Monday 05 October 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🇩🇰 Breach exposes 8.8M Danish citizen records

💧 Hackers breach water utility via SharePoint

🔒 Microsoft fixes Exchange mailbox flaw

🎯 AI-found file server bug is now under attack

⚠️ FortiMail zero-day lets hackers write files unauthenticated

Plus: 💡 6 strategies & tactics, 🎁 8 more stories you might like, 🧰 6 tools, and 📚 5 papers.

EasyDMARC 3.0 connects the context and controls IT and Security need:

• Security: Strengthen DMARC and authentication. Detect spoofing, impersonation, and threats to your domains and infrastructure.

• Deliverability: Monitor sender behavior, reputation, receiver feedback, and delivery conditions.

• Compliance: Control configuration, changes, ownership, and policies with clear auditability.

Try EasyDMARC 3.0
🇩🇰 Breach exposes 8.8M Danish citizen records LINK
  • Denmark has confirmed unauthorized access to its Central Person Register (CPR), exposing personal records for about 8.8 million people, more than the country's population, because the database also holds deceased individuals and former residents who left.
  • The national registry itself was not directly compromised; instead, unknown actors abused a Danish company's legitimate, authorized ability to search the CPR system, retrieving names, residential addresses, and CPR numbers, though officials have not disclosed the technical method used.
  • Authorities detected irregular activity on October 2 and traced unauthorized searches back to September; the company's access is suspended, and because a CPR number is a central identifier, the data could fuel convincing phishing, vishing, smishing, impersonation, and identity-verification bypass.
💧 Hackers breach water utility via SharePoint LINK
  • A China-linked group is breaking into critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecom provider, a university and a regional government across Europe, Africa and Latin America, by exploiting Microsoft SharePoint flaws to deploy Warlock ransomware.
  • According to Symantec, the attacks exploit unpatched SharePoint servers, continuing from the 2025 "ToolShell" bugs into newer 2026 flaws, letting the hackers gain a foothold and, in one case, use a tool to disable security software on dozens of hosts before deploying the ransomware.
  • The campaign follows CISA's warning one month ago that six new SharePoint vulnerabilities are being exploited to give attackers wide access, and because SharePoint ties into Microsoft's authentication, a foothold there can let skilled hackers move deeper into victim networks.
🔒 Microsoft fixes Exchange mailbox flaw LINK
  • Microsoft has shipped a revised V2 security update for on-premises Exchange Server, dated September 2026, adding a fix for a mailbox flaw (CVE-2026-96940) that was missing from the original September package.
  • The revised update, published on Thursday, covers Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016; Exchange Online customers are not affected and need no server-side update.
  • Because Exchange 2016 and 2019 are now end of support, only organizations enrolled in Microsoft's Period 2 Extended Security Update program receive the fix, and Microsoft warns hybrid setups that patch only legacy servers can stay exposed even after mailboxes move to the cloud.
🎯 AI-found file server bug is now under attack LINK
  • Hackers have started exploiting a critical flaw in Rejetto HTTP File Server (HFS) to bypass login and run code on affected servers, security firm VulnCheck warned on Friday.
  • The bug (CVE-2026-61500, CVSS 9.3, critical) stems from HFS leaking outputs of its weak session-cookie generator to unauthenticated clients at login, letting an attacker collect a few login responses, rebuild the signing key, and forge valid administrator cookies.
  • With forged admin access, an attacker gains remote code execution through the server_code configuration feature; the exploitation so far is small-scale reconnaissance from a China Telecom IP, and version 3.2.1, released on July 13, contains the fix.
⚠️ FortiMail zero-day lets hackers write files unauthenticated LINK
  • Fortinet is warning that hackers are actively exploiting a zero-day in the FortiMail management interface, letting unauthenticated attackers write arbitrary files on vulnerable devices to run unauthorized code or commands.
  • The flaw, CVE-2026-104286, is rated critical (CVSS 9.8) and combines a path-traversal and NULL-byte handling weakness that lets an attacker write files on the underlying system by sending crafted HTTP or HTTPS requests, no login needed.
  • Patched versions aren't available yet across the affected FortiMail branches, so Fortinet says admins should disable IBE feature support or block internet access to the management interface, and has published indicators of compromise and log entries to spot compromised appliances.

For product teams moving at AI speed.

