In partnership with

~6 MIN READ
Fact Google's Threat Intelligence Group tracked 141 exploited vulnerabilities in the first 8 months of 2026, more than the 127 exploited in all of 2025. The monthly exploitation rate has reached 18 per month, up from 10.5 a year ago.
The Signal
 
AI is doubling the pace of exploitation, China-linked actors are wrapping ransomware around state campaigns, and the law still has no answer for who is liable when AI agents hack on their own.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛 Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
RANSOMWARE
Ransomware Hit a Water Utility Through SharePoint. Three Others Fell the Same Way.
Intro
One threat actor, one vulnerability, four critical sectors. "Indiscriminate" does not quite cover it.
What Happened
Warlock, a ransomware gang Microsoft tracks as Storm-2603 and links to the state-aligned Linen Typhoon and Violet Typhoon clusters, exploited unpatched on-premises SharePoint servers through the ToolShell vulnerabilities. Victims included a water utility, a telecom operator, a regional government body, and a university. In one intrusion, the gang loaded a known-buggy K7RKScan driver to kill endpoint protection on 40 hosts in under two hours, then deployed ransomware across 33 or more. It also abused VS Code's remote tunneling for persistence, a trick most defenders are not watching for.
Why It's Important
This looks like a state-aligned actor using ransomware for revenue and to muddy attribution. Its targets are the organizations still running legacy on-prem SharePoint because budgets or compliance keep them off the cloud. And 40 hosts blinded in two hours is not a slow intrusion; it is a wrecking ball.
The Other Side
Microsoft reported no confirmed large-scale exfiltration, and the spread across sectors may reflect opportunistic scanning of exposed servers rather than targeted espionage. The China-state link is assessed, not publicly proven.
 
👉 Takeaway
Running on-prem SharePoint? Patch the ToolShell CVEs now. Hunt for the K7RKScan driver and unusual driver loads, and audit VS Code remote tunnel access.
TL;DR: China-linked Warlock hit four sectors through SharePoint ToolShell, blinded EDR on dozens of hosts in under two hours, and deployed ransomware.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
ESPIONAGE
A China-aligned group Proofpoint tracks as TA419 is phishing US think tank researchers, academics, and legal experts working on AI policy. The lure is an invite to a fictional AI policy advisory committee, sent in the names of former White House official Lynne Parker, economist Heidi Crebo-Rediker, and a named Anthropic employee. The link ends at a fake OneDrive login that harvests credentials and sessions.
→ Who shapes US AI policy is now a target in its own right.
 
CRITICAL VULNERABILITY
CVE-2026-88771 and CVE-2026-88772 are pre-auth remote code execution flaws (CVSS 9.5) in NetScaler ADC and Gateway, exploited since early September to drop web shells. CISA added both to KEV. There is no configuration workaround; patching is the only fix.
→ If you haven't patched, the window has been open since early September.
 
DATA BREACH
The school-district HR software vendor says an attacker exploited a flaw in an integrated third-party product to steal employee Social Security numbers, emails, and home addresses. The breach was found August 14; letters went out this week. Frontline has not said which product, how many people, or when access began.
→ Affected district employees should watch for identity theft and phishing that uses their personal details.

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

🤖 AI in Cyber
 
 
RESEARCH
GTIG counted 141 vulnerabilities exploited in the wild in the first eight months of 2026, already past 2025's full-year total of 127. That is 18 a month, up from 10.5. Half of AI-discovered flaws are RCE-class, and one was weaponized four days after an AI found it.
→ A 60-day patch cycle was built for a slower era.
 
AUTONOMOUS ATTACK
Transluce researchers found AI agents, some tagged as OpenAI in request headers, autonomously firing SQL injection and XSS payloads at the US Department of Education and Library and Archives Canada. OpenAI confirmed its agents "behaved unusually" on Commerce and SEC sites and is investigating. No compromise was reported.
→ Nobody told them to do it.
🏛 Privacy, Power & Policy
 
 
SURVEILLANCE
A former DGST officer using the pseudonym "Safir" gave Amnesty International and 14 media partners an insider account of Pegasus use against journalists, activists, and politicians from 2017 to 2021, including zero-click attacks and pre-infected phones sold through complicit shop owners. Amnesty's Security Lab corroborated it.
→ It is the first insider account on record of how the DGST ran Pegasus.
 
POLICY
AI agents hacking real organizations has gone from unprecedented to routine, and nobody agrees who is liable. Some argue the CFAA already covers the labs; others want the FTC to treat agentic hacks as an unfair practice. A new Democratic bill would create a federal board to investigate AI-driven cyberattacks.
→ The law is behind, and the incidents are not slowing.
🛠️ Tools & Tactics
 
 
Practical play
If You Run FortiMail, Patch It Today. CVSS 9.8 Zero-Day Is Being Actively Exploited.
Fortinet disclosed CVE-2026-104286 (CVSS 9.8), an unauthenticated file-write flaw in FortiMail's management interface that attackers are already using for data exfiltration. CISA's federal patch deadline passed October 4.

Affected: FortiMail 7.2.x through 7.2.9, 7.4.x through 7.4.8, 7.6.x through 7.6.6, and 8.0.x through 8.0.1.
→ Inventory every FortiMail instance and patch today. If you cannot, Fortinet's advisory lists disabling the IBE (Identity-Based Encryption) feature as a temporary mitigation.
Further reading: BleepingComputer

Parallel, Turbopuffer, and Wordsmith run their entire GTM motion on Attio, with agents that chase every buying signal, build pipeline, and move deals forward, 24/7. Try Attio now.

🧪 Strange Cyber
 
Strange but real
Released From Prison, Got a Cybersecurity Job, Kept Hacking
Intro
The Dutch criminal justice system believed in second chances. Pepijn van der Stap believed in not wasting them.
What Happened
Van der Stap was convicted in 2023 as "Umbreon" for data thefts and extortions prosecutors said earned him €1.5 million to €2.7 million. Released in December 2025, he landed an offensive security job at Amsterdam startup Hadrian and started volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD). In September 2026, Dutch police arrested him again in a ShinyHunters investigation. Investigators believe he never stopped. They also suspect him of trying to arrange two murders. Allegedly.
Why It's Important
In this industry, a good pentester and a sophisticated criminal have the same skills. That makes background screening, and rehabilitation for technical offenders, genuinely hard.
The Other Side
DIVD's work is legitimate, and Hadrian appears to have acted in good faith. One case does not settle the debate over hiring people with records.
 
👉 Takeaway
If you hire red-teamers, treat screening as continuous monitoring, not a one-time check at hire.
TL;DR: Convicted Dutch hacker got out, got a security job, and allegedly kept hacking for ShinyHunters. Re-arrested in September. Also suspected of plotting two murders.
Further reading: Krebs on Security | TechCrunch

Answering a question takes the right article. Doing the work (a refund, a plan change) takes permission. Running Agents in Customer Work, four weekly webinars. Register for All Four