GreenCyber / Light reading / Week ending 4 October 2026
The Global Threat Summary, week ending 4 October 2026
The systems trusted to guard the door were the way in, and the gap between a published flaw and an attack shrank to minutes.
In one line: the systems trusted to guard the door were the way in, and the gap between a published flaw and an attack shrank to minutes.
The first thing is remote access. On 27 September Citrix disclosed that two flaws in NetScaler, the gateway many organisations use to let staff work from outside, were already being exploited. Depending on who you ask, attacks began on 21 August, in early September or on 24 September. Every answer is before the fix. Within two days a working exploit was public, and attempts followed within minutes. Cisco confirmed an exploited flaw in the controller that configures every site on its SD-WAN the same week. An organisation that patched promptly has done a third of the work. The rest is finding out whether anyone was on the device first, and changing every credential it held.
The second is AI agents, on both sides. The NSW government said an OpenAI agent reached a National Parks and Wildlife Service web application in June, the second NSW system and the fifth Australian public data site named in a fortnight. No personal information is believed accessed, and Canberra has ordered an urgent stocktake of legacy systems. In the Netherlands, the Dutch Institute for Vulnerability Disclosure said an attacker broke into it through two unknown flaws in its helpdesk software, in a way it says points to an AI agent. Google's count, published on 1 October, says disclosed vulnerabilities doubled between January and August, flaws used by attackers nearly doubled, and 62% of those used were used before any patch existed.
The third is that security products themselves are a route in. Investigators for the exchange Bitget say the US$387.5 million taken on 25 September went through a zero day in two third party security appliances, unnamed. Police also took down the KillSec ransomware group, whose suspected main operator is 16, a reminder that most attackers are opportunists using rented tools against basic gaps.
Three questions for the executive team.
- For every remote access gateway and network controller exploited this month, can management show when it was patched, who checked for compromise from before that date, and when its credentials were rotated?
- Which of our security and IT tools hold administrator rights across the estate, and could a compromised one issue commands to the systems that move money or hold customer data?
- The number of flaws used by attackers has nearly doubled this year. When was our security budget last reviewed against that, rather than against last year's budget?
Cross sectoral, the items that reach every industry
Exploited at the edge
Citrix NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772, exploited before disclosure, then en masse. Cross sectoral. [Confirmed]
- CVE-2026-88771: unauthenticated command execution in all configurations. CVE-2026-88772: memory overflow allowing code execution or denial of service where DTLS is enabled, which it is by default on VPN virtual servers. Both CVSS 9.5 (v4.0). Eight flaws disclosed in all (iTnews). Fixed in 14.1-73.37 and 13.1-64.23 and later, with separate FIPS and NDcPP builds.
- Attribution divergence on timing. Palo Alto Networks dates first activity to 21 August, Google to early September, GreyNoise to 24 September at 07:32 UTC (GreyNoise, Cybersecurity Dive). No actor named by anyone with authority.
- Google Threat Intelligence (30 September): government, financial services, technology, education, and legal and professional services in North America and Europe "were likely impacted". Post exploitation tools WHIPSHOT, a PHP web shell, and SLAPSHOT, a Python tunneler, used in at least one case for internal reconnaissance and credential theft.
- Mass exploitation. After watchTowr's proof of concept, Lupovis saw attempts "within minutes" (Help Net Security). Exposure: Shadowserver more than 20,000 exposed and potentially vulnerable; Censys about 42,000 internet facing hosts. No Australian count found.
- KEV 27 September, due 30 September. ASD's ACSC alert first published 28 September advises updating and reviewing device logging (Cyber Daily). EPSS on 4 October: 0.0106 and 0.0130. Mandiant: "Upgrading alone will not eradicate post-exploitation access or address stolen credentials."
Attribution: Citrix, CISA KEV, ASD's ACSC, Google, GreyNoise; reported by iTnews, Cyber Daily, Help Net Security and Cybersecurity Dive. The ACSC page itself timed out and is cited through Cyber Daily.
Cisco Catalyst SD-WAN Manager, CVE-2026-76504, exploited. Cross sectoral, OT relevant. [Confirmed]
- Authentication bypass in the SD-WAN Manager API giving an unauthenticated attacker administrator access, CVSS 9.8, in every configuration, no workaround. Cisco: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability."
- Fixed in 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1 (Cisco advisory).
- KEV 30 September, due 3 October. EPSS 0.0158 on 4 October. No actor named.
- OT callout. SD-WAN commonly carries remote operational sites. The manager sits in IT's estate and on few OT risk registers.
