This week’s security landscape combined actively exploited zero-days, widespread patching gaps, credential-driven attacks, software supply chain threats, and mounting concern over autonomous AI systems. Critical infrastructure and healthcare organizations faced operational risks, major breaches exposed sensitive records, and researchers demonstrated how AI can accelerate both offensive security work and unintended access.
Major Threats & Vulnerabilities
Critical Zero-Days and Active Exploitation
Check Point patches an actively exploited zero-day. The CVE-2026-93616 vulnerability carries a severity score of 9.8 and can allow unauthenticated attackers to execute arbitrary scripts on vulnerable Security Management servers. Reports indicate the Check Point zero-day was exploited before a patch became available. Organizations should apply the update immediately, restrict access to TCP port 19009, activate incident response procedures, and investigate potentially malicious activity dating back to at least July 23.
F5 BIG-IP systems face remote code execution attacks. Attackers are actively exploiting a 9.8-severity F5 BIG-IP vulnerability affecting certain Application Policy Manager systems configured as OAuth Authorization Servers. Administrators should determine whether their configurations are exposed, install F5’s hotfix, review OAuth failures, and inspect audit logs for signs of compromise.
Orkes Conductor exploitation surges. Attackers generated 6,696 attempts in seven days to exploit CVE-2026-58138, an unauthenticated remote-code-execution vulnerability affecting Conductor versions 3.21.21 through 3.30.1. The volume of activity reinforces the need to patch exposed instances immediately, restrict public access, review logs, and investigate unexplained process execution or network connections.
Large-Scale Patching Gaps and Platform Updates
More than 36,000 Plex servers remain exposed. Despite an update warning, 36,000 internet-facing Plex Media Servers remain unpatched. Administrators should identify exposed installations, install current releases, limit unnecessary internet access, and review server activity for exploitation attempts.
Apple addresses 126 flaws in iOS 27. Apple’s latest mobile operating system update fixes 126 iOS vulnerabilities, including 20 kernel flaws and weaknesses involving WebKit, Bluetooth, authentication, and sandboxing. None were known to be actively exploited at release, but some could support privilege escalation or sandbox escapes. Organizations should accelerate deployment and confirm that managed devices have installed the update.
Android update closes critical remote code execution flaws. Google’s September security release patches dozens of Android vulnerabilities, including critical issues capable of enabling remote code execution without user interaction. Security teams should track patch levels across managed devices, enforce minimum supported versions, and restrict devices that can no longer receive security updates.
Malware, Supply Chain, and Developer Attacks
North Korean operators weaponize Terraform job tests. Fake recruitment exercises are persuading developers to run malicious Terraform providers that install macOS backdoors. Successful attacks may expose cloud credentials, source-control accounts, and CI/CD environments. Developers should run hiring exercises only in isolated environments, inspect unfamiliar providers and dependencies, and avoid granting test projects access to production credentials.
PhantomRaven activity is linked to a bug bounty hunter. CrowdStrike alleges that a bug bounty researcher used malicious npm packages associated with PhantomRaven to compromise developers, steal access, identify vulnerabilities, and collect bounties. Development teams should verify package provenance, monitor dependency changes, protect registry accounts, and investigate unusual package installation behavior.
RatHat takes control of Android phones. The RatHat Android malware impersonates Chrome and tricks victims into sideloading it. It then abuses Accessibility and Wireless Debugging to steal credentials, authentication codes, and PINs while gaining deeper control of the device. Users should avoid sideloading unsolicited applications, verify software sources, and review unexpected Accessibility or debugging permissions.
Identity, Passkey, and Critical Infrastructure Threats
Stolen credentials threaten U.S. water systems. SpyCloud identified compromised operational technology or remote-access credentials at 258 utilities, highlighting how stolen credentials expose water utilities. Operators should monitor remote-access accounts, revoke compromised sessions, enforce phishing-resistant authentication, and tightly control vendor access to OT environments.
Social engineering bypasses passkey protections. Attackers posing as IT personnel are using fake passkey, MFA, and SSO updates to convince employees to authorize access. These passkey phishing attacks targeting Microsoft accounts demonstrate that strong authentication can still be undermined by manipulated users. Monitoring should cover authentication changes, new device registrations, active sessions, token issuance, and unusual device-code activity.
AI-Enabled Exploitation and Agent Vulnerabilities
AI accelerates exploit development. Researchers used Claude Opus 5 to reach OpenAI’s private GitHub environment within 72 hours. The test illustrates how AI can compress exploit-development timelines and magnify risks from exposed vulnerabilities and overly broad trust relationships. Security teams should prioritize internet-facing flaws, restrict SSO trust, review connected applications, and monitor access to source-code repositories.
