This is the security briefing for Sunday the 4th of October 2026, drawn from the BlueTeamSec community on infosec.pub. A busy one today, with eighteen stories to get through.
CISA have confirmed active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway — both allow remote code execution. Both have been added to the Known Exploited Vulnerabilities catalogue, and CISA are urging organisations to check for compromise before patching, to preserve forensic evidence.
Fortinet have disclosed a critical path traversal vulnerability in FortiMail that's being exploited in the wild. Unauthenticated attackers can write arbitrary files via crafted requests to the Identity-Based Encryption feature, leading to remote code execution. Affects versions seven-point-two through eight-point-oh-one.
OX Security disclosed a critical authentication bypass in LiteLLM, an open-source AI gateway. The flaw in the JWT authentication logic lets attackers forge tokens to hijack user accounts — including admin ones — and permanently link attacker tokens to victim accounts, giving full control over organisational AI infrastructure and upstream API credentials. Worth flagging if you're running LiteLLM versions through one-point-one-hundred-point-one.
Europol have announced the takedown of the KillSec ransomware group in an operation called KillSwitch. Three arrests, including a suspected sixteen-year-old leader, and infrastructure seized containing a hundred and ten terabytes of stolen data. The group had conducted roughly a thousand attacks since twenty twenty-four using double extortion tactics, exploiting software vulnerabilities and insecure cloud storage — with AI-assisted victim identification, apparently.
Broadcom have written up a Warlock ransomware campaign by the Longlegs threat actor targeting critical infrastructure in Portuguese and Spanish-speaking countries — water utilities and telecom providers. The attackers exploited unpatched SharePoint vulnerabilities, used a bring-your-own-vulnerable-driver technique to disable security tools, and leveraged Visual Studio Code for persistence before deploying ransomware via SYSVOL shares. This follows CISA guidance we covered a week ago on critical infrastructure operators working with third-party integrators.
In May this year, an actor calling themselves SVA-twenty-twenty-seven leaked extensive internal data from Spetsvuzavtomatika, a Russian research institute serving as an R&D arm for the SVR. The leak exposed source code and documentation for offensive cyber tools including automated exploitation platforms, lateral movement tools, and reconnaissance capabilities — revealing a fairly structured ecosystem for developing espionage and cyber warfare capabilities. We've seen related Russian infrastructure and tooling come up a few times in recent weeks.
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family used by the China-attributed threat actor Storm-three-oh-six-nine since October last year. It's used for long-term persistence in targeted operations against telecoms, universities, medical nonprofits, and government entities. Features DLL sideloading, multi-stage loading with anti-analysis techniques, and WebSocket command-and-control — all geared towards espionage operations.
A targeted spear-phishing campaign impersonated three European organisations to deliver malware to Moldovan media and civil society groups between the ninth and twenty-fifth of September. Attackers used conversation-first social engineering, sending password-protected archives containing malicious shortcuts that deployed decoy PDFs while executing hidden loaders for persistence. At least five organisations affected.
Jamf Threat Labs discovered CloudSyncD, a sophisticated two-stage macOS backdoor distributed through a fake Zoom installer. The malware uses social engineering to bypass Gatekeeper, harvests administrator credentials via local validation, and obfuscates stolen passwords with zero-width Unicode characters before establishing command-and-control connectivity for remote payload execution. One for Mac-heavy environments.
Daniel Koifman and Nikolas Bielski released ADE-Skills, an open-source knowledge base that helps security teams identify and fix false negatives in detection rules. The project defines four categories of detection-logic bugs that attackers exploit by modifying techniques to bypass narrow detection logic, and includes a catalogue of nearly six hundred bypass findings from public detection rule sets. Particularly useful if you're reviewing or tuning detections.
Researchers from Southeast University, Hong Kong Polytechnic, and Zhongguancun Laboratory introduced CyberClear, a benchmark comprising four hundred and fifty instances designed to evaluate large language model capabilities in reconstructing complete APT attack chains from long-context security logs. The study reveals that current state-of-the-art models struggle with long-context evidence reasoning and causal attack progression — generative reasoning alone isn't sufficient for accurate forensic reconstruction without ground-truth execution-based validation.
On a similar note, Zhongguancun Laboratory introduced APTInvestBench, a benchmark framework for evaluating how large language models perform autonomous APT investigation tasks under seven different telemetry conditions. The research assesses various model capabilities to analyse security telemetry data and conduct threat hunting, identifying performance variations based on available telemetry richness.
A Eurobarometer survey found seventy-five percent of EU employees encountered suspicious digital activities at work, with phishing the most prevalent threat at thirty-nine percent, followed by personal data theft and malware. The findings highlight a gap between employee awareness of cyber threat consequences — eighty-three percent — and their practical ability to identify sophisticated attacks, particularly AI-generated content, where only forty-eight percent felt confident.
Researchers from Huawei developed the Speculative Safety Honeypot, a proactive defensive framework that protects large language model agents against multi-turn adversarial attacks including indirect prompt injection and distributed jailbreaks. The system uses multi-agent simulation with diversity-oriented beam search to predict and neutralise malicious intent before harmful actions occur — achieved zero percent attack success rate in benchmarks while preserving system utility.
The National Cyber Security Centre published strategic guidance on disruptive cyber attacks targeting Critical National Infrastructure and large organisations. The guidance provides a framework focused on three defensive pillars: recovery operations including restoring minimum viable operations, preparation through planning and crisis management capabilities, and risk reduction through cybersecurity fundamentals to minimise compromise likelihood and impact.
Abstract Security examined how AI-driven automated agents and sophisticated attackers bypass CDN and cloud proxy protections by discovering exposed origin server IPs through DNS reconnaissance, subdomain enumeration, and favicon hash pivoting. Attackers directly target backend infrastructure to circumvent web application firewall rules and rate limiting, then employ anti-forensic techniques to evade detection. Adds useful context if you're relying on CDN-based protection.
And researchers at ERNW developed an attack framework that compromises autonomous AI penetration testing agents by injecting fake Identity Provider references into public content like GitHub issues and forums. The framework tricks AI agents into connecting to attacker-controlled OAuth or SAML services, enabling credential theft and persistent monitoring. This exploits the fundamental design of AI agents that consume and act upon untrusted user-generated content during reconnaissance — which is either impressive tradecraft or a sign that someone left a door open, depending on your perspective.
That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated. We'll be back with the next briefing soon.