Week in review: FortiBleed is still active, Patch Tuesday forecast
Week in review: FortiBleed is still active, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
Three questions a hospital CISO should ask a healthcare fintech vendor
In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers how Cylerity keeps PHI away from its bank partner, why AI models recommend but never act, and why turning on MFA for email is the cheapest fix for small practices.
MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board
CircuitMess, a Croatian electronics kit maker, is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that buyers program in MicroPython or Arduino C++ and extend with plug-in hardware.
RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models
A developer has released RemoveMacAI, a free command-line tool that turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded AI models. It requires a Mac with Apple silicon.
U.S. Bank CISO says the security role keeps growing and no one can own all of it
In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnerships across technology, risk, legal, and business teams matter most.
Automation, AI agents or people? Sorting out who handles each security finding
Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today.
Who watches the AI watching your street?
Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera footage. His system adds an independent record-keeper and unannounced spot checks to the AI’s outputs.
Pricing your bad days and how to build an economic model for security decisions
Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He suggests starting with a few loss scenarios, then working down to the assets that drive them.
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine. The program MATCHBOIL installs is a spying tool, and the access it creates may be useful to other groups.
Thousands of wind and solar park systems sit exposed on the internet across Europe
Modat and NCSC-NL, the Dutch government’s cybersecurity center, found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet. The systems range from login screens to a turbine control page that offers a Stop button to anyone with a browser.
What the BPFDoor backdoor tells us about attacks on the network edge
A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor. The Linux malware waits for a special “magic packet” before it acts. In this interview with Help Net Security, Christiaan Beek, VP of Rapid7 Intelligence, explains why its operators go after mail gateways and other edge devices that can’t run endpoint agents, and why a hacked telecom network can put a whole nation at risk.
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.”
CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)
CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.”
Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it.
YouTubers targeted with fake sponsorships and “channel verification” phishing
Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners. By sending out personalized emails that reference a creator’s own videos and directing targeted creators to a convincing fake collaboration platform, the fraudsters walk them through what looks like a routine brand deal, right up until the moment they’re asked to sign in with Google.
NIS2 compliance: 7 low-cost steps to secure credentials
Security budgets rarely stretch to cover a full NIS2 programme in one pass. Credential controls are where a constrained team can start, because they make access visible, revocable, and reviewable without new infrastructure. NIS2 compliance rests on risk-management measures that fit the actual risk an organization faces under Article 21, with the choice of specific products and policies left to that assessment.
AI endpoint management: Visibility, compliance, and remediation
Endpoint estates are growing faster than the teams that look after them. Hybrid work, cloud adoption, contractor laptops, a steady stream of new CVEs, and rising compliance pressure mean security teams manage more devices, more software, and more exceptions than a spreadsheet or a monthly scan can hold. Manual tracking and manual remediation no longer keep up.
How AI can fix cybersecurity compliance: From dashboards to continuous execution
Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works. The problem is the cost of delivering it.
October 2026 Patch Tuesday forecast: Time for an Office cleanup
September 2026 Patch Tuesday set an all-time record with 973 CVEs addressed across the Microsoft portfolio. We’re only four months into the Patch Apocalypse and everyone seems to be numb with respect to the insane number of CVEs reported.
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The security company also ranked 11 attack tactics by how often it sees them and how much damage each can do, and RMM abuse sits farthest right on the chart, the position for tactics it sees most often.
AI slop submissions force Google to freeze its open-source bug bounty
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them.
Detained ShinyHunters hacker reportedly helping FBI track down fellow members
A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group. Reuters reports that Jordanian authorities detained Saif al-Din Khader, alias Rey, last week, with two of its three sources placing the arrest on Tuesday.
Fake brand discounts on social media prey on shoppers’ fear of missing out
Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB has warned. The phishing kit called Milk Dragon (also known as NaiLong) has been active since October 2025, and is linked to 258 phishing pages and victims in 66 countries.
Data breach at Denmark’s population register exposes 8.8 million people
A data breach at Denmark’s Central Population Register (CPR) has exposed the personal information of 8.8 million people. These include people living in Denmark, deceased people and citizens who have moved abroad.
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
Rogue OpenAI agents made unauthorized edits on Wikimedia wikis and sent millions of automated requests to Wikimedia’s public APIs, traffic that may have contributed to a partial outage of the Wikidata Query Service in May, the Wikimedia Foundation said on Monday.
OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing
The OpenSSH team released version 10.6 on Oct. 6 and said it will ship releases more often for now to get bugfixes into users’ hands more quickly. The maintainers have received a large number of security reports, many found by AI models or with AI help, and in a number of cases a different researcher independently found the same bug later.
ASOS confirms data breach after “hacked” app alert reaches shoppers
UK fashion retailer ASOS has confirmed a data breach after a notification claiming hackers had broken into its data was sent to shoppers through its app. According to the company’s update to investors, the unauthorised notification went out to its customers at around 10am on 6 October 2026.
Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Attackers who took control of three country-code top-level domains (ccTLDs) used that access to obtain HTTPS certificates for several Google domains and for domains run by other large organizations, Google disclosed on Tuesday.
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service advisory. FortiBleed targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory cites SOCRadar, which has verified more than 86,644 compromised devices in 194 countries.
