Weekly Security Roundup — week ending Sunday, 4 October 2026

Security Stories

Warlock and China-Linked Infrastructure Campaign

A China-linked ransomware group called Warlock targeted a water utility, telecom operator, regional government body, and university via SharePoint vulnerabilities. Simultaneously, CVE-2026-104286 (FortiMail, CVSS 9.8) was confirmed actively exploited in the wild, and a critical authentication bypass in Rejetto HTTP File Server — identified by Anthropic's Mythos model — was weaponised by Chinese IP addresses targeting US and Japanese hosts within the same week. The pre-patch window has effectively collapsed.

NHS England — 38.23 Million Records Alleged for Sale

Threat actor "chara" claimed to be selling 38.23 million NHS England records including NHS IDs, names, dates of birth, addresses, GP practice details, COVID pass data, organ donation decisions, and appointment history. NHS England was previously breached in October 2024. The claim had not been confirmed or denied as of publication. If accurate, this is one of the largest exposures of sensitive UK personal data on record.

Ransomware — Operational Depth Over Volume

Rhysida claimed Electro Heat Sweden (2.55TB — full SolidWorks CAD vault, ABB settlement agreement, Hitachi/Scania contracts) and Skaff Group Lebanon (268GB — national ID scans, bank files, payroll source code). Wallstreet hit St. Francis Healthcare Systems of Hawaii ⚠️ and the FIFA World Cup 2034 Jeddah stadium contractor (17TB, 150K+ employee PII, full architectural design docs). incransom claimed SCADA credentials at Sangre de Cristo Electric Association, New Mexico, with an explicit threat of further disruptive action.

ShinyHunters — Three Headlines in One Week

Mandiant/GTIG published analysis of UNC6240 (ShinyHunters) actively targeting Oracle PeopleSoft infrastructure across the education sector. The group separately claimed 300 million French records for sale. A suspected member known as "Rey" was detained in Jordan and is cooperating with the FBI. Mandiant analysis.

GitLab AI Gateway RCE and the Expanding AI Attack Surface

GitLab warned of a critical unauthenticated RCE in its AI Gateway service — the component connecting GitLab coding tools to backend models. Apple simultaneously tightened macOS Full Disk Access controls citing AI agent risk. California signed AI worker protection laws restricting job-prediction AI and workplace surveillance.

Flock Surveillance Ruling and Fortra BoKS Patches

A US federal judge ruled Flock ALPR cameras constitute "indiscriminate mass surveillance"; Bernie Sanders proposed the Ban Flock Act. Separately, Fortra patched critical vulnerabilities in BoKS PAM covering authentication bypass, shell command execution, and memory corruption. PAM products are high-value targets that warrant immediate patching.


Key Themes

The pre-patch window has collapsed. China-linked actors exploited the Rejetto HFS authentication bypass within days of its identification. Warlock's SharePoint campaign and the FortiMail active exploitation reinforce that defenders must assume near-zero lag between public disclosure and active weaponisation.

Healthcare remains the most targeted sector globally. NHS England (38.23M), St. Francis Healthcare Hawaii, Booba Project cluster, Clinica Vesalio Peru, and the DTU breach all land in the same week. The combination of sensitive data and mission-critical operations makes healthcare uniquely exploitable.

AI is simultaneously the attacker's tool and the new attack surface. Anthropic's Mythos identified a vulnerability that was then actively exploited; GitLab's AI Gateway introduced an unauthenticated RCE; Apple is pre-emptively restricting agent permissions. The security implications of agentic AI are moving from theoretical to operational.


NCSC / CISA KEV

No new NCSC blog posts were published in the past seven days. No new CISA Known Exploited Vulnerabilities were added to the KEV catalogue this week.


HaveIBeenPwned Activity

One breach added this week: Medela (added 30 Sep 2026) — 423,947 accounts. Swiss breast pump and medical equipment company. Exposed data: email addresses, employers, job titles, names, phone numbers, physical addresses, salutations, support tickets.

Show Comments