Opens in a new tab

Security Roundup, October 1: Cisco SD-WAN Zero-Day and Bitget Theft

  • Home
  • Blog
  • Security Roundup, October 1: Cisco SD-WAN Zero-Day and Bitget Theft
Security roundup October 1 covers a glowing red data breach striking a shielded server

Cisco shipped emergency patches on October 1 for a critical SD-WAN flaw that is already being exploited in the wild, while the Bitget cryptocurrency exchange confirmed a $387.5 million theft tied to a third-party zero-day. Researchers from Google also warned that vulnerabilities surfaced by AI tools are being weaponized faster than ever, and a separate breach exposed Pentagon personnel records for more than 3 million people.

What Is the Cisco Catalyst SD-WAN Manager Zero-Day?

Cisco released urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, that attackers are actively exploiting. The flaw carries a CVSS score of 9.8 and lets a remote, unauthenticated attacker reach the system as the admin user. The bug stems from improper handling of URI encoding in HTTP requests to the API, which lets a crafted request slip past authentication and hit a restricted endpoint.

All Catalyst SD-WAN Manager deployments are affected, regardless of configuration, and Cisco says there are no workarounds. Fixed releases cover versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Cisco-managed SD-WAN environments were patched automatically. The U.S. Cybersecurity and Infrastructure Security Agency added the defect to its Known Exploited Vulnerabilities catalog and gave federal agencies a three-day patch deadline.

Source: SecurityWeek.

How Did the Bitget $387.5 Million Theft Happen?

Cryptocurrency exchange Bitget confirmed that a zero-day in a third-party service provider led to the theft of roughly $387.5 million in digital assets. Details from the exchange’s investigation point to a supply-chain compromise that gave attackers access to wallet infrastructure tied to customer funds.

Bitget said the affected systems have been contained and that the exchange is working with blockchain analytics firms and law enforcement to trace the stolen funds. The exchange has historically maintained a reserve fund to cover user balances in the event of platform-level losses, and the announcement stressed that customer holdings are being covered.

Source: The Hacker News.

Are AI-Found Vulnerabilities Being Exploited Faster?

Research from Google Threat Intelligence Group shows that vulnerabilities discovered by AI tools are being weaponized quickly, with attackers exploiting one AI-found flaw within four days of public disclosure. The researchers reviewed disclosure and exploitation data from January 2025 through August 2026 and found the volume of disclosed CVEs doubled over the period, from 5,045 in January 2026 to 10,740 in August 2026. Only about 0.23% of disclosed vulnerabilities, or roughly one in 431, were seen exploited in the wild.

Exploitation is growing even though it remains rare. Google recorded 141 exploited vulnerabilities between January and August 2026, more than the 127 seen across all of 2025. Zero-day exploitation rose from an average of 8 per month in 2025 to 11 per month in 2026, and most of the growth is coming from n-days, older flaws that attackers are now racing to weaponize using large language models to study patches, advisories, and proof-of-concept code.

Google also reported that AI-discovered bugs tend to be more severe. Half of the vulnerabilities Google classified as likely AI-found lead to remote code execution, compared with 26% of flaws found by other means. AI-found bugs are also less likely to be rated low risk.

Source: Help Net Security.

What Can Google Gemini 4 Argon Do for Security Teams?

Google introduced Gemini 4 Argon, a frontier model designed to locate, validate, and patch critical software vulnerabilities with minimal human input. Google is rolling the model out first to trusted cyber defenders through its Fairwind Program, with broader access coming later for paid API customers and Google AI Ultra subscribers, and a final stage for consumers. The model can write up to 1 million tokens in a single response, giving it room to reason over very large code bases.

Early results include a critical vulnerability in healthcare software used by hospitals worldwide that earlier frontier models had missed, and internal work at Google that freed more than 300 tebibytes of memory across data centers and replaced 32,000 lines of SIMD code in the libgav1 video decoder with Rust code that runs 2.7 times faster. Security vendor Wiz is also using Argon through its Scan for Good program to find and fix high-risk exposures in critical public infrastructure at no charge.

Source: Help Net Security.

What Is the Citrix NetScaler Post-Exploitation Payload?

Security researchers detailed a post-exploitation payload targeting Citrix NetScaler that creates a superuser account on compromised appliances and hides a web shell behind URLs styled to look like ordinary CSS requests. The technique makes the malicious traffic blend in with normal browsing patterns, making it harder to spot in logs.

Admins who run NetScaler ADC or NetScaler Gateway appliances should review authentication logs for new or unexpected local accounts, audit management interface access, and confirm that devices are running the latest firmware. Organizations that suspect compromise should rotate administrative credentials, review configuration exports, and inspect the management plane for unauthorized changes.

Source: The Hacker News.

What Was Stolen in the Pentagon Personnel Records Breach?

The Pentagon’s Defense Manpower Data Center is notifying more than 3 million people that their personnel data was stolen after attackers exploited a vulnerability in the agency’s file-sharing systems. The breach ran from October 2025 to July 2026, and the stolen data includes Social Security numbers, names, dates of birth, contact details, sex, race, and military personnel information. The total includes nearly 2.8 million living individuals and 294,000 deceased individuals.

The DMDC said it initiated privacy and cybersecurity incident response procedures as soon as the vulnerability was discovered and is offering 12 months of free credit monitoring through IDX to affected individuals, who must enroll by August 19, 2027. Service members, veterans, and family members connected to the Defense Manpower Data Center should enroll in the credit monitoring offer, place fraud alerts with the major credit bureaus, and watch for phishing attempts that reference military or benefit information.

Source: BleepingComputer.

What to Do This Week

  • Patch every Cisco Catalyst SD-WAN Manager appliance to a fixed release immediately. The bug is under active exploitation and there are no workarounds.
  • Review NetScaler ADC and Gateway appliances for unexpected local user accounts and audit the management interface for suspicious activity.
  • Treat any third-party service connected to crypto custody or wallet infrastructure as part of your attack surface and confirm vendors are running patched, monitored systems.
  • Watch for indicators of compromise and prioritize n-day patching.
  • If you or your team are connected to the Defense Manpower Data Center, enroll in the free IDX credit monitoring before the August 2027 deadline and place a fraud alert on credit files.

FAQ

What is CVE-2026-76504?

CVE-2026-76504 is a critical authentication bypass in Cisco Catalyst SD-WAN Manager, scored 9.8 on CVSS, that lets remote unauthenticated attackers gain administrative access. Cisco patched it on October 1, 2026 after detecting active exploitation.

How much was stolen in the Bitget cryptocurrency theft?

Bitget confirmed roughly $387.5 million in digital assets were stolen in an attack tied to a zero-day vulnerability in a third-party service provider. The exchange said customer holdings are covered.

How many people were affected by the Pentagon data breach?

The Pentagon’s Defense Manpower Data Center is notifying more than 3 million people, including nearly 2.8 million living individuals and 294,000 deceased individuals, that their personnel data was stolen between October 2025 and July 2026.


This article summarizes reporting from securityweek.com.

← All Articles