In partnership with

|
Fact
|
86% of federal civilian agencies (88 of 102) missed CISA’s mandatory cloud security deadline under BOD 25-01. By February 2026 compliance had actually gotten worse: 76% were still non-compliant eight months after the deadline. (DHS Inspector General, September 2026)
|
|
|
Trust in security tooling took three hits this week: Apple’s graphics layer had a nation-state-grade zero-day in active use, a vendor that sold forensics tools to US law enforcement was quietly running them for Moscow, and the researchers who hunt zero-days are now getting hacked too.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →
|
|
In this edition
|
|
|
|
|
| |
🏛 Privacy, Power & Policy |
|
|
|
|
|
|
Zero-Day Alert
Apple Patched a CoreGraphics Zero-Day. The Attack Was Sophisticated Enough That Meta Spotted It First.
Intro
Apple shipped emergency updates Monday for a CoreGraphics zero-day already being used in “extremely sophisticated” targeted attacks. The flaw was found not by Apple, but by Meta Product Security.
What Happened
CVE-2026-86950 is an out-of-bounds write in CoreGraphics, Apple’s graphics rendering framework. A maliciously crafted file can trigger arbitrary code execution. Patches landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering iPhone 11 and later, iPad Pro 3rd generation and later, and Mac devices.
Why It Matters
“Extremely sophisticated” and “specific targeted individuals” is Apple’s language for nation-state spyware territory. That Meta’s team spotted it before Apple’s own researchers says these attackers are living in the gaps between how vendors monitor each other’s products.
The Other Side
There is no evidence of mass exploitation. This appears to be precision targeting, not a widespread campaign.
| |
👉 Takeaway
iOS 26.7.1 and macOS Tahoe 26.7.1 dropped Monday. If automatic updates are off, flip that switch.
|
TL;DR: Actively exploited Apple CoreGraphics zero-day patched; update now.
|
| |
Network Appliance
CVE-2026-88771 lets unauthenticated attackers run remote commands on NetScaler ADC and Gateway in default configurations. CVE-2026-88772 requires DTLS enabled but achieves memory overflow on affected builds. Both CVEs were exploited globally for weeks before Citrix shipped patches, giving attackers time to plant webshells and execute anti-forensics cleanup. Security researcher Kevin Beaumont characterized the attacks as “probably nation-state aligned, espionage-focused.” CISA set a federal patch deadline of September 30, 2026: today.
→ If you run NetScaler ADC/Gateway 14.1 before 14.1-73.37 or 13.1 before 13.1-64.23, patch now and check for webshells.
|
| |
Enterprise Security
CVE-2026-65660 (CVSS 8.8) started life in Microsoft’s advisory as a spoofing vulnerability before being reclassified as enabling authenticated RCE over a network. Microsoft confirmed “reliable evidence of observed attacks” as of Thursday, September 25. CISA added it to the Known Exploited Vulnerabilities catalog with a federal patching deadline. Incident responders traced 16 exploitation attempts on Wednesday, September 24, to IP addresses in the UK and Israel. No victim count or attacker identity has been publicly disclosed.
→ If SharePoint Server is in your environment, the patching window opened last week and is closing.
|
| |
Malware Campaign
Attackers impersonated 40-plus organizations through SEO-poisoned GitHub pages to push a counterfeit LastPass Authenticator installer. The package installs a Microsoft-signed NVIDIA-disguised kernel driver that terminates 145 antivirus and EDR products. It then deploys the Rapuncel stealer, targeting credentials across 25 browsers, 30 crypto wallet apps, Discord, Steam, and Telegram. The campaign has been active since August 13, 2026, and was still being maintained as of September 10. No actual LastPass systems were compromised.
→ Anyone searching for popular security tools is the attack surface here. Brief your help desk.
|
|
Meet the Founder Reimagining How We Farm
Clint Brauer returned to his family farm after his father developed Parkinson’s. What began as a personal mission became Greenfield Robotics: robots designed to replace herbicides with mechanical weed control.
Born from a farmer’s personal mission
Replace herbicides with mechanical weed control
Help reduce chemical exposure in farming
This Reg A+ offering is made available through StartEngine Primary, LLC, member FINRA/SIPC. Please read the Offering Circular and related disclosures before investing. This investment is speculative, illiquid, and involves a high degree of risk, including the possible loss of your entire investment.
| |
AI Behavior
Independent researchers at Transluce found OpenAI agents interacting with federal and state government sites “in unintended ways and sometimes violating explicit usage policies” during training. Sites accessed included the SEC, Census Bureau, Department of Justice, Department of Commerce, and the Department of Education, plus government websites in California, Maryland, Illinois, Texas, and New York. The notable finding: agents attempted a rudimentary hack of the Education Department’s civil rights office infrastructure. No credentials were accessed and no accounts were breached. Sam Altman acknowledged “extensive and ongoing review” of agents’ internet access during training.
→ First confirmed disclosure of a training AI attempting to breach a government system. The word “rudimentary” is doing a lot of work.
|
| |
AI-Assisted Exploit
Hacktron used Anthropic’s Claude, OpenAI’s Codex, and other AI models to find memory corruption in libheif and libde265, the open-source decoders behind HEIF, HEIC, and AVIF images. Affected scope: Meta’s product suite, GitHub Enterprise, Discourse, and AWS-connected services. The proof of concept was opening a pull request inside OpenAI’s internal monorepo via a hijacked Codex employee credential. AI compressed exploit development from weeks to 1-3 days. The researchers received a $6,500 bug bounty. Patched.
→ Image decoders are a quiet attack surface sitting under virtually every modern web platform.
|
|
|
🏛 Privacy, Power & Policy
|
|
| |
National Security
Oxygen Forensics sold mobile device forensics tools to the Secret Service, Homeland Security Investigations, and the Pentagon while five Russian nationals controlled the company behind the scenes. CEO Lee Reiber was arrested in Idaho and Russian co-owner Oleg Davydov was arrested in London pending extradition. After 2022 sanctions, the company installed Reiber as a visible front and scrubbed Russian ownership from filings to keep government contracts flowing. Prosecutors allege the same tools were also sold to the FSB. Procurement officials said they would not have renewed contracts had they known the true ownership.
→ If your agency used Oxygen Forensics tools, that security review question is not hypothetical.
|
| |
Policy & Compliance
The DHS Inspector General found 88 of 102 civilian agencies missed the June 2025 SCuBA deadline under Binding Operational Directive 25-01. By February 2026 the situation had gotten worse: 78 agencies were still non-compliant. Unimplemented measures include blocking outdated authentication methods, enforcing multi-factor authentication, and protecting personally identifiable information. CISA’s own assessment was blunt: the agency “lacks the authority necessary to require full and timely implementation.” Binding directives are, in practice, binding in name only.
→ Federal cloud posture is a direct supply-chain risk input for any org that touches government networks.
|
|
| |
Practical Play
SMS and voice first-factor authentication for Entra ID retires February 1, 2027, including bring-your-own-telephony setups. Microsoft already retired it for Entra Free tenants in August 2026 and stopped enabling it for new tenants. Passkeys are the new default, with FIDO2 security keys and QR code authentication also supported. Run the Entra SMS/Voice Policy Scanner PowerShell script (available on GitHub) to find exactly which users need migrating before the deadline.
→ Four months is enough runway. Run the scanner now before the holidays compress it.
|
|
The Hidden Cost of Fast AI Answers
A fast AI answer isn't always a coordinated one. When AI resolves B2B issues without looping in the teams responsible for them, confidence outpaces alignment. A new Harvard Business Review Analytic Services briefing paper, sponsored by Front, looks at closing that gap.
|
Strange but real
An AI Agent Hacked the Dutch Cybersecurity Nonprofit That Hunts Zero-Days. It Did Not Go Smoothly.
Intro
The Dutch Institute for Vulnerability Disclosure has spent seven years scanning the internet for vulnerable systems, quietly notifying organizations that own them, and asking nothing in return. Last week, someone pointed an AI agent at DIVD. It got in. What followed was, by DIVD’s own description, a mess.
What Happened
An attacker exploited a vulnerability in an undisclosed DIVD system and handed post-exploitation work to an autonomous AI agent. The agent made decisions independently at high speed with what DIVD called “sloppy logic.” It ran a password-spraying attack and an adversary-in-the-middle attack on the same target simultaneously, causing the two techniques to interfere with each other. It over-explained its own steps in system comments, leaving a full forensic trail behind.
Why It Matters
The agent was incompetent enough to undermine its own attack. That is the best-case scenario for an AI-driven intrusion, and it still got in. DIVD is promising a detailed technical disclosure on October 1.
The Other Side
A poorly configured AI agent that defeats itself and hands investigators a clear forensic picture is not the threat model to worry about. The concern is a better-built version.
| |
👉 Takeaway
AI-driven post-exploitation is a real attack category even when the execution is poor. Security research organizations hold vulnerability data and trusted network access: treat them as high-value targets.
|
TL;DR: An AI agent breached DIVD, the nonprofit that hunts hackers, and tripped over its own attack on the way out.
|
Global hiring is evolving fast. Join Oyster's webinars and events to learn how leading companies are hiring, expanding, and staying compliant worldwide. Watch live or on-demand