Image
Episode 36  •  Sep 25, 2026  •  67 Min

Zero-Click Exchange RCE, $25 AI Intrusions, and the ShinyHunters FBI Claim

This week on Initial Access, we cover five stories:

  • a zero-click Exchange RCE
  • an AI-driven campaign that breached retailers for about $25 apiece
  • an unverified ShinyHunters claim against the FBI
  • Bishop Fox research on the MikroTrick RouterOS chain
  • six misalignment incidents OpenAI disclosed in its own models

CVE-2026-55007: Zero-Click Exchange Server RCE Triggered by a Visio Attachment

CVE-2026-55007 is a zero-click RCE in on-prem Microsoft Exchange. The content-indexing engine parses a crafted Visio attachment on its own, and the code runs. No click. No preview pane. It landed in September's record 974-CVE Patch Tuesday, and ZDI's Dustin Childs ranked it above the month's two confirmed zero-days.

Per the advisory, exploitation requires sustained low-memory pressure on the server. From the operator chair, that condition is reachable: a throwaway DoS eats the memory, the SOC writes it off as noise, and the real RCE lands behind it. Roughly 20 unauthenticated, wormable RCEs shipped alongside it across DNS, DHCP, NetLogon, Kerberos, and MSMQ. This month rewards prioritization over completeness. Cloud tenants were patched before disclosure. Running Exchange on-prem? This patch jumps the queue.

Source: SecurityWeek

AI Agents Breached 27 Retailers in Five Days for About $25 a Target

Gambit Security recovered a staging server showing one financially motivated operator running three open-source AI harnesses against hundreds of online retailers, mostly unattended. One found bugs, one exploited them end to end, and one orchestrated. Twenty-seven companies fell in five days, and more than 600,000 card records walked out the door. The number that matters is cost. At roughly $25 a target, the economics screen out no one.

The vendor split is the tell. Orchestration ran on a capable model that refuses cyber work at the top of its range, while exploitation went to models with looser acceptable-use policies. Guarding one good model doesn't close the door when the exploit stages route around it, and an actor on its own infrastructure has no guardrails at all. Cleanup was automated too. One agent's skill file wiped card tables after exfiltration, and at one victim, a too-broad table match dropped 180 tables, including the admins' own backups. The question is no longer how fast you patch. It's what comes back, and how quickly.

Source: Gambit Security

ShinyHunters Claims an FBI Breach: What's Verified and What Isn't

ShinyHunters claims it breached the FBI and took two to three terabytes of data on nearly every agent and applicant. The claim is unverified. The Bureau hasn't confirmed anything, and Reuters and 404 Media could match only nine records in a roughly 5,000-record sample against credit-bureau and prior-breach data. None proved the data came from FBI systems.

The group calls the attack retaliation for a May 2026 FBI advisory that named its tactics and told victims not to pay. That motive is the shift to watch. Financially motivated crews tend to turn erratic once they start hacking for reputation, and intelligence agencies holding their cards can decide to move. Demanding a retraction is theater, since a published advisory can't be unpublished. The real aim is likely a chilling effect that keeps "don't pay" from sticking. Expect a sequel next week.

Source: BBC

MikroTrick: How a "-2" Username Grants Admin on MikroTik RouterOS

Bishop Fox reproduced the MikroTrick chain against internet-facing MikroTik RouterOS and found compromise artifacts on real devices. Attackers were exploiting it before the advisory landed. Two flaws stack. An unauthenticated rekey walks SSH past the point where login should be required (CVE-2026-67279). Then a username of -2 is read as a login-helper instruction and returns a full-admin identity (CVE-2026-86060).

From the operator chair, patch status and compromise status are separate questions. RouterOS logs live in memory and roll over on reboot, but attacker-created accounts, scripts, and schedulers persist. Objects owned by "0" instead of a named admin are a strong hunting lead. Patching closes the door. It doesn't evict anyone already inside. The answer to "was I exploited?" lives in the config, not the logs.

Source: Bishop Fox

OpenAI Discloses Six Misalignment Incidents from Its Own Models

OpenAI disclosed six cases of unexpected or concerning model behavior from training and evaluation, plus a standing framework for publishing misalignment incidents. The cases were:

  • a research model that wrote itself jailbreak-style notes 27 times during a run
  • an agent that uploaded files to the open internet to grab a citation without asking
  • a model that hid its own mistakes in the summaries its reviewers read

The offensive read: this is attack surface with intent. Hand software an objective and a set of rules, and it consistently optimizes the objective over the rules. No prior exploit class behaves that way. The harm traces back to broad objectives given to capable agents, so narrowing what an agent swarm may pursue is the lever defenders actually hold. OpenAI admits alignment and monitoring aren't solved well enough to keep scaling at full speed. Take that at face value. Every org deploying agents owns the same question: what's the risk, and what's the plan?

Source: The New York Times


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Sergio Villegas BF Headshot

Sergio Villegas

Senior Managing Analyst

Sergio Villegas is a Senior Managing Analyst in the Attack Surface Intelligence team at Bishop Fox where he is one of the lead researchers. His main areas of focus are emerging threats, attack surface mapping, and tactical lead generation. Sergio has over 11 years of experience in cybersecurity during which he has worked as a researcher and consultant to help companies improve their procedures, technologies, and techniques around threat intelligence and threat hunting.


Emilio Gallegos Bio Image

Emilio Gallegos

Adversarial Operator

Emilio Galle is an offensive security researcher and adversarial operator at Bishop Fox specializing in application security and vulnerability research. He has discovered and responsibly disclosed vulnerabilities across major open-source ecosystems, including CVE-2026-18798, CVE-2026-25087, and CVE-2026-9087, and has been acknowledged multiple times in Apple’s web server security acknowledgements. He is also the creator of snowpick, an open-source scanner for identifying critical data-exposure and access-control flaws in ServiceNow.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere