CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (2 October 2026)

Published: Loading…

At a Glance

  • Cisco confirmed active exploitation of CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager granting admin-level access.
  • Microsoft tracked exploitation of Zimbra flaw CVE-2026-73570 beginning weeks before its public disclosure on 13 August 2026.
  • Police arrested a 16-year-old suspected leader of the KillSec ransomware group and seized its leak site under Operation KillSwitch.
  • A Dutch national was indicted and arrested for operating KillSec, which exploited vulnerabilities to steal data since March 2025.
  • Autonomous AI agents exploited two Zammad zero-days to hijack sessions and escalate to root access at the Dutch Institute for Vulnerability Disclosure.
  • China-aligned group TA419 impersonated AI policymakers to phish Microsoft 365 credentials from US think tank and university experts.

Editorial Analysis

The KillSec takedown and the DIVD breach landed on the same day, but illustrate very different operating speeds. Operation KillSwitch identified a 16-year-old as KillSec's suspected administrator and separately indicted a Dutch national in the UK, seizing a leak site holding 110 terabytes from roughly 1,000 suspected attacks. DIVD's incident involved an agentic attack that chained two Zammad zero-days from session hijacking to root access within seconds, without a human operator directing each step.

Cisco's CVE-2026-76504 is the second confirmed authentication bypass this week rooted in a decoding mismatch, following the NetScaler pattern reported Monday. VulnCheck traced the flaw to vManage's login module and application server disagreeing over whether a request path had already been URL-decoded, allowing a single percent-encoded character to bypass the password check. Supplying one of four hardcoded internal usernames then provides a valid administrator session. Around 1,500 internet-exposed SD-WAN vManage devices are affected. Cisco's incident responders discovered the exploitation while investigating a routine support case, giving the flaw a quieter route to detection than the vendor advisories and researcher telemetry behind several other zero-days this month.

TA419's phishing campaign against AI policy experts arrived as OpenAI disclosed a separate distillation campaign linked to individuals associated with Moonshot AI. Proofpoint found TA419 impersonating a former White House science policy official and a prominent Anthropic employee, using benign outreach to establish rapport before deploying a Browser-in-the-Browser kit that relays genuine Microsoft sign-in traffic in real time and captures session cookies after MFA succeeds. The targeting comes alongside MI5's warning that more than 100 UK academics contributed to Chinese-funded research with links to the Ministry of State Security.

Highlights of the Day

Researchers Detail How Cisco SD-WAN Auth Bypass Grants Admin Access

VulnCheck reproduced CVE-2026-76504, a Cisco Catalyst SD-WAN vManage authentication bypass, tracing the flaw to a mismatch between how two components interpret URL-encoded request paths. A percent-encoded path skips the normal password check, and supplying one of four hardcoded internal usernames, such as viptela-reserved-cloudops, grants a valid admin-level session with a single request. VulnCheck identified around 1,500 internet-exposed SD-WAN vManage devices, and Cisco disclosed the flaw as an actively exploited zero-day.

Source: VulnCheck

International Operation Dismantles KillSec Ransomware Group's Leak Site

A Dutch national known as Archduke was indicted and arrested in the UK for operating the KillSec ransomware group, which exploited vulnerabilities to steal data and extort victims between March and November 2025. Authorities across the US and Europe conducted eight residential searches, made three provisional arrests, and seized KillSec's leak site along with at least 110 terabytes of data under Operation KillSwitch. The investigation covers around 1,000 suspected attacks worldwide, with roughly 500 confirmed as successful so far.

China-Aligned Group Impersonates Policymakers to Target AI Experts

Proofpoint identified TA419, a China-aligned espionage actor, impersonating a former White House science policy official and a prominent economist to phish AI policy experts at US think tanks and universities since July 2026. The group builds rapport with benign outreach before directing targets through a multi-stage redirect chain to a customised Browser-in-the-Browser phishing kit targeting Microsoft 365 accounts. The kit relays genuine Microsoft sign-in traffic in real time, capturing session cookies even after multi-factor authentication succeeds, and automatically extends stolen sessions.

Source: Proofpoint

MetaMask Responds to Infrastructure Security Incident

MetaMask is investigating a security incident affecting part of its infrastructure, with no indication that user wallets or customer funds have been affected. As a precaution, the company worked with partners to exit affected validators within its non-custodial staking operations, which do not involve MetaMask managing withdrawal keys on clients' behalf. Containment and verification work continues alongside external security advisors.

Source: MetaMask

Pentagon Data Breach Exposes Records of 3 Million Military-Linked Individuals

A breach of the Defense Manpower Data Center exposed unencrypted personal data, including Social Security numbers and dates of birth, belonging to nearly 2.8 million living individuals and 294,000 deceased people with military ties. Unauthorised users had access from October 2025 to July 2026, after a vulnerability in a file-sharing system was discovered and patched on 16 July. A Pentagon official said there is no indication the exposed data has been misused, and affected individuals will receive 12 months of credit monitoring through IDX.

Malware Drains Crypto Exchange Accounts and Hides Confirmation Emails

Netskope identified a stealer campaign using an Aotera/Tedy loader to inject malicious scripts into victims' Chrome or Edge browsers, draining cryptocurrency exchange accounts through their existing logged-in sessions. Within a Binance session, the malware disables withdrawal allow lists, converts balances to Bitcoin, and transfers funds to operator-controlled addresses, then rewrites withdrawal confirmation emails in webmail so they appear routine. The operation has netted roughly $100,000 in traceable on-chain proceeds from an estimated 350 to 430 victims since telemetry began in October 2023.

Source: Netskope

TIKTOUK Toolkit Harvests WordPress Credentials at Scale

LevelBlue analysed TIKTOUK, a toolkit combining WordPress probing, exposed configuration scanning and JavaScript secret collection to recover plaintext credentials from encrypted SMTP plugin settings. Its components target exposed files such as wp-config.php.bak, decrypt WP Mail SMTP, Easy WP SMTP and FluentSMTP settings using recovered keys, and scan client-side JavaScript for API tokens including AWS, SendGrid and Anthropic patterns. A leaked TIKTOUK panel examined by LevelBlue contained around 50,000 server-side credentials across roughly 37,000 domains, including hundreds of validated live AWS keys.

Source: LevelBlue

Warlock Ransomware Group Hits Water and Telecom Operators via SharePoint

Symantec attributes recent Warlock ransomware attacks on four organisations, including a water utility and a telecommunications provider, to a China-nexus group it tracks as Longlegs. The group continues exploiting Microsoft SharePoint Server vulnerabilities, including the ToolShell chain, to forge signed payloads for remote code execution, then disables security software using the vulnerable K7RKScan driver before deploying ransomware. In one intrusion, attackers pushed the security-disabling tool to over 40 hosts within two hours and staged Warlock in the domain's SYSVOL share, infecting at least 33 machines through ordinary domain replication.

Source: Symantec

Daily Coverage

Developments
Cisco Sd-Wan Zero-DayZimbra Pre-Disclosure ExploitationKillsec ArrestsDivd Zammad Breach
Vulnerabilities
CVE-2026-76504Cisco Catalyst Sd-Wan Manager 18.3.6 (Critical)CVE-2026-73570Collaboration (High)CVE-2026-86950Ios And Ipados (High)CVE-2026-104286Fortimail 8.0.0 (Critical)CVE-2026-86134Fireware Os 2026.3 (High)CVE-2026-50375Windows 10 Version 1809 10.0.17763.0 (Medium)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.