2026-W40 · 28 Sep – 04 Oct 2026 Makani Lab · Cyber Watch Operations · Force Protection · Professionals
BLUF — Edge devices drove the week: Citrix NetScaler intrusions began three weeks before the patch, and Cisco SD-WAN Manager and FortiMail joined KEV. Needs attention: the DMDC breach exposed SSNs and service records of 2.76 million people.
Cisco Talos named UAT-11587 on 30 Sep after ten months of espionage in Asia.
Mentions, 30d
2 this week
PACOM relevance
Victims include Philippine and Taiwanese government and defense organizations.
Notable TTPs
Tailored spear-phishing decoys
Five-stage chain staged on Cloudflare
Rust backdoor Antino with Outlook/OneDrive C2
Countermeasures
Alert on Graph and OneDrive calls from non-browser processes
Block HTA execution on endpoints
Share Talos indicators with partner liaisons
OperationsThreats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.
Citrix patched NetScaler zero-days CVE-2026-88771 and -88772 (in KEV) on 27 Sep. According to Mandiant, exploitation began 3 Sep and hit dozens of government, finance and telecom organizations.
So what: NetScaler fronts partner remote access; intrusions predate the patch.
Consider: Recommend checking NetScaler for compromise, not only patch status.
CISA added Cisco SD-WAN Manager CVE-2026-76504 (auth bypass to admin) and FortiMail CVE-2026-104286 (unauthenticated file write) to KEV on 30 Sep; both were zero-days.
So what: Both sit at the edge of partner networks.
Consider: Consider confirming with the S6 that neither is internet-exposed.
NORTHCOMVulns & exploits
UNCLASSIFIED · open-source reporting only · 6 sources · built 2026-10-04 06:54 HSTCyber Watch · 2026-W40 · page 1 of 2
UNCLASSIFIED
Force ProtectionWhat Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.
DMDC is notifying about 2.76 million people that attackers took SSNs, birth dates and service details from an unencrypted server, Oct 2025 to Jul 2026 (Malwarebytes, citing CNN). DOW offers 12 months of IDX monitoring.
So what: Guardians and families may be affected; the data aids targeted phishing.
Consider: Consider a commander's call note: IDX, credit freeze, IRS IP PIN.
NORTHCOMBreach & leaked dataOPSEC & personal security
According to Proofpoint, China-aligned TA419 posed as a former OSTP official, a former State economist and an Anthropic employee, inviting AI policy experts to a fake advisory committee and then phishing their Microsoft logins.
So what: Staff who work with think tanks get the same invitations.
Consider: Be aware that known names can be spoofed; verify out of band.
CISA added Apple CoreGraphics CVE-2026-86950 to KEV on 28 Sep. Malwarebytes found a fake iPhone Duo preorder page that runs the DarkSword exploit chain on unpatched iPhones when opened.
So what: Opening one link is enough on an unpatched personal iPhone.
Consider: Recommend updating Apple devices; real preorders open 16 Oct.
NORTHCOMApps & devicesVulns & exploits
Space & Cyber ProfessionalsContext for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.
Cyber Mastery Incentive Pay, part of CYBERCOM 2.0, launched 1 Oct. Documents reviewed by DefenseScoop show cuts of $100 to $1,000 a month in at least one branch.
So what: Pay changes bear on retaining cyber operators.
Consider: Recommend reviewing how C-MIP applies to USSF cyber billets.
A 31 Aug memo from the assistant secretary for cyber policy, obtained by Recorded Future News, set demands for CYBERCOM leadership after a cluster of suicide deaths.
So what: Cyber force wellness is now an OSD oversight issue.
Consider: Consider checking in on the welfare of cyber teams.