The Signal
Today’s operational signal is the range of routes to high-value access: a vulnerable collaboration platform, credential interception through an adversary-in-the-middle phishing operation, and an intrusion of a vulnerability-disclosure organization. These accounts should be assessed by access boundary and victim role rather than treated as one AI-related category. [1][2][3]
Must Know
Incident · Malwarebytes Labs
What happened
Arizona’s court system said attackers gained access after an employee clicked a malicious link in a phishing email and copied sensitive backup files involving protective orders and foster care cases. [4]
The court later said attackers copied more than 150,000 Foster Care Review Board recommendation reports covering current and past children’s-care cases dating back to 2010. [4]
Why it matters
The reports can include children’s information, names of involved parties, case materials, findings, and recommendations; the court said they do not contain addresses or telephone numbers. [4]
Identity · Arstechnica Security
What happened
Microsoft warned that attackers were exploiting critical CVE-2026-73570 in Zimbra Collaboration Suite to seek email backups and authentication credentials from vulnerable organizations. [1]
The vulnerability allows unauthenticated attackers to remotely issue operating-system commands. [1]
Why it matters
Shadowserver reported that scans found 274 separate compromised Zimbra instances. [1]
AI & Agents · Cyberscoop
What happened
Proofpoint attributed phishing campaigns to TA419, a China-aligned cyber espionage group, targeting U.S. AI policy experts and seeking access to cloud accounts at think tanks, universities, and law firms. [2]
The campaigns impersonated prominent officials, economists, and an Anthropic employee, using invitations about AI policy committees, export controls, supply chains, or military use of Claude models to start conversations. [2]
Why it matters
Proofpoint characterized the operation as adversary-in-the-middle phishing: victims could interact with genuine Microsoft infrastructure, enter passwords, complete multifactor authentication, and pass access checks while session information was captured. [2]
AI & Agents · Helpnetsecurity
What happened
An agentic AI-powered attack against the Dutch Institute for Vulnerability Disclosure on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer-support ticketing system. [3]
The two flaws reportedly enabled session hijacking, remote code execution, and privilege escalation from a Zammad user to root within seconds. [3]
Why it matters
After reaching root, the attackers were able to access other services and read additional information; the supplied excerpt truncates the remainder of this account. [3]
Also Worth Knowing
AI & Agents · Cyberscoop
What happened
OpenAI said it disrupted a coordinated campaign to extract reasoning capabilities from its models; it attributed a core activity cluster to individuals working for Moonshot AI, while noting that not all activity may be related. [5]
AI & Agents · Securityaffairs
What happened
Google announced Gemini 4 Argon, initially rolling it out to trusted cyber defenders through the Fairwind Program rather than releasing it directly to the public. [6]
The reported healthcare-software finding is a concrete evaluation point, but it does not establish that the model will identify comparable flaws in other settings. [6]
Exploitation · The Hacker News
What happened
Bitget confirmed that attackers stole $387.5 million and said the theft involved a zero-day flaw in third-party security products, based on ongoing findings from SlowMist. [7]
The account highlights a scoping boundary: incident review may need to include external security products alongside the affected exchange. [7]