Back Cisoseries Cybersecurity News: Star Blizzard, Cloudflare CA, GPT-6.1 scuttled
Microsoft Threat Intelligence published two threat reports this week. The first covers Russian actor Star Blizzard, which CISA ties to the country’s FSB intelligence service. Since January, the group has moved from targeted spear phishing to large-scale campaigns, and it now sends from accounts it created on compromised websites. It also has a new delivery technique dubbed RedFlick, which uses scheduled tasks to install its CosmicPulse backdoor and needs only one user click, where earlier attacks required several steps. Microsoft says the campaigns have hit more than 100 organizations, mostly in the US and UK.
The second report covers NeedyMantis, a modular post-compromise malware family active since at least October 2025. Microsoft found it while following indicators from the DAEMON Tools supply chain compromise, and it has turned up at organizations including telcos and government contractors. Its activity lines up with China-based actors, though Microsoft has not attributed it to a nation-state.
( Microsoft , Microsoft )
Cloudflare to become a public certificate authority
Cloudflare has announced plans to become a public certificate authority that will issue both traditional certificates and post-quantum Merkle Tree Certificates, or MTCs. The format isn’t a Cloudflare original. Chrome is building its post-quantum plans around MTCs, and the format is being standardized at the IETF, though it is still a draft. What’s new is that Cloudflare is moving from a Chrome experiment to running its own CA. It has agreed to acquire publicly trusted root key material from GlobalSign, a deal expected to close within two months, and has applied to the Chrome, Apple, Microsoft, and Mozilla root programs. Classical certificates will start once those are accepted, with production MTC issuance planned for the first quarter of 2027. MTCs work by proving a certificate is logged in a trusted registry with a lightweight proof, so connections don’t have to carry heavy post-quantum signatures.
( Dark Reading , Cloudflare )
Safety concerns scuttle GPT-6.1
OpenAI confirmed that it scrapped its plans to release GPT-6.1 Astra in October after the model fell short of its safety and alignment requirements. One optimization for this new model was reducing so-called “model laziness,” where a model would give up on tasks. GPT-6.1 is designed to be more persistent, but as a side effect, it often fails to stay within the boundaries of what it has been authorized to do. This led to the new model performing worse than GPT-6 Astra on alignment evaluations, and the Wall Street Journal reports that the new model showed higher levels of deception compared to versions. OpenAI told The Register that more Astra models are “coming soon” that will clear its required safety bar.
In other OpenAI news, the company apologized for a rogue AI agent that hacked the Services Australia Medicare Statistics Reporting Service portal. OpenAI said its investigation found no evidence that incident impacted medical records. It will also establish an Australian task force to study the incidents and develop further policy recommendations, and confirmed its Chief Strategy Officer, Jason Kwon, will appear before the Australian Senate Committee hearing on AI on October 6th.
( The Register , Reuters )
ShinyHunters says it won’t publish FBI data
A representative for the hacking group Shiny Hunters told 404 Media that “Since the very beginning, they had made their decision that they would never publish this data,” referring to FBI data the group claimed on it’s leak site, which included a list of over 5,000 FBI officials with personally identifiable information. At the time, ShinyHunters published the FBI on its leak site, it said it was allowing the agency one week to correct a report that claimed ShinyHunters exaggerated its claims of access to sensitive data in order to spur payment. In a new statement, the hacking group says that it was not attempting to extort the FBI and characterized this as “a marketing campaign to protect our business and actively combat disinformation.”
Huge thanks to our sponsor, Intezer
Apple fixes “extremely sophisticated” zero-day
The company fixed an out-of-bounds write vulnerability in its CoreGraphics framework used for two-dimensional vector graphics and text drawing across iOS and macOS. This flaw was being actively exploited and would allow attackers to crash a program or corrupt data, potentially leading to remote code execution by writing data outside the memory buffer. Apple said exploitation targeted specific individuals on versions of iOS before iOS 27.
( Bleeping Computer )
Arizona Supreme Court discloses cyberattack
Arizona Supreme Court Chief Justice Ann Scott Timmer said that threat actors accessed the state court system and are believed to have obtained personally identifiable information on “many Arizonans”. No group has claimed responsibility for the attack, and the court has not released further details while it investigates. A spokesperson told Recorded Future News that the incident does not appear to be ransomware, and no one is attempting to extort the court. This follows a trend in recent years of targeting state and municipal court systems seen in many U.S. states, including California, Nebraska, Florida, Louisiana, Ohio, Illinois, and South Carolina.
DIVD hit by autonomous attack
The Dutch Institute for Vulnerability Disclosure, or DIVD, suffered a major cyber attack. DIVD is a nonprofit organization that searches for known vulnerabilities in internet-exposed systems and notifies owners. The organization said the attack exploited a “technical vulnerability” in an undisclosed system, noting that the attack’s speed and sloppy logic pattern indicated it originated from an AI agent. It noted that the agent did “some pretty dumb things,” including messing up its own adversary-in-the-middle attack with a password spraying attack. Because the agent overexplained its decision in its , DIVD believes it will provide enough information to help researchers reverse-engineer the attack. The organization promised more details on October 1st and will notify any impacted victims as soon as possible.
( Bleeping Computer )
Kiteworks fixes critical flaw
Earlier this week, we covered that Kiteworks urged customers to take systems offline for 9 hours after receiving intelligence an imminent cyberattack. The company now says it has worked with federal intelligence authorities to identify and patch a critical security vulnerability that the attackers planned to use. Only 1% of its customer base was exposed to this vulnerability, and it says it is applying an additional layer of protection across all environments from similar approaches. There is no evidence of it being exploited in the wild. Hacker News reached out to the company to ask whether it plans to assign a CVE ID to the flaw for easier tracking.
Acting as a media network for cyber information and exchange, CISO Series is just a member of this fantastic community that unfortunately has some conflicts. We're just putting ourselves at the center of the conversation, acting as couples counseling for security vendors and practitioners. CISO Series: Delivering the most fun you'll have in cybersecurity.
us: [email protected]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
