this week in security — october 4 2026 edition
To call this a busy week in security might be an understatement… There's a lot of news to blast through in this newsletter edition. Let's go!

THIS WEEK, TL;DR
Millions affected by data breach of U.S. military's human resources and identity unit
Federal News Network: Another major breach of U.S. government data has been confirmed. A file transfer system used by the Pentagon's records keeping unit, Defense Manpower Data Center, or DMDC, was compromised by a "small" but unspecified number of unauthorized people during a months-long breach between Oct. 2025 and July 2026. The data was unencrypted (I gasped when I read it) affects 2.8 million current and former military staff, and around 300,000 deceased people, including their names, dates of birth, Social Security numbers, demographic details, and information about their military service. DMDC holds some 60 million records on servicemembers, staff, and their families for getting entitlements and benefits, such as retirement and healthcare. DMDC also serves as an identity provider by issuing secure credentials, like logins and smart cards for military bases. Expect this to be another major counterintelligence nightmare, and so soon after the FBI's reported breach of agents' data…
More: SecurityWeek | CNN | ABC News | Military Times | TechCrunch ($) | /r/AirForce
Dutch police arrest ShinyHunters member who planned murders; Jordanian authorities detain another member
Krebs on Security: Breathtakingly good reporting here by @briankrebs, who was first to break news that Dutch cybercrime police arrested a 24-year-old Amsterdam resident Pepijn van der Stap, a convicted and allegedly reformed cybercriminal... until he wasn't. He was arrested on Sept. 16 for membership of the ShinyHunters gang, but after his laptop was seized, Dutch cops found files relating to the planning of at least two would-be murders and was held in custody. After the Dutch confirmed its arrest, the FBI released a slightly weird chest-thumpy video saying that the feds were coming after ShinyHunters, but made no mention of the group's massive hack earlier in September that stole data on most of the bureau's agents and job applicants, which happened after Van der Stap was arrested. The hackers told me (among other journalists) that they have no plans to release the stolen FBI data and that this was never about extortion. Over the weekend, Jordanian authorities nabbed another long-standing ShinyHunters member, a teenager called Rey who Krebs spoke with last year, who is now helping the feds there identify other members of the gang, per Reuters ($). Is this the slow demise of the ShinyHunters hacking gang? The FBI is certainly hoping it is.
More: Politie | New York Times ($) | 404 Media ($) | CBS News | USA Today | NPR | @josephfcox | @FBIDirectorKash
Assume compromise as Citrix NetScaler bugs come under active attack
CISA: Last week's brief newsletter mention of rumblings about Citrix NetScaler compromises has turned into a full-blown mass-compromise of customer systems in an ongoing hacking campaign. The two bugs under attack, now confirmed by Citrix, allow hackers to remotely plant code on an affected NetScaler system, defeat its defenses, and access the organization's wider network. It's not clear who's exploiting the bugs, but Mandiant points to evidence of "dozens" of compromises dating back to early September. (I've heard anecdotally that some have seen hacks dating back even earlier.) And that's just Mandiant's visibility — the number of affected organizations is likely far higher. At this point it's far easier to assume compromise and to take CISA's advice by preserving forensics and then patching. The good folks at IFIN have you covered with the freshest threat intel, which flagged evidence of another seemingly separate attack on NetScaler that's currently unraveling. #HugOps to remediators!
More: Citrix | HelpNeSecurity | Cybersecurity Dive | Dark Reading | Ars Technica | Bleeping Computer | Ars Technica | rud.is | ~this week in security~ | @GossiTheDog
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
You can also submit a one-time tip to show your support, or consider gifting a paid subscription.
~ ~
THE STUFF YOU MIGHT'VE MISSED
The pardoned mechanic who wants your car to stop spying on you
Cowboy State Daily: Here's the long-read backstory of Matt Geouge, a mechanic who was pardoned during the current Trump administration for building a device that blocks in-vehicle telematics and data-collection tech from collecting reams of data about its drivers. This story looks at why and how motivations, and peeks inside the grubby world of vehicle data collection. (via @DeniseG)
LuaRocks discloses several server hacks in recent months
LuaRocks: The website that hosts the package manager for the Lua programming language, LuaRocks, was hacked several times from July through September, prompting the website to treat the incident as if everything had been compromised and to rebuild the server from scratch. A hacker's write-up explained how the compromise went down.

After months-long U.K. test, results show facial recognition doesn't really work
The Guardian: According to a Freedom of Information request, a six-month trial of facial recognition tech across London's train stations cost over £300,000, used over 100 police hours, and led to one alert — a false positive — but no arrests. Police have nevertheless extended the trial anyway.
U.K. spies warn universities to cut ties with China's spies
Financial Times ($): Sticking with the U.K. for a hot second… British domestic spy agency MI5 has warned universities to cut ties with China's General Technology Research Institute, which the spies say has "very strong ties" (*coughs loudly*) to the Chinese government. The highly unusual public alert [PDF] said that the research institute's primary purpose was funding research to improve Beijing's technical espionage abilities.
Hackers breached propulsion systems of U.S.-bound oil tanker
Bloomberg ($): The FBI and Coast Guard confirmed that the hackers who broke into an oil tanker last month while it was hurtling towards the U.S. coast had its propulsion systems compromised. Exactly how and by whom hasn't been disclosed — but it sparked major fears among military and intel officials. It probably doesn't take much to think of a worst-case scenario here, but note that tankers do have manual controls as backup.
U.S.-bought spyware doesn't have a 'kill switch' to prevent misuse
Wired ($): @kimzetter got an exclusive interview with Andrew Boyd, the chief executive of Paragon, a spyware maker that claims to be more ethical than other surveillance vendors (and yet has a $2 million contract with U.S. ICE immigration agency). Boyd revealed that the company did not bother to investigate alleged spyware abuses in Italy, and instead opted to cut off the country instead. Boyd also confirmed that the firm's spyware doesn't have a kill switch in the event of identified abuse. That's a big ol' yikes from me. Some more context via @vaspanagiotopoulos thread on Bluesky.

Apple to limit 'Full Disk Access' citing abuse from AI agents
Daring Fireball: Apple said it will introduce "additional controls" for its Full Disk Access permissions on macOS after the company blamed AI agents and other software for abusing the feature to "sidestep" into a user's full cache of personal data. By putting the kibosh on this broad access, Apple is likely to roll out more granular controls in the near future. The move comes in the same week that a journalist said Meta's Muse AI agent gained access to his private text messages on his Mac without permission. Meta disputed this account, but then again Meta has burned up so much of people's trust over the years that it's a hard sell to believe anything the company actually claims.
MyChart maker Epic pauses product development to fix urgent security flaws
The New York Times ($): Judy Faulkner, the founder and chief executive of medical records giant Epic, which makes the MyChart software used across U.S. healthcare, told Modern Healthcare ($) that her company is pausing product development for the next six weeks to fix cybersecurity flaws discovered by Anthropic's AI model Mythos. Per the Times, the bugs could potentially allow hackers to tamper with medical records without leaving a trace. A rare move, but props to the company for prioritizing security fixes over pushing product features.
~ ~
OTHER NEWSY NUGGETS
"Damn, we got hacked": Dutch Institute for Vulnerability Disclosure, aka DIVD, confirmed it had been hacked during a "loud and very very messy" attack by an autonomous AI agent. The attack left tons of evidence to help the nonprofit reconstruct the incident, and identified two previously undiscovered zero-days in the Zammad helpdesk and ticketing software as the root of the breach. Unsurprisingly, DIVD handled the incident well and were pretty candid in its details. (via DIVD, LinkedIn ($), DataBreaches.net)
Huge batch of passport data exposed: A huge database of publicly exposed documents belonging to a platform used by "all hotels in a certain country" is storing over 32 million records with passport information. This includes over 600,000 records relating to U.K. passport holders. (via LinkedIn ($))
Polish invoicing platform hacked: Hackers stole a "large part" of a Polish invoicing giant's master database, allowing the thieves to grab personal and sensitive information, including invoices, payment details, API keys, and more. The hacked company, Fakturownia, is used by more than half a million businesses in Poland and the breach is likely to affect a significant number of people. (via The Record, TVP World)
Fear the phone call: I published some words for Astonishing admin subscribers about why some of the world's most prolific cybercriminals rely on simple phone calls to breach companies, and why this kind of attack is incredibly effective and difficult to defend against. Don't underestimate the threat from a single phone call!
Meet the physical pen-testers: This was a really fun story about "authorized burglars" — aka physical pen-testers — who are paid to break into buildings, facilities, and other real-world places to stress-test their defenses. You'd be amazed at how far a fancy lanyard might get you! (via The Times ($), @jamesrball)
Apple fixes bug under attack: Apple released iOS, iPadOS, and macOS 26.7.1 to fix a graphics bug that the company says it's aware has been exploited in attacks. The older software is still used by some 75-80% of customers, so update today. Meta discovered the bugs, but it's unclear who's behind the attacks. Separately: Here's a fun bug that allows anyone to spoof an iCloud email address; and, Apple fixed a separate bug that allowed silent and "zero-click" access to an affected device. (via Apple, @datalocaltmp, ironPeak)
Cops can bypass phone restart counters: Phone unlocking firm Magnet Forensics claims it can bypass an iPhone's auto-restart feature to make it easier for cops to break in. Apple introduced the security feature in 2024 to prevent forensic devices used from accessing a user's data, as rebooting a phone puts it in a more secure state than after it's been unlocked after restarting. (via 404 Media ($), @lorenzofb)
Arizona hit by statewide data breach: Arizona's supreme court said hackers breached the state's court system and stole personal data, including Social Security numbers, of about 1.3 million people. A phishing email was reportedly used to gain access. Also: U.S. District of Columbia's health care finance unit inadvertently exposed personal information of residents between 2023 and July 2026. (via The Record, KJZZ, @jik)
Teenage ransomware hacker nabbed: A 16-year-old(!) hacker was arrested and indicted as the alleged leader of the KillSec ransomware gang, which hacked at least 500 organizations, including government agencies. (via Dark Reading)
~ ~
THE HAPPY CORNER
We've all earned a bit of peace and quiet in the ~happy corner~.
A very exciting moment for @malwarejake, who found a rare technology fossil in the wild!
Speaking of, if you're too young to know what Windows XP is, then you can recreate the joys of the early-2000s with this web-based recreation, including what it feels like to "dial in" to the internet for the first time. (I can almost feel the static from the cathode ray monitor, he says, as he collapses into a heap of dust.)

Meanwhile, @ciaranmartin seems to have awoken the singularity.
Android users, rejoice: Google has a bunch of security features for its Advanced Protection offering, aimed at securing high-risk users from advanced cyberattacks. This includes intrusion logging, which can help defend against spyware and stalkerware with physical access to someone's phone. (via @evacide)
If you have a few minutes, check out this great Reddit AMA with six CISOs and security chiefs to talk about jobs, career advice, and offer some guidance for anyone who wants to get into the role. The thread also touches on important matters, like managing stress and being mindful of your (and others') mental health.
Also this week: Find out why a Pentagon login page has a microsite dedicated to a dog called Nick.
Bonus cybercat: This void floof has absolutely no patience for this year's ~spooky~ season.
And, lastly, this week:

Have good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
This week's cyber cat is Zhu Long Bao, or BaoBao for short… and I've seen this face before… A ransomcat has appeared: "Hand over the treats, or I'm not telling you where I hid your YubiKey!" Thanks so much to Ivan T. for sending in!
🐈 Send in your cyber cats! 🐈⬛ Drop me an email with a photo of your cat (or non-feline friend) and their name and they'll appear in a later newsletter!
~ ~
SUGGESTION BOX
That was... a crazy busy week. Thanks so much for making it through and reading this edition. Let's do this again next Sunday!
If you liked this newsletter, please feel free to share it on your social media, feeds, Slacks, emails, and more. It's really appreciated. And if you have any feedback for me, please get in touch — it's a joy hearing from you.
Take it easy, get some rest, and let's go into Monday ready and raring to go. We got this!
Peace,
@zackwhittaker