Daily briefing: Thursday, October 1, 2026

Cisco revealed that attackers have exploited a critical zero-day authentication bypass in Catalyst SD-WAN Manager. International law enforcement dismantled the KillSec ransomware gang, arresting three suspects and seizing 110 terabytes of stolen data. The Pentagon is notifying over 3 million people that hackers stole their personal records from its human resources management system.

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Cisco revealed that attackers have exploited a critical authentication bypass vulnerability, tracked as CVE-2026-76504, in its Catalyst SD-WAN Manager solution. The vulnerability, which allows remote attackers to gain administrative API access without authentication, was added to CISA's Known Exploited Vulnerabilities catalog. Researchers report the login module and application server disagree about whether a request path has been URL-decoded yet.

16-year-old suspected leader of KillSec ransomware group arrested

Law enforcement agencies dismantled the KillSec ransomware gang during Operation KillSwitch, arresting three individuals including a 16-year-old suspected of being the group's main operator. Authorities seized the group's leak site and servers, securing at least 110 terabytes of stolen data. Eurojust says the group has been active since 2024 and is responsible for almost 1,000 attacks worldwide.

Kiteworks patches max severity code injection vulnerability

Kiteworks released security updates to address 126 vulnerabilities across products including Kiteworks Core and the Email Protection Gateway, which contained a maximum-severity code injection flaw. An unauthenticated remote attacker could potentially achieve arbitrary code execution by exploiting a combination of input-handling flaws in publicly reachable endpoints.

Hackers stole Pentagon personnel records of over 3 million people

The Pentagon's Defense Manpower Data Center is notifying 2.76 million living and 294,000 deceased individuals that hackers stole their personal data from its human resources system. Officials state the data was stolen during an October 2025 breach of the Pentagon's human resources management system. Exposed information includes Social Security numbers, military records, and other personal details of defense personnel and their dependents.

Google says Gemini 4 Argon can find and patch critical software flaws

Google announced Gemini 4 Argon, a frontier AI model that the company claims can locate, validate, and patch critical software flaws without human assistance. The model is being rolled out to vetted cyber defenders through the Fairwind Program, with Google planning to release a version without cyber guardrails for these teams. Google says the model successfully identified a critical vulnerability in healthcare software that exposed sensitive personal data.

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet warned that a critical path traversal vulnerability in FortiMail, tracked as CVE-2026-104286, is being actively exploited in zero-day attacks. The flaw allows attackers to execute unauthorized code or commands on vulnerable devices and has been added to CISA's Known Exploited Vulnerabilities catalog.

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

An agentic AI-powered attack exploited two critical zero-day vulnerabilities in the Zammad open-source helpdesk system to breach the Dutch Institute for Vulnerability Disclosure.

The Day-One Hole in Zero Trust Architecture

Specops reports that Zero Trust architecture faces a gap during user onboarding before strong authentication and credentials exist. John Kindervag, who coined the framework, insists the model remains effective against AI-assisted attacks if the implementation is correct.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.