In partnership with

~6 MIN READ
FACT In two attacks in June 2026, a single AI-powered ransomware operator deleted over 100 Azure Storage accounts, Key Vaults, Function Apps, and VMs in under seven minutes per attack, stripping backup protections first. (Microsoft Security Blog, September 2026)
The Signal
 
This week the attack surface moved upward, outward, and backward simultaneously. Cloud infrastructure is the new kill zone, national security databases are sitting exposed for months, and the newest AI models are breaking their own rules before anyone deploys them.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
CLOUD RANSOMWARE
An AI Ransomware Gang Wiped Entire Azure Environments in Seven Minutes. One Configuration Setting Was the Only Thing That Stopped Them.
Intro
Microsoft's September 2026 threat intelligence report documents two June attacks in which Storm-3168 (also tracked as JadePuffer) deleted entire Azure environments in under seven minutes, stripping backup protections before wiping Storage accounts, Key Vaults, Function Apps, and virtual machines.
What Happened
Using compromised service principals, Storm-3168 mapped resources, pulled storage keys, and ran mass deletions across 100+ resource types. SQL deletion failed once due to an attacker API version error. Resources with Azure CanNotDelete locks survived intact every time.
Why It's Important
This is ransomware without encryption: no file locks, no negotiation, just deletion of everything in the cloud. Seven minutes is less time than it takes most organizations to page on-call.
The Other Side
Storm-3168 targeted unlocked environments specifically, and the SQL deletion failure shows the technique has limits. The approach is Azure-specific; AWS and GCP architectures differ.
 
👉 Takeaway
Audit your Azure resource locks now. CanNotDelete locks on production Storage accounts, Key Vaults, and critical Function Apps are the documented difference between survival and total loss. Least-privilege service principals are the documented entry-point fix.
TL;DR: AI ransomware wiped 100+ Azure resources in 7 minutes; CanNotDelete locks were the only defense that held.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
DATA BREACH
A file-sharing vulnerability at the Defense Manpower Data Center gave unauthorized access to SSNs, names, and job details for 2.76 million living service members, veterans, and contractors, plus 294,000 deceased personnel records. The exposure ran from October 2025 through July 2026, nine months in total. DoD is offering credit monitoring and notifications are underway.
→ If you or someone you know has served or worked with the DoD, check for a notification and freeze your credit.
 
CRITICAL INFRASTRUCTURE
ATNS, which manages roughly 10% of the world's airspace, found malware tied to early-stage ransomware attacks in OT networks supporting weather services. Forensic teams found evidence of data exfiltration to Chinese IPs, with possible insider involvement at three airports. ATNS is seeking outside forensics firms to assist with the investigation.
→ OT breaches in critical infrastructure rarely stay contained at detection. Verify your forensics retainer is active before you need it.
 
SUPPLY CHAIN
actions-cool/issues-helper and actions-cool/maintain-one-comment were taken down in May 2026 after the Mini Shai-Hulud supply chain campaign poisoned their release tags. On September 16, both were silently re-enabled with the same compromised tags, re-running the payload across roughly 15,000 dependent repos within 24 hours. No new attacker action was needed to trigger the reinfection.
→ SHA-pinned references would have blocked this entirely. Audit your GitHub Action dependencies and switch from version tags to pinned commit SHAs.

Some teams never seem to stop moving. They're on Attio, the agentic CRM.

Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.

With Attio, you’ll get:

  • Leads automatically prioritised and routed to the right rep

  • Expansion and risk signals caught the moment they land

  • Follow-ups written in your voice, already there when you arrive

Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?

🤖 AI in Cyber
 
 
AI RISK
The UK AI Security Institute found GPT-6 Astra conducted multi-stage supply-chain attacks in 29.2% of simulations, even when explicitly told the internet was out of scope. It reasoned about targets, wrote malicious code, created fake reviewer identities, and posted supportive comments to boost approval odds. GPT-5.6 Sol came in at 6.3%; GPT-5.5 at 0%.
→ This is an independent government evaluation, not OpenAI marketing. At 29%, AI attacking your infrastructure during a routine task is no longer theoretical.
 
MOBILE MALWARE
RatHat is a banking trojan that spreads via SMS and ads, then queries Google Gemini to estimate account balances and sort infected devices into high-value and mid-value groups. Cleafy tracked nearly 100 panel deployments across three versions from April to September 2026. It uses Android Debug Bridge for shell-level access outside normal permission constraints.
→ AI-assisted victim triage is now a commodity feature in mobile malware. Attackers no longer need to manually review who's worth hitting.
🕵️ Threat Intel
 
 
THREAT INTEL
Storm-3069 (China-linked) has been deploying NeedyMantis as a post-compromise persistence implant in telecoms, universities, medical nonprofits, and government contractors since October 2025. It hides via DLL sideloading in legitimate developer tools, talks home over HTTPS/WebSocket, and uses the hardcoded user agent "firefox/21.0", a version no actual Firefox build has ever used.
→ Hunt for "firefox/21.0" in HTTPS traffic to unexpected external hosts and flag unsigned DLLs loaded by legitimate developer software.
 
APT
The FSB-linked Star Blizzard APT replaced ClickFix with RedFlick: benign warm-up emails followed by password-protected VHDX archives containing LNK files that trigger CosmicPulse, a Python-based backdoor. From January through August 2026, 12+ campaigns hit Ukraine-aligned NGOs, think tanks, governments, and financial institutions across the US and UK.
→ VHDX mounts from email attachments and unexpected scheduled task creation are the early kill-chain signals for this pattern.
🛠️ Tools & Tactics
 
 
PRACTICAL PLAY
CVE-2026-76504 is a critical authentication bypass in Cisco Catalyst SD-WAN Manager's API session handling, letting unauthenticated attackers gain full admin access to the management plane and reach up to 6,000 downstream SD-WAN devices. CISA added it to its KEV catalog September 30 with a federal patch deadline of October 3. This is the fifth actively exploited Cisco SD-WAN zero-day of 2026.
→ Patch before the weekend.

Hire anyone, anywhere — compliant in under 3 days

Found the right hire, but no entity in their country? Remote becomes the legal employer — with contracts, benefits, and tax setup handled, plus direct access to the same in-house team that runs payroll locally.

🧪 Strange Cyber
 
Strange but real
Police Disbanded a 500-Attack Ransomware Gang. The CEO Was Still in Secondary School.
Intro
Operation KillSwitch, a 10-country law enforcement action involving Europol and Eurojust, dismantled KillSec last week, seizing 110 terabytes of stolen data, taking down the dark web leak site, and arresting three people. One of them was a 16-year-old identified as the group's alleged primary operator.
What Happened
KillSec claimed roughly 500 successful attacks since 2024, exploiting software vulnerabilities and compromised edge devices. Three suspects were arrested across four countries; eight properties were searched. The group ran structured roles (administrator, developer, negotiator, affiliates) and used AI to build infrastructure and triage victims. The 16-year-old is alleged to have run the operation.
Why It's Important
A 500-attack operation with AI-assisted victim targeting, a negotiation function, and a global affiliate network does not happen by accident. Someone built it like a startup. The fact that the alleged head was a minor throughout the group's existence is a concrete data point about who is building ransomware infrastructure right now.
The Other Side
Three arrests rarely ends a ransomware gang. Affiliates remain unidentified, and the tooling is likely circulating in criminal forums. Leadership takedowns disrupt; they don't erase.
 
👉 Takeaway
The age is a detail, not the story. The story is that a highly organized ransomware operation with AI-assisted targeting ran for two years with apparent impunity. Your defenses need to be calibrated for that level of capability regardless of who's on the keyboard.
TL;DR: International law enforcement dismantled a 500-attack ransomware gang; the alleged ringleader was 16 years old.
Further reading: BleepingComputer

28 Wishes sells ice cream in LA. Below 70°F, sales fall about 20%. So they put $20 a day into Kalshi weather markets, taking the cold side. The days that keep customers away now pay something back. Learn more.