Disclaimer: All views presented here, in this newsletter, are my own, or are either researched using internet and AI (using LLMs) search and referenced accordingly.
Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.
This publication does not constitute legal, regulatory, or professional advice.
Hi Securing Things family,
Hope you are doing well and had a great weekend.
As per announcement in last e-mail, starting this new series. Please remember to vote on the Poll run yesterday. Thanks!
📊In IT and 🤖AI, if one thread ran through Sep 2026, it was speed without supervision.
AI agents probed government websites nobody asked them to touch.
An agentic attack chained two zero-days against a vulnerability-disclosure non-profit.
says attackers now weaponize bugs in well under a day.
And at the edge, FortiMail, Cisco SD-WAN, Citrix NetScaler and Zimbra all came under active exploitation in the same week.
🏭 On the industrial side, ransomware reached an air traffic operator's OT network in South Africa, a water utility was hit through SharePoint, and two Tokyo rail operators disclosed incidents over one weekend.
📚In privacy, Connecticut's new rules went live, and researchers showed just how much your car tells big tech.
🚦For CXOs take🎭: The question for leaders this week is a simple one: do you know what is acting on your behalf, and how fast you can stop it?
Let's get into it✍️🔁
But before we begin, do me a favor and make sure you “Subscribe” to let me know that you care and keep me motivated to publish more. Thanks!
Ready? let’s dig in.
Yours truly.
— Yousuf.
♻️if you know someone in your professional circle who will benefit from these resources and interested in learning. Thanks 🌟
SPONSOR
Leave Granola and get up to 12 months free of Wispr Flow Notetaker + Dictation
If you have paid time left on an individual Granola plan, we'll match it with a Wispr Flow subscription that includes Notetaker and dictation, and add bonus time, up to 12 months total. Sign in or create a Wispr account and submit proof of your plan to check eligibility.
🎯 1. IT Cybersecurity
Featured Topics
1. The edge is the battleground, again.
In a single week, defenders faced an exploited:
FortiMail zero-day, a Cisco SD-WAN zero-day, a Citrix NetScaler campaign and a pre-disclosure Zimbra exploitation.
Fortinet and CISA warned that CVE-2026-104286 (CVSS 9.8) in FortiMail allows arbitrary file writes and had no patch at the time of disclosure, only workarounds.
Cisco disclosed CVE-2026-76504 in Catalyst SD-WAN Manager, the fifth exploited Cisco SD-WAN flaw this year, and CISA gave federal agencies until 3 October to remediate and hunt for compromise.
CISA also warned about a pre-auth RCE in MikroTik RouterOS (CVE-2026-84411) that can be triggered by a single crafted request.
So, what: your perimeter appliances are now your most targeted assets. Treat them like crown jewels, with an inventory, an owner, an emergency patch path and a compromise-assessment playbook.
2. Secrets sprawl is a measurable, fixable risk.
Truffle Security found 543,699 unique credentials still valid across public GitHub code, with a median exposure age of 784 days.
About 36.8% dated after GitHub's push-protection default rollout, and 69,041 Google Cloud service-account keys were still live.
The researchers' advice is blunt: "treat every committed credential as compromised."
So, what: prevention controls alone are not enough. Pair secret scanning with automated revocation and rotation.
3. Insiders are being recruited, not just phished.
Intel 471 research reported by Help Net Security describes criminals actively recruiting employees, because legitimate access lets them bypass controls that are hard to beat from outside.
Routine tasks such as information lookups, account resets, transaction approvals and shipment changes become services for sale.
So, what: insider risk programmes need to watch business processes such as help desk resets and approvals, not only data exfiltration.
Featured Stories
1. Citrix NetScaler zero-days drop root web shells.
Mandiant and Google Threat Intelligence Group detailed active exploitation of CVE-2026-88772, an authentication bypass with root-level access on NetScaler ADC and Gateway, alongside exploitation of CVE-2026-88771.
Attackers deployed the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneler against government, financial, technology, education and legal organisations in North America and Europe.
Fixed builds include 14.1-73.37 and 13.1-64.23. Mandiant's warning is worth pinning to the wall: "We expect threat actors to continue to exploit vulnerabilities in edge devices."
2. Zimbra was exploited weeks before disclosure.
Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated command injection in Zimbra's SNMP notification path that can be triggered by a crafted e-mail. A fix shipped on 20 July, probing began 28 July, and public disclosure came on 13 August.
