Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws.

The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and defensive tooling.

The Pentagon confirmed that unauthorized users accessed a Defense Manpower Data Center information system through a file-sharing vulnerability. The incident affected 2.76 million living people and approximately 294,000 deceased individuals, with access reportedly occurring between October 2025 and July 2026 before DMDC discovered and patched the flaw on July 16.

The compromised files contained unencrypted information that could include names, Social Security numbers, birth dates, contact details, demographic data, and military occupational information. The Pentagon has reported no evidence of misuse, but the long-lived nature of identity data creates continuing fraud, phishing, impersonation, and counterintelligence risks; affected people are being offered one year of credit monitoring and identity-restoration services.

Apple Patches Actively Exploited CoreGraphics Zero-Day

Apple released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, an out-of-bounds write in CoreGraphics that may have been exploited in an extremely sophisticated attack against specifically targeted individuals. Processing a maliciously crafted file could trigger memory corruption and allow arbitrary code execution in the affected process.

The issue affects iPhone 11 and later, as well as supported iPad Pro, iPad Air, iPad, and iPad mini models. Apple credited Meta Product Security and fixed the flaw with improved bounds checking; users and fleet administrators should install the update immediately and verify deployment through mobile-device-management systems.

FortiMail Zero-Day Exploited in Attacks

Fortinet warned that CVE-2026-104286, a critical FortiMail vulnerability rated CVSS 9.8, is being exploited in the wild. The unauthenticated flaw combines path traversal and improper NULL-byte handling, enabling attackers to write files through crafted HTTP or HTTPS requests.

Affected releases include FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Administrators should disable IBE support or remove the management interface from public access while tracking fixed releases, preserve logs, and investigate Fortinet’s published file, account, cron, and network indicators for evidence of prior compromise.

Citrix NetScaler RCE Zero-Days Reportedly Exploited

Security firm watchTowr reported two undisclosed NetScaler remote-code-execution vulnerabilities found during forensic investigations and allegedly exploited in real-world attacks. At publication time, Citrix had not issued an advisory, CVE identifiers, affected-build details, exploitation prerequisites, patches, or indicators, so the reports represented a credible warning rather than a fully vendor-confirmed disclosure.

Organizations should inventory all NetScaler instances, reduce public exposure, restrict management access, preserve evidence, and inspect authentication events, sessions, configuration changes, files, processes, and outbound traffic. High-risk organizations unable to mitigate the exposure may need to isolate affected appliances under an approved continuity plan while monitoring Citrix’s bulletin channel for authoritative guidance.

Security Teams Can Monitor Claude Chats, Files and Agent Activity

Anthropic’s Claude Compliance API gives security teams visibility into Claude Enterprise conversations, uploaded files, projects, and supported Claude Code and Cowork session data, including prompts, responses, tool calls, skills, and transcript artifacts. The telemetry can feed DLP, SIEM, identity, eDiscovery, governance, and incident-response workflows.

Claude Platform customers receive administrative and system activity events, but not conversation prompts or model responses. Only a Claude Enterprise organization’s Primary Owner can enable the API and create access keys, while enterprises remain responsible for least privilege, connector review, key protection, retention controls, and clear AI-use policies.

OpenClaw Launches Enterprise Agent Platform

OpenClaw introduced OpenClaw Enterprise, a free MIT-licensed platform for centrally deploying and governing persistent AI agents. Its control plane supports multi-tenancy, sandboxing, granular permissions, lifecycle auditing, and model-based reviews intended to separate trusted services from untrusted agent workloads.

The project remains under development ahead of a planned 1.0 release and is recommended for internal pilots rather than unrestricted production use. Organizations can self-host it with Kubernetes and replace its models, sandboxes, and agent harnesses, but should independently test isolation, permissions, auditing, plugins, and secret handling before connecting critical systems.

Claude Code Agent Allegedly Deletes 48,000 Files

A Claude Code user reported that an agent deleted 48,218 live Windows project files and damaged the repository’s Git object store in 103 seconds while rebuilding a mirror. According to the user-provided verifier report, the deletion script mishandled 614 Windows directory junctions, traversed into the live project tree, and erased nested content.

