Cyber Threat Intelligence 06 October 2026
-
Healthcare Sector
- Three Questions a Hospital CISO Should Ask a Healthcare Fintech Vendor
"In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers how Cylerity keeps PHI away from its bank partner, why AI models recommend but never act, and why turning on MFA for email is the cheapest fix for small practices. He also lists three questions a hospital CISO should ask a fintech vendor, and the answer that should end the talk."
https://www.helpnetsecurity.com/2026/10/05/drew-mccombs-cylerity-healthcare-fintech-security/
New Tooling
- Keyorix: Open-Source Secrets Management For Teams That Can’t Use SaaS
"Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code. It ships as one binary and, in its core form, needs no internet connection. Keyorix SL, the company behind it, pitches that to teams that cannot send credentials to a cloud service, such as air-gapped networks and European enterprises that need to line up with NIS2 and DORA, the EU’s security and financial-resilience rules. The company’s own comparison table sets Keyorix against two tools: Vault, which runs on premises but requires a dedicated admin, and Doppler, which is simple but SaaS-only."
https://www.helpnetsecurity.com/2026/10/05/keyorix-open-source-on-premise-secrets-management/
https://github.com/keyorixhq/keyorix
Vulnerabilities
- Horizon3’s Tales From The Trenches: Anthropic’s Mythos And Rejetto HFS
"Anthropic started Project Glasswing with the mission of securing the world’s most critical software. Since joining the project in July of 2026, Horizon3 has used Anthropic’s Mythos model in its vulnerability research pipelines to discover many critical vulnerabilities. Horizon3’s participation in the project came with our own internal mission to find vulnerabilities likely to be found and exploited in the wild by threat actors at scale. Before gaining access to Mythos, it’s hard to know what to believe when you hear about model capabilities as they’re applied to a domain that seemingly required decades of expertise to operate in. Our use of Mythos thus far has exceeded what we thought was possible without significant harness engineering."
https://horizon3.ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/ - Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
"Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026. The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access."
https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
https://www.helpnetsecurity.com/2026/10/05/exchange-server-vulnerability-cve-2026-96940/ - New Dell System Update Flaw Lets Hackers Gain Root Privileges
"Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure. In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness."
https://www.bleepingcomputer.com/news/security/new-dell-system-update-flaw-lets-hackers-gain-root-privileges/
Malware
- Rejetto HFS Servers Now Actively Scanned For Critical RCE Flaw
"Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). VulnCheck VP of Security Research Caitlin Condon posted on LinkedIn over the weekend that the company's Canary Intelligence honeypots had observed probes targeting CVE-2026-61500. Condon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States."
https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
https://securityaffairs.com/200444/ai/anthropic-mythos-found-a-bug-in-rejetto-hfs-attackers-are-now-exploiting-it.html - ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
"FortiGuard Labs has been tracking a Linux malware strain we call ClingSTUN that exploits known, unpatched vulnerabilities in Internet-facing devices to establish a persistent foothold. The campaign highlights how gaps in basic cyber hygiene, including delayed patching, unsupported firmware, and unnecessarily exposed services, can leave organizations vulnerable to compromise. Maintaining an accurate device inventory, applying security updates promptly, and limiting Internet exposure are essential to reducing these opportunities."
https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure
https://www.darkreading.com/iot/clingstun-vulnerable-iot-devices-proxy-nodes
https://www.infosecurity-magazine.com/news/clingstun-backdoor-unpatched-iot/
https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/ - A STUNning Disguise: Cling Malware Masquerades As Google
"During routine monitoring of our customer telemetry, we observed multiple attempts to exploit CVE-2021-35394 affecting internet-exposed devices. Most of the activity resembled opportunistic scanning, but a subset led to a different finding: a botnet whose command-and-control design abuses legitimate-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands and make malicious activity less obvious from a network monitoring perspective."
https://www.nozominetworks.com/blog/a-stunning-disguise-cling-malware-masquerades-as-google-
https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html - OpenAI “rogue” Agent Activities Found On Wikimedia Projects
"Recently, multiple organisations have disclosed how clusters of so-called “rogue” AI agents attempted to break into websites and online services, sometimes successfully. Agents from OpenAI’s environment, in particular, are known to have used other public wikis (collaboratively edited websites not owned by us) to communicate and coordinate with each other. These types of successful intrusions can expose sensitive data or disrupt website services that users rely on, while clusters of agents can attempt attacks at a scale that is difficult for defenders to manage. They affect people behind the websites who may not understand the nature of the attack, or have the tools to effectively fight back. For a site like Wikipedia, agents might find and use security vulnerabilities or make misleading edits at scale. Wikipedia’s volunteer editors and the Wikimedia Foundation’s security teams have to detect and undo that activity."
https://wikimediafoundation.org/news/2026/10/05/openai-rogue-agent-activities-found-on-wikimedia-projects/
https://therecord.media/wikimedia-foundation-openai-agents-report - Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace And Open VSX
"The Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present themselves as polished color themes, contain executable JavaScript despite primarily providing visual customization, and exhibit signs of brandjacking or name-squatting. Theme extensions can be particularly risky because they can contain and execute malicious code, and VS Code lacks granular permission controls to restrict what that code can do."
https://socket.dev/blog/glassworm-vscode-themes
Breaches/Hacks/Leaks
- Denmark Population Registry Data Breach Affects 8.8 Million People
"Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. This includes people who live in the country, individuals who have moved abroad, and also deceased people. The CPR is the country's national civil registry, containing personal information on residents, including names, addresses, dates of birth, marital status, and unique CPR identification numbers."
https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/
https://therecord.media/denmark-breach-register-cyberattack
https://securityaffairs.com/200437/data-breach/denmark-s-population-registry-breached-8-8-million-affected.html - South Korea Probes Bank Breaches Amid Suspected AI-Powered Attacks
"South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected other South Korean banks, including Kookmin Bank. Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets."
https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/ - Ukraine Grocery Chain ATB Confirms Cyberattack As Hackers Threaten To Leak Data
"Ukraine’s largest grocery store chain, ATB, confirmed Monday that it was hit by a cyberattack after hackers posted an extortion demand on its website. The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers. A countdown timer for the ransom demand appeared on the retailer’s website but was later removed. The website was unavailable at the time of writing. ATB denied that customer data had been compromised. The company temporarily took some online services offline for what it described as technical maintenance."
https://therecord.media/atb-ukraine-cyberattack-ransomware - University Of Illinois Chicago Affected By Ransomware Attack On Medical School
"The University of Illinois Chicago (UIC) recently discovered a ransomware attack that limited access to some systems at its College of Medicine. A spokesperson for the university told Recorded Future News the hackers were able to steal some information held on the college’s servers and an investigation is underway to determine whether “any personal, research or academic information was compromised.” “As a result of this ransomware event, some College of Medicine systems were temporarily unavailable,” the spokesperson said. “However, all affected systems have since been restored. The university's main network was not affected, and there was no impact on patient care delivery at UI Health.”"
https://therecord.media/ransomware-university-illinois-chicago - Belarusian Hacktivists Spent Two Years Inside Russian Healthcare Network, Researchers Say
"A Belarusian activist hacking group reportedly spent nearly two years inside the network of a Russian healthcare organization, potentially gaining access to sensitive medical data, according to new research. Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, said it discovered the intrusion in December 2025 but traced the earliest signs of the compromise to early 2024. In a report released last week, researchers attributed the attack to the Belarusian Cyber Partisans, a group best known for disruptive attacks against government agencies and businesses in Belarus and Russia."
https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network - Japanese Media Group Nikkei Discloses Intrusions Targeting Employees And Users
"The Japanese media giant Nikkei disclosed two cyber incidents involving employee email accounts on Sunday, joining a growing list of major Japanese companies hit by data breaches in recent weeks. In the more recent incident, an attacker compromised a Microsoft 365 account belonging to a Nikkei employee and used it to send roughly 9,000 phishing emails to people inside and outside the company, including journalistic sources. The emails sent on September 30 contained links directing recipients to malicious websites and targeted people who had previously communicated with Nikkei employees, the company said."
https://therecord.media/nikkei-cyberattack-japan-data - 250,000 Impacted By Data Breaches At New Jersey, Texas Healthcare Firms
"Healthcare organizations Clover Health Investments and AngMar Management Services are notifying more than 250,000 people that their information was stolen in separate data breaches. Jersey City, New Jersey-based Clover Health Investments was hacked in early July, after attackers used social engineering to compromise three non-managerial health plan employee accounts. The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI), the company said in an SEC filing in July."
https://www.securityweek.com/250000-impacted-by-data-breaches-at-new-jersey-texas-healthcare-firms/
General News
- Alleged Dev Of Ploutus ATM Malware Appears In US Court After Arrest
"The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. Also known as "Prometheus" and "The Engineer," 50-year-old Anibal Alexander Canelon Aguirre was the first cybercriminal added to the FBI's "Top 10 Most Wanted Fugitives" list in March 2026. According to court documents, Canelon Aguirre and his accomplices deployed Ploutus malware and emptied bank and credit union automated teller machines (ATMs) in jackpotting attacks between February 2024 and December 2025."
https://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/ - Need For Speed: AI-Driven Attacks Are Changing Security Strategies
"Concerns over AI-powered attacks are top of mind for organizations, as security teams race to keep up with threats operating at machine speed. According to the latest Dark Reading readership poll, which inquired about themes from Black Hat USA 2026, the topic that mattered most for security teams was "AI-driven attacks vs. AI-powered defenses in the SOC [security operations center]," with 50% of respondents selecting it. A distant second with 22% was "Scaling SecOps with automation, validation, and trusted AI.""
https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies - Iranian Hacker Accused Of Draining 31TB From University Inboxes Extradited To The US
"Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, picked up by Montenegro’s Police Directorate after the FBI issued a warrant. “He is accused of committing the following crimes: conspiracy to commit computer fraud and computer hacking, as well as identity theft, by conducting massive hacking attacks on the infrastructure of the United States of America since 2013, as an associate of a legal entity from the territory of Iran – at over 150 universities in the United States of America, causing damage estimated at more than 3.4 billion US dollars.” reads the press release published by Montenegro’s Police."
https://securityaffairs.com/200387/security/iranian-hacker-accused-of-draining-31tb-from-university-inboxes-extradited-to-the-us.html - FBI Confirms 'multiple' Arrests Related To ShinyHunters Hack
"The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register. “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday. The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters."
https://www.theregister.com/security/2026/10/05/fbi-confirms-multiple-arrests-related-to-shinyhunters-hack/5301178
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Three Questions a Hospital CISO Should Ask a Healthcare Fintech Vendor