In partnership with

~4 MIN READ
FACT South Korean investigators traced the AI-driven intrusions at seven-plus banks to 33 IP addresses spread across 12 countries. (The Record, October 2026)
The Signal
 
This edition is about rules catching up to reality: a healthcare bill that took one catastrophic breach to move, courts putting limits on mass surveillance tools, and a hacking contest confirming that AI tooling is now a first-tier target.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Healthcare / Policy
It Took 190 Million Stolen Records to Get Hospital Cybersecurity Rules Through the Senate
Intro
The US Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent, a rare bipartisan move to stop hospitals being the easiest ransomware payday around.
What Happened
Sponsored by Senators Bill Cassidy, Maggie Hassan, John Cornyn, and Mark Warner, the bill funds grants for prevention, response, and training, adds support for rural clinics, updates regulations around cybersecurity best practices, requires an HHS incident response plan, and gives CISA a direct threat intelligence pipeline to the sector. It passed the Senate; the House still has to act before any of it becomes law.
Why It's Important
The 2024 Change Healthcare attack is believed to have exposed data on more than 190 million people and delayed care and electronic prescribing across the country. That is the incident hanging over every line of this bill.
The Other Side
Grants and "best practices" language are softer than hard mandates, and the details will depend on how HHS writes the rules.
 
👉 Takeaway
If you run security for a healthcare organization, assume regulatory expectations are about to get more specific, and get ahead of it while the grant money is still being designed.
TL;DR: After the largest healthcare breach in US history, the Senate finally passed a hospital cybersecurity bill. The House is next.
Further reading: SecurityWeek
🚨 Can't Miss
 
 
Fraud
The DOJ charged Zohar Pinhasi, CEO of ransomware recovery firm MonsterCloud, with fraud. Prosecutors say the firm paid one attacker $8,200 for a key, then billed the victim $150,000 while claiming no ransom was paid. The alleged total across victims: $19 million.
→ If you vet ransomware recovery firms, ask exactly how they handle ransom payments, and get the answer in writing.
 
Law Enforcement
A 28-year-old Russian national suspected of working with the Qilin ransomware-as-a-service operation was arrested in Osaka in May and extradited to Germany on October 2. He faces charges tied to a September 2024 attack on a German logistics firm that netted more than $160,000 in cryptocurrency.
→ One arrest does not take down a RaaS operation, but it shows affiliates that traveling is a risk.
 
Infrastructure
Attackers compromised the country-code registries for Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL), changed DNS records for Google's domains in those zones, and obtained unauthorized HTTPS certificates. Google's own systems were not breached; the registries above them were. Google revoked the certificates through Chrome's CRLSets.
→ You own your domain. Someone else owns the registry that controls it.

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

For its first CTV campaign, Jennifer Aniston’s DTC haircare brand LolaVie had a few non-negotiables. The campaign had to be simple. It had to demonstrate measurable impact. And it had to be full-funnel.

LolaVie used Roku Ads Manager to test and optimize creatives — reaching millions of potential customers at all stages of their purchase journeys. Roku Ads Manager helped the brand convey LolaVie’s playful voice while helping drive omnichannel sales across both ecommerce and retail touchpoints.

The campaign included an Action Ad overlay that let viewers shop directly from their TVs by clicking OK on their Roku remote. This guided them to the website to buy LolaVie products.

Discover how Roku Ads Manager helped LolaVie drive big sales and customer growth with self-serve TV ads.

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

🤖 AI in Cyber
 
 
Zero-Day Research
Researchers exploited 32 unique zero-days on the first day of Pwn2Own Ireland 2026 and collected $388,500. Targets included the Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle's Autonomous AI Database, and the OpenAI Codex CLI, which fell to an argument-injection bug.
→ AI developer tooling is now on the same target list as phones and routers. Treat it that way in your threat model.
 
Financial Crime
South Korean officials believe ARTEX AI, an open-source, LLM-based penetration testing tool available on GitHub, was used against at least seven financial institutions including Shinhan, Hana, and KB Kookmin. About 68,000 customers had names, phone numbers, income, and borrowing history exposed. President Lee Jae Myung warned that AI lets people hack without specialized skills.
→ The skill floor for running an automated intrusion campaign just dropped. Plan detection for volume, not just sophistication.
🏛️ Privacy, Power & Policy
 
 
Surveillance / Legal
Judge Sara Hill of the US District Court for the Northern District of Oklahoma ruled that a deputy's warrantless search of Flock's national license plate database was an unconstitutional search. The search turned up 50 instances of Melisa Kyle's car traveling across multiple states over a month. Hill leaned on the Supreme Court's June 2026 Chatrie geofencing decision, calling the practice "approaching dragnet-type law enforcement."
→ Chatrie is already reshaping digital evidence cases. Expect more ALPR challenges, including the pending suit against Norfolk, Virginia.
 
Regulation
A federal judge issued a preliminary injunction against Utah's SB 73, which would have forced adult sites to geolocate every visitor or block VPN users. Siding with EFF's arguments, the court found that "geolocation perfection is not presently possible", and that the law would burden users far outside Utah.
→ Other states eyeing VPN restrictions now have a ruling explaining why they don't work.
🛠️ Tools & Tactics
 
 
Practical Play
Cisco disclosed critical NX-OS vulnerabilities affecting Nexus 3000 and 9000 Series switches that can be exploited remotely for root-level code execution or denial of service through NX-API, MPLS OAM, or NGOAM traffic. No active exploitation yet, but these switches sit at the core of many datacenters.
→ Run Cisco's Software Checker to find which NX-OS builds need upgrading, and disable NX-API, MPLS OAM, and NGOAM wherever they are unused until you patch.

Some teams never seem to stop moving. They're on Attio, the agentic CRM.

It’s your always-on revenue engine: agents and workflows build pipeline, chase every buying signal, and move deals forward alongside your team.

Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?

🧪 Strange Cyber
 
Strange but real
The Alleged ShinyHunters Leader Extorted a Former Boeing Unit. His Dad Works for Royal Jordanian.
Intro
Sometimes the hacking scene delivers a detail so specific it feels invented. This one was not.
What Happened
"Rey," the suspected leader of ShinyHunters, has been identified as Saif Al-din Khader, a teenager from Amman, Jordan. When Jordanian authorities detained him, the gang was actively extorting Jeppesen ForeFlight, a former Boeing subsidiary that makes aviation navigation and flight planning tools. Malware data from the family's shared computer showed Rey's father using the same credentials to log in to multiple Royal Jordanian Airlines employee portals.
Why It's Important
Telegram chatter credits Rey with more than $200 million in damages across ShinyHunters operations. Whatever the real number, a teenager allegedly ran one of the most disruptive extortion crews around, and a shared family PC helped unmask him.
The Other Side
Jeppesen ForeFlight says its investigation found "no impact to our operations or products." Khader was reportedly cooperating with the FBI to identify other members of the gang.
 
👉 Takeaway
Infostealer logs cut both ways. The same malware data that fuels these crews is now how investigators find them.
TL;DR: The alleged ShinyHunters boss went after a former Boeing company, and his dad's airline logins helped reveal who he was. ("Rey" means "king" in Spanish.)
Further reading: Krebs on Security

A $70k salary rarely costs $70k. Local taxes, benefits, and compliance can change the math. Oyster's free calculator helps estimate what a global hire may really cost. Try the calculator.