10 min read

this week in security — october 4 2026 edition

Millions of U.S. military staff hit by Pentagon data breach, ShinyHunters hackers arrested, Citrix NetScaler bugs mass-hacked, U.K. facial recognition trial fails, the U.S. spyware with no 'kill switch', Apple to revoke Mac "full disk access," a huge batch of passports exposed online, and more.
~ ~

To call this a busy week in security might be an understatement… There's a lot of news to blast through in this newsletter edition. Let's go!

an animated GIF of a character on Agents of Shield walking towards the camera and saying, "buckle up"
~ ~

Millions affected by data breach of U.S. military's human resources and identity unit
Federal News Network: Another major breach of U.S. government data has been confirmed. A file transfer system used by the Pentagon's records keeping unit, Defense Manpower Data Center, or DMDC, was compromised by a "small" but unspecified number of unauthorized people during a months-long breach between Oct. 2025 and July 2026. The data was unencrypted (I gasped when I read it) affects 2.8 million current and former military staff, and around 300,000 deceased people, including their names, dates of birth, Social Security numbers, demographic details, and information about their military service. DMDC holds some 60 million records on servicemembers, staff, and their families for getting entitlements and benefits, such as retirement and healthcare. DMDC also serves as an identity provider by issuing secure credentials, like logins and smart cards for military bases. Expect this to be another major counterintelligence nightmare, and so soon after the FBI's reported breach of agents' data… 
More: SecurityWeek | CNN | ABC News | Military Times | TechCrunch ($) | /r/AirForce

Dutch police arrest ShinyHunters member who planned murders; Jordanian authorities detain another member
Krebs on Security: Breathtakingly good reporting here by @briankrebs, who was first to break news that Dutch cybercrime police arrested a 24-year-old Amsterdam resident Pepijn van der Stap, a convicted and allegedly reformed cybercriminal... until he wasn't. He was arrested on Sept. 16 for membership of the ShinyHunters gang, but after his laptop was seized, Dutch cops found files relating to the planning of at least two would-be murders and was held in custody. After the Dutch confirmed its arrest, the FBI released a slightly weird chest-thumpy video saying that the feds were coming after ShinyHunters, but made no mention of the group's massive hack earlier in September that stole data on most of the bureau's agents and job applicants, which happened after Van der Stap was arrested. The hackers told me (among other journalists) that they have no plans to release the stolen FBI data and that this was never about extortion. Over the weekend, Jordanian authorities nabbed another long-standing ShinyHunters member, a teenager called Rey who Krebs spoke with last year, who is now helping the feds there identify other members of the gang, per Reuters ($). Is this the slow demise of the ShinyHunters hacking gang? The FBI is certainly hoping it is.
More: Politie | New York Times ($) | 404 Media ($) | CBS News | USA Today | NPR | @josephfcox | @FBIDirectorKash

Assume compromise as Citrix NetScaler bugs come under active attack 
CISA: Last week's brief newsletter mention of rumblings about Citrix NetScaler compromises has turned into a full-blown mass-compromise of customer systems in an ongoing hacking campaign. The two bugs under attack, now confirmed by Citrix, allow hackers to remotely plant code on an affected NetScaler system, defeat its defenses, and access the organization's wider network. It's not clear who's exploiting the bugs, but Mandiant points to evidence of "dozens" of compromises dating back to early September. (I've heard anecdotally that some have seen hacks dating back even earlier.) And that's just Mandiant's visibility — the number of affected organizations is likely far higher. At this point it's far easier to assume compromise and to take CISA's advice by preserving forensics and then patching. The good folks at IFIN have you covered with the freshest threat intel, which flagged evidence of another seemingly separate attack on NetScaler that's currently unraveling. #HugOps to remediators!
More: Citrix | HelpNeSecurity | Cybersecurity Dive | Dark Reading | Ars Technica | Bleeping Computer | Ars Technica | rud.is | ~this week in security~ | @GossiTheDog

The pardoned mechanic who wants your car to stop spying on you
Cowboy State Daily: Here's the long-read backstory of Matt Geouge, a mechanic who was pardoned during the current Trump administration for building a device that blocks in-vehicle telematics and data-collection tech from collecting reams of data about its drivers. This story looks at why and how motivations, and peeks inside the grubby world of vehicle data collection. (via @DeniseG)

LuaRocks discloses several server hacks in recent months
LuaRocks: The website that hosts the package manager for the Lua programming language, LuaRocks, was hacked several times from July through September, prompting the website to treat the incident as if everything had been compromised and to rebuild the server from scratch. A hacker's write-up explained how the compromise went down.

a screenshot from LuaRocks' post, which reads: "Because a remote code execution took place, we assume anything on the machine was read by the attacker: • Account information: usernames, email addresses and bcrypt password hashes; • API keys (all revoked); • Two-factor authentication secrets (all removed); • Tokens from linking GitHub accounts. These only granted access to your GitHub profile and email address, and have all been revoked through GitHub; • Session records, account activity logs, and the IP addresses and browser details stored in them; • Server credentials for third-party services, which have all been revoked"

After months-long U.K. test, results show facial recognition doesn't really work
The Guardian: According to a Freedom of Information request, a six-month trial of facial recognition tech across London's train stations cost over £300,000, used over 100 police hours, and led to one alert — a false positive — but no arrests. Police have nevertheless extended the trial anyway. 

U.K. spies warn universities to cut ties with China's spies
Financial Times ($): Sticking with the U.K. for a hot second… British domestic spy agency MI5 has warned universities to cut ties with China's General Technology Research Institute, which the spies say has "very strong ties" (*coughs loudly*) to the Chinese government. The highly unusual public alert [PDF] said that the research institute's primary purpose was funding research to improve Beijing's technical espionage abilities.

Hackers breached propulsion systems of U.S.-bound oil tanker
Bloomberg ($): The FBI and Coast Guard confirmed that the hackers who broke into an oil tanker last month while it was hurtling towards the U.S. coast had its propulsion systems compromised. Exactly how and by whom hasn't been disclosed — but it sparked major fears among military and intel officials. It probably doesn't take much to think of a worst-case scenario here, but note that tankers do have manual controls as backup.

U.S.-bought spyware doesn't have a 'kill switch' to prevent misuse
Wired ($): @kimzetter got an exclusive interview with Andrew Boyd, the chief executive of Paragon, a spyware maker that claims to be more ethical than other surveillance vendors (and yet has a $2 million contract with U.S. ICE immigration agency). Boyd revealed that the company did not bother to investigate alleged spyware abuses in Italy, and instead opted to cut off the country instead. Boyd also confirmed that the firm's spyware doesn't have a kill switch in the event of identified abuse. That's a big ol' yikes from me. Some more context via @vaspanagiotopoulos thread on Bluesky. 

Kim Zetter post on Bluesky: "Exclusive: Israeli spyware maker Paragon positions itself as more responsible than competitor NSO Group. But company's new US CEO says in candid interview that while they will cut off customers who misuse their spyware they have no ability to detect or investigate customer misuse, nor want ability"

Apple to limit 'Full Disk Access' citing abuse from AI agents
Daring Fireball: Apple said it will introduce "additional controls" for its Full Disk Access permissions on macOS after the company blamed AI agents and other software for abusing the feature to "sidestep" into a user's full cache of personal data. By putting the kibosh on this broad access, Apple is likely to roll out more granular controls in the near future. The move comes in the same week that a journalist said Meta's Muse AI agent gained access to his private text messages on his Mac without permission. Meta disputed this account, but then again Meta has burned up so much of people's trust over the years that it's a hard sell to believe anything the company actually claims.

MyChart maker Epic pauses product development to fix urgent security flaws
The New York Times ($): Judy Faulkner, the founder and chief executive of medical records giant Epic, which makes the MyChart software used across U.S. healthcare, told Modern Healthcare ($) that her company is pausing product development for the next six weeks to fix cybersecurity flaws discovered by Anthropic's AI model Mythos. Per the Times, the bugs could potentially allow hackers to tamper with medical records without leaving a trace. A rare move, but props to the company for prioritizing security fixes over pushing product features.

"Damn, we got hacked": Dutch Institute for Vulnerability Disclosure, aka DIVD, confirmed it had been hacked during a "loud and very very messy" attack by an autonomous AI agent. The attack left tons of evidence to help the nonprofit reconstruct the incident, and identified two previously undiscovered zero-days in the Zammad helpdesk and ticketing software as the root of the breach. Unsurprisingly, DIVD handled the incident well and were pretty candid in its details. (via DIVD, LinkedIn ($), DataBreaches.net)

Huge batch of passport data exposed: A huge database of publicly exposed documents belonging to a platform used by "all hotels in a certain country" is storing over 32 million records with passport information. This includes over 600,000 records relating to U.K. passport holders. (via LinkedIn ($))

Polish invoicing platform hacked: Hackers stole a "large part" of a Polish invoicing giant's master database, allowing the thieves to grab personal and sensitive information, including invoices, payment details, API keys, and more. The hacked company, Fakturownia, is used by more than half a million businesses in Poland and the breach is likely to affect a significant number of people. (via The Record, TVP World)

Fear the phone call: I published some words for Astonishing admin subscribers about why some of the world's most prolific cybercriminals rely on simple phone calls to breach companies, and why this kind of attack is incredibly effective and difficult to defend against. Don't underestimate the threat from a single phone call!

Meet the physical pen-testers: This was a really fun story about "authorized burglars" — aka physical pen-testers — who are paid to break into buildings, facilities, and other real-world places to stress-test their defenses. You'd be amazed at how far a fancy lanyard might get you! (via The Times ($), @jamesrball)

Apple fixes bug under attack: Apple released iOS, iPadOS, and macOS 26.7.1 to fix a graphics bug that the company says it's aware has been exploited in attacks. The older software is still used by some 75-80% of customers, so update today. Meta discovered the bugs, but it's unclear who's behind the attacks. Separately: Here's a fun bug that allows anyone to spoof an iCloud email address; and, Apple fixed a separate bug that allowed silent and "zero-click" access to an affected device. (via Apple, @datalocaltmp, ironPeak)

Cops can bypass phone restart counters: Phone unlocking firm Magnet Forensics claims it can bypass an iPhone's auto-restart feature to make it easier for cops to break in. Apple introduced the security feature in 2024 to prevent forensic devices used from accessing a user's data, as rebooting a phone puts it in a more secure state than after it's been unlocked after restarting. (via 404 Media ($), @lorenzofb)

Arizona hit by statewide data breach: Arizona's supreme court said hackers breached the state's court system and stole personal data, including Social Security numbers, of about 1.3 million people. A phishing email was reportedly used to gain access. Also: U.S. District of Columbia's health care finance unit inadvertently exposed personal information of residents between 2023 and July 2026. (via The Record, KJZZ, @jik)

Teenage ransomware hacker nabbed: A 16-year-old(!) hacker was arrested and indicted as the alleged leader of the KillSec ransomware gang, which hacked at least 500 organizations, including government agencies. (via Dark Reading)

We've all earned a bit of peace and quiet in the ~happy corner~.

A very exciting moment for @malwarejake, who found a rare technology fossil in the wild!

Speaking of, if you're too young to know what Windows XP is, then you can recreate the joys of the early-2000s with this web-based recreation, including what it feels like to "dial in" to the internet for the first time. (I can almost feel the static from the cathode ray monitor, he says, as he collapses into a heap of dust.)

an animated GIF of a Windows 95-style simulation that shows a dial-up window connecting to the internet, and then a web browser loading very slowly, line by line, as if to show how slow it's loading.

Meanwhile, @ciaranmartin seems to have awoken the singularity. 

Android users, rejoice: Google has a bunch of security features for its Advanced Protection offering, aimed at securing high-risk users from advanced cyberattacks. This includes intrusion logging, which can help defend against spyware and stalkerware with physical access to someone's phone. (via @evacide)

If you have a few minutes, check out this great Reddit AMA with six CISOs and security chiefs to talk about jobs, career advice, and offer some guidance for anyone who wants to get into the role. The thread also touches on important matters, like managing stress and being mindful of your (and others') mental health.

Also this week: Find out why a Pentagon login page has a microsite dedicated to a dog called Nick.

Bonus cybercat: This void floof has absolutely no patience for this year's ~spooky~ season.

And, lastly, this week:

da_667 post on Mastodon, which reads: "when you've seen enough IoT vulnerabilties that the fabric of the universe unravels," followed by a grey and white cat, sat on a comfy green blanket, staring into the camera lens slightly cross-eyed

Have good news to share? Get in touch! this@weekinsecurity.com.

This week's cyber cat is Zhu Long Bao, or BaoBao for short… and I've seen this face before… A ransomcat has appeared: "Hand over the treats, or I'm not telling you where I hid your YubiKey!" Thanks so much to Ivan T. for sending in!

BaoBao is a very cute grey and white-bellied kitty who can be seen here stood up on his hind legs, with their paws in front of him, as if to show they are asking for something.

That was... a crazy busy week. Thanks so much for making it through and reading this edition. Let's do this again next Sunday!

If you liked this newsletter, please feel free to share it on your social media, feeds, Slacks, emails, and more. It's really appreciated. And if you have any feedback for me, please get in touch — it's a joy hearing from you.

Take it easy, get some rest, and let's go into Monday ready and raring to go. We got this!

Peace,
@zackwhittaker