This is the security briefing for Friday the 9th of October 2026, drawn from the BlueTeamSec community on infosec.pub. A busy one today, with fourteen stories to get through.
Trend Micro have written up Earth Sirrush, a Russia-aligned espionage group that's been targeting Ukrainian government and defence organisations since 2022. They've developed over ten malware families and may be providing initial access for Sandworm, the Russian military intelligence unit known for destructive operations. One for anyone tracking Eastern European threats.
JPCERT have issued a warning about a surge in unauthorised access incidents hitting Japanese organisations since September. Attackers are exfiltrating data rather than deploying ransomware, exploiting vulnerabilities in business intelligence tools and employee management systems through SQL injection and API misuse. Worth flagging if you're running internet-exposed internal systems.
Google's Threat Intelligence Group have released their analysis of vulnerability and exploitation trends in the AI era. Monthly vulnerability disclosures have doubled to over ten thousand, and exploitation rates are up as well, primarily through rapid weaponisation of recently patched bugs. AI gateways and agent orchestration frameworks are the prime targets, with half of AI-discovered vulnerabilities leading to remote code execution.
And another exploitation story — eSentire have documented active exploitation of a Citrix NetScaler zero-day by multiple threat actor clusters. Each cluster has distinct technical indicators and tradecraft, suggesting independent discovery or shared intelligence. We've covered NetScaler compromise tooling a few times recently, so this one adds useful context if you're tracking that attack surface.
Searchlight Cyber disclosed two critical vulnerabilities in the Discourse forum platform back in June. One allowed cache poisoning leading to stored cross-site scripting with content security policy bypass, the other enabled arbitrary file read via a race condition in the image upload pipeline using a JPEG bomb and ImageMagick exploitation. Both have been patched.
ProjectDiscovery demonstrated a supply chain attack vector affecting open-source AI models, where backdoors can be injected through minimal fine-tuning on poisoned data. The backdoored models perform normally on benchmarks but execute remote payloads when triggered, with abliterated models on platforms like Hugging Face particularly at risk. Standard scanners won't catch this, which is the worrying bit.
Zenity documented a new attack class they're calling autonomous agent abuse. Rogue AI agent swarms exploited public URL scanning infrastructure to bypass browser-based security controls and extract data from Russian government websites, hijacking sandbox environments to perform multi-step evasion strategies. One to watch if you're running agent-based workflows.
Tellter published an incident report for their Double Counter service after a multi-stage breach on the 4th of October. An attacker exploited a Metabase vulnerability on legacy infrastructure to steal credentials and compromise cloud resources, exposing twenty-eight million Discord user IDs, IP addresses, and email addresses, along with bot compromise and unauthorised charges. The charges were refunded, for what that's worth.
Google have written up their response to recent country-code top-level domain registry hijacks. Attackers compromised third-party registries for dot-GH, dot-SL, and dot-AS, manipulating authoritative DNS records to obtain unauthorised HTTPS certificates for domains belonging to Google and other organisations. Google caught it via Certificate Transparency logs and pushed mitigations through CRLSets, but they're clear that browser-side fixes aren't enough — organisations should be monitoring CT logs proactively.
On the defence side, Google's Project Zero have published an analysis of the critical gap between vulnerability discovery and patch deployment, particularly now that large language models are accelerating exploitation timelines. They detail rapid response mechanisms including feature flags, filtering, alternate update channels, and hotpatching to mitigate actively exploited bugs before traditional patches land.
And the CHERI Alliance are advocating for a hardware-based memory safety architecture that uses cryptographically protected capabilities to enforce bounds and permissions at the processor level. The pitch is to fundamentally prevent memory-safety vulnerabilities in C and C++ code rather than relying on patching after the fact. Targets infrastructure, IoT, and embedded systems — anyone dealing with memory-unsafe code, really.
Tal Be'ery has written an analysis arguing that AI-driven automation has created a surge in vulnerability discovery and weaponisation, but hasn't led to a corresponding increase in successful breaches. The bottleneck isn't initial access, which has become commoditised, but the labour-intensive and risky monetisation and money laundering stages that follow. Economic and operational constraints remain the primary barrier, not technical defences.
A couple of tools flagged today. Radka Warnecke has released stackd, a local AWS emulator with Go control planes and AWS-compatible HTTP APIs, designed for development purposes with optional SQLite persistence and real runtime backends for compute and database workflows.
And Lab52 conducted an experiment called Cyber Morocco, using Claude Sonnet to automate the intelligence cycle for geopolitical and cyber intelligence analysis. They successfully automated OSINT acquisition, translation, processing, and synthesis to produce structured intelligence reports on Morocco's cyber capabilities and strategic relationship with Spain. Interesting proof of concept for automating the intelligence workflow.
That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated.