Breach Watch Weekly: Legitimate Access Did the Damage (Oct 3-9)
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH WEEKLY
The week in breach intelligence for security leaders · October 3–9, 2026

The week in one line: Most of the damage this week came through access the victim had already granted or let leak: a partner's lawful query rights at Denmark's population register, stolen customer logins on a legacy Oracle Health server, reused credentials on Fortinet firewalls, and one phishing click inside Arizona's court system. The exploited flaws were real, but the common failure was a trusted path nobody was watching.

BY THE NUMBERS

31 distinct items across five daily editions (October 4 through 8), counted from each edition's lead, supporting and Also Notable slates, with follow-ups to earlier stories counted once. Reported exposure ran from hundreds of people to nearly 20 million: Oracle Health (nearly 20 million, a Texas Attorney General figure Oracle has not confirmed), Denmark's population register (about 8.8 million), Arizona's courts (about 1.3 million), Southern Company's Georgia Power and Alabama Power portal (about 400,000 accounts) and Denmark's DTU (up to 200,000 people, single source). Three newly reported flaws drew attack activity within days of disclosure: Citrix NetScaler CVE-2026-88779 (added to CISA's Known Exploited Vulnerabilities catalog on October 4), Rejetto HFS CVE-2026-61500, and Atlassian CVE-2026-21589, where exploitation attempts reached a honeypot about a day after the patch.

Compilation note: the window is the seven U.S. Eastern days ending October 9. Daily editions on file cover October 4 through 8; none ran on October 3. The October 8 edition was awaiting approval when this weekly was drafted.

Sector tally
  • Enterprise software and web applications: 6 (Atlassian, Microsoft Exchange, Rejetto HFS, Dell System Update, Chrome 155, WordPress plugins Ninja Forms and WPC Product Bundles)
  • Network edge and security products: 5 (Citrix NetScaler, FortiBleed, SonicWall SMA1000, Cisco Nexus, Fortra BoKS)
  • Cloud, developer and internet infrastructure: 5 (IDCF Cloud, the .gh/.sl/.as registry hijacks, two npm campaigns, FakeGit)
  • Threat actor activity and enforcement: 5 (Warlock ransomware, the reported ShinyHunters detention, the Flax Typhoon domain seizures, MonsterCloud charges, Midnight Mimosa)
  • Government and public sector: 3 (Denmark's CPR, Arizona's courts, the FBI jobs site contractor)
  • Healthcare: 2 (Oracle Health, Clover Health and AngMar)
  • Retail and manufacturing: 2 (ASOS, Advantest)
  • Financial services: 1 (South Korean banks)
  • Education: 1 (DTU)
  • Energy and utilities: 1 (Southern Company)
Four themes that repeated
  1. Legitimate access did the damage. Denmark's attackers borrowed a private company's approved search rights. The Oracle Health intruders logged in with customer credentials. FortiBleed operators sign in with leaked passwords and then create their own administrators. The FBI says a contractor's missed patch let ShinyHunters into its jobs site. None of this needed a novel exploit, and ordinary logs show each request looking normal.
  2. Edge devices were attacked in cycles, not events. Citrix shipped a third exploited NetScaler fix in days, with attempts against appliances that had just been updated. Fortinet administrators are being locked out of devices they thought they had cleaned. Cisco, SonicWall and Fortra each shipped critical fixes. A patch window that closes on Friday can reopen on Monday.
  3. Attackers moved in hours, disclosure moved in months. Atlassian exploitation attempts arrived roughly a day after the patch, and Rejetto's July fix was attacked in October. Yet the Oracle Health count, from a breach that began in January 2025, surfaced through a state filing in October 2026. Your detection clock matters more than the vendor's disclosure clock.
  4. The system nobody watched was the one that failed. A legacy Cerner server outside the cloud migration, copied court backups, one shared cloud region in Japan serving 495 customers, and country-code registries sitting above Google's own DNS all sat outside the controls their owners reasoned about.

The week's most significant incidents

1. Oracle Health's 2025 breach is now reported at nearly 20 million people

CRITICAL · HEALTHCARE DATA

A Texas Attorney General report, cited by Bloomberg, puts the number of people affected by the 2025 Oracle Health (Cerner) intrusion near 20 million. Oracle has not confirmed the total. Oracle's own notice to customers, as reported by SecurityWeek, says an attacker used stolen login details to reach a legacy server not yet moved to Oracle Cloud, after January 22, 2025, and copied data to a remote system. Per a sample notice filed in California, the data includes names, Social Security numbers and clinical details. Hospitals, not Oracle, were reportedly the extortion targets, and that claim rests on anonymous sources. The practical question for any CISO who hands regulated data to a platform vendor is which of your records still sit on the older parts of the vendor's estate. See the October 8 edition. Sources: SecurityWeek, eSecurity Planet, Techzine.

2. FortiBleed attackers are locking administrators out of Fortinet firewalls

CRITICAL · ACTIVE CAMPAIGN

An FBI advisory, issued jointly with the U.S. Secret Service according to Help Net Security and The Record, says the FortiBleed credential campaign that began with a June leak is still running. In some incidents the attackers create their own administrator accounts and then delete the original admins or change their passwords. SOCRadar counts 86,644 compromised devices; that is SOCRadar's estimate, not an independently verified figure. Reporting also describes offline cracking of password hashes taken from devices already reached. A password reset done after the June warning may have closed only part of the exposure, so audit every account on every device, review configuration changes, and treat any firewall that was internet-reachable as potentially accessed. See the October 7 edition. Sources: BleepingComputer, Help Net Security, The Record.

3. Attackers used a private company's lawful access to pull Denmark's population register

CRITICAL · CONFIRMED BREACH

Danish authorities say unauthorized parties extracted records on about 8.8 million people from the Central Person Register by abusing a private company's approved access, which has since been blocked. The incident occurred in September and the register's administrators became aware on October 2. Names, addresses and civil registration numbers are involved. How the company's access was obtained has not been disclosed, and no attacker has been named. The lesson is about ceilings: legitimate credentials used through a legitimate interface produce normal-looking logs one request at a time, so the control that matters is a per-partner volume limit with an alert that reaches a person. See the October 5 edition. Sources: BleepingComputer, The Hacker News, TechCrunch.

4. Citrix shipped a third exploited NetScaler fix in days, this time for SAML deployments

CRITICAL · ACTIVELY EXPLOITED

CVE-2026-88779 is a memory flaw in NetScaler ADC and Gateway appliances configured for SAML sign-in, rated CVSS 8.7 by BleepingComputer. Citrix says targeted attacks cause denial of service and is still investigating whether code execution is possible; researchers saw crafted requests containing shell commands, which shows attempted exploitation, not confirmed execution. CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 4 with an October 7 deadline for federal agencies. Fixed builds are 14.1-73.41 and 13.1-64.28, and customers who applied the earlier fixes must upgrade again. The process lesson outweighs the single CVE: if approving an edge-device patch takes a week, your window is longer than the attackers' release cycle. See the October 4 edition. Sources: BleepingComputer, SecurityWeek, Tenable.

5. One phishing click exposed data on about 1.3 million people in Arizona's courts

CRITICAL · CONFIRMED BREACH

The Arizona Supreme Court says the attack began when an employee clicked a malicious link. Court technology staff detected it on September 24 and shut it down about two hours later, with the intrusion stopped on a backup server where information had been copied. The affected people have unpaid fees, fines or restitution going back about 30 years. Reporting by SecurityWeek and Malwarebytes also describes nearly 30,000 protection orders and more than 150,000 foster care review reports, which raises the harm well beyond a typical fee database. No group has claimed it. Backups tend to be the oldest and largest copy of your data and the least watched; know what yours contain and who can reach them. See the October 6 edition. Sources: SecurityWeek, The Record, Fox10 Phoenix.

6. Atlassian's critical file-access flaw drew attack attempts about a day after the patch

HIGH · EXPLOITATION ATTEMPTS

CVE-2026-21589 allows unauthenticated file access across eight self-hosted Atlassian products and was rated CVSS 9.3 in SecurityWeek's coverage. Atlassian published fixes on October 6, watchTowr released a technical write-up, and the threat intelligence firm Previdian reported exploitation attempts against its honeypots a few hours later. Reports describe attempts, not confirmed compromises, and details on public proof-of-concept code differ by source. Treat the advisory day as the deadline for any internet-exposed Data Center or Server instance, and check access logs from October 6 onward. See the October 6 and October 7 editions. Sources: Help Net Security, BleepingComputer, SecurityWeek.

Also across the week

  • Google says attackers compromised the operators of the .gh, .sl and .as country-code registries, changed DNS records and obtained HTTPS certificates for Google domains and others. Google says its own systems were not compromised. Certificate Transparency monitoring is the control that shows this class of event. BleepingComputer
  • Symantec and The Hacker News describe the Longlegs group (also tracked as Storm-2603) using on-premises SharePoint flaws and a vulnerable driver to disable security software on about 40 hosts in roughly two hours before deploying Warlock ransomware. Symantec
  • The FBI says a contractor failed to apply an available patch on the PeopleSoft platform behind its jobs site, and removed the contractor. The attackers had claimed a zero-day, so the accounts differ. SecurityWeek
  • South Korea's Shinhan, KB Kookmin and Hana banks are investigating breaches of internal systems. Customer counts differ by outlet, and the suspected AI penetration-testing tool is analyst suspicion, not a finding. BleepingComputer
  • Attackers are forging administrator sessions on unpatched Rejetto HFS servers (CVE-2026-61500, CVSS 9.3), more than three months after the fix shipped. SecurityWeek
  • A ransomware attack took IDCF Cloud's East Japan Region 1 offline from October 7 for 495 companies and local governments, with no restoration date at the time of reporting. BleepingComputer
  • The FBI and Department of Justice seized seven domains tied to tooling used by the China-linked Flax Typhoon group, and Cisco patched critical Nexus NX-OS flaws it says have not been exploited. The Hacker News
  • Southern Company's Georgia Power and Alabama Power disclosed unauthorized access to a customer portal affecting about 400,000 accounts; entry method undisclosed. SecurityWeek
  • ASOS confirmed third-party platform access through its app notifications, later linked to social engineering. The attackers' Snowflake claim is unverified. BleepingComputer
  • Also noted: a reported ShinyHunters administrator detention (unnamed sources), SonicWall SMA1000 and Fortra BoKS critical fixes, Dell System Update and Exchange flaws, Chrome 155's 247 fixes, Advantest's ransomware confirmation, charges against the owner of ransomware negotiator MonsterCloud, and several single-source npm and GitHub malware campaigns. Breach Intelligence hub

What to watch next week

  • Oracle Health confirmation. Watch for Oracle or other state regulators to confirm or revise the 20 million figure. If you are a customer, ask which of your data sat on the unmigrated server.
  • More FortiBleed victim disclosures. The advisory suggests persistence through accounts and crackable hashes, so expect responders to publish more indicators. Finish account audits before they do.
  • Atlassian: attempts versus compromises. Look for confirmed victims and any CISA catalog action. Patch internet-exposed instances now.
  • Denmark's inquiry. The name of the company whose access was abused and how the access was obtained would show whether this was credential theft, a compromise or misuse.
  • NetScaler and Fortinet follow-ons. Three exploited NetScaler fixes in days suggest more researcher and attacker attention on edge authentication code.
  • IDCF Cloud recovery. The restoration date and any post-incident report will show how a shared cloud region fails for dependent customers.

FAQ

What was the biggest breach story of the week?
Oracle Health, where a Texas Attorney General report puts the 2025 breach near 20 million people. Oracle has not confirmed the figure, and the access reportedly came through stolen customer credentials on a legacy server.

What is FortiBleed and what changed this week?
FortiBleed is a credential campaign against Fortinet firewalls that began with a June leak. This week the FBI said attackers are creating their own administrator accounts and in some cases removing the originals, so a password reset alone may not end the exposure.

Which vulnerabilities should we patch first?
The ones with reported exploitation: Citrix NetScaler CVE-2026-88779 on SAML-configured appliances, Atlassian CVE-2026-21589 on self-hosted products, and Rejetto HFS CVE-2026-61500. Confirm build numbers on the device, not in the ticket.

How did attackers pull Denmark's population register?
They abused a private company's approved search access to the register and extracted records on about 8.8 million people. Authorities have not said how the access was obtained.

What was the common thread across the week?
Trusted access paths: partner query rights, stolen vendor and firewall credentials, a phishing click and a contractor's missed patch. Rate limits, account audits and tighter patch approval on edge devices address more of the week than any single product would.

CISO Platform Breach Intelligence Team

More from the community: the CISO Platform Breach Intelligence hub, and peer resources on vulnerability management, third-party risk, and ransomware.

Stay ahead of the next breach

Join a vendor-neutral community of senior security leaders who share what actually works.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion