In partnership with

~6 MIN READ
Fact On day one of Pwn2Own Ireland 2026, researchers exploited 32 zero-days in a single day, including in a Samsung Galaxy S26, a Philips Hue hub, and OpenAI's Codex coding agent, for $388,500 in payouts. (BleepingComputer, October 2026)
The Signal
 
The biggest leaks this week did not need a zero-day. They needed one trusted login, one trusted brand, or one trusted employee, and attackers found all three.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
DATA BREACH
8.8 Million Danish ID Records Walked Out Through One Small Company's Login
Intro
Denmark has about 6 million residents. Its national ID register just leaked records on 8.8 million people.
What Happened
Attackers abused a small private company's legitimate access to the Central Population Register (CPR) in September, brute-forcing valid CPR numbers and pulling the matching names, addresses, ID numbers, dates of birth, and marital status. The count tops the population because the register's roughly 11 million records include deceased people and people who moved abroad. CPR administrators found the breach October 2; police are investigating and the company's access is blocked.
Why It's Important
The CPR number is the key to Danish healthcare, tax, and banking. Danish law lets private businesses query the register, so the weakest company with access sets the security bar for the whole country.
The Other Side
Minister Christina Egelund called it "an extremely serious incident" and briefed Parliament. Security specialist Jan Kaastrup argues the real failure is treating CPR numbers as secrets at all.
 
👉 Takeaway
Audit every third party with API access to your crown-jewel data. Rate-limit and alert on enumeration patterns, because a legitimate account doing brute-force lookups should never look normal.
TL;DR: One small company's legitimate access let attackers brute-force Denmark's national register and walk off with 8.8 million records.
Further reading: BleepingComputer | The Register
🚨 Can't Miss
 
 
ACTIVELY EXPLOITED
Horizon3.ai used Anthropic's Mythos model to find CVE-2026-61500 (CVSS 9.3): Rejetto HFS leaks outputs of its reversible Math.random() generator at login, letting attackers rebuild the signing key, forge admin cookies, and reach code execution. VulnCheck saw small-scale exploitation attempts from a China Telecom IP starting October 2.
→ Update to HFS 3.2.1 or later; the patch has been out since July.
 
CRITICAL VULNERABILITY
CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker read specific files in the web root of every version of Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, and Crucible/Fisheye Data Center. Attackers need exact file paths, and no exploitation is confirmed yet.
→ Patch now, or pull internet-facing instances off the network until you can.
 
DATA BREACH
Attackers pushed an alert through the retailer's own app claiming they had "fully compromised the Snowflake instance." ASOS confirmed names and contact details may be exposed but says card data and passwords were not. A group calling itself "Xuanye group" took credit on Telegram, without proof.
→ Your push notification service is a broadcast channel to every customer. Lock its credentials down like it is one.

Some teams never seem to stop moving. They're on Attio, the agentic CRM.

Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.

With Attio, you’ll get:

  • Leads automatically prioritised and routed to the right rep

  • Expansion and risk signals caught the moment they land

  • Follow-ups written in your voice, already there when you arrive

Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?

🤖 AI in Cyber
 
 
AI AGENTS
The Wikimedia Foundation says OpenAI agents made unpublished, "potentially malicious" edits designed to misuse a citation tool to fetch data from remote services, and unsuccessfully tried to exploit its Etherpad notes tool. The traffic may have contributed to a May outage. OpenAI did not comment.
→ If your public tools fetch URLs on a user's behalf, assume an agent will try to make them fetch something else.
 
BUG BOUNTY
As of October 1, Google stopped taking product vulnerability reports to its OSS VRP, citing "a significant rise in automated submissions, the vast majority of which are not valid." Supply chain reports still count. The Internet Bug Bounty paused submissions in March for a similar reason.
→ If you run a disclosure program, plan triage capacity for AI-generated volume now.
🕵️ Threat Intel
 
 
ESPIONAGE
Rapid7 says Red Menshen is running a new BPFDoor variant, BPF Rekoobe, and a new implant, AVERAT, posing as SpamSniper and ShareTech email security software on telecom and edge systems in South Korea and Taiwan. AVERAT uses SMTP for command and control, so its traffic blends in with mail.
→ Audit BPF filters and raw sockets; alert on outbound port 25 from non-mail servers.
 
HACKTIVISM
Russian firm Solar says the Belarusian Cyber Partisans held access to an unnamed Russian healthcare organization from early 2024 to December 2025, using a Telegram-controlled backdoor called Vasilek to reach sensitive medical data. They destroyed nothing, which Solar reads as a sign they were saving the access for espionage.
→ Quiet attackers are the expensive ones. "Nothing broke" is not proof nobody is inside.
🛠️ Tools & Tactics
 
 
Practical play
CVE-2026-86360 is a path traversal flaw in Dell System Update (DSU) before version 2.3.0.0 that can let an unauthenticated remote attacker run code as root. The same release fixes four more high-severity bugs. No exploitation has been reported yet.
→ Inventory every Dell server running DSU, confirm the version, and push 2.3.0.0 or later through your normal update channel this week. Update tools run with top privileges everywhere, so treat them like the attack surface they are.

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Blu Dot used Roku Ads Manager to drive incredible results for its furniture sales event. Its strategy hinged on custom audiences and retargeting, where intent was strongest.

“Roku has been a top performer,” said Blu Dot’s Claire Folkestad. “We have seen…CPMs lower than any other CTV partner we've worked with.”

🧪 Strange Cyber
 
Strange but real
He Locked 3,284 Workstations for Ransom. His Search History Was Less Careful.
Intro
Most extortion crews hide behind Tor. Daniel Rhyne used his employer's admin credentials and a search engine.
What Happened
In November 2023, Rhyne, a 57-year-old engineer from Kansas City, Missouri, changed the admin password at his New Jersey industrial employer to "TheFr0zenCrew!", deleted 13 domain admin accounts, and locked staff out of 254 servers and 3,284 workstations. He then emailed coworkers "Your Network Has Been Penetrated," demanding 20 bitcoin (about $750,000). Investigators found he had searched for "how to remotely shutdown a computer usign cmd," typo included, on his laptop a week earlier. He has now been sentenced to 32 months.
Why It's Important
The scariest ransomware actor is the one who already has domain admin. No phishing, no exploit, just an insider with the keys.
The Other Side
The plot failed, nobody paid, and the evidence trail was about as subtle as the password. Most insiders are not this sloppy.
 
👉 Takeaway
Alert on mass admin password changes and account deletions, and review privileged access regularly, not just at offboarding.
TL;DR: An engineer locked 3,000+ of his employer's machines for a $750,000 ransom, searched the how-to first, and got 32 months.
Further reading: BleepingComputer

Your next enterprise deal dies in security review without a SOC 2 report. Sprinto gets you audit-ready in 14 days: three sessions, AI agents collect the evidence, you approve.