CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (5 October 2026)

Published: Loading…

At a Glance

  • Critical Rejetto HFS authentication bypass CVE-2026-61500 is under active exploitation, with attacks traced to a China-hosted IP address.
  • A breach of Denmark's DTU identity management system may have exposed personal data of up to 200,000 current and former users.
  • China-linked Warlock exploits SharePoint flaws to disable security tools and deploy ransomware in Spanish- and Portuguese-speaking countries.
  • MI5 warned China's MSS used the China General Technology Research Institute to fund research involving over 100 UK-linked academics.
  • China-nexus TA419 ran Microsoft AitM credential phishing campaigns targeting US AI policy experts at think tanks and universities.
  • ShinyHunters suspect Rey was reportedly detained in Jordan and is cooperating with the FBI to identify other group members.

Editorial Analysis

DTU's breach notice is notable for how much it cannot establish. Attackers used compromised DTU profiles to reach DTUBasen, the identity and access management system, giving them access to personal data dating back to 2003. DTU says it cannot determine what was downloaded or how many people are affected, only that the system holds records on about 40,000 active and 160,000 former users. Former users' addresses, profile pictures and next-of-kin details are deleted after six months, while CPR numbers and full names remain. DTU has no CPR numbers for next of kin and only a few for guests and external partners, so it has published a public notice to reach people it cannot contact directly.

The Rejetto HFS case shows an exploit chain that Horizon3 says it had previously abandoned. CVE-2026-61500 combines a session signing key generated with V8's reversible Math.random(), an endpoint that leaks raw outputs from the same generator, and an administrative API that allows custom JavaScript execution. Horizon3 said the lack of mathematical expertise and the time needed to build such an exploit had put it off pursuing similar flaws. Mythos identified the chain and produced a working exploit using the Z3 solver. VulnCheck then detected exploitation within a day of disclosure, first from a China-hosted IP address and later from two US addresses that appear to be proxies. It is the second Mythos-linked vulnerability known to be exploited in the wild, out of 286 CVEs tracked so far.

The reported detention of ShinyHunters suspect Saif al-Din Khader, known as Rey, follows the Dutch arrest of Pepijn van der Stap. Two sources say Khader is helping the FBI and international partners locate other members and is reportedly walking investigators through his devices and correspondence. The group's dark-web site went offline on Wednesday, and its operators told Reuters they want no further escalation with the FBI. Khader's identity and alleged role have been publicly known for some time, and Krebs reported last year that he claimed to have quit and begun cooperating with law enforcement. ShinyHunters continued operating into 2026, so the effect of his detention on the group's activity remains unclear.

Highlights of the Day

Cyberattack on DTU Exposes Personal Data Dating Back to 2003

Attackers compromised DTU user profiles and used them to access DTUBasen, the university's identity and access management system. The system holds data on about 40,000 active and 160,000 former users, and DTU cannot confirm which records were downloaded. Exposed information may include CPR numbers, full names, home addresses and next-of-kin details, and the breach has been reported to the Danish Data Protection Agency.

Mythos Chains Weak Random Numbers Into Admin Takeover of Rejetto HFS

Horizon3 used Anthropic's Mythos model to find CVE-2026-61500, where Rejetto HFS signs session cookies with a key derived from V8's non-cryptographic Math.random(). An unauthenticated endpoint leaks raw random outputs, which the Z3 solver uses to recover the generator state and reconstruct the signing key. Attackers can then forge an admin session cookie and run code through built-in HFS functionality.

Suspected ShinyHunters Member Detained in Jordan Is Cooperating With FBI

Jordanian authorities detained Saif al-Din Khader, alleged to use the alias Rey, on Tuesday, according to three sources cited by Reuters. Two sources said he is helping the FBI and international law enforcement locate other group members. ShinyHunters claims to have stolen data on every FBI employee, and a Reuters analysis of a sample found personal, medical and psychiatric information.

Source: Reuters

Daily Coverage

Developments
Rejetto Hfs ExploitationDtu Data BreachWarlock Sharepoint AttacksMi5 Espionage Alert
Vulnerabilities
CVE-2026-61500Hfs 3.0.0 (Critical)