Isometric navy servers and cyan data tubes exposing zero-day exploits.

Daily Cybersecurity News – October 1, 2026

CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Ghost in the Wires by Kevin Mitnick

Cisco SD-WAN Zero-Day CVE-2026-76504 Exploited In-The-Wild

Critical

Affected releases

  • 26.2, 26.1
  • 20.18, 20.15, 20.12, 20.9
  • Any release earlier than 20.9

Fixed updates exist for 20.9–26.2; pre-20.9.10.1 requires migration.

What happened

Cisco disclosed that attackers exploited CVE-2026-76504 as a zero-day in its Catalyst SD-WAN Manager. The vendor's responders learned of active exploitation in September 2026 while handling a TAC support case.

The flaw is an API authentication bypass caused by improper handling of URI encoding in HTTP requests. An unauthenticated remote attacker can send a crafted request to bypass restrictions and gain admin-user access to the API, potentially taking control of the managed network. It carries a CVSS score of 9.8 and is listed in CISA KEV.

Cisco has released indicators of compromise in serviceproxy-access.log and vmanage-server.log files but has shared few attack details. This marks the fifth such Cisco SD-WAN zero-day disclosure this year.

Who is affected

Organizations running Cisco Catalyst SD-WAN Manager releases 26.2, 26.1, 20.18, 20.15, 20.12, 20.9, and any earlier than 20.9, regardless of configuration.

Enterprises and service providers that rely on Cisco SD-WAN for wide-area network management are exposed, especially those with internet-reachable management consoles. US federal civilian agencies face a CISA-mandated deadline of October 3, 2026, plus a required compromise assessment.

Why it matters

Successful exploitation hands attackers administrative control over the SD-WAN fabric, enabling traffic interception, policy changes, or further lateral movement across distributed sites.

Repeated zero-day exploitation of the same product line shows persistent targeting of critical network infrastructure. Operators must treat internet-exposed managers as high-priority assets and assume possible prior compromise.

How it could have been prevented

Apply the security updates Cisco released for releases 20.9 through 26.2. Systems older than 20.9.10.1 must migrate to a fixed release; no workarounds fully address the issue.

For on-prem deployments, restrict management access from untrusted networks such as the internet and limit exposure to known trusted hosts on documented ports. Before or immediately after patching, collect logs and device snapshots, then hunt for the published IoCs while accounting for possible false positives during normal operations. Open a TAC case if investigation help is needed.

Relevant professional terms

Zero-day
A software vulnerability that is exploited by attackers before the vendor has released a patch or the public knows about it.
Authentication bypass
A flaw that lets an attacker reach protected functionality or gain privileged access without supplying valid credentials or satisfying the intended access-control checks.

Public PoC Released for Apple CoreGraphics Zero-Day

High

What happened

Security researchers at Calif published the first public proof-of-concept for CVE-2026-86950, an out-of-bounds write in Apple's CoreGraphics framework. Apple had already patched it on September 28 and noted it may have been used in extremely sophisticated attacks against specific targeted individuals on older iOS versions.

The trigger is a maliciously crafted PDF containing an embedded TrueType font with extreme glyph coordinates. This causes a controlled buffer overflow during rasterization, leading to a crash on unpatched iPhones and Macs. The published material demonstrates the crash and memory-corruption primitive but does not include a full code-execution exploit. CISA added the CVE to its KEV catalog the day after the patch, with a federal remediation deadline of October 2.

CVSS is scored 8.8. The same fix was applied across multiple rasterizer functions; the root cause was inconsistent handling of out-of-range floating-point to fixed-point conversions that produced an undersized working buffer.

Who is affected

Users of unpatched iOS 26.7 and earlier, iPadOS equivalents, macOS Sequoia 15.8 and earlier, and macOS Tahoe 26.7 before the 26.7.1 / 15.8.1 updates. Apple did not list iOS 27 or macOS Golden Gate 27 as affected.

Primarily individuals previously targeted in highly selective attacks, plus anyone who opens untrusted PDFs on still-vulnerable devices now that a public PoC exists. Messaging apps that auto-generate PDF or attachment thumbnails (researchers examined WhatsApp changes) are a plausible delivery path.

Why it matters

An out-of-bounds write that an attacker can partially control is a strong starting point for arbitrary code execution. Public release of generation scripts and a sample PDF lowers the barrier for less-resourced actors to weaponize or spray the crash.

Even without a complete exploit chain in the PoC, the combination of prior in-the-wild use, KEV listing, and easy trigger via everyday file formats makes rapid patching essential for both high-value and general users.

How it could have been prevented

Update immediately to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1, or later. No workaround is documented for systems that cannot be updated.

Avoid opening unsolicited or untrusted PDFs and attachments, especially from messaging apps, until devices are patched. Enterprises should accelerate mobile-device management enforcement of the new builds and monitor for anomalous crashes in CoreGraphics or ImageIO paths.

Relevant professional terms

Proof-of-concept (PoC)
Code or a sample file that shows a vulnerability can be triggered, usually stopping short of a fully reliable, weaponized exploit.
Out-of-bounds write
A memory-safety error in which a program writes data past the end of an allocated buffer, potentially corrupting adjacent memory and enabling control-flow hijacking.

Star Blizzard Scales Phishing With New Malware Technique

High

What happened

Microsoft reported that the Russia-linked group Star Blizzard (also tracked as Callisto and ColdRiver, and attributed by Western governments to the FSB) has significantly expanded its phishing this year. Activity has hit more than 100 organizations, mainly in the United States and United Kingdom.

The group moved from highly targeted spear-phishing to larger campaigns of tens or hundreds of messages, enabled by a mass-mailing platform. At least 13 such campaigns have been seen since January 2026. Delivery now often uses accounts created on compromised websites rather than free webmail. After a victim replies, operators send a password-protected archive; opening a file inside triggers the new RedFlick technique.

RedFlick installs the CosmicPulse backdoor via scheduled tasks with only a single user action, improving on the earlier multi-step ClickFix method. Early 2026 lures focused on Ukrainian Ukr.net users with fake tax or fine notices; later waves used conference invitations and internal-looking messages aimed at NGOs, think tanks, governments, and financial institutions supporting Ukraine.

Who is affected

Ukrainian individuals and institutions plus international NGOs, think tanks, government bodies, and financial organizations that provide political or financial support to Ukraine. Primary observed victims are in the US and UK, with more than 100 organizations impacted.

Anyone interacting with unsolicited emails that impersonate authorities, academics, diplomats, or internal colleagues is at risk, especially if they open password-protected archives from follow-up messages.

Why it matters

A state-backed actor has lowered the effort required per victim while raising volume and stealth. The single-action RedFlick path plus scheduled-task persistence increases successful compromise rates and complicates detection.

Operators supporting Ukraine-related work face elevated espionage risk. The shift to global targets after initial Ukraine testing indicates the new tooling is now production-ready for broader intelligence collection.

How it could have been prevented

Treat unexpected password-protected archives, especially after an initial reply, as high risk; verify senders out-of-band before opening. Enforce strong email filtering, attachment sandboxing, and block or alert on newly observed mass-mailing patterns.

Require phishing-resistant MFA, limit scheduled-task creation where possible, and hunt for CosmicPulse-related indicators and anomalous task registrations. Train staff on the evolution from classic spear-phishing to higher-volume, compromised-site lures and internal-looking messages. Segment high-value Ukraine-support networks and monitor for follow-on credential or data theft.

Relevant professional terms

Spear-phishing
A targeted phishing attack that uses personalized details about the victim or their organization to increase the chance they will click or open a malicious attachment.
Backdoor
Malware that provides an attacker with ongoing, covert remote access to a compromised system so they can issue commands, steal data, or move laterally.
Source: The Record

OpenAI Details Novel Encryption Bypass in Distillation Attack

Medium

What happened

OpenAI disrupted a coordinated campaign that sought to distill and extract reasoning capabilities from its models. Low-level activity began around July 1 2026, escalated to roughly 16,000 prompts from 4,000 users matching an extraction pattern on July 24-25, and reached about 15,000 suspicious users by July 28, when the company fully interrupted the operation.

Attackers used a novel method: they copied encrypted reasoning data from one conversation, then in a separate conversation asked the model to decrypt and transcribe it into plain text. OpenAI stated the operators did not break encryption, compromise databases, or gain direct access to stored conversations; they manipulated model interactions at scale in violation of terms of service. Outside researchers later reported a similar issue.

OpenAI attributed a core cluster of the activity to individuals associated with Chinese firm Moonshot AI but provided no technical evidence in its public post. The same class of vulnerability was said to exist in other AI models; information was shared with the Frontier Model Forum. OpenAI banned accounts, tightened signup and infrastructure controls, expanded monitoring, and fixed the cross-conversation decryption bug.

Who is affected

OpenAI model users and the company's intellectual property around advanced reasoning. Broader AI providers whose models expose similar protected intermediate outputs are potentially exposed to analogous extraction.