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims
The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom. Zohar Pinhasi (aka “Zack Silver” and “Zack Green”), a 50-year-old US and Israeli national from Hollywood, Florida, allegedly billed MonsterCloud clients more than $19 million while paying more than $8 million to the ransomware gangs that attacked them.
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims.
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France.
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad.
High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Hundreds of internet-exposed graphics processing unit (GPU) servers were open to a high-severity flaw in NVIDIA’s DCGM Exporter (CVE-2026-47483) that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads, according to Lava.
Keyorix: Open-source secrets management for teams that can’t use SaaS
Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code. It ships as one binary and, in its core form, needs no internet connection.
Apple tightens macOS disk access as AI agents become more powerful
Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous. Users will need to take explicit action to grant apps this permission. The company has not specified a rollout date or detailed how the controls will work.
Product showcase: Webroot Mobile Security screens texts, blocks risky sites, and checks for data leaks
Webroot Mobile Security combines device security checks, Safari protection, text scam filtering, and data breach monitoring. It is available for iPhone, iPad, and Android devices. The app requires an active Webroot subscription and is included with Essentials, Premium, and Total Protection.
Reflection’s Beam trails top open models on coding tests but claims lower inference compute
Reflection AI has built Beam, a 501-billion-parameter open-weight model for coding and agent tasks, and plans to publish the weights under an Apache 2.0 license later this month. Open-weight means developers can download the trained model and run it on their own hardware. Beam uses a mixture-of-experts design, so 23 billion of its parameters fire for any given token, which keeps the cost of each answer down.
GitHub’s ReviewBench puts AI code reviewers to the test
GitHub’s ReviewBench measures how well AI code review tools detect problems before software is released. Available in research preview through its website, the benchmark lets users compare review agents and evaluate their own tools.
Check your X.Org server version because a dozen vulnerabilities have been patched
X.Org fixed 12 security flaws in the X server and Xwayland, with the repairs shipping in xorg-server 21.1.25 and xwayland-24.1.14. Nine of the flaws can lead to arbitrary code execution. The other three can crash the server or disclose information.
Even with OT network visibility, critical infrastructure operators struggle with legacy equipment
Large critical infrastructure operators run seven separate security tools on average, and most still cannot see every asset on their operational technology (OT) networks. That is the picture from a Palo Alto Networks survey of more than 1,600 security and operations leaders.
AI Agent Gateway: Open-source tool keeps credentials out of agent configs
Tuskira’s AI Agent Gateway is an open-source solution that sits between AI agents and everything they call: the MCP tool servers that connect them to services like GitHub and Jira, and the model providers they send prompts to. The gateway runs in your own environment without a Tuskira account.
Anthropic loosens Claude’s cyber restrictions for verified defenders
Anthropic expanded its Cyber Verification Program (CVP), giving approved security professionals access to advanced Claude capabilities with fewer automated blocks on work such as malware analysis and vulnerability testing.
Your Windows PC can now reach other PCs through Windows App
Microsoft has made remote PC connections generally available in Windows App on Windows. Users can access physical or virtual Windows PCs alongside Windows 365, Azure Virtual Desktop, and Microsoft Dev Box resources.
Cisco quantum network controller lets apps order entanglement on demand
Cisco has built a Quantum Network Controller, a research prototype that lets an application ask a quantum network for entanglement and leaves the network to work out the delivery. Entanglement, a linked quantum state shared between distant points, is the resource these networks distribute, and operators today set up the hardware that produces it device by device, link by link.
Medical devices patients rely on most are least prepared for quantum attacks
Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations (HDOs) to deploy ransomware, demand payments and monetize stolen patient data, according to Forescout’s Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness report.
Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws
IBM and Red Hat have found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, their program for patching open source code that companies already run in production.
The people who know passkeys best are still typing passwords
Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts. The most common answer was a username and password, at 43%, from a group in which 87% said they were familiar with passkeys.
GitHub adds AI to catch passwords before a code push
GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories. The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history.
Anthropic’s new budget model gets much better at ignoring hidden commands
Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and writing exploits than its predecessor. The company has given it stricter cybersecurity safeguards than Haiku 4.5, though lighter ones than its more advanced models, whose offensive skills remain well ahead.
Companies want autonomous IT operations but hesitate to let AI act alone
Ninety percent of companies want to move toward autonomous IT operations over the next two years, with agentic AI, software that plans and carries out multi-step tasks on its own, doing the work. Yet 77 percent say their own organization hesitates to let AI make an operational decision without a human approving it.
PCI SSC calls for human approval of AI agent actions involving cardholder data
The PCI Security Standards Council (PCI SSC) has published Security Considerations for AI Systems, guidance covering the protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks.
Product showcase: SimpleLogin keeps your email address private with aliases
SimpleLogin is an email alias service from Proton that forwards messages to an existing mailbox. Users create addresses for registrations, purchases, and correspondence, giving them control over where their primary email address is shared. The service is open source and supports self-hosting.
Anthropic offers free AI security scans to open-source maintainers
Anthropic’s OSS Scanner is a new, free service that uses the company’s strongest AI models to find security vulnerabilities in open-source software. Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them.
Cybersecurity jobs available right now: October 6, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.