The account is based on a Reddit post and has not been independently established as a Claude Code product defect. Even so, it illustrates why agents performing destructive operations need dry runs, explicit path manifests, reversible moves, least-privilege accounts, filesystem-restricted sandboxes, and human approval; Bash-based deletions may also fall outside checkpoint-based recovery.

AI Coding Agents Leak 13,000 Internal Screenshots

Glow Labs’ PixelLeak research found more than 13,000 internal screenshots from over 300 organizations in more than 900 public GitHub repositories. Coding agents reportedly created public repositories or used public release assets to host images for private pull requests, exposing credentials, customer records, internal dashboards, financial interfaces, and unreleased features.

The visibility gap was amplified because 93% of the cases involved repositories under employee usernames rather than corporate organizations, while the gitshot utility contributed to exposures at roughly one-third of affected companies. Defenders should inspect employees’ public repositories, gists, releases, and _gitshot tags; remove exposed material, rotate visible secrets, disable blanket agent approvals, and use authenticated private upload mechanisms such as GitHub CLI’s --attach option.

Custom GPTs Used to Deliver Remote Access Malware

Attackers are abusing ChatGPT Custom GPT pages as the first stage of a ClickFix chain involving sponsored search results, a fake service notice, a counterfeit CAPTCHA, and instructions to paste an obfuscated PowerShell command. Huntress examined at least 40 incidents linked to the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs.

The chain silently installs an MSI, uses signed Canon or Stardock executables for DLL sideloading, bypasses AMSI, executes .NET code in memory, and establishes persistence for a capable RAT. Defenders should hunt for PowerShell spawning msiexec, signed binaries running from unusual user-profile paths, modified adjacent DLLs, and suspicious scheduled tasks; users should never paste shell commands supplied by a CAPTCHA or AI-service page.

Apache HTTP Server 2.4.69 Fixes 20 Vulnerabilities

Apache HTTP Server 2.4.69 addresses 20 vulnerabilities—five moderate and 15 low—covering possible code execution, crashes, information exposure, request smuggling, and authentication problems. CVE-2026-63292 can cause a stack overflow through an oversized Host header in specific mod_vhost_alias configurations, while CVE-2026-42356 can cause an existing file to execute as CGI after particular internal redirects.

The reported code-execution paths are configuration-dependent and should not be interpreted as universal attacks against default Apache installations. Administrators should upgrade to 2.4.69 and prioritize systems using affected virtual-host settings, CGI redirects, WebDAV, digest authentication, HTTP/2, and proxy modules.

OpenSSL Flaw Can Leak Heap Memory in Plaintext

CVE-2026-84782 is a high-severity out-of-bounds read in OpenSSL’s DTLS handshake retransmission logic. When a handshake write is suspended, stale buffer-position state can cause a retransmission to include adjacent heap data as plaintext or crash the process, potentially exposing secrets or creating denial of service.

Fixed releases include OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with supported fixes also available for older branches. Security teams should inventory applications, appliances, VPNs, and embedded products using DTLS—including statically bundled copies that host package managers may miss—and update through the relevant software or operating-system vendor.

TeamViewer Fixes Five High-Severity Vulnerabilities

TeamViewer patched five high-severity flaws affecting Full Client, Host, and related components across Windows, Linux, and macOS. They include local path traversal and privilege escalation, a Windows installer race condition, unsafe link resolution, a heap overflow in .tvs recording playback, and CVE-2026-92370, an access-control flaw that could let an authenticated remote attacker bypass session restrictions and potentially execute code.

TeamViewer reported no known public exploitation and recommends upgrading to version 15.82 or the latest supported maintenance release. Administrators should also review remote-access policies and watch for unusual installer activity, malicious recording files, or unexpected modification of protected files.

Wireshark 4.6.9 Fixes 19 Security Flaws

Wireshark 4.6.9 and 4.4.19 address 19 documented vulnerabilities across dissectors, capture parsers, Sharkd, and configuration profiles. The leading issue, CVE-2026-96419, can crash Wireshark or potentially execute code when a victim imports a crafted profile; other flaws can trigger loops, leaks, crashes, and resource exhaustion through malformed traffic or files.

Wireshark reported no known exploitation, but analyst workstations routinely handle untrusted evidence. Teams should update immediately, include forensic workstations and automated capture pipelines in the rollout, and use sandboxes or disposable virtual machines for unknown profiles and packet captures until patching is complete.