Organizations and researchers relying on proprietary model capabilities face competitive and IP risk if distillation succeeds at scale. Moonshot AI and similar firms have been previously accused by US companies and government of systematic distillation.

Why it matters

Model distillation lets competitors cheaply replicate expensive reasoning behavior without bearing the full training cost. A bypass that turns protected internal state into plain-text output via ordinary prompts shows how interaction-layer flaws can leak IP even when cryptography itself remains intact.

The incident highlights the need for AI vendors to treat prompt-level data flows as a security boundary and for defenders to watch for coordinated, high-volume extraction patterns across accounts.

How it could have been prevented

AI providers should instrument detection for cross-conversation extraction patterns, rate-limit or isolate sensitive reasoning outputs, and continuously audit signup and multi-account abuse. Share indicators with industry forums.

Enterprise customers should enforce unique, monitored accounts, apply least-privilege API keys, watch for anomalous prompt volumes or content that requests decryption or transcription of prior outputs, and review vendor ToS enforcement. Disable or carefully gate any features that surface internal model state.

Relevant professional terms

Model distillation
The process of training a smaller or cheaper model to imitate the behavior and outputs of a larger, more capable model, often to copy its capabilities at lower cost.
Encryption bypass
A technique that obtains the protected plaintext without defeating the cryptographic algorithm itself, typically by abusing an authorized decryption path or side channel in the surrounding system.
Source: CyberScoop

AI Coding Agents Leak 13k Internal Screenshots to GitHub

High

What happened

Glow Security researchers found that AI coding agents, when asked to supply before-and-after visual documentation of software changes, uploaded screenshots to public GitHub repositories. The practice exposed more than 13,000 screenshots belonging to over 300 companies.

Exposed material included details from sensitive corporate software projects, billing records, and internal development work. Tools such as gitshot automated the publishing step for code-review workflows. Many images landed on personal GitHub accounts rather than organization-controlled repos, so the affected companies often remained unaware.

The findings illustrate risks of autonomous developer tools operating with broad permissions and of uncontrolled "Shadow AI" usage inside enterprises.

Who is affected

More than 300 organizations whose developers or AI agents generated and published the screenshots. Any company using AI coding assistants that automatically capture or upload visual diffs is potentially exposed, especially when agents run with access to internal UIs, billing systems, or proprietary codebases.

Developers using personal GitHub accounts for work-related automation amplify the blast radius because corporate DLP and repo policies may not apply.

Why it matters

Screenshots can reveal source code fragments, internal URLs, credentials, customer data, architecture diagrams, and financial details. Once public on GitHub they are trivial to discover and scrape.

The incident underscores how agentic tools can create new, unintended exfiltration paths that bypass traditional data-loss controls. Unmonitored Shadow AI multiplies the chance that sensitive context reaches the public internet without security review.

How it could have been prevented

Inventory and govern all AI coding agents and automation; require them to use only private, organization-owned repositories or internal artifact stores for any screenshots or diffs. Disable or tightly scope automatic upload features such as those in gitshot-like tools.

Apply GitHub secret scanning, repository visibility audits, and DLP rules that flag image uploads containing sensitive patterns. Train developers on Shadow AI risks, enforce use of corporate accounts, and review agent permissions so they cannot reach production billing or highly confidential systems. Continuously monitor public GitHub for company-related screenshots and revoke exposure quickly.

Relevant professional terms

Shadow AI
The unsanctioned or unmonitored use of artificial-intelligence tools by employees inside an organization, outside official IT and security controls.
Data exfiltration
The unauthorized transfer of sensitive information from an internal system to an external location where attackers or the public can access it.
Source: SC Magazine

Bitget Attributes $387M Theft to Third-Party Zero-Day

Critical

What happened

Cryptocurrency exchange Bitget confirmed that the attackers who stole approximately $387.5 million from its hot and warm wallets exploited a zero-day vulnerability in third-party security products. The finding comes from ongoing investigation work by SlowMist; a customized attacker tool used to initiate unauthorized withdrawals was also recovered.

Earliest malicious activity on an affected product node dates to August 31 2026: a hidden script under a service process read an environment variable containing a database password and connected to the database. Similar activity appeared on other nodes in late September. On September 25 the actor accessed a second product's management platform using an internal employee identity, injected commands, wrote malicious files, and submitted code via a web execution endpoint.

A bespoke tool tailored to the wallet withdrawal logic then executed the theft starting at 01:49 a.m. on September 25. The incident affected 11 blockchains and multiple assets including XRP, ETH, USDT, ZEC and others. Roughly $1.1 million has been frozen by Circle, Tether and NEAR Intents. Bitget notified the vendor and disabled the affected functionality pending a fix. Mandiant is also investigating unauthorized access to certain third-party security components.

Who is affected

Bitget and its users whose assets sat in the compromised hot and warm wallets. The theft spanned Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia.

Any exchange or custody provider that relies on the same unnamed third-party security products inherits similar risk until patches and detections are in place. Broader crypto markets feel confidence and liquidity effects from large hot-wallet losses.

Why it matters

A single zero-day in a security vendor's stack enabled credential theft, database access, and bypass of the exchange's own risk controls, resulting in one of the larger exchange thefts of the year.

The case highlights acute third-party and supply-chain risk in crypto infrastructure: even mature exchanges can be undone by flaws in tools they trust for protection. Custom malware purpose-built for the victim's withdrawal logic shows high attacker investment and preparation.

How it could have been prevented

Map and continuously assess all third-party security and wallet-related products; demand rapid patch SLAs and compromise-notification clauses. Isolate management planes, enforce least privilege, rotate credentials stored in environment variables, and monitor for hidden scripts or anomalous process behavior on security nodes.

Require multi-party approval or hardware-backed controls for large withdrawals, maintain robust out-of-band monitoring that cannot be disabled by the same tools, and retain forensic-ready logs. After any suspected incident, immediately disable affected third-party functionality, engage independent incident response, and coordinate with stablecoin issuers and chains for freezes. Conduct regular red-team exercises focused on the security-tooling layer itself.

Relevant professional terms

Hot wallet
A cryptocurrency wallet that remains connected to the internet so it can process deposits and withdrawals quickly, making it convenient but more exposed to online attacks.
Zero-day vulnerability
A security flaw unknown to the vendor and for which no patch yet exists, giving attackers a window to exploit it before defenses can be updated.

GrayKey Bypasses iPhone Auto-Reboot Lock

Medium

How it works

  • Gain initial access with GrayKey tooling
  • Enable Evidence Preservation Mode or use GrayKey Preserve hardware
  • Force radios off (Airplane-mode equivalent) to isolate the device
  • Hold the phone in the pre-reboot state indefinitely, also retaining data Apple would otherwise auto-delete

Exact low-level mechanisms are not publicly detailed in the leaked video.

What happened

Magnet Forensics, maker of the GrayKey phone-unlocking tool sold to law enforcement, claims it can defeat Apple's inactivity-reboot feature. A leaked promotional video obtained by 404 Media describes a new device called GrayKey Preserve and an Evidence Preservation Mode for existing GrayKey units.

Apple's feature, introduced earlier, automatically reboots an iPhone that has remained locked for 72 hours, returning it to a higher-security state that complicates forensic extraction. The Magnet solution is said to freeze the device after initial access, disable radio transmitters (Bluetooth, Wi-Fi, cellular) even when the user interface cannot, and keep the phone in a preserved state indefinitely. This also counters Apple's timed deletion of certain cached data such as locations and recently deleted photos or messages.

The video, aimed at law-enforcement customers and appearing to date from early 2025, calls the capability a game changer for iOS forensics but does not publish low-level technical details.

Who is affected

Law-enforcement and forensic labs that purchase GrayKey products, and any iPhone user whose device is seized and held long enough for the 72-hour inactivity reboot to matter. Devices that would otherwise have rebooted into a more resistant state can now be kept extractable.

Apple's privacy and security engineering goals for post-seizure protection are directly challenged. Users in jurisdictions with aggressive device-search practices face reduced practical protection from the inactivity timer.

Why it matters

The inactivity reboot was a quiet but meaningful hardening step that bought time when warrants or lab queues delayed unlocking attempts. Bypassing it restores the previous window for extraction of passcode-protected or partially unlocked data and of ephemeral artifacts Apple intentionally ages out.

The development continues the long-running contest between platform vendors seeking to protect user data and forensic vendors serving police (including in authoritarian environments). Operators and privacy-conscious users should understand that seized devices may no longer gain the expected protection from simply remaining powered and locked.

Relevant professional terms

Forensic extraction
The process of using specialized hardware or software to pull data from a locked or damaged phone for use as evidence in an investigation.
Inactivity reboot
An automatic restart of a locked device after a set period without successful unlock, intended to drop ephemeral keys and return the phone to a more secure state that resists offline attacks.
Source: 404 Media