried out more than 7,600 transactions and made at least $232,000. Kutleshi faces prison time and will be sentenced in February 2027.

Dutch police arrested a 24-year-old man from Amsterdam suspected of being connected to the ShinyHunters hacking group. Police found a large amount of information on his laptop and also discovered evidence related to a separate investigation involving planned murders. 

Spanish National Police arrested a man accused of running an online scam network that caused more than €1 million in losses. He allegedly manipulated payment systems to get tickets, flights, hotel bookings, food deliveries, and other services without fully paying. He also used fake identities and multiple payment methods to hide his activities. He was arrested in a luxury hotel in Madrid.

Malachi Morgan Thomas, a US citizen, was sentenced to 40 years in prison for sexually exploiting minors and possessing child sexual abuse material. According to the US authorities, he used a hacked Snapchat account to threaten and manipulate girls aged 12 to 17 into sending or performing explicit content. He also threatened some victims and their families if they refused.

Back to the list