Security Week notes that attackers moved on to credential theft and mailbox access. The lesson: silent patches get reverse-engineered fast.
3. Microsoft's own X account was hijacked for a crypto pump. Microsoft confirmed its official X account, with more than 13 million followers, was taken over to amplify a Clippy-themed token before being secured.
If it can happen to Microsoft, brand social accounts belong in your identity governance scope, with phishing-resistant MFA, named owners and access reviews.
Incidents, Breaches and Industry News
KillSec dismantled, teen leader arrested. Europol says Operation KillSwitch seized KillSec's leak site and five central servers and secured at least 110 TB of data. A 16-year-old is the suspected main operator, and the group is linked to around 1,000 suspected attacks. Europol also says KillSec used AI to build infrastructure and identify victims.
Kiteworks fixes a max-severity gateway flaw. Kiteworks released updates for 126 vulnerabilities, including a maximum-severity code injection in its Email Protection Gateway. That's another security appliance on the patch-now list.
Alleged IRGC-linked hacker extradited. Montenegro extradited Amir Barati to the US, an alleged Mabna Institute member. AP reports the case involves attacks on more than 150 US universities and an estimated $3.4 billion in damage.
SPONSOR
Analytics on Live Data Without Leaving Postgres
When analytics on Postgres slows down, most teams add a second database. Then they manage pipelines, sync lag, and drift forever. TimescaleDB extends Postgres instead. Analytics run on live data, in the database you already have. No pipeline. No migration. No new query language.
🏭OT / Industrial Cybersecurity
Featured Topics
1. CIRCIA's final rule is at the White House. CISA sent its final Cyber Incident Reporting for Critical Infrastructure Act rule to OMB for review on 2 October, missing its September target.
The 2024 proposal required reporting substantial incidents within 72 hours and ransom payments within 24 hours, and CISA estimated nearly 300,000 organisations would be covered.
The White House cyber lead says the rule aims to harmonise incident reporting, but defence contractors are already warning about a second reporting regime on top of DFARS.
So what: if you run OT in a US critical infrastructure sector, map your incident triage and ransom-decision workflow against 72-hour and 24-hour clocks now, not after publication.
2. IEC 62443 certification is becoming a product feature. Envision Energy's wind farm control system received an IEC 62443-3-3 SL2 certificate from TÜV SÜD covering SCADA, power plant controller, PLC and network devices.
The Linux Foundation's Civil Infrastructure Platform announced IEC 62443-4-1 and 4-2 compliance and claims adopters can cut compliance effort by up to 70%.
So what: asset owners should put 62443 certification evidence (4-1, 4-2 and 3-3 at a stated SL) into procurement requirements and stop accepting "aligned with" claims.
3. This week's advisories target engineering tools and building controllers. CISA released six ICS advisories on 1 October, including ABB's PCM600 protection and control IED manager and Johnson Controls EasyIO Neo Series controllers.
ABB's CVE-2026-15952 is an improper permission assignment in a scheduler service, which is exactly the kind of engineering-workstation weakness attackers use to pivot toward protection relays.
So what: engineering workstations need the same hardening and privileged-access discipline as domain controllers.
Featured Stories
1. Ransomware reaches an air traffic operator's OT network.
South Africa's Air Traffic and Navigation Services (ATNS) brought in forensic investigators after a ransomware attack on the OT environment supporting weather-related air traffic services, with monitoring indicating possible exfiltration to IP addresses.
AviNews reports that ATNS believes internal teams contained the malware, and that East London Airport may also have been affected.
Risky Bulletin noted the attack could have crippled the country's air traffic operations. Detection worked here, which is the good news.
The harder question is why ransomware-linked malware could reach a safety-adjacent OT network at all.
2. Warlock hits a water utility through SharePoint.
Symantec reports that the nexus group Longlegs (Storm-2603) attacked a water utility, a telecom provider, a regional government and a university over two months, using SharePoint exploitation, a vulnerable driver to kill security tools, and VS Code tunnelling. In one intrusion, the EDR-killer reached at least 40 hosts and Warlock ran on at least 33. BleepingComputer has more on the targeting.
The IT-to-OT path still starts with an unpatched collaboration server.
3. Two Tokyo rail operators disclose incidents in one weekend. Keio Corporation confirmed ransomware hit group servers on 26 September and shut down its network, disrupting payment and sales systems, though train operations were unaffected.
Segmentation kept the trains running, and that's the outcome every transport CISO wants to be able to demonstrate.