AI Agent Finds Linux Kernel Bug Enabling Root Access

XBOW disclosed CVE-2026-72018, a high-severity out-of-bounds write in the Linux kernel’s DIBS loopback implementation for SMC-D. Although exploitation yielded only a constrained 16-byte zero write, researchers used it to overwrite fields in the kernel credential structure and obtain local root privileges without a separate information leak.

The demonstrated path requires CAP_NET_ADMIN and manipulates SMC-D handshake traffic through NFQUEUE; the proof of concept succeeded on 22 of 100 boots in a mitigation-disabled test environment. Administrators should deploy kernel updates containing the bounds check, reboot affected systems, and review containers and workloads granted CAP_NET_ADMIN.

Chrome Update Delivers 32 Security Fixes

Google released Chrome 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, fixing 32 vulnerabilities. The most severe, CVE-2026-102331, is a critical ANGLE buffer overflow, while high-severity fixes address V8 type confusion and buffer overflows, WebUI cross-site scripting, use-after-free conditions, authorization weaknesses, and UI misrepresentation.

Technical details for several bugs remain restricted while the update reaches users. Organizations should accelerate browser patching, verify that managed devices relaunch into the corrected build, and include long-running browser sessions and shared endpoints in compliance checks.

New Process Injection Bypasses Common EDR Signals

A proof-of-concept technique called console named-pipe injection avoids the familiar VirtualAllocEx and WriteProcessMemory sequence. It launches a console child such as nslookup.exe or netsh.exe, sends payload bytes through redirected standard input, finds the resulting buffer, changes its protection with VirtualProtectEx, and redirects a thread to execute it.

The method does not eliminate telemetry: memory scanning, executable permission changes, redirected handles, and thread-context manipulation remain observable. Detection engineering should correlate unusual console-process creation, binary-like stdin activity, remote memory-protection changes, and SetThreadContext behavior rather than depending on one high-signal API call.

Malware Hidden Inside Modified 7-Zip Installers

Researchers found OpenSUpdater—also detected as Snackarcin—embedded in modified 7-Zip self-extracting installer code. The package contains a genuine foobar2000 installer as a decoy, while a concealed call inside the rebuilt extraction component contacts attacker infrastructure and downloads DLLs plus an encrypted payload.

This is not a vulnerability in ordinary 7-Zip archives; it is deliberate tampering with open-source installer code. Analysts should inspect the extraction stub itself, not only its embedded program and configuration, and treat nested installers, mismatched publishers, odd version metadata, and padded certificates as reasons for deeper review.

Forgotten Microsoft 365 Accounts Breached

Proofpoint linked a password-spraying campaign called UNK_CondorFiltration to the TeamFiltration testing framework. The activity targeted 5,714 accounts across 28 Microsoft 365 tenants and resulted in seven confirmed compromises, all involving functional or service identities rather than personal employee accounts.

The compromised accounts were enabled, unmonitored, apparently lacked MFA, and in six cases were breached within seven minutes—consistent with shared or unchanged default passwords. Organizations should inventory non-human identities, assign owners, rotate inherited secrets, enforce MFA or workload identities, and alert on first-time access and broad password failures from distributed cloud infrastructure.

Antino Backdoor Runs Its C2 Through Microsoft 365

Cisco Talos identified Antino, a Rust backdoor that uses Microsoft Graph and stores its native command-and-control workflow in Outlook and OneDrive. The UAT-11587 campaign targeted government, defense, diplomatic, academic, and policy organizations, with Talos assessing links to China with high confidence.

Outlook carries commands and responses, while OneDrive handles registration, heartbeats, stolen data, and additional tools, helping the malware blend into trusted cloud traffic. Delivery involved tailored phishing, fake installers, Windows scripting, encrypted JavaScript, unsafe .NET processing, DLL sideloading, and abuse of Windows troubleshooting components for execution and persistence.

NeedyMantis Preserves Covert Access in Breached Networks

Microsoft uncovered NeedyMantis, a modular post-compromise framework used in a limited number of targeted intrusions affecting telecommunications, universities, medical nonprofits, intergovernmental bodies, and government contractors. Activity dates to at least October 2025, and Microsoft assesses that the malware is deployed after initial access rather than through a single consistent infection vector.

