UNCLASSIFIED

Cyber Watch

2026-W40 · 28 Sep – 04 Oct 2026
Makani Lab · Cyber Watch
Operations · Force Protection · Professionals
BLUF — Edge devices drove the week: Citrix NetScaler intrusions began three weeks before the patch, and Cisco SD-WAN Manager and FortiMail joined KEV. Needs attention: the DMDC breach exposed SSNs and service records of 2.76 million people.

Last 7 days by lane · 345 items

Operations 215Force Protection 86Space & Cyber Professionals 44

Categories

Vulns & exploits
143
Breach & leaked data
73
AI & cyber
48
Supply chain
46
Malware & tooling
46

Rising terms · 7d vs prior

ransomware210 (+117.2)AI85 (+38.4)China40 (+23.6)healthcare35 (+20.7)energy26 (+17.2)

By the numbers

Known Exploited Vulnerabilities (KEV) added 4 (0 ransomware-linked) · leak-site victims 184 (90 PACOM AOR)

Leak-site victims by country · 30d

US
150
??
62
DE
23
BR
18
GB
16

Threat actor spotlight — UAT-11587 · China-nexus (per Cisco Talos) · Overlaps Jewelbug (Symantec)

Why now
Cisco Talos named UAT-11587 on 30 Sep after ten months of espionage in Asia.
Mentions, 30d
2 this week
PACOM relevance
Victims include Philippine and Taiwanese government and defense organizations.
Notable TTPs
  • Tailored spear-phishing decoys
  • Five-stage chain staged on Cloudflare
  • Rust backdoor Antino with Outlook/OneDrive C2
Countermeasures
  • Alert on Graph and OneDrive calls from non-browser processes
  • Block HTA execution on endpoints
  • Share Talos indicators with partner liaisons

OperationsThreats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.

CISA Cybersecurity Advisories · 2026-09-27
Citrix patched NetScaler zero-days CVE-2026-88771 and -88772 (in KEV) on 27 Sep. According to Mandiant, exploitation began 3 Sep and hit dozens of government, finance and telecom organizations.
So what: NetScaler fronts partner remote access; intrusions predate the patch.
Consider: Recommend checking NetScaler for compromise, not only patch status.
CYBERCOMVulns & exploits
CISA Cybersecurity Advisories · 2026-09-30
CISA added Cisco SD-WAN Manager CVE-2026-76504 (auth bypass to admin) and FortiMail CVE-2026-104286 (unauthenticated file write) to KEV on 30 Sep; both were zero-days.
So what: Both sit at the edge of partner networks.
Consider: Consider confirming with the S6 that neither is internet-exposed.
NORTHCOMVulns & exploits
UNCLASSIFIED · open-source reporting only · 6 sources · built 2026-10-04 06:54 HSTCyber Watch · 2026-W40 · page 1 of 2

UNCLASSIFIED

Force ProtectionWhat Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.

Malwarebytes Labs · 2026-10-01
DMDC is notifying about 2.76 million people that attackers took SSNs, birth dates and service details from an unencrypted server, Oct 2025 to Jul 2026 (Malwarebytes, citing CNN). DOW offers 12 months of IDX monitoring.
So what: Guardians and families may be affected; the data aids targeted phishing.
Consider: Consider a commander's call note: IDX, credit freeze, IRS IP PIN.
NORTHCOMBreach & leaked dataOPSEC & personal security
Nextgov/FCW — cybersecurity · 2026-09-30
According to Proofpoint, China-aligned TA419 posed as a former OSTP official, a former State economist and an Anthropic employee, inviting AI policy experts to a fake advisory committee and then phishing their Microsoft logins.
So what: Staff who work with think tanks get the same invitations.
Consider: Be aware that known names can be spoofed; verify out of band.
PACOMNORTHCOMSocial engineeringCloud & identityTA419
CISA Known Exploited Vulnerabilities · 2026-09-28
CISA added Apple CoreGraphics CVE-2026-86950 to KEV on 28 Sep. Malwarebytes found a fake iPhone Duo preorder page that runs the DarkSword exploit chain on unpatched iPhones when opened.
So what: Opening one link is enough on an unpatched personal iPhone.
Consider: Recommend updating Apple devices; real preorders open 16 Oct.
NORTHCOMApps & devicesVulns & exploits

Space & Cyber ProfessionalsContext for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.

DefenseScoop · 2026-10-01
Cyber Mastery Incentive Pay, part of CYBERCOM 2.0, launched 1 Oct. Documents reviewed by DefenseScoop show cuts of $100 to $1,000 a month in at least one branch.
So what: Pay changes bear on retaining cyber operators.
Consider: Recommend reviewing how C-MIP applies to USSF cyber billets.
CYBERCOMWorkforce & trainingStrategy & organization
The Record (Recorded Future) · 2026-09-30
A 31 Aug memo from the assistant secretary for cyber policy, obtained by Recorded Future News, set demands for CYBERCOM leadership after a cluster of suicide deaths.
So what: Cyber force wellness is now an OSD oversight issue.
Consider: Consider checking in on the welfare of cyber teams.
CYBERCOMWorkforce & trainingStrategy & organization

Watch list

  • KEV due 5 Oct: chained Zammad CVE-2026-102489 and -102490.
  • SDA PWSA transport launch from Vandenberg, 5 Oct.
  • Further Mandiant reporting on NetScaler attribution.
  • Fake iPhone Duo preorder lures before 16 Oct.

Recommendations (for awareness)

  • Recommend checking NetScaler for compromise, not only patch status.
  • Consider verifying SD-WAN Manager and FortiMail exposure with the S6.
  • Consider a commander's call note on the DMDC breach and Apple updates.
UNCLASSIFIED · open-source reporting only · 6 sources · built 2026-10-04 06:54 HSTCyber Watch · 2026-W40 · page 2 of 2