Floating servers exposing cybersecurity threats in navy-blue isometric diorama.

Daily Cybersecurity News – October 4, 2026

CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Ghost in the Wires by Kevin Mitnick

GitLab AI Gateway critical flaw enables command execution

Critical

What happened

GitLab warned of a critical vulnerability in its AI Gateway that lets authenticated attackers execute arbitrary commands on affected self-hosted instances.

Tracked as CVE-2026-90970 with a CVSS score of 9.9, the flaw stems from improper neutralization. Attackers with basic privileges and Duo Agent Platform access can escape the prompt template sandbox.

GitLab released patches in versions 19.2.4, 19.3.2, and 19.4.1. Cloud-hosted AI Gateway customers are already protected. The issue is not listed in CISA KEV and carries a low EPSS score.

Who is affected

Self-hosted GitLab AI Gateway deployments running versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.

Any organization using the Duo Agent Platform on unpatched self-hosted instances. GitLab is widely deployed across major corporations.

Why it matters

Successful exploitation yields command execution on the AI Gateway host, potentially enabling full system compromise, data theft, or lateral movement.

AI gateways sit at a sensitive intersection of code, data, and automation. A breakout from the sandbox undermines trust in AI-assisted development pipelines used by large enterprises.

How it could have been prevented

Immediately upgrade self-hosted AI Gateway instances to 19.2.4, 19.3.2, or 19.4.1.

Restrict Duo Agent Platform access to least-privilege accounts, monitor for unusual command activity from the gateway, and confirm cloud-hosted customers remain on the protected service.

Relevant professional terms

Remote code execution
A flaw that lets an attacker run their own commands or programs on a target system as if they were a legitimate user.
Prompt template sandbox
An isolation boundary meant to confine AI prompt processing so untrusted input cannot break out and affect the underlying host or other systems.
Source: SC Magazine

Warlock exploits SharePoint flaws to deploy ransomware

High

What happened

The suspected China-linked group tracked as Warlock (also Gold Salem, Longlegs, Storm-2603) continues weaponizing Microsoft SharePoint vulnerabilities to breach organizations and deploy ransomware.

Symantec and Carbon Black observed recent attacks against critical infrastructure, government, and education targets in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. After initial access the actors drop web shells, steal ASP.NET machine keys to forge signed payloads for RCE, use DLL sideloading, living-off-the-land tools, and BYOVD with the vulnerable K7RKScan.sys driver (CVE-2025-1055).

They stage ransomware via the domain SYSVOL share for rapid spread and have disabled security tools on dozens of hosts in single intrusions. The group previously exploited ToolShell SharePoint flaws and other vectors.

Who is affected

On-premises Microsoft SharePoint Server deployments, especially unpatched ones, in critical infrastructure (water, telecom), government, and education sectors.

Organizations in Portuguese- and Spanish-speaking regions. Victims have included at least four entities in the past two months, with rapid multi-host ransomware deployment observed.

Why it matters

SharePoint often holds sensitive internal data and sits deep in enterprise networks. Successful exploitation quickly escalates to domain-wide ransomware, security tool disablement, and operational disruption for utilities and governments.

The combination of web shells, key theft, BYOVD, and SYSVOL staging shows a mature, high-impact playbook that defenders must detect early.

How it could have been prevented

Apply all available SharePoint security updates promptly and harden on-premises instances. Monitor for web shells, unusual ASP.NET machine key access, SYSVOL modifications, and known vulnerable drivers like K7RKScan.sys.

Restrict outbound connections, enforce least privilege, deploy application allow-listing, and hunt for living-off-the-land and DLL sideloading activity. Segment critical infrastructure networks.

Relevant professional terms

Ransomware
Malicious software that encrypts files or systems and demands payment before restoring access.
BYOVD
Bring Your Own Vulnerable Driver: a technique where attackers load a legitimately signed but flawed driver to gain kernel-level privileges and disable security tools.

JavaScript obfuscation bypasses Manus AI agent protections

Medium

How it works

  1. Attacker places a malicious prompt inside an email or other untrusted content.
  2. The payload is heavily obfuscated with JSFuck so initial inspection misses it.
  3. The AI agent decodes the JavaScript and executes it in its server environment.
  4. This bypasses prompt guards and allows arbitrary code execution before later controls engage.