AI makes it easier to ship anything, even bad ideas. The hard part is knowing which ideas are worth building.

Jira Product Discovery brings your ideas, customer insights, and priorities into one place, so your team can decide what to ship and move forward with confidence.

Capture ideas, prioritize with evidence, and build living roadmaps your team can rally around—all while staying connected to delivery in Jira, so everyone can see what’s being built and why.

Better product decisions in the AI era.

💡 Strategies & Tactics

> Safari history database tags can reveal users’ browsing themes in forensic investigations: Safari quietly labels visited pages with Wikipedia-linked topic tags, giving forensic investigators a quick way to infer browsing themes across thousands of URLs.
> How RMM abuse gives attackers a way in that looks like business as usual: Attackers increasingly install legitimate remote management software to gain persistent access that looks like ordinary administrator work, so defenders must inventory which such tools are approved.
> Proving your MDR works: testing detection coverage and response effectiveness: Regularly test whether your managed detection and response provider's alerts actually fire against the specific threats facing your environment, since silence can mask blind spots.
> Bouncy Castle CVE-2026-71885 harvested the credential binding that authenticates agent-to-agent channels: A flaw in Bouncy Castle's encryption library let attackers forge identities and join secure group chats, so update to version 1.86.
> Google’s AI hacker finds 500+ XSS flaws and builds working exploit chains: Google's PageBreak proves each flaw it finds with a working exploit before alerting engineers, cutting false alarms that plague ordinary AI security scanners.
> 'The agent itself has become its own entity to secure': Bitdefender's new free Mac tool goes after flaws that let attackers fool AI models: Bitdefender's free Mac tool screens AI agents' actions against user rules before execution, blocking hidden instructions that trick agents into misusing files and credentials.

Other news & articles you might like

  • Glassworm supply chain attack hides malware inside VS Code color themes LINK
  • SMTP is the key: BPFDoor and AVERAT hitting the network edge LINK
  • Dell asks admins to patch max severity CSM flaws as soon as possible LINK
  • GitLab warns of critical RCE vulnerability in AI Gateway service LINK
  • Hackers abuse legitimate ScreenConnect tool to gain remote access through phishing LINK
  • Citrix patches NetScaler SAML zero-day exploited in attacks LINK
  • Vercel confirms KVM zero-day VM escape, awards researcher $50,000 LINK
  • Hackers built a Windows backdoor whose entire C2 lives inside Microsoft 365 LINK

🛠️ Trending tools

Replay QA Security Scan: runs automated pentests on web apps to catch injection flaws, broken access control, IDOR, and cross-tenant data exposure introduced by AI coding agents. LINK
chat-recall: searches your team's AI assistant conversations across five coding tools, strips passwords locally, and surfaces past work so you stop duplicating effort. LINK
Koreshield: screens customer messages, retrieved documents, and proposed tool calls before your AI support agent acts, catching prompt injection, data leaks, and unsafe actions with logged decisions. LINK
WebDecoy for Vercel: monitors crawlers and AI bots hitting your Vercel site via log drains, reporting user agents, paths, and IPs without code changes or redeploys. LINK
Pair2FA: a minimal 2FA authenticator with team sharing, letting workspaces manage shared accounts securely while members sign in with their own accounts and export data anytime. LINK
reverify: verifies AI-generated claims against ground truth using deterministic tools and evidence, with facts persisting across resets; includes MCP server and CLI. LINK

📚 Trending research papers

Chip reverse engineering can now reconstruct how a physical chip distributes its clock signal, revealing the designer's hidden layout choices, which aids competitive analysis and hardware security auditing, demonstrated on a commercial chip with open-sourced tools. LINK
Factory attack reconstruction turns raw sensor data from industrial control systems into a map of likely hacker actions, cutting false alarms by about 34% though the gains did not hold on two other datasets. LINK
Fast yes-no helpers that let AI agents make quick routing and safety calls in one shot were tested head to head, with the hosted option beating the open one on 9 of 11 decisions yet both failing at model routing. LINK
AI text fingerprinting stays detectable even after chunks of the text are deleted or reworded, letting companies reliably prove which model wrote a passage despite tampering that normally breaks such hidden markers. LINK
Misuse detectors for open models that tag harmful outputs like phishing with hidden signals can be completely defeated by attackers who tweak the model or reword its text, so they aren't reliable safeguards. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
★  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free