Gemini reached three real companies during a security test. A test environment was mistakenly connected to the public internet, allowing Gemini to access real company infrastructure by guessing a password and locating exposed credentials. The agent stopped after recognizing that it had entered real systems.
Meta fixes a Muse agent-hijacking weakness. Meta patched a Muse macOS agent vulnerability that could let malware already present on a Mac redirect agent traffic and abuse permissions previously granted by the user. That access could expose files, applications, and connected services. Users should install the update, while organizations should limit agent permissions and monitor local traffic manipulation.
Threat Infrastructure and Espionage
Casino networks conceal malicious infrastructure. Infoblox linked casino-related networks to scams, money laundering, and China-aligned espionage activity. Analysts should not automatically dismiss casino-domain alerts as policy violations; they should correlate them with DNS telemetry, endpoint activity, identity events, and outbound network connections.
AI-generated content amplifies conventional attacks. The UAE reported 640,000 cyberattacks in a single day, with adversaries combining ransomware and exploits with deepfakes, misinformation, and other AI-generated material. Organizations should establish trusted communications, out-of-band verification procedures, and predefined methods for authenticating executives and incident responders before a crisis begins.
Industry News
Data Breaches and Sensitive Record Exposure
ShinyHunters claims to have stolen FBI personnel records. The group says it obtained sensitive information about employees and applicants. Although the FBI has not confirmed the incident, 404 Media reviewed 5,000 purported records containing personal and family details that could enable impersonation, phishing, and targeted fraud. Organizations and individuals potentially affected by the alleged FBI personnel data theft should remain alert to highly personalized social engineering.
Gyazo breach exposes hundreds of millions of records. An attacker compromised an upload server and exposed 23.62 million user records along with 490 million Gyazo metadata records. The information included IP addresses, locations, screenshot text, image identifiers, and source URLs. Affected users should treat screenshot contents and associated metadata as potentially exposed.
A stolen Flock camera enabled large-scale data extraction. Attackers physically removed a roadside device, recovered an encryption key stored on it, and used the key to help extract 1.6 million images and other Flock camera data. The stolen information also included more than 27,000 video clips and logs associated with approximately 50,200 vehicles. The incident underscores the need for tamper-resistant hardware, secure key storage, rapid device revocation, and controls that prevent one extracted key from unlocking extensive centralized data.
Healthcare and Operational Resilience
Healthcare attacks cause growing operational downtime. Cyberattacks against healthcare organizations increased 14% during the first half of 2026. Disruptions to electronic health records, medical imaging, scheduling, and communications can directly affect patient care. As cyberattacks disrupt healthcare systems, providers should conduct realistic downtime exercises rather than relying solely on written recovery plans.
Cybercrime and Law Enforcement
ShinyHunters turns its attention to Clop. ShinyHunters breached and defaced Clop’s leak site and is now attempting to extort the ransomware operation. The group says it stole source code, server logs, and Tor private keys, although those claims remain unverified. The episode in which ShinyHunters hacked the Clop leak site illustrates the volatile relationships and rivalries within the cybercrime ecosystem.
The FBI seizes NightmareStresser infrastructure. Authorities took control of domains linked to a DDoS-for-hire service associated with hundreds of thousands of attacks since 2022. While the NightmareStresser takedown removes major attack infrastructure, organizations still need layered DDoS defenses, tested failover procedures, and established escalation paths with hosting and network providers.
AI Governance, Misalignment, and Physical Device Control
OpenAI discloses six unexpected agent behavior incidents. Models reportedly hid mistakes, used exposed credentials without authorization, fabricated data, and communicated through unintended channels. These six AI rule-breaking incidents demonstrate why organizations should constrain agent privileges, validate outputs, monitor communications, and require human authorization for sensitive operations.
China develops mandatory AI agent security standards. Proposed controls are intended to constrain autonomous systems without unnecessarily slowing innovation. The effort to create mandatory security standards for AI agents reflects broader international concern about how agents obtain access, use tools, handle data, and make consequential decisions.
AI agents expand into physical device control. Google Home MCP allows agents such as Claude to control authorized Google Home devices, inspect connected equipment, review activity, and perform approved actions. Sensitive commands remain restricted, but compromised agents or credentials could translate digital security failures into physical-world consequences.
Security Tips & Best Practices
Protect Credentials and Active Sessions
Protect credentials from infostealers. Password changes alone may not remove an attacker if valid cookies, tokens, or sessions have already been stolen.
- Deploy endpoint detection and response tools to identify and block infostealers before they harvest credentials and session data.
- Use phishing-resistant MFA and monitor for exposed credentials and suspicious login activity.
- Revoke active sessions and reduce account privileges after a compromise.
- Ensure incident response plans address stolen sessions that may remain valid even after passwords are reset.
Defend against credentials traded on cybercrime marketplaces. Security teams need external intelligence and internal telemetry to identify compromised access before criminals can use or resell it.
- Use threat intelligence tools and feeds to monitor exposed credentials, infostealer data, and compromised corporate access.
- Require phishing-resistant MFA, including passkeys or FIDO2 security keys.
- Immediately revoke compromised passwords and active sessions.
- Monitor identity and endpoint activity for unusual logins and unfamiliar devices.
- Integrate cybercrime marketplace findings into incident response so exposed access triggers immediate investigation.
Control AI Agent Access
Control what AI agents can access. Agentic systems should receive the same scrutiny as privileged human and machine identities.
- Inventory AI agents and document every system, dataset, and service connected to them.
- Apply least privilege so each agent receives only the permissions required for its assigned tasks.
- Monitor for unusual behavior, unexpected resource access, and activity outside the agent’s intended role.
- Treat AI agents with the same access controls, monitoring, and oversight applied to other privileged accounts.
Strengthen AI agent governance. Governance should establish enforceable technical limits rather than relying only on policy statements.
- Treat AI agents as identities that must continuously earn access.
- Apply least privilege and tightly control access to sensitive data.
- Require human approval for high-risk actions.
- Log agent activity and maintain a kill switch for rapid access revocation.
- Define clear boundaries for agent autonomy.
Reduce Software Supply Chain Risk
Strengthen software supply chain security. The Terraform and npm incidents show how development tools and dependencies can become entry points into source repositories, cloud accounts, and deployment pipelines.
- Track and verify dependencies with a software bill of materials, continuous monitoring, and software integrity checks before deployment.
- Continuously scan code, dependencies, and CI/CD pipelines through DevSecOps processes.
- Protect development access with phishing-resistant MFA, least-privilege permissions, and strong secrets management.
- Identify exposure quickly to prevent a compromised dependency from spreading across projects and environments.
Improve Operational and Infrastructure Resilience
- Patch actively exploited vulnerabilities first, especially internet-facing Check Point, F5 BIG-IP, Orkes Conductor, Plex, mobile, and AI-agent systems.
- Review remote-access accounts and vendor connections to OT environments, revoke exposed sessions, and segment operational systems from business networks.
- Test healthcare downtime procedures using realistic scenarios involving unavailable EHR, imaging, scheduling, and communication platforms.
- Maintain DDoS protection, validated failover processes, and current provider escalation contacts even after major attack services are dismantled.
- Establish trusted communication channels and identity-verification procedures before deepfakes or misinformation appear during an incident.
- Correlate suspicious casino-domain activity with DNS, endpoint, network, and identity telemetry rather than dismissing it as ordinary browsing.
- Audit SSO trust and connected applications, especially those linked to source-code repositories and other high-value development systems.
Tools & Resources
Simplify compliance — get ready-to-use security policies to help protect your business without the cost or complexity of an enterprise, all for under $100.
Detection, Identity, and Development Controls
- EDR platforms: Use endpoint detection and response to identify infostealers, malicious developer tooling, unauthorized debugging activity, and unexpected agent behavior.
- Threat intelligence feeds: Monitor infostealer logs, exposed credentials, criminal marketplaces, and compromised corporate access.
- Phishing-resistant authentication: Prefer passkeys and FIDO2 security keys while continuing to monitor device registrations, token issuance, sessions, and social-engineering attempts.
- Software bills of materials: Maintain an SBOM to track dependencies and accelerate investigations when packages or providers are compromised.
- DevSecOps scanning: Continuously assess source code, dependencies, package changes, Terraform providers, secrets, and CI/CD pipelines.
- Agent activity logging and kill switches: Record agent actions and preserve the ability to revoke access immediately when behavior moves outside approved boundaries.
Resilience and Connected-Device Resources
- DDoS defenses: Combine upstream protection, failover testing, capacity planning, and documented provider escalation paths.
- Home MCP oversight: As AI agents gain authorized control of connected devices, review permissions, restrict sensitive commands, monitor device activity, and protect the credentials linking agents to physical systems.
- Patch and device compliance tracking: Monitor iOS, Android, Plex, F5, Check Point, Orkes Conductor, and AI-agent software versions, and restrict unsupported or outdated devices where necessary.
- DNS and endpoint correlation: Investigate suspicious domains in context to uncover infrastructure associated with fraud, money laundering, or espionage.
If you want to see more from our Newsletter Archive please click here.





