CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-01 12:15 UTC · REPORT BRIEF-20261001-121559
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
17
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.
The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 01 Oct 2026 10:51:39 +0000
https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/
02
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 01 Oct 2026 10:42:49 +0000
https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/
03
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.
The vulnerability, tracked as CVE-2026-76504 (CVS
SRC: The Hacker News
Thu, 01 Oct 2026 16:03:16 +0530
https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html
04
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9
SRC: Security Affairs
Thu, 01 Oct 2026 08:35:37 +0000
https://securityaffairs.com/200152/security/u-s-cisa-adds-cisco-catalyst-sd-wan-manager-flaw-to-its-known-exploited-vulnerabilities-catalog.html
05
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim.
The post OpenAI reveals ‘novel’ encryption bypass used in distillation attack appeared first on CyberScoop.
SRC: CyberScoop
Wed, 30 Sep 2026 22:17:34 +0000
https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/
06
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. […]
SRC: BleepingComputer
Wed, 30 Sep 2026 10:01:11 -0400
https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/
07
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models.
A "core cluster of the activity," going back to the first week of July, has been attributed to individual
SRC: The Hacker News
Thu, 01 Oct 2026 16:12:36 +0530
https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html
08
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. […]
SRC: BleepingComputer
Thu, 01 Oct 2026 05:44:28 -0400
https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/
09
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program.
"It delivers frontier performance in complex workflows across real-world software engineering, ent
SRC: The Hacker News
Thu, 01 Oct 2026 13:19:36 +0530
https://thehackernews.com/2026/10/google-rolls-out-gemini-4-argon-to.html
10
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. […]
SRC: BleepingComputer
Wed, 30 Sep 2026 16:34:01 -0400
https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/
11
500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
The post 500,000 Active Credentials Left Exposed on GitHub appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 01 Oct 2026 09:43:56 +0000
https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/
12
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. […]
SRC: BleepingComputer
Wed, 30 Sep 2026 14:08:34 -0400
https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
13
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
"Once executed, the legitimate MSP360 installe
SRC: The Hacker News
Wed, 30 Sep 2026 22:02:59 +0530
https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
14
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.
The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 01 Oct 2026 11:40:51 +0000
https://www.securityweek.com/kevin-mandias-armadin-raises-255-million-at-2-5-billion-valuation/
15
Microsoft enables Windows settings backup by default for orgs
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. […]
SRC: BleepingComputer
Thu, 01 Oct 2026 07:14:28 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-enables-windows-settings-backup-by-default-for-orgs/
16
Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. […]
SRC: BleepingComputer
Thu, 01 Oct 2026 03:33:57 -0400
https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
17
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure.
"We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet
SRC: The Hacker News
Thu, 01 Oct 2026 10:40:09 +0530
https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