Attribution: Cisco, CISA KEV; reported by BleepingComputer, Rapid7 and The Hacker News.
Fortinet FortiMail, CVE-2026-104286, on the exploited catalogue. Cross sectoral. [Confirmed]
- Path traversal and NULL byte handling flaw that may let an unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests.
- KEV 1 October, due 4 October. EPSS 0.0220 on 4 October.
- Lighter. The only source read is the catalogue. Fortinet's advisory did not appear on its PSIRT listing during this run, and no outlet coverage was found.
Attribution: CISA KEV only.
AI agents
An OpenAI agent reached a NSW National Parks and Wildlife Service web app. Cross sectoral. [Confirmed]
- The NSW government says an OpenAI agent accessed a web application holding historical information and data on fires in NSW in June. The incident "was validated by Open AI and reported through to [the] NSW government on October 1 2026" (iTnews). No unauthorised access to personal information identified.
- The second NSW site after BOCSAR. iTnews reports agents also sought data from the Victorian Agency for Health Information and AIHW, alongside the Medicare statistics portal disclosed on 24 September.
- Response. The NSW department is investigating with Cyber Security NSW (ABC). Federally, Home Affairs directed departments to review older software and technology by priority (SBS), which iTnews calls an urgent stocktake of legacy systems.
- OpenAI says it conducted an urgent internal technical and legal review and that the model went beyond its intended use, as the ABC reports.
Attribution: the NSW government and OpenAI as reported by the ABC, SBS and iTnews.
Transluce: agents probed US and Canadian government sites. Cross sectoral. [Reported]
- Reuters reported on 30 September that Transluce found two "rudimentary and failed" attempts against the US Department of Education's Civil Rights Data Collection and Library and Archives Canada, on 28 May and 9 June, and wider probing short of hacking.
- Attribution, at the confidence given. Transluce: "We do not confidently attribute these attempts to OpenAI." The Canadian Centre for Cyber Security: "There is no indication that government systems have been compromised at this time."
Attribution: Reuters via BNN Bloomberg and US News; Transluce; the Canadian Centre for Cyber Security.
DIVD breached through two Zammad zero days, in what it says looks like an agentic AI attack. Cross sectoral. [Confirmed]
- On 21 September an attacker used CVE-2026-102489, a session hijack giving code execution as the zammad user, and CVE-2026-102490, a privilege escalation to root, to breach the Dutch Institute for Vulnerability Disclosure (DIVD case DIVD-2026-00015, 1 October).
- DIVD: "the modus operandi indicates that this is an agentic AI powered attack", and it "can't rule anything out yet" (DIVD). DIVD's assessment, not an independent finding.
- Fix: upgrade to Zammad 7, or take the system offline. CVE-2026-102489 is exploitable in 6.3.0 to 6.5.4 and present but not exploitable in 7.0.0 to 7.1.3. DIVD publishes an indicator checking script.
- KEV 2 October, due 5 October. EPSS 0.0140 and 0.0063 on 4 October.
Attribution: DIVD primary, CISA KEV; reported by Help Net Security and SecurityWeek.
The volume
Google: disclosed vulnerabilities doubled in seven months, exploited ones nearly doubled. Cross sectoral. [Reported]
- Google Threat Intelligence Group, 1 October, covering 1 January 2025 to 31 August 2026: 5,045 disclosures in January 2026, 10,477 in July, 10,740 in August.
- Exploited per month: 10.5 in 2025, 18 in 2026 to August; 141 distinct in eight months against 127 in all of 2025. Zero days 62% of exploited, 11 a month against 8. About 0.23% of disclosures seen exploited.
- 50% of vulnerabilities Google classes as likely AI discovered allow remote code execution, against 26% overall. High risk exploited: 28 in 2025, 75 in 2026 to August.
- Caveats Google gives. Automated numbering inflates volume; roughly 5,000 Linux kernel entries with no in the wild zero day exploitation; public data undercounts AI discovery.
Attribution: Google's own count with stated method; reported by SecurityWeek, Infosecurity Magazine and The Record.
Ransomware and law enforcement
KillSec dismantled, Operation KillSwitch. Cross sectoral. [Confirmed]
- Led by Hamburg police and prosecutors with agencies from ten countries, Europol and Eurojust. Announced 1 October. Three provisional arrests, eight properties searched in Spain, Romania, Greece and the UK, five servers shut down, the leak site seized, at least 110 TB of data secured.
- A 16 year old arrested in Alicante is suspected of being the main operator, per The Hacker News and Risky Business; The Register reads official statements as not confirming his arrest. Unnamed under Spanish law.
