Summary: The Defense Manpower Data Center is notifying military personnel that a small number of unauthorized users had access to sensitive data between October 2025 and July 2026 after exploiting a vulnerability in its file-sharing systems. Stolen fields vary by person and include Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information. Pentagon officials told Federal News Network the breach affects more than 3 million people, including nearly 2.8 million living individuals and 294,000 deceased individuals. DMDC said it started privacy and cybersecurity incident response after discovery and is offering 12 months of IDX credit monitoring, with enrollment required by August 19, 2027.
Key takeaway / Actionable note: Recipients should enroll in the offered monitoring and treat unsolicited calls or messages that cite DMDC, SSNs, or military records as suspect.
Summary: Cisco released fixes for CVE-2026-76504 after its PSIRT became aware in September 2026 of active exploitation. The flaw is improper handling of URI encoding in an HTTP request, which lets an unauthenticated remote attacker bypass an authentication rule and reach a specific API endpoint as the admin user. It affects all deployments regardless of configuration. Cisco said attackers are using %6a as the URI-encoded character “j,” and pointed investigators to serviceproxy-access.log and vmanage-server.log for j_security_check entries from unknown addresses. CISA added the CVE to the Known Exploited Vulnerabilities catalog and ordered federal agencies to secure systems by Saturday, October 3. Fixed trains include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.
Key takeaway / Actionable note: Upgrade Catalyst SD-WAN Manager to a fixed release and review the log paths Cisco named for encoded j_security_check hits.
Summary: Bitget said SlowMist and Mandiant found attackers reached its wallet environment after compromising two security appliances with zero-day exploits. Mandiant said that on September 24, 2026, a threat actor gained unauthorized privileged access to appliances A and B, deployed a web shell on appliance B, then moved to the production wallet job server and deployed malicious packages.
SlowMist said the earliest malicious activity in available logs dates to August 31, when a service on one node of Product A was hit by a zero-day and a hidden script read a database password.
The theft after midnight on September 25 used a custom withdrawal tool and spanned nearly three hours across multiple chains. CEO Gracy Chen attributed the attack to North Korean hackers based on IP behavior and on-chain analysis. The vendor names of the appliances were not disclosed.
Key takeaway / Actionable note: Treat security appliances as tier-zero assets: patch, segment management interfaces, and hunt for unexpected web shells on the devices themselves.
Summary: LevelBlue’s Threat Hunt Operations & Research team analyzed exploitation of CVE-2026-88771, a pre-authentication command-injection flaw (CVSS 9.5) in Citrix NetScaler ADC and NetScaler Gateway, across multiple customer environments. Authentication events contained attacker-controlled usernames with variations of the pitboss and NSPPE strings.
Observed commands fetched payloads, staged configuration data, and in one case ran a Python reverse shell. A Perl payload modified /flash/nsconfig/ns.conf to create a local account named sec_monitor with the superuser role, archived /flash/nsconfig, and deployed a PHP web shell mapped to URLs resembling legitimate NetScaler CSS resources. The disclosure follows Mandiant and Google Threat Intelligence Group reporting that CVE-2026-88772 was used to deliver the WHIPSHOT web shell and the SLAPSHOT Python tunneler.
Key takeaway / Actionable note: Patch both NetScaler CVEs, then hunt for sec_monitor, CSS-like PHP paths under LogonPoint, and unexpected config archives.
Summary: MetaMask disclosed an ongoing infrastructure security incident and said there is no immediate threat to MetaMask wallets. As a precaution it is exiting affected validators in its non-custodial staking operations and said it does not manage withdrawal keys for stake on behalf of clients.
Lido Finance said MetaMask Staking has begun exiting Ethereum validators in the Lido protocol, with final validators expected to be exited, but not fully withdrawn, by the end of October 7, 2026, and that the steps may incur foregone rewards and possible downtime penalties. A spokesperson redirected reporters to the public statement when asked what was accessed.
Key takeaway / Actionable note: Staking clients should follow MetaMask and Lido notices; wallet users were told there is no immediate threat to wallets.
Summary: CISA published ICS advisory ICSA-26-272-06 on CVE-2026-84411, a pre-authentication integer underflow in RouterOS web-management HTTP request-body handling. A single crafted request can produce code execution as root or a denial of service.
CISA said it has no knowledge of active exploitation. The advisory says versions below 7.24 are affected, while also saying the vendor recommends updating to 7.23 or later; the latest stable release cited is 7.24.4 and the latest long-term release is 7.23.7. MikroTik had not published its own advisory at the time of the report.
Key takeaway / Actionable note: Keep RouterOS web management off the internet and move to a current stable or long-term release while the version guidance is clarified.
Summary: The Dutch Institute for Vulnerability Disclosure said its network breach was possible by chaining CVE-2026-102489 and CVE-2026-102490 in the open-source Zammad ticketing system. Used together, the flaws allowed session hijacking, remote code execution, and escalation from the Zammad user to root, in seconds because of the agentic component.
The attacker accessed other services and read and exfiltrated data; segmentation and incident response stopped deeper movement. DIVD, working with Merlon Security, recommends upgrading to Zammad version 7, which it considers safe, or taking the instance offline.
Key takeaway / Actionable note: Self-hosted Zammad operators should upgrade to version 7 or isolate the instance, then review tickets and shell history for unexpected root activity.
Summary: Microsoft said the Russian state actor Star Blizzard is using a delivery method it calls RedFlick to deploy the CosmicPulse backdoor. Phishing is followed by a password-protected ZIP or RAR that holds a VHDX with an LNK disguised as a PDF; opening it runs a hidden command and shows a decoy PDF. An MSI creates three scheduled tasks that beacon, prepare WebDAV, and run a Control Panel applet downloader (NOROBOT and BAITSWITCH) for CosmicPulse.
Since the start of the year Microsoft has seen at least 13 large-scale phishing campaigns hitting more than 100 organizations, mainly in the United States and the United Kingdom. RedFlick campaigns have targeted Ukrainian individuals and institutions and international NGOs, think tanks, governments, and financial institutions that have supported Ukraine.
Key takeaway / Actionable note: Block or detonate VHDX and LNK attachments, and alert staff that a single opened shortcut is enough to start this chain.
Summary: Microsoft Security Research said attackers weaponized CVE-2026-73570, an unauthenticated OS command injection (CVSS 8.9) in Zimbra Collaboration Suite when SNMP notifications are enabled and the optional zimbra-snmp package is installed. A crafted SMTP request can trigger it.
Zimbra patched it in July 2026 with version 10.1.20. Observed follow-on activity included JSP web shells, reverse shells, privilege escalation, the Zimclient2 remote-access agent, collection of authentication secrets such as zimbraPreAuthKey and zimbraAuthTokenKey, and mailbox archive staging. Activity was identified between the July 20 fix and the August 13 public disclosure, across more than one region and industry.
Key takeaway / Actionable note: Confirm ZCS is on 10.1.20 or later, and if SNMP was enabled during the exposure window, hunt web shells and rotate Zimbra authentication secrets.
Also noted
Bottom line
Edge appliances and identity-adjacent systems are still the day’s real exposure: an unauthenticated admin path on Cisco SD-WAN Manager, live NetScaler shells, and a pre-auth MikroTik root bug.
The Pentagon notice shows file-share flaws can sit open for months before letters go out, and Bitget’s write-up is a reminder that the security stack itself can be the entry point. Patch the named CVEs, then check for the accounts, shells, and log strings the vendors already published.

