43AA 6E9A 54EE B550 D830 EF7A 36EE 72FB 8AD1 F5CC

Infosec bits for 2026 week 40

Heloise Meyer | Oct. 2, 2026, 9:30 a.m.

Cybersecurity News:

  • Four Cyber Threats Harboring Big Plans for the Future [Steve Durbin, SecurityWeek]
  • UK academic institutions are under assault by hackers [Emma Woollacott, ITPro]
  • Know Your Enemy: Browser-Based Attack Techniques in 2026 [The Hacker News, The Hacker News]
  • Vulnerabilities & Patches:

  • Citrix confirms two NetScaler RCE zero-days exploited in attacks [Lawrence Abrams, BleepingComputer]
  • Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks [Eduard Kovacs, SecurityWeek]
  • Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials [Alessandro Mascellino, Infosecurity Magazine]
  • Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager [Swati Khandelwal, The Hacker News]
  • Fortinet warns of critical FortiMail flaw exploited in zero-day attacks [Lawrence Abrams, BleepingComputer]
  • Cyberattacks:

  • Automated AI agent used to breach cybersecurity nonprofit DIVD [Bill Toulas, BleepingComputer]
  • Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix [Mark O'Halloran, Huntress]
  • Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 [Microsoft, Microsoft]
  • Artificial Intelligence:

  • AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment [Jerry Bui, DarkReading]
  • OpenAI agents go rogue: When AI agents bypass guardrails [Siroui Mushegian, Barracuda]
  • OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to [Sinisa Markovic, Help Net Security]
  • Shadow AI explained: The work shortcut that could leak your company’s secrets [Pieter Arntz, Malwarebytes]