Skip to content

Home/Digest/Past issues

Daily digest,

Critical Authentication Bypass in Rejetto HFS Exploited Within 24… (+7 more)

Vulnerabilities

Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours

Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to China. The vulnerability arises from insecure handling of session authentication using JavaScript's Math.random(), which is reversible due to the xorshift128+ algorithm. This flaw enables attackers to forge valid session cookies and gain administrative access. Users are urged to update to version 3.2.1 or later to mitigate the risk. The software had previously been listed on CISA's Known Exploited Vulnerabilities catalog for a different issue in 2024.

Vulnerability · 2 sources · score 80 · CVE-2024-23692, CVE-2026-61500

Dell Patches Critical CSM Flaws Allowing Unauthenticated Access

Dell has issued security updates for six critical vulnerabilities in its Container Storage Modules (CSM) that could enable unauthenticated attackers to gain administrative access to storage backends and root control over Kubernetes clusters. The vulnerabilities, tracked as CVE-2026-63688 and CVE-2026-63692, both carry a maximum CVSS score of 10.0, allowing attackers to bypass authentication and access sensitive credentials. Additional vulnerabilities, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-67273, also pose significant risks, with CVSS scores ranging from 9.6 to 9.9. All versions prior to 1.17.0 are affected, and Dell recommends immediate upgrades to version 1.18.0 or later. Although Dell has not confirmed active exploitation, the potential impact on storage services and Kubernetes clusters is significant. Administrators are urged to rotate JWT signing secrets as part of the remediation process.

Vulnerability · 8 sources · score 61 · CVE-2021-21551, CVE-2026-22769, CVE-2026-54472, CVE-2026-61421, CVE-2026-63688

Epic Halts Development to Address Cybersecurity Vulnerabilities in MyChart

Epic, the company behind the MyChart patient portal, has paused most product development for approximately six weeks to address significant cybersecurity vulnerabilities. These flaws were discovered by an AI cybersecurity model, which indicated that certain configurations of MyChart could allow unauthorized access to patient records without detection in system logs. The exact nature of these vulnerabilities remains undisclosed, but the risks prompted the company to take immediate action. Epic's chief security officer noted that while the AI model did not confirm if records could be altered undetected, the potential for exploitation was serious enough to warrant a pause. Epic's MyChart software manages over 320 million patient records across the U.S., making the implications of these vulnerabilities particularly concerning. The healthcare sector has seen a rise in cyberattacks, with numerous breaches affecting millions of individuals in recent years, including significant incidents at Change Healthcare and CareCloud. The Department of Health and Human Services lists a breach at DentaQuest affecting 15 million people as the largest healthcare-related data breach of 2026 so far.

Breach · 2 sources · score 52

Ransomware

Warlock Ransomware Exploits SharePoint Vulnerabilities

Warlock ransomware has been reported to exploit vulnerabilities in Microsoft SharePoint to breach networks. The ransomware targets organizations using SharePoint, leveraging flaws to gain unauthorized access. Specific CVEs related to these vulnerabilities have not been disclosed in the articles. The scope of the impact remains unclear, but organizations using SharePoint are advised to enhance their security measures. As of the latest reports, the ransomware is actively being used in the wild, posing a significant threat to affected systems. Security professionals are urged to monitor their networks for unusual activity and apply necessary patches as they become available. The situation is evolving, and further updates are expected as more information becomes available.

Ransomware · 3 sources · score 64 · Warlock, Warlock Ransomware

Breaches

South Korea's Financial Sector Faces Widespread Hacking Attacks

South Korea's Financial Services Commission (FSC) has summoned CEOs from all financial firms due to a series of hacking attacks that have compromised personal data across major banks and non-bank lenders. The breaches began with Shinhan Bank leaking 25,000 customer records on September 30, followed by incidents at Hana Bank and KB Kookmin Bank. The damage has extended to secondary institutions, including Yegaram Savings Bank and Hyundai Capital. The FSC's emergency meeting on October 4 aims to assess the situation and enhance security measures across the sector. The urgency of the meeting was prompted by additional breaches confirmed at Hyundai Capital and Yegaram Savings Bank, which heightened concerns about the security response framework. Financial authorities are still determining whether the attacks were conducted by the same group or multiple actors.

Breach · 3 sources · score 55

Threat actors and malware

North Korea-Linked Hackers Steal $387 Million from Bitget Using AI for Fund Tracing

On September 24, 2026, hackers attributed to North Korea stole $387 million from the Bitget crypto exchange. The funds were rapidly transferred across multiple blockchains, primarily Ethereum and XRP, using complex laundering techniques to obscure their trail. Chainalysis utilized in-house AI to trace the stolen funds, compressing over 20 hours of manual reconciliation into under 10 minutes. The investigation revealed that the stolen assets were moved through cross-chain liquidity protocols and instant swaps, complicating tracking efforts. The total value of cryptocurrency stolen by North Korean actors in 2026 has now surpassed $1 billion. Chainalysis continues to monitor the identified addresses and track the movement of the stolen funds. The speed and sophistication of the operation highlight ongoing risks from state-sponsored cyber theft in the crypto sector.

APT · 6 sources · score 76

China-Nexus UAT-11587 Campaign Uses Antino Backdoor Across Asia

Cisco Talos has identified a cyberespionage campaign, tracked as UAT-11587, linked to a China-nexus threat actor targeting government and policy organizations across eight Asian countries. The campaign, which began in September 2025, has deployed a previously undocumented Rust-compiled backdoor named Antino, utilizing Microsoft 365 services for command-and-control communications. Targets include entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, with at least 16 organizations confirmed affected. The attack vector primarily involves spear-phishing emails that spoof trusted senders, leading to a multi-stage infection process. Antino supports various malicious functionalities, including shell access and file transfers, while blending its traffic with legitimate Microsoft 365 activity. The campaign has shown significant activity spikes, particularly between March and June 2026, with a notable wave of attacks on June 8-9. Talos assesses the threat actor with high confidence as being linked to China based on technical indicators and operational patterns.

Malware · 5 sources · score 76 · Antino, UAT-11587

New Linux Malware Mimics Asian Email Security Appliances

Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam software used by over 6,000 organizations. Another tool, AVERAT, is linked to attacks on Taiwanese mail security vendor ShareTech Information. These backdoors exploit TCP Port 25 to blend command-and-control traffic with normal email communications, complicating detection efforts. The campaigns are characterized by their advanced mimicry techniques, replicating filenames and operational habits of the legitimate software they impersonate. The threat landscape is particularly concerning for organizations in the Asia-Pacific region, where these appliances are prevalent. Current status indicates ongoing research and monitoring of these threats.

Malware · 2 sources · score 51 · BPFDoor, Rekoobe, SpamSniper, Korea Campaign, Taiwan Campaign

New on leak sites

17 victims listed on ransomware leak sites by 7 groups in the 24 hours before this issue. The most active:

Also moving

  • Malware: Antino, Agewheeze, BPFDoor, Chameleon, ClickFix
  • CVEs: CVE-2026-102489, CVE-2026-102490, CVE-2026-18397, CVE-2026-85706, CVE-2026-88771
  • Ransomware groups: Warlock
  • APT groups: 4HMDOS4
  • Campaigns: African Lion, Antino Backdoor Campaign, C5+1
  • Vulnerabilities: Citrix NetScaler

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.