Daily briefing: Thursday, October 1, 2026
Cisco revealed that attackers have exploited a critical zero-day authentication bypass in Catalyst SD-WAN Manager. International law enforcement dismantled the KillSec ransomware gang, arresting three suspects and seizing 110 terabytes of stolen data. The Pentagon is notifying over 3 million people that hackers stole their personal records from its human resources management system.
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco revealed that attackers have exploited a critical authentication bypass vulnerability, tracked as CVE-2026-76504, in its Catalyst SD-WAN Manager solution. The vulnerability, which allows remote attackers to gain administrative API access without authentication, was added to CISA's Known Exploited Vulnerabilities catalog. Researchers report the login module and application server disagree about whether a request path has been URL-decoded yet.
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability SecurityWeek
- New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504) Help Net Security
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV The Hacker News
- Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) VulnCheck Blog
- Vulnerability in Cisco Catalyst SD-WAN CERT-FR
- Cisco security advisory (AV26-978) Canadian Centre for Cyber Security
16-year-old suspected leader of KillSec ransomware group arrested
Law enforcement agencies dismantled the KillSec ransomware gang during Operation KillSwitch, arresting three individuals including a 16-year-old suspected of being the group's main operator. Authorities seized the group's leak site and servers, securing at least 110 terabytes of stolen data. Eurojust says the group has been active since 2024 and is responsible for almost 1,000 attacks worldwide.
- 16-year-old suspected leader of KillSec ransomware group arrested Help Net Security
- Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader SecurityWeek
- Police dismantle KillSec ransomware gang allegedly led by 16-year-old BleepingComputer
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers The Hacker News
- Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members CyberScoop
- Alleged KillSec Ransomware Mastermind a 16-Year-Old Dark Reading
Kiteworks patches max severity code injection vulnerability
Kiteworks released security updates to address 126 vulnerabilities across products including Kiteworks Core and the Email Protection Gateway, which contained a maximum-severity code injection flaw. An unauthenticated remote attacker could potentially achieve arbitrary code execution by exploiting a combination of input-handling flaws in publicly reachable endpoints.
- Kiteworks patches max severity code injection vulnerability BleepingComputer
- Kiteworks security advisory (AV26-988) Canadian Centre for Cyber Security
- A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution CIS MS-ISAC
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon's Defense Manpower Data Center is notifying 2.76 million living and 294,000 deceased individuals that hackers stole their personal data from its human resources system. Officials state the data was stolen during an October 2025 breach of the Pentagon's human resources management system. Exposed information includes Social Security numbers, military records, and other personal details of defense personnel and their dependents.
- Hackers stole Pentagon personnel records of over 3 million people BleepingComputer
- Pentagon breach exposes personal data of more than 3 million people Help Net Security
- Pentagon breach exposes Social Security numbers and military records of millions Malwarebytes Labs
Google says Gemini 4 Argon can find and patch critical software flaws
Google announced Gemini 4 Argon, a frontier AI model that the company claims can locate, validate, and patch critical software flaws without human assistance. The model is being rolled out to vetted cyber defenders through the Fairwind Program, with Google planning to release a version without cyber guardrails for these teams. Google says the model successfully identified a critical vulnerability in healthcare software that exposed sensitive personal data.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet warned that a critical path traversal vulnerability in FortiMail, tracked as CVE-2026-104286, is being actively exploited in zero-day attacks. The flaw allows attackers to execute unauthorized code or commands on vulnerable devices and has been added to CISA's Known Exploited Vulnerabilities catalog.
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
An agentic AI-powered attack exploited two critical zero-day vulnerabilities in the Zammad open-source helpdesk system to breach the Dutch Institute for Vulnerability Disclosure.
The Day-One Hole in Zero Trust Architecture
Specops reports that Zero Trust architecture faces a gap during user onboarding before strong authentication and credentials exist. John Kindervag, who coined the framework, insists the model remains effective against AI-assisted attacks if the implementation is correct.
- The Day-One Hole in Zero Trust Architecture BleepingComputer
- Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks SecurityWeek
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.