Chainalysis Reactor: AI-Driven Tracing of the $387M Bitget Bridge Exploit
On September 28, 2024, attackers exploited smart contract vulnerabilities within Bitget's cross-chain bridge validator sets, enabling unauthorized minting and burning of wrapped assets. The exploit resulted in the theft of approximately $387 million, comprising ~120,000 ETH and various ERC20, BEP20, and SPL tokens. Attackers utilized Wormhole, Multichain, and Synapse bridges alongside mixers to obfuscate fund movements. Utilizing the Chainalysis Reactor platform and graph-based machine learning models, investigators reduced the manual reconciliation time from over 20 hours to under 10 minutes, successfully clustering 1,400 associated addresses and identifying over 15% of the stolen assets moving toward exchange hot wallets for potential recovery.
Google Gemini 4 Argon Enters Post-Training and Enhances Agentic Cyber Defense
Google DeepMind has transitioned the Gemini 4 Argon model into the early post-training phase, significantly expanding its operational capacity for autonomous security tasks. By increasing the output token ceiling from 64k to 1M tokens, Argon enables sustained agentic workflows, specifically for automated vulnerability discovery, validation, and patching. While Argon demonstrates benchmark leadership over OpenAI’s GPT6 Astra and Anthropic’s Claude Opus 5.5, Google Threat Intelligence Group (GTIG) data highlights an escalating risk: AI-identified vulnerabilities are being exploited by threat actors within days of disclosure. This advancement accelerates the dual-use nature of frontier LLMs in the cyber domain.
Star Blizzard Scales Phishing Operations with RedFlick Malware Delivery
Since January 2026, the Russian state-linked threat actor Star Blizzard has expanded its phishing campaign using large‑volume email lures, compromised web infrastructure, and a novel RedFlick delivery chain that inserts password‑protected ZIP/RAR archives into ongoing trusted email threads, ultimately deploying the CosmicPulse backdoor. Over 100 organizations across ≥13 campaigns in government, diplomacy, research, public policy, journalism, and finance—primarily in the US, UK, and allied NATO states—have been compromised, with single‑victim interaction sufficient for infection and persistence via scheduled tasks, registry Run keys, and service creation.
Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504
Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.
Armadin Agent Swarm Security Platform Raises $255.5M at $2.5B Valuation
Armadin, an AI-native offensive security startup founded by Mandiant creator Kevin Mandia, has secured $255.5 million in Series B funding at a $2.5 billion post-money valuation. Led by Andreessen Horowitz and Accel, the capital will scale Armadin’s Agent Swarm Orchestrator and AI-Native Offensive Engine. The platform utilizes autonomous AI agents to perform Continuous Autonomous Red Teaming (CART), emulating adversary tactics across cloud, on-prem, and hybrid environments. By integrating with existing SIEM, SOAR, and XDR stacks, the platform validates exploit paths and generates real-time remediation playbooks, shifting security posture from periodic testing to persistent, automated validation.
Apple CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks
In late September 2026 Apple disclosed CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework triggered by a malicious PDF containing a crafted embedded font, enabling arbitrary code execution on unpatched iOS (<27) and macOS (Ventura <13.6, Monterey <12.7, Big Sur <11.7). The flaw was actively exploited in highly targeted attacks against high-value individuals. Emergency updates were released; public PoC appeared shortly after. Impact includes full device compromise, data exfiltration, and persistence.
Critical Fortinet FortiMail Zero-Day: CVE-2026-104286 Enables Unauthenticated Arbitrary File Writes
In October 2026, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation targeting Fortinet FortiMail email security gateways. This CVSS 9.8 vulnerability arises from the intersection of improper pathname limitation (CWE-22) and improper neutralization of null bytes (CWE-158) within the web management interface. Unauthenticated attackers can leverage crafted HTTP requests containing path traversal sequences and null bytes to bypass directory restrictions, allowing arbitrary file writes outