Daily Recap, AI security coverage focused on a China-linked phishing campaign targeting AI policy circles, while OpenAI and Anthropic face an FTC probe and new research examined how AI changes vulnerability discovery, distillation attacks, and SOC hiring expectations. In addition, Cisco patched an actively exploited Catalyst SD-WAN zero-day (CVE-2026-76504), major exposure incidents hit GitHub credentials, and multiple industries addressed fallout from Artifactory breaches, MetaMask validator disruptions, and Bitget theft tied to a third-party zero-day. #China #TA419 #OpenAI #Anthropic #FTC #CatalystSDWAN #CVE-2026-76504 #Cisco #SDWANManager #Pentagon #GitHub #JFrog #Artifactory #OpenInfra #MetaMask #Ethereum #Bitget #RedFlick #KillSec #RedFlick #MSP360 #ScreenConnect #EntraID #Microsoft #Thales #SentinelEnvelopePlus
AI Security
- AI policy circles were targeted in a China-linked phishing operation, while OpenAI and Anthropic face an FTC probe, and new research highlights how AI is reshaping vulnerability discovery, distillation attacks, and SOC hiring expectations. β AI Phishing, FTC Probe, AI Discovery, Distillation Attack, AI SOC Jobs
- New tools and research focus on securing AI workflows, with DeepKeep adding controls for coding-agent leaks and destructive commands, and Google launching Gemini 4 Argon with guardrail-free access for vetted defenders. β AI Lens, Gemini 4
- AI-driven attack and defense coverage also expanded with reports on how βcoworkersβ break agent security models and how attackers are using novel techniques to bypass encryption in model attacks. β Agent Model, Bypass Attack
Zero-Days & Patching
- Cisco patched an actively exploited Catalyst SD-WAN zero-day (CVE-2026-76504) after warnings that attackers were exploiting a critical authentication bypass in SD-WAN Manager. β Cisco Patch, SD-WAN Zero-Day, Auth Bypass
- NetScaler, MikroTik RouterOS, WatchGuard Fireware, Zammad, and Zimbra all drew urgent attention after reports of zero-days, critical RCE, code injection, and web-shell deployment in the wild. β NetScaler, MikroTik RCE, WatchGuard Patch, Zammad Zero-Days, Zimbra Flaw
Data Breaches & Exposure
- A breach of a Pentagon human resources system reportedly exposed records for over 3 million people, underscoring the scale of government data theft. β Pentagon Breach
- More than 500,000 active credentials were left exposed on GitHub, with a separate report finding over 543,000 valid credentials in public repositories. β GitHub Exposure, Repo Exposure
- OpenInfra Europe said its JFrog Artifactory instance was breached, potentially compromising packages and software supply-chain trust. β Artifactory Breach
- MetaMask disclosed a security incident that prompted the exit of affected Ethereum validators. β MetaMask Incident
- Bitget confirmed a third-party zero-day led to a $387.5 million cryptocurrency theft, highlighting the continued risk to digital-asset platforms. β Bitget Theft
Ransomware & State Actors
- Authorities arrested a 16-year-old suspected leader of the KillSec ransomware group, while separate reporting detailed Russian state hackers using the new RedFlick technique to deliver malware. β KillSec Arrest, RedFlick Malware
Phishing & Fraud
- Employment scams surged, with victims tripling at financial firms across 21 countries, showing how criminal groups continue to target hiring workflows and finance staff. β Employment Scams
- MSP360 was abused to deploy ScreenConnect in dual-RMM phishing attacks, combining legitimate remote-management tools for persistence and access. β RMM Phishing
Privacy & Consumer Tech
- Research found some connected-car apps are quietly sharing ownersβ data with big tech companies, raising new privacy concerns around vehicle telemetry and app permissions. β Car App Privacy
- Microsoft said it will block Entra ID script-injection attacks starting in October, tightening identity-platform protections. β Entra Block
- Thales introduced Sentinel Envelope Plus to add software protection without requiring source-code changes. β Sentinel Plus