The framework uses DLL sideloading, custom encrypted archives, obfuscated loaders, WebSockets, and modular payload delivery. Defenders should hunt for traffic to corp.tripswithengine[.]com, unexpected DLL loads beside Poedit, curl, Vim, or TightVNC components, Impacket activity, and suspicious encoded data in HTTPS cookie headers; a detection should trigger a broader investigation into lateral movement and credential theft.

Attackers Abuse Microsoft Defender Exclusions

Attackers are using Microsoft Defender exclusions to shield malicious directories and file types while leaving antivirus visibly enabled. Because changing these settings requires administrative access, the behavior is a post-compromise evasion technique rather than an initial-entry mechanism.

Exclusions can be configured through PowerShell, WMI, Group Policy, or registry changes, and a policy can hide them from normal PowerShell queries by administrators and SYSTEM. Defenders should monitor the underlying exclusion registry locations, investigate broad drive or staging-directory exemptions, and correlate new exclusions with concealment-policy changes rather than accepting an empty query result as proof of a clean configuration.

SQL Server Used for Commands and Data Exfiltration

ThreatMon investigated an intrusion linked to a Viva Aerobus environment in which attackers used SQL Server’s xp_cmdshell to run Windows commands and encoded PowerShell. The same database connection carried exfiltrated files by splitting them into chunks, Base64-encoding the content, and returning it through query results.

An exposed attacker server revealed 17 tools for credential harvesting, SQL password testing, file movement, and lateral-movement preparation, along with collected source code and configuration material. Defenders should investigate unexpected xp_cmdshell activation, PowerShell or cmd.exe launched by SQL Server service accounts, unusual query output volumes, and any credentials or secrets that may have reached the exposed staging server.

GlobalProtect Flaw Fuels 2.4 Million Fraud Messages

Operation Master combined exploitation of CVE-2026-0257, a GlobalProtect authentication bypass, with SQL injection and large-scale invoice fraud. Investigators confirmed unauthorized sessions through seven gateways in four countries and data theft from at least nine database systems, including one reconstructed theft involving 24,558 debtor records.

The stolen data was used to personalize fraudulent bills sent through hijacked Microsoft 365 mailboxes, SMS gateways, and WhatsApp templates. Defenders should patch exposed gateways, inspect abnormal VPN sessions, restrict database command execution, monitor anomalous DNS exfiltration and cloud-mail activity, and scrutinize device-code approvals.

Teen Researcher Finds Critical Microsoft Titan Auth Flaw

A 16-year-old researcher known as Faav found that Microsoft’s internal Titan analytics service accepted manipulated JSON Web Tokens without cryptographically validating their signatures. An unsigned token using the user value admin mapped to a privileged local account and allowed unauthorized SQL queries without Microsoft credentials.

The researcher estimated that connected analytics systems held approximately 17.3 trillion rows, but stressed that this was a storage estimate containing historical, duplicated, and derived data—not 17.3 trillion unique people or confirmed leaked records. Microsoft restricted the endpoint four days after disclosure, awarded a $5,000 bounty, and found no reported evidence of malicious exploitation.

Alleged ShinyHunters Leader Arrested

Dutch police arrested a 24-year-old Amsterdam suspect whom FBI Director Kash Patel described as one of the alleged leaders of the ShinyHunters cyber-extortion group. The operation involved FBI support, seized storage devices, and an ongoing international investigation; a Rotterdam court ordered 90 days of pretrial detention.

Dutch authorities did not publicly name the suspect, while a private-sector executive identified him as security professional Pepijn van der Stap. ShinyHunters denied that he was associated with the group, so descriptions of his precise role remain allegations that have not been proven in court.

Windows 11 Update Causes Black Screens

Microsoft confirmed that updates released from August 27 onward can prevent Windows Explorer from launching after sign-in, leaving users with a black screen. The problem primarily affects Azure Virtual Desktop hosts using FSLogix and certain existing user profiles on Windows 11 26H1, 25H2, and 24H2.

Users can temporarily restore the shell by opening Task Manager and running explorer.exe. Enterprise administrators should deploy the matching Known Issue Rollback policy—KB5124006 for 26H1 or KB5124010 for 25H2 and 24H2—restart affected systems, and retain the rollback until Microsoft delivers a permanent fix.

The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News.