What happened

Security researchers at Salt Labs bypassed prompt-injection protections in the Manus AI agent and achieved code execution using JavaScript obfuscation.

They embedded a hidden prompt inside an email that Manus initially flagged. By encoding the payload with JSFuck, an extreme JavaScript obfuscation style, the agent decoded and ran arbitrary JavaScript in its server-side environment before full security checks completed.

The specific issue was patched by Meta via its bug bounty program. The case shows prompt inspection alone is insufficient when agents hold broad tool and API access.

Who is affected

Organizations and developers deploying AI agents similar to Manus that process untrusted content (such as email) and can execute code or call external services.

Enterprises granting agents wide permissions to third-party tools, APIs, or internal systems.

Why it matters

AI agents with tool access create a new attack surface where creative encoding can turn untrusted input into executable actions, violating security boundaries.

Builders must assume prompt filters will be bypassed and design controls around the actions the agent is allowed to take, not only the text it reads.

Relevant professional terms

Prompt injection
An attack that tricks an AI system into ignoring its original instructions by embedding malicious directives inside user-supplied content.
JSFuck
An esoteric JavaScript encoding that uses only six characters to represent any code, making payloads hard for simple filters to recognize.
Source: SC Magazine

Linux malware mimics Korean Taiwanese edge appliances

High

What happened

Researchers have identified sophisticated Linux implants that closely mimic Korean and Taiwanese network edge appliances to evade detection.

One campaign uses new variants of the BPFdoor backdoor and Rekoobe RAT that impersonate South Korean anti-spam software SpamSniper and blend in as legitimate background processes. A second campaign deploys the novel AVERAT tool against Taiwanese ShareTech Information mail security appliances.

Both families abuse TCP port 25 (SMTP) for command-and-control so traffic mixes with normal email flows. The implants copy filenames, allowed firewall traffic patterns, and operational habits of the real devices.

Who is affected

Organizations running or adjacent to South Korean SpamSniper anti-spam systems and Taiwanese ShareTech mail security appliances, especially secure email gateways at the network edge.

Any environment where Linux-based email security devices sit in privileged positions with limited endpoint visibility.

Why it matters

Secure email gateways are high-value targets because they handle sensitive mail and sit at the perimeter with few monitoring options. Mimicry plus SMTP C2 makes the malware extremely hard to baseline or detect.

Closed appliances limit traditional EDR, so a successful implant can persist and exfiltrate or pivot with little noise.

How it could have been prevented

Inventory and tightly control network edge Linux appliances. Monitor SMTP traffic for anomalous C2 patterns even on port 25, enforce strict egress filtering, and apply vendor firmware updates.

Deploy network detection that baselines appliance behavior, restrict management access, and hunt for unexpected processes or filenames that match known legitimate appliance binaries.

Relevant professional terms

Backdoor
Malware that gives an attacker persistent remote access to a system while trying to stay hidden.
Living-off-the-land C2
Command-and-control that blends with legitimate protocols and services already allowed on the network, such as standard SMTP on port 25, to avoid standing out.
Source: SC Magazine

Fortra patches critical BoKS authentication and execution bugs

Critical

What happened

Fortra released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), three of them critical.

CVE-2026-79901 (CVSS 9.9) allows authentication bypass in deployments using BoKS keytab for Active Directory service accounts because passwords are generated from a predictable sequence seeded by the Unix timestamp. CVE-2026-79898 (CVSS 9.1) is a command injection in crlserver that lets an authenticated user run shell commands as root on the BoKS Master via BCC or WSI APIs. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in autoregistration that can cause memory corruption from a remote attacker.

Five additional high- and medium-severity issues involving buffer overflows, out-of-bounds reads, insecure temp files, and predictable passwords were also fixed. No active exploitation is noted in CISA KEV.

Who is affected

Organizations using Fortra BoKS for centralized privileged access management on Unix and Linux fleets, especially those relying on BoKS keytab for AD service accounts or exposing BCC/WSI/autoregistration services.

Any environment where BoKS Master or related components are reachable by authenticated or network attackers.

Why it matters

BoKS controls privileged access across large Unix/Linux estates. Authentication bypass or root command execution on the Master can give attackers the keys to the entire managed fleet.