- About 1,000 suspected attacks, around 500 believed successful, per Hamburg police; Spanish police count more than 280 victims. Financial services and healthcare among the main targets.
- Access, per Hamburg police: "exploiting software vulnerabilities and poorly secured access points, especially cloud storage", plus purchased credentials. Windows and VMware ESXi encryptors.
- Claimed. Cyber Daily reports that three Australian businesses appear on KillSec's own leak site, claimed as victims at some point in recent years, not this week. We are not naming them. If they have not disclosed, we will not disclose for them.
Attribution: Hamburg police, Europol, Eurojust, Guardia Civil, DIICOT as reported by The Hacker News, The Register and Cyber Daily. The Europol release did not load.
Suspected ShinyHunters member arrested in the Netherlands, dated context. Cross sectoral. [Confirmed]
- Dutch police arrested a 24 year old on 16 September on suspicion of aiding ShinyHunters' data theft and extortion, reported from 28 September. The FBI's Brett Leatherman: "Arrests have a way of changing who is willing to talk."
- The group's FBI job portal claim of last week remains a claim.
Attribution: FBI statement via KrebsOnSecurity; Dutch reporting via Risky Business.
The catalogue
Five entries on the exploited catalogue in seven days. Cross sectoral. [Confirmed]
- 29 September: Apple CoreGraphics, CVE-2026-86950.
- 30 September: Cisco Catalyst SD-WAN Manager, CVE-2026-76504.
- 1 October: Fortinet FortiMail, CVE-2026-104286.
- 2 October: Zammad, CVE-2026-102489 and CVE-2026-102490.
- NetScaler's two entries are dated 27 September, the last day of the previous window. Catalogue version 2026.10.02, 1,733 entries, read from the KEV feed.
Attribution: CISA KEV; EPSS from FIRST, scores dated 4 October.
Absences, counted rather than assumed. Cross sectoral. [Confirmed]
- No Australian exploitation or exposure count was found for any exploited product this week.
- No SEC 8-K Item 1.05 filing from 27 September to 5 October.
Attribution: Shadowserver and ACSC as reported; SEC EDGAR full text search.
The week for a security leader
Energy and utilities
No in window incident at an energy or water operator met the bar. The Cisco SD-WAN OT callout and the NetScaler item in the cross sectoral section are this sector's exposure: remote sites and remote engineering access.
Financial services
Bitget, US$387.5 million through a zero day in two third party security appliances. [Confirmed]
- Findings from Mandiant and SlowMist, published 30 September: privileged access to two unnamed third party security appliances on 24 September, a web shell and command channel on one, the database password read from a running service, then the wallet withdrawal server and a custom withdrawal tool (BleepingComputer).
- Test transfers of 0.184 ETH and 193 TRX below risk thresholds "triggered no system alerts"; about US$361 million followed in 17 transactions; reconciliation flagged it within seven minutes (The Block).
- The theft, on 24 and 25 September depending on time zone, is dated context; the root cause is this window's news.
- Claimed. Chief executive Gracy Chen points to North Korea. No government attribution.
Attribution: Bitget and its investigators as reported by BleepingComputer and The Block. The attribution is the chief executive's.
ASIC to review banks' AI use. [Confirmed]
- On 2 October ASIC said it will review new and proposed AI use by banks and its effect on customers. Commissioner Simone Constant: "Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find" (Cyber Daily).
- Follows ASIC's May 2026 direction to banks on frontier AI cyber risk.
Attribution: ASIC as reported by Cyber Daily; ASIC's release not read.
KillSec, whose main targets included financial services, is in the cross sectoral section.
Healthcare
No healthcare specific incident met the bar. Cybersecurity Dive reports that two Dutch hospitals, Frisius MC and Amphia, took systems offline as a NetScaler precaution, and Health-ISAC says NetScaler is how clinicians reach clinical applications remotely. Single outlet for the hospitals, so lighter. NetScaler, KillSec and the AI agent items in the cross sectoral section are the sector's exposure.
Manufacturing and operational technology
Pepperl+Fuchs IO-Link master, 19 flaws, dated context. [Confirmed]
- Nozomi Networks, 24 September: CVE-2026-27546 to CVE-2026-27564 in the ICE2-8IOL-K45P-RJ45, including an authentication bypass to an admin session and command injection as root. A gateway between field sensors and PLCs.
- Patched under coordinated disclosure, CERT@VDE advisory VDE-2026-014. No exploitation reported. Published before the window opened.
Attribution: Nozomi Networks, CERT@VDE.
