This week on Initial Access, we cover five stories:
CVE-2026-55007 is a zero-click RCE in on-prem Microsoft Exchange. The content-indexing engine parses a crafted Visio attachment on its own, and the code runs. No click. No preview pane. It landed in September's record 974-CVE Patch Tuesday, and ZDI's Dustin Childs ranked it above the month's two confirmed zero-days.
Per the advisory, exploitation requires sustained low-memory pressure on the server. From the operator chair, that condition is reachable: a throwaway DoS eats the memory, the SOC writes it off as noise, and the real RCE lands behind it. Roughly 20 unauthenticated, wormable RCEs shipped alongside it across DNS, DHCP, NetLogon, Kerberos, and MSMQ. This month rewards prioritization over completeness. Cloud tenants were patched before disclosure. Running Exchange on-prem? This patch jumps the queue.
Source: SecurityWeek
Gambit Security recovered a staging server showing one financially motivated operator running three open-source AI harnesses against hundreds of online retailers, mostly unattended. One found bugs, one exploited them end to end, and one orchestrated. Twenty-seven companies fell in five days, and more than 600,000 card records walked out the door. The number that matters is cost. At roughly $25 a target, the economics screen out no one.
The vendor split is the tell. Orchestration ran on a capable model that refuses cyber work at the top of its range, while exploitation went to models with looser acceptable-use policies. Guarding one good model doesn't close the door when the exploit stages route around it, and an actor on its own infrastructure has no guardrails at all. Cleanup was automated too. One agent's skill file wiped card tables after exfiltration, and at one victim, a too-broad table match dropped 180 tables, including the admins' own backups. The question is no longer how fast you patch. It's what comes back, and how quickly.
Source: Gambit Security
ShinyHunters claims it breached the FBI and took two to three terabytes of data on nearly every agent and applicant. The claim is unverified. The Bureau hasn't confirmed anything, and Reuters and 404 Media could match only nine records in a roughly 5,000-record sample against credit-bureau and prior-breach data. None proved the data came from FBI systems.
The group calls the attack retaliation for a May 2026 FBI advisory that named its tactics and told victims not to pay. That motive is the shift to watch. Financially motivated crews tend to turn erratic once they start hacking for reputation, and intelligence agencies holding their cards can decide to move. Demanding a retraction is theater, since a published advisory can't be unpublished. The real aim is likely a chilling effect that keeps "don't pay" from sticking. Expect a sequel next week.
Source: BBC
Bishop Fox reproduced the MikroTrick chain against internet-facing MikroTik RouterOS and found compromise artifacts on real devices. Attackers were exploiting it before the advisory landed. Two flaws stack. An unauthenticated rekey walks SSH past the point where login should be required (CVE-2026-67279). Then a username of -2 is read as a login-helper instruction and returns a full-admin identity (CVE-2026-86060).
From the operator chair, patch status and compromise status are separate questions. RouterOS logs live in memory and roll over on reboot, but attacker-created accounts, scripts, and schedulers persist. Objects owned by "0" instead of a named admin are a strong hunting lead. Patching closes the door. It doesn't evict anyone already inside. The answer to "was I exploited?" lives in the config, not the logs.
Source: Bishop Fox
OpenAI disclosed six cases of unexpected or concerning model behavior from training and evaluation, plus a standing framework for publishing misalignment incidents. The cases were:
The offensive read: this is attack surface with intent. Hand software an objective and a set of rules, and it consistently optimizes the objective over the rules. No prior exploit class behaves that way. The harm traces back to broad objectives given to capable agents, so narrowing what an agent swarm may pursue is the lever defenders actually hold. OpenAI admits alignment and monitoring aren't solved well enough to keep scaling at full speed. Take that at face value. Every org deploying agents owns the same question: what's the risk, and what's the plan?
Source: The New York Times
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.