Predictable password generation and remote memory corruption raise the risk of rapid privilege escalation and domain-wide compromise in enterprises that depend on the product for policy enforcement.

How it could have been prevented

Apply the Fortra patches for all eight issues without delay. Review and rotate any AD service account passwords managed by BoKS keytab.

Restrict network access to BCC, WSI APIs, crlserver, and autoregistration services, enforce strong authentication, and monitor for unusual ticket requests or command activity on the BoKS Master.

Relevant professional terms

Authentication bypass
A vulnerability that lets an attacker gain access or privileges without providing valid credentials.
Kerberos service principal
A unique identity for a service in a Kerberos realm that is used when requesting and validating service tickets for authentication.
Source: SecurityWeek

Attackers hijack Microsoft X account for crypto pump-and-dump

Medium

What happened

Unknown attackers compromised the official Microsoft account on X (formerly Twitter) and used it to promote a cryptocurrency token in a pump-and-dump scheme.

The account, which has more than 13 million followers, began following and reposting an impersonator before pushing the $Clippy token that claimed a liquidity pool paired with $MSFT. Microsoft confirmed the unauthorized access, secured the account, removed the posts, stated it does not endorse any cryptocurrency, and said it will pursue legal action.

This follows earlier hijacks of Microsoft regional accounts and other high-profile X accounts used for similar crypto scams.

Who is affected

Followers of the official Microsoft X account and anyone who interacted with or purchased the promoted $Clippy token.

Broader users of X who trust verified brand accounts for announcements, plus the cryptocurrency community exposed to rapid pump-and-dump schemes.

Why it matters

A verified brand account with millions of followers can instantly lend credibility to a scam, driving buys before the operators dump and disappear.

Repeated hijacks of major corporate and government accounts show that social platform takeover remains an effective, low-tech path to financial fraud and reputational harm.

How it could have been prevented

Enforce phishing-resistant MFA (passkeys or hardware keys) on all social media admin accounts, limit the number of users with posting rights, and monitor for unexpected follows, reposts, or content.

Maintain offline recovery channels, educate followers that the company never endorses random tokens, and have an incident plan to reclaim and clean the account quickly.

Relevant professional terms

Account takeover
When an attacker gains control of someone else's online account, usually to post malicious content or steal data.
Pump-and-dump
A scheme where promoters artificially inflate an asset's price with hype so they can sell their holdings at the peak, leaving later buyers with losses.
Source: SC Magazine

DTU breach exposes data of up to 200000 people

High

What happened

The Technical University of Denmark (DTU) disclosed that attackers accessed its identity and access management system, DTUBasen, using compromised credentials and downloaded a large volume of data.

Up to roughly 40,000 active users and 160,000 former users may be affected. Exposed information can include Danish CPR civil registration numbers, full names, home addresses, profile pictures, work emails, job titles, office locations, and next-of-kin names, relationships, and phone numbers.

DTU cannot determine exactly what was taken. Former-user sensitive fields are normally deleted after six months. The university is notifying people via e-Boks and warns of identity fraud and targeted phishing risks.

Who is affected

Current and former DTU students, employees, and some guests or external partners whose data resided in DTUBasen, potentially totaling up to 200,000 individuals.

Next of kin whose contact details were stored. Impact is concentrated in Denmark given the CPR numbers involved.

Why it matters

CPR numbers are long-lived national identifiers. Combined with addresses, employment data, and family contacts they enable highly convincing identity fraud, tax or benefit abuse, and spear-phishing.

A university IAM system holds decades of records; a single credential compromise can expose an entire historical population and erode trust in the institution.

How it could have been prevented

Reset and strengthen credentials for IAM and privileged accounts, enforce phishing-resistant MFA, and review access logs for anomalous downloads.

Limit retention of sensitive fields such as CPR and next-of-kin data, segment IAM systems, monitor for bulk exports, and prepare clear notification and credit-monitoring support for affected individuals.

Relevant professional terms

Identity and access management
The system that controls who can log in, what they can reach, and how user identities and permissions are stored and enforced.
Civil registration number
A unique national personal identifier (such as Denmark's CPR) used for official records, making its exposure especially valuable for identity fraud.