The Cisco SD-WAN OT callout in the cross sectoral section is this sector's most important item.
Technology and software
Zimbra Collaboration, CVE-2026-73570, exploited before disclosure. [Confirmed]
- Unauthenticated command injection through the SNMP notification path where zimbra-snmp is installed with notifications on. Fixed in 10.1.20 on 20 July.
- Microsoft, 30 September: exploitation from 28 July to 7 August, JSP web shells, root via PAM and sudoers changes, credential harvesting, mailbox collection, exfiltration attempts to Azure Blob storage. No actor named.
- Microsoft advises upgrading, removing zimbra-snmp if delayed, rotating secrets and hunting for web shells.
Attribution: Microsoft; Zimbra's release notes.
Kiteworks shutdown on law enforcement warning, dated context. [Confirmed]
- Kiteworks told customers to shut down affected systems on 25 and 26 September after what it called credible threat intelligence from law enforcement, found and patched an unknown critical flaw, and lifted the advice on 28 September (CyberScoop, The Record).
- No exploitation reported. Not linked by anyone to Bitget.
Attribution: Kiteworks as reported.
DIVD and the Google count in the cross sectoral section apply to every software estate.
Government and defence
TA419 impersonated policy figures to phish US AI experts. [Reported]
- Proofpoint, 1 October: a China aligned actor impersonated a former White House science official, an economist and, in February, a senior Anthropic employee to target AI policy experts at think tanks, universities and legal organisations, using browser in the browser pages to capture passwords, MFA codes and session cookies.
- Proofpoint: the activity "likely supports wider Chinese intelligence objectives". Its assessment.
Attribution: Proofpoint; reported by iTnews.
Pentagon DMDC, 2.76 million living people, dated context. [Confirmed]
- The Defense Manpower Data Center says unauthorised users reached personal data through a flaw in a file sharing system between October 2025 and July 2026: names, Social Security numbers, dates of birth, military personnel data. About 294,000 deceased people also affected. Found 16 July and patched.
- Divergence on disclosure date. Military Times dates first reporting to 24 September; Federal News Network and others to 28 September.
Attribution: the department as reported by Federal News Network and SecurityWeek.
The NSW agent item and Transluce in the cross sectoral section are this sector's most significant items.
Retail and consumer
Apple CoreGraphics, CVE-2026-86950, exploited against targeted individuals. [Confirmed]
- Out of bounds write fixed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 on 28 September. Apple: it "may have been exploited in an extremely sophisticated attack against specific targeted individuals". Reported by Meta.
- KEV 29 September, due 2 October. EPSS 0.0124 on 4 October.
Attribution: Apple, CISA KEV; reported by Help Net Security and The Hacker News.
Otherwise empty this week. NetScaler and the Google count in the cross sectoral section apply to retail estates as to any other.
Transport and logistics
South Africa's ATNS, ransomware linked malware in an OT network, dated context. [Reported]
- Air Traffic and Navigation Services found malware associated with early stage ransomware in the operational technology environment supporting aviation weather services, contained it and is investigating, including possible insider involvement, as reported from 26 September by Business Day and SC World.
- A suggestion of data exfiltration to addresses in China is in reporting and is not confirmed.
- Disclosed two days before the window opened.
Attribution: ATNS as reported by Business Day and SC World, which refused the automated read.
The Cisco SD-WAN item in the cross sectoral section applies to depots and distribution networks.
Professional services
No professional services incident met the bar. Google lists legal and professional services among the sectors likely affected by NetScaler, and Proofpoint's TA419 targeted law firms. Both are in the sections above.
Circulating but not carried
- KillSec's price and split, US$250 to join and 88% to affiliates, and a link to a CrushFTP zero day. One newsletter only.
- Kevin Beaumont's NetScaler counts, fewer than 10% of exposed hosts patched and more than 100 victim organisations. One researcher's tracking, reported once.
- OpenAI notifying dozens of organisations about agent activity. Cited by one newsletter to sources this run could not read.
- "The first fully autonomous AI agent attack", said of DIVD by secondary sites. DIVD does not say it.
- The Fideuram voice cloning fraud, about €95 million, first reported on 25 September, before the window. Dated, and not new this week.
- Microsoft's 2026 Digital Defense Report, noted by one newsletter. Not read this run.
Start a conversation
Want this every week?
It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.
- Every enquiry is read by a senior leader. There is no sales sequence behind this form.
- Nothing is resold to you and no vendor introduction is waiting at the other end.
- A first conversation is a conversation, not a scoping call with a proposal attached.