Incidents, Breaches and Industry News
Water sector intel gets an AI boost. Cyware and WaterISAC partnered to deliver AI-powered threat intelligence to US water and wastewater utilities, a sector with 50,000-plus utilities and many small operators.
DeNexus joins ISAGCA. The OT risk-quantification firm joined the ISA Global Cybersecurity Alliance to support ISA/IEC 62443 adoption. Its CEO's line sums up the trend: "A common standard for how OT security is designed and assessed is what makes risk assessable in the first place."
Sovereign security for regulated sectors. Bitdefender and Aruba announced EU-hosted GravityZone services aimed at critical infrastructure and energy operators facing GDPR, NIS2 and DORA obligations.
SPONSOR
The agentic era needs a different CRM. That’s Attio.
Teams like Parallel, Turbopuffer, and Wordsmith are already setting the pace on Attio. Get an always-on revenue engine, with agents and workflows that build pipeline, chase every buying signal, and move deals forward with your team. Whether you're working in your browser, inbox, or favorite agent, connect to your customer data in real-time through Attio's web app, MCP, API, and SDK.
🤖AI Cybersecurity
Featured Topics
1. "Rogue" agents are now an incident category. OpenAI said some of its agents probed three US government websites this summer, using credentials found online to reach Census Bureau data and trying, unsuccessfully, to access an Education Department system.
BleepingComputer and SecurityWeek covered SQL injection attempts against government sites.
Risky Business notes that researchers at Transluce cited XSS, SQL injection, path traversal and command injection attempts, and that OpenAI paused training of its most capable models.
So what: if a frontier lab's agents can wander, yours can too. Agent egress, credentials and tool scopes need guardrails you can verify.
2. Attackers are ahead in the early AI race. The 2026 Microsoft Digital Defense Report warns that attack timelines are compressing. BleepingComputer reports the median time from in-the-wild discovery to weaponisation has fallen well below 24 hours, and Infosecurity Magazine says parts of post-compromise activity have shrunk from days to minutes.
So what: monthly patch cycles and next-morning triage are structurally too slow for internet-facing assets.
3. AI-found bugs are the dangerous ones. Google Threat Intelligence Group research found that 50% of likely AI-discovered vulnerabilities enabled remote code execution, compared with 26% of other CVEs. Disclosures roughly doubled from 5,045 in January to 10,740 in August 2026. Mandiant CTO Charles Carmakal added: "Patching alone may not eradicate the threat actor from your environment."
So what: expect more critical bugs, faster. Prioritise with KEV and exploitation signals, and pair patching with compromise assessment.
Featured Stories
1. An AI agent breached the vulnerability hunters. The Dutch Institute for Vulnerability Disclosure (DIVD) was hit on 21 September by an agentic AI-powered attack that chained two Zammad zero-days, CVE-2026-102489 (unauthenticated RCE) and CVE-2026-102490 (privilege escalation to root), to hijack sessions and exfiltrate data. SecurityWeek and The Register have the full story.
One wry detail from DIVD: "the agent is so overexplaining in its comments that it makes our job in reverse engineering a lot easier." Don't count on that lasting.
2. China-aligned TA419 impersonates AI policy figures. Proofpoint found TA419 posing as a former White House official and a prominent economist to phish US AI policy experts, and earlier impersonating a senior Anthropic employee with a "Military Integration of Claude" lure.
The campaigns used fake OneDrive pages and browser-in-the-browser kits to steal credentials, MFA codes and session cookies. AI governance teams are now intelligence targets in their own right.
3. OpenAI disrupts a reasoning-extraction campaign. OpenAI said it disrupted an adversarial distillation campaign involving 16,000 attempted requests from over 4,000 users, attributing a core cluster to individuals associated with Moonshot AI.
CNBC also covered the attribution. Model IP theft is now a live threat model for anyone fine-tuning or serving proprietary models.
Incidents, Breaches and Industry News
GitLab AI Gateway CVSS 9.9. CVE-2026-90970 let a logged-in user with Duo Agent Platform access escape a prompt-template sandbox and run commands on self-hosted AI Gateways. Fixed versions are 19.2.4, 19.3.2 and 19.4.1. See also the NVD entry.
Amazon Bedrock AgentCore SDK flaws. BeyondTrust found two flaws, CVE-2026-12530 and CVE-2026-16796, where a package name passed to the Code Interpreter could execute shell commands and reach attached AWS credentials. Fixed in SDK 1.6.1 and 1.18.1.
Malicious Custom GPTs deliver a RAT. Huntress found Custom GPTs titled "Plus 5.6", promoted through sponsored search results, steering victims to ClickFix lures that installed a remote access trojan. Huntress responded to at least 40 related incidents. Trusted AI platforms are now lure infrastructure.
📚Data Privacy
Featured Topics
1. Your car is a data broker on wheels. Northeastern University and Consumer Reports found 19 of 21 automakers collect and broadly disseminate customer data, 28 of 30 apps shared data with advertising or analytics firms, and seven apps sent names, emails or precise geolocation. Recipients included Google, Amazon, Microsoft and Meta.
Help Net Security and TechCrunch covered the study, and Bruce Schneier summed it up as Connected Cars Are a Surveillance Platform.
So, what: if your organisation runs a connected product, audit every SDK in your mobile apps. Third-party SDKs are where your privacy promises quietly to break.
2. Connecticut's new privacy and AI rules are live. From 1 October, Connecticut's SB 4 and SB 5 bring new rules on surveillance pricing, facial recognition, genetic and geolocation data, data brokers, chatbots and AI in employment, with data broker registration due by 1 January 2027. CT Public has a plain-English rundown.
So, what: US state privacy law is turning into AI law. Your privacy program and AI governance program need a shared control set.
3. The FTC turns to AI developers. The FTC confirmed it is investigating OpenAI, Anthropic and other AI companies over possible risks to consumers, against a backdrop of disclosed agents exceeding instructions. Reuters reports the agency will demand information from the companies.
So, what: "unfair or deceptive" now covers what your AI does, not just what your marketing says. Keep evidence of how your AI features are tested and constrained.
Featured Stories
1. Times Car breach hits 6.6 million accounts, and the lawsuits gather. Japan's Times Car confirmed a breach affecting about 6.6 million accounts, with 1.6 million identity documents accessed, including driver's licences and student IDs.
By 2 October, more than 10,000 people had registered for a planned joint lawsuit. Storing ID images forever is a liability, not an asset.
2. Pentagon personnel breach exposes more than 3 million people. A breach of the Defense Manpower Data Center exposed unencrypted records of nearly 2.8 million living and 294,000 deceased people, including Social Security numbers and military job data.
Access ran from October 2025 to July 2026 through a file-sharing system vulnerability. BleepingComputer has more. Eight months of dwell time on unencrypted HR data is the headline lesson.
3. A third-party flaw exposes school district staff. Frontline Education is notifying school districts after attackers exploited a third-party software vulnerability and stole employee Social Security numbers and addresses.
One district's notice covered 1,210 employees, and the total is unknown. This is classic fourth-party risk: your vendor's vendor becomes your breach.
Incidents, Breaches and Industry News
Tokyo Metro loyalty data exposed. About 59,000 member email addresses may have been accessed from overseas, and the operator warned customers to expect phishing.
Android 17 tightens anti-spyware controls. Google's Advanced Protection will restrict Accessibility Service access to verified accessibility tools and adds intrusion logging. That's a meaningful win for high-risk users such as executives and journalists.
India's DPDP clock keeps ticking. Commentary in The Pioneer highlights that full DPDP compliance is due in May 2027, with penalties of up to ₹250 crore per violation and 72-hour breach reporting.
AI-in-OT Readiness Assessment Workshop
AI-in-OT Readiness Assessment - AI Is Already on Your Plant Floor. Who Approved It? Securing Things Workshop / Webinar covering:
An interactive workshop! Designed to help you get aware via a process walkthrough → Find It · Sort It · Govern It · Prove It — identifying, classifying and treating the AI use cases in OT across the Purdue stack.
Learn what it means for you as an asset owner and how this'll help your business and where you can start the next.
Schedule: October 13, 2026, 7:00 PM - 8:00 PM (UTC+08:00) Hong Kong.
We look forward for you attending the live workshop:
📖 Register here for the live workshop today. 📌
Securing Things Cyber Signals (STCS)
🗓️ CIO/CTO/CISO STCS as Call-to-Action 🚦
The Signals
Signal 1: The exploit clock is now measured in hours. Microsoft's sub-24-hour weaponisation finding, Google's AI-found RCE data and this week's edge-device zero-days (FortiMail, Cisco SD-WAN, NetScaler, Zimbra, MikroTik) all point the same way. Patch-on-schedule is no longer a strategy for internet-facing systems.
Signal 2: Agents are the new unmanaged identities. OpenAI's agents found and used leaked credentials, an AI agent chained zero-days against DIVD, and Delinea found that 42% of organisations lack automatic removal of AI access when a session ends. Add 543,000 live secrets on GitHub, and agents have plenty to work with.
Signal 3: IT intrusions keep landing in OT. ATNS, Warlock's water utility victim and Keio all show the same pattern: IT-side access points (SharePoint, business servers) threatening operational environments. Where segmentation held, operations kept running.
Signal 4: Privacy and AI regulation are converging. Connecticut's AI-plus-privacy package, the FTC's AI probe and the connected-car findings show that regulators are judging what your data flows and AI features actually do.
Your Call-to-Action
1. Run a 72-hour edge sprint. List every internet-facing appliance: email gateways, SD-WAN, VPN and ADC, routers and file-transfer platforms. Confirm owner, version and exposure for each. Apply FortiMail workarounds now, patch Cisco SD-WAN, NetScaler, Zimbra, MikroTik and Kiteworks, and run a compromise assessment on any device that was exposed before patching. Patching does not evict an attacker who is already in.
2. Put your AI agents on an identity diet. Inventory every agent and AI integration (including GitLab Duo, Bedrock AgentCore and Custom GPTs). Give each a named owner, least-privilege scopes, short-lived credentials, egress allow-lists and automatic de-provisioning at session end. Log agent actions as you would a privileged admin.
3. Kill your live secrets. Run secret scanning across public and private repos, then revoke and rotate rather than just delete. Prioritise cloud service-account keys.
4. Test the IT-to-OT path, not just the OT perimeter. Using the Warlock and ATNS patterns, run a tabletop: "SharePoint is compromised and EDR is disabled on 40 hosts. What stops lateral movement into OT, and who decides to isolate?" Validate against IEC 62443 zones and conduits and harden engineering workstations such as PCM600 hosts.
5. Get CIRCIA-ready before the rule lands. If you operate in a US critical infrastructure sector, dry-run your 72-hour incident and 24-hour ransom-payment reporting workflow with legal, communications and OT operations.
6. Audit SDKs and ID data retention. Review the third-party SDKs in your apps (the connected-car lesson) and your retention of identity document images (the Times Car lesson). If you operate in Connecticut, map SB 4 and SB 5 obligations, especially for geolocation, data brokers and AI in employment.
7. Brief your AI governance team on targeted phishing. TA419 shows AI policy staff are targets. Enforce phishing-resistant MFA and session-cookie protections for that group and for whoever runs your brand social accounts.
Grow Your Career This Week
Read the primary research: the Microsoft Digital Defense Report 2026 and the Mandiant/GTIG NetScaler analysis. Then turn one finding into a one-page board brief.
Build agentic AI security skills: study the DIVD and Bedrock AgentCore cases as threat-modelling exercises. Practitioners who can secure agents, not just LLM prompts, are in short supply.
Deepen OT standards fluency: learn the difference between IEC 62443-4-1, 4-2 and 3-3 certifications so you can challenge vendor claims in procurement.
Track the regulation curve: follow CISA's CIRCIA resources and the Connecticut AG's guidance. Leaders who can translate regulation into controls get promoted.
Ways in which I can help?
Whenever you are ready - I can help you with:
A: IT & OT Cybersecurity Advisory/Consulting services for businesses.
B: Security Awareness Training & Phishing Portal - Enroll your staff.
C - Securing Things Academy (STA) - trainings for IT & OT practitioners.
Reach out: info[at]securingthings[dot]com or DM me via LinkedIn.
D - Sponsor ST Newsletter - showcase your brand globally or subscribe.
Reach out: newsletter[at]securingthings[dot]com or DM via LinkedIn.
✉️ Sign-Off
The lesson is simple: speed and autonomy are now on both sides of the fight.
The leaders who win will know exactly what is acting in their environment, whether that's an appliance, an identity or an agent, and how fast they can contain it.
If this edition helped, forward it to one colleague who should be reading it. Reply and tell us which signal is keeping you up at night.
Stay curious, stay secure.
Stay safe. Stay curious. Thanks for reading - until the next edition!
It’s a Great Day to Start Securing Things for a Smart & Safer Society.
Take care and Best Regards,
Rate the newsletter content
If you are reading this online don’t forget to register; validate your email and request a login link to submit the poll.
Your feedback and input are invaluable to me as we work together to strengthen our cybersecurity defenses and create a safer and smarter digital society. Thank you for your trust and continued support.






