Cybersecurity News | Daily Recap [01 Oct 2026]

Cybersecurity News | Daily Recap [01 Oct 2026]
Daily Recap, AI security coverage focused on a China-linked phishing campaign targeting AI policy circles, while OpenAI and Anthropic face an FTC probe and new research examined how AI changes vulnerability discovery, distillation attacks, and SOC hiring expectations. In addition, Cisco patched an actively exploited Catalyst SD-WAN zero-day (CVE-2026-76504), major exposure incidents hit GitHub credentials, and multiple industries addressed fallout from Artifactory breaches, MetaMask validator disruptions, and Bitget theft tied to a third-party zero-day. #China #TA419 #OpenAI #Anthropic #FTC #CatalystSDWAN #CVE-2026-76504 #Cisco #SDWANManager #Pentagon #GitHub #JFrog #Artifactory #OpenInfra #MetaMask #Ethereum #Bitget #RedFlick #KillSec #RedFlick #MSP360 #ScreenConnect #EntraID #Microsoft #Thales #SentinelEnvelopePlus

AI Security

  • AI policy circles were targeted in a China-linked phishing operation, while OpenAI and Anthropic face an FTC probe, and new research highlights how AI is reshaping vulnerability discovery, distillation attacks, and SOC hiring expectations. – AI Phishing, FTC Probe, AI Discovery, Distillation Attack, AI SOC Jobs
  • New tools and research focus on securing AI workflows, with DeepKeep adding controls for coding-agent leaks and destructive commands, and Google launching Gemini 4 Argon with guardrail-free access for vetted defenders. – AI Lens, Gemini 4
  • AI-driven attack and defense coverage also expanded with reports on how β€œcoworkers” break agent security models and how attackers are using novel techniques to bypass encryption in model attacks. – Agent Model, Bypass Attack

Zero-Days & Patching

Data Breaches & Exposure

  • A breach of a Pentagon human resources system reportedly exposed records for over 3 million people, underscoring the scale of government data theft. – Pentagon Breach
  • More than 500,000 active credentials were left exposed on GitHub, with a separate report finding over 543,000 valid credentials in public repositories. – GitHub Exposure, Repo Exposure
  • OpenInfra Europe said its JFrog Artifactory instance was breached, potentially compromising packages and software supply-chain trust. – Artifactory Breach
  • MetaMask disclosed a security incident that prompted the exit of affected Ethereum validators. – MetaMask Incident
  • Bitget confirmed a third-party zero-day led to a $387.5 million cryptocurrency theft, highlighting the continued risk to digital-asset platforms. – Bitget Theft

Ransomware & State Actors

  • Authorities arrested a 16-year-old suspected leader of the KillSec ransomware group, while separate reporting detailed Russian state hackers using the new RedFlick technique to deliver malware. – KillSec Arrest, RedFlick Malware

Phishing & Fraud

  • Employment scams surged, with victims tripling at financial firms across 21 countries, showing how criminal groups continue to target hiring workflows and finance staff. – Employment Scams
  • MSP360 was abused to deploy ScreenConnect in dual-RMM phishing attacks, combining legitimate remote-management tools for persistence and access. – RMM Phishing

Privacy & Consumer Tech

  • Research found some connected-car apps are quietly sharing owners’ data with big tech companies, raising new privacy concerns around vehicle telemetry and app permissions. – Car App Privacy
  • Microsoft said it will block Entra ID script-injection attacks starting in October, tightening identity-platform protections. – Entra Block
  • Thales introduced Sentinel Envelope Plus to add software protection without requiring source-code changes. – Sentinel Plus

Cybersecurity News | Daily Recap – hendryadrian.com