Here are today’s top cybersecurity stories for Thursday, October 1, 2026.
Police Dismantle KillSec Ransomware Gang Allegedly Led by a 16-Year-Old
Operation KillSwitch, carried out on September 30, seized the KillSec leak site and infrastructure with help from ten countries, Europol, Eurojust, Bitdefender, and Group-IB. Authorities identified a 16-year-old as the main operator, made three provisional arrests, and recovered about 110 terabytes of stolen data. Investigators know of roughly 500 successful attacks. BleepingComputer
Zammad Zero-Days Exploited in AI-Powered Attack on Dutch Vulnerability Disclosure Group
The Dutch Institute for Vulnerability Disclosure reports an agentic AI attack on September 21 chained CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4. The flaws allowed session hijacking, remote code execution, and privilege escalation to root on its Zammad helpdesk. Network segmentation stopped deeper access, though some data was exfiltrated. DIVD advises upgrading to Zammad 7 or taking instances offline. SecurityWeek
WordPress Backdoor Rebuilds Itself After Cleanup
Sucuri researchers describe a WordPress backdoor named SC with eight persistence points, including a .user.ini file, drop-ins, a must-use plugin, a theme file, and System V shared memory. Deleting one component triggers the others to rewrite it. The malware hides from admin screens, creates hidden administrator accounts, injects JavaScript aimed at visitors, and uses the Ethereum blockchain for command and control. The delivery method is unknown. The Hacker News
Chinese Warlock Ransomware Group Hits Spanish and Portuguese Organizations
Symantec reports the actor, also tracked as Longlegs and Storm-2603, struck a water utility, a telecommunications provider, a regional government body, and a university across Africa, Europe, and Latin America over the past two months. Initial access comes through Microsoft SharePoint flaws, including the ToolShell chain. The group uses DLL sideloading, vulnerable drivers, VS Code remote tunneling, and ransomware staged in Active Directory SYSVOL shares. Dark Reading
MetaMask Discloses Security Incident and Exits Affected Ethereum Validators
MetaMask reports an ongoing incident affecting part of its infrastructure and says it has found no immediate threat to wallets. The company is exiting affected validators in its non-custodial Ethereum staking operations on Lido. Exits are expected to finish by October 7, and MetaMask does not manage withdrawal keys for clients’ staked assets. The Hacker News
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders
Google released Gemini 4 Argon first to trusted defenders through its Fairwind Program. The model outperforms its predecessor at finding flaws, mapping attack surfaces, and building proofs of concept. Google says it found a previously unknown critical vulnerability in healthcare software used by hospitals worldwide and has not named the product. The Hacker News
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI says a coordinated campaign began July 1 and used adversarial distillation to reproduce protected model reasoning. Activity spiked July 24 and 25 with 16,000 attempted requests from more than 4,000 users, and OpenAI fully disrupted it on July 28. The company attributes a core cluster to individuals associated with Moonshot AI and says it closed a replay pathway for encrypted reasoning. The Hacker News
Kiteworks Patches Maximum-Severity Email Protection Gateway Flaw
Kiteworks fixed 126 vulnerabilities, including 11 critical flaws. CVE-2026-54154 allows unauthenticated code execution and root control of the Email Protection Gateway through path traversal and missing authentication. All releases before 9.4.1 are affected. The flaw came through the company’s bug bounty program, and no exploitation is confirmed. BleepingComputer
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing
Microsoft detected phishing campaigns in July posing as meeting invitations, PDF reader updates, Zoom installers, and e-cards. Victims run signed MSP360 installers hosted on Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. The installer then uses PowerShell to add ConnectWise ScreenConnect as a second access channel, and Microsoft saw other attacks substituting Faronics Deploy Agent. The Hacker News
Stay tuned for today’s in-depth analysis posts.






