Infosec bits for 2026 week 40
Heloise Meyer
| Oct. 2, 2026, 9:30 a.m.
Cybersecurity News:
Four Cyber Threats Harboring Big Plans for the Future [Steve Durbin, SecurityWeek]
UK academic institutions are under assault by hackers [Emma Woollacott, ITPro]
Know Your Enemy: Browser-Based Attack Techniques in 2026 [The Hacker News, The Hacker News]
Vulnerabilities & Patches:
Citrix confirms two NetScaler RCE zero-days exploited in attacks [Lawrence Abrams, BleepingComputer]
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks [Eduard Kovacs, SecurityWeek]
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials [Alessandro Mascellino, Infosecurity Magazine]
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager [Swati Khandelwal, The Hacker News]
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks [Lawrence Abrams, BleepingComputer]
Cyberattacks:
Automated AI agent used to breach cybersecurity nonprofit DIVD [Bill Toulas, BleepingComputer]
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix [Mark O'Halloran, Huntress]
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 [Microsoft, Microsoft]
Artificial Intelligence:
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment [Jerry Bui, DarkReading]
OpenAI agents go rogue: When AI agents bypass guardrails [Siroui Mushegian, Barracuda]
OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to [Sinisa Markovic, Help Net Security]
Shadow AI explained: The work shortcut that could leak your company’s secrets [Pieter Arntz, Malwarebytes]