CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-02 12:15 UTC · REPORT BRIEF-20261002-121522
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
17
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Crypto Scammers Hijack Microsoft’s Official X Account
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account.
The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 02 Oct 2026 11:46:10 +0000
https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/
02
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 02 Oct 2026 09:34:41 +0000
https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/
03
Microsoft’s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. […]
SRC: BleepingComputer
Fri, 02 Oct 2026 05:29:56 -0400
https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
04
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.
The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 02 Oct 2026 08:07:33 +0000
https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/
05
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
SRC: DarkReading
Thu, 01 Oct 2026 21:37:50 GMT
https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old
06
Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unles
SRC: Security Affairs
Thu, 01 Oct 2026 18:08:47 +0000
https://securityaffairs.com/200200/cyber-crime/operation-killswitch-police-dismantle-killsec-ransomware-group.html
07
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
SRC: DarkReading
Thu, 01 Oct 2026 13:00:00 GMT
https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
08
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.
The 16-year-old was one of 3 people arrested on September 30, when
SRC: The Hacker News
Thu, 01 Oct 2026 22:25:57 +0530
https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
09
In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.
The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 02 Oct 2026 11:14:34 +0000
https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/
10
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday.
The post National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations appeared first on CyberScoop.
SRC: CyberScoop
Thu, 01 Oct 2026 19:21:37 +0000
https://cyberscoop.com/sean-cairncross-ai-security-china-industry-collaboration/
11
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.
The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 01 Oct 2026 14:30:00 +0000
https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/
12
AI policy circles targeted in China-linked phishing operation
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts.
The post AI policy circles targeted in China-linked phishing operation appeared first on CyberScoop.
SRC: CyberScoop
Thu, 01 Oct 2026 14:06:19 +0000
https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
13
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. […]
SRC: BleepingComputer
Thu, 01 Oct 2026 10:01:11 -0400
https://www.bleepingcomputer.com/news/security/the-day-one-hole-in-zero-trust-architecture/
14
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides.
SRC: The Hacker News
Fri, 02 Oct 2026 17:00:00 +0530
https://thehackernews.com/2026/10/why-cisos-struggle-to-answer-boards.html
15
AI Agents Aimed SQL Injection at US and Canadian Government Sites
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.
The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 02 Oct 2026 08:38:46 +0000
https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
16
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.
With malicious Android applications abusing the API serving as the main conduit for malware and financia
SRC: The Hacker News
Fri, 02 Oct 2026 13:31:30 +0530
https://thehackernews.com/2026/10/android-17-advanced-protection-locks.html
17
Investigators trace an AI agent ‘s path from research task to reconnaissance
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian governme
SRC: Security Affairs
Fri, 02 Oct 2026 06:05:52 +0000
https://securityaffairs.com/200215/ai/investigators-trace-an-ai-agent-s-path-from-research-task-to-reconnaissance.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
