Top 5 Cybersecurity News

This week’s Top 5 Cybersecurity News for October 9, 2026 has one thing in common: nobody needed a new exploit. A credential campaign against Fortinet firewalls now locks owners out of their own devices and feeds ransomware affiliates. An open-source AI tool probed South Korean banks through employee-facing systems. ASOS customers received their breach announcement through the retailer’s own app. A Japanese university lost about 500 servers and, reportedly, its backups. And a China-linked group keeps turning unpatched SharePoint servers into ransomware at a water utility and a telecom provider. Five exposure layers, one shared condition: the weak point was something the victim already owned and had stopped watching.

1) FortiBleed Now Locks Owners Out of Their Own Firewalls

Top 5 Cybersecurity News illustration of a firewall administration console with unfamiliar admin accounts and a locked login prompt

FBI and Secret Service advisory of October 6: SOCRadar counts more than 86,000 compromised Fortinet FortiGate devices in 194 countries, and attackers sometimes delete or change original admin accounts to lock owners out.

On October 6, the FBI and US Secret Service published a joint advisory on FortiBleed, the credential-harvesting campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. There is no CVE. Attackers use reused and leaked credentials, credential stuffing and password spraying, then pull password hashes off compromised devices and crack them offline on GPU clusters. The agencies cite SOCRadar’s verification of 86,644 compromised devices across 194 countries. Two points are new. Attackers create admin accounts that were never on the device and sometimes delete or change the original ones, so legitimate owners lose access. And the intrusion chain has been seen as an entry point for ransomware affiliates linked to INC/Lynx and Payload.

Patching does nothing here, which is why this story can slip past a vulnerability-driven process. A device that was in the pool needs every administrative and VPN session terminated, every credential reset, and every account checked for names nobody remembers creating. The Record reports that stolen credentials were sorted and validated by the victim’s revenue and network structure, so mid-market organisations are ranked, not ignored. The lockout detail adds a practical problem: if you cannot log in, you cannot see which accounts exist, so out-of-band console access needs to be arranged before you need it.

DIESEC covered FortiBleed in the June 19 edition, when the story was a password-hash migration gap. Almost four months later the same operation supplies access to ransomware crews, and the FBI now names Payload alongside INC/Lynx. A credential campaign does not end when the vendor fixes how passwords are stored; it matures into an access market. Admin credentials on edge devices belong in an inventory with owners and expiry dates, because with no CVE, no scanner or patch tracker will ever raise a ticket for them.

Read more on: FBI IC3 Advisory · The Record

2) An Open-Source AI Tool Probes South Korean Banks Through Their Least-Watched Systems

Abstract view of many parallel automated probes reaching a bank's internal employee portal in a dark control room

A Korea Financial Security Institute official told The Herald Business that evidence points to ARTEX AI, an open-source penetration-testing tool, in the South Korean bank breaches; Shinhan Bank’s exposure is put at roughly 25,000 people.

A wave of breaches hit South Korean financial institutions from late September, with Shinhan Bank reporting first. An official at the Korea Financial Security Institute told The Herald Business that investigators traced attack IPs and server logs and found evidence pointing to ARTEX AI, an open-source, LLM-based autonomous penetration-testing system distributed through GitHub and aimed at Chinese-speaking users. The official was clear that a human directed it. Other outlets, including SBS and BleepingComputer, note that the banks and authorities had not formally confirmed the tool’s use. Every confirmed intrusion hit internal employee or partner-facing systems rather than customer apps. Shinhan’s exposure, through a loan-agent inquiry service, is put at roughly 25,000 people (25,729 per The Herald Business). KB Kookmin reported 119 records, Hana Bank 89, and BNK Busan Bank 11 contract workers. Police began a preliminary probe on October 2 and opened a formal investigation on October 6 with 28 investigators.

The institute’s own assessment is the useful part: attackers rotate IP addresses, but the method and the vulnerabilities they exploit stay the same, so blocking addresses is “emergency first aid.” Customer-facing banking had been hardened heavily; internal tools had been managed less rigorously, spread across so many management points that the banks struggled to find them. Direct theft of funds is considered unlikely, while leaked personal data feeds voice phishing. Regulators told financial firms to inspect every externally reachable system, including those that are not customer-facing. Any organisation with a partner portal, an HR or sales-support tool, or a legacy intranet exposed to the internet is in the same position.

Attribution is open, and the tool’s open-source status means its fingerprints say little about who used it. What matters is the economics. A defender’s quiet assumption is that obscure internal systems are safe because nobody will bother to look. A tool that tries every weakness against every reachable system removes the cost of bothering. The Herald Business adds a policy wrinkle: regulators have been relaxing network-separation rules for AI security testing since June, and some observers expect these breaches, which hit internal systems, to slow that push.

Read more on: Korea JoongAng Daily · The Herald Business

3) ASOS Customers Learn About the Breach From the Retailer’s Own App

Top 5 Cybersecurity News illustration of a smartphone showing an unexpected warning notification from a retail app

ASOS confirmed on October 6 that third-party customer-communication platforms were accessed without authorization after app users received a push notification reading “ASOS HACKED.”

On the morning of October 6, ASOS app users received a push notification reading “ASOS HACKED,” claiming the Snowflake instance had been fully compromised and pointing to a Telegram channel run by a group calling itself “Xuanye group.” ASOS confirmed that third-party platforms it uses to communicate with customers were accessed without authorization, and that basic personal information such as names and contact details may be exposed. It does not believe payment card data or passwords were affected, and it restricted access to the notification platforms. The company has not confirmed the Snowflake claim, and Snowflake told the press it had found no compromise of its platform so far. The number of affected customers is unknown. Press reports put the share price fall at around 10 percent.

Marketing and engagement platforms rarely appear on a crown-jewel list, yet they hold customer lists, device identifiers and send rights to every customer in the company’s own voice. Whoever controls them does not need to steal anything to cause damage; they can write the breach notification themselves, on the channel customers trust most. For a mid-market company the question is concrete: which third-party tools can push messages, emails or texts to your customers, who holds the logins, and is multi-factor authentication enforced on each? Treat the attacker’s claims as claims until ASOS or an independent source confirms them.

The usual vendor-risk question is what data a supplier stores. This incident adds a second one: what authority have you delegated to speak on your behalf? The attacker picked the channel where customers were most likely to read and believe the message, and ASOS itself had to tell customers not to click the link in the message. Concentration risk includes the right to talk to your customers, and few organisations track that right the way they track data.

Read more on: ASOS RNS Statement · BleepingComputer

4) Osaka Metropolitan University Loses About 500 Servers and, Reportedly, Its Backups

Rows of dark server racks in a university data center with most status lights off

Osaka Metropolitan University said on October 5 that a ransomware attack from outside is believed to have taken about 500 servers offline since October 2; classes were cancelled through October 8.

On October 2, about 500 servers and related systems at Osaka Metropolitan University stopped working. At a press conference on October 5 the university said it believes ransomware caused the failure and is investigating with outside specialists. The outage reached the internal network, email, academic administration, financial accounting, payroll, human resources and library services, according to The Record. Classes were cancelled through October 8, with in-person teaching planned to resume on October 9. The affected systems hold at least 130,000 records of personal information; the university has not confirmed that any data was stolen or whether a ransom was demanded. Japanese reporting carried by News On Japan, citing Yomiuri, says much of the backup data was encrypted as well. That detail comes from media, not from a university statement we reviewed.

What stayed up is as informative as what went down. Entrance-exam applications and enrollment, hosted on external servers, kept running, and so did the electronic medical records at the university hospital. Everything that shared the core infrastructure went dark together, including the systems that pay staff and keep the books. For a company, the downtime figure that matters is not how fast you can buy new servers but how quickly payroll, invoicing and email come back. That depends on whether the attacker could reach your backups from the same network and the same administrator accounts as production.

Ransomware changes recovery assumptions before it changes anything else. A backup that can be encrypted from the production environment is a second copy of the problem, not a recovery plan. The segments that were kept apart in Osaka stayed available, and that kind of separation is decided years before an incident. If your last restore test pre-dates your latest identity or network changes, the result of that test no longer tells you what would happen today.

Read more on: The Record · News On Japan

5) Warlock Turns Old SharePoint Flaws Into Ransomware at a Water Utility and a Telecom Provider

Top 5 Cybersecurity News illustration of an on-premises server room feeding a water treatment facility and a telecom tower

Symantec and Carbon Black report that Warlock, also tracked as Longlegs and Storm-2603, hit at least four organizations in two months, including a water utility and a telecom provider, through on-premises SharePoint flaws.

Symantec and Carbon Black reported (report published October 1) that the actor known as Warlock (also tracked as Longlegs and Storm-2603) attacked at least four organizations in two months across Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America: a water utility, a telecom provider, a regional government body and a university. Initial access came through on-premises SharePoint Server flaws, likely both older ones such as the 2025 ToolShell chain and newer ones. In the intrusion Symantec reconstructed, a web shell appeared on July 22. It collected the farm’s ASP.NET machine keys, which let the attackers forge signed payloads and run code inside SharePoint. A signed but vulnerable driver then disabled security software on at least 40 hosts in about two hours, and ransomware reached at least 33 hosts through the domain’s SYSVOL share.

The SYSVOL step deserves attention from any Active Directory shop. Ordinary domain replication delivered the ransomware, so no exploit was needed once the attackers had domain-level reach, and an unexpected executable in SYSVOL is a cheap thing to monitor for. Assessment (DIESEC, not from the Symantec report): because the web shell targets the farm’s machine keys, a patched server that was compromised earlier should be treated as a rebuild-and-rotate case, not just an update. Symantec itself says the approach depends on finding SharePoint servers that have not been properly patched or mitigated.

On-premises collaboration servers are slow to patch because the business has built workflows on them, and attackers plan around that lag. Symantec cannot say whether the focus on Portuguese- and Spanish-speaking countries reflects opportunism or deliberate tasking, and that uncertainty is the point: the target list is simply whichever servers are still exposed. Water and telecom operators in other regions, including Germany, run the same product. Whether a given one is exposed is an inventory question, not a geography question.

Read more on: Symantec and Carbon Black · The Hacker News

If this week tells us anything, it’s this:

Each of the five incidents turned on something the victim already owned: an administrator account on a firewall, internal portals nobody had mapped, a messaging platform with send rights to every customer, backups reachable from production, a SharePoint server nobody had retired. None of them needed a zero-day. What has changed is the cost of finding them. Automated tooling, credential brokers and ransomware affiliates have turned discovery into a commodity, so the old protection of being too obscure to bother with has largely expired.

The strategic question for a board or a CISO is therefore not which vulnerability is newest. It is which assets and accounts hold real authority while having no named owner and no review date. Those are the places where an attacker’s cost is lowest and your visibility is thinnest, and they sit in a different register from the one most vulnerability programmes look at.

If any of this raises questions about your own environment, you are welcome to get in touch with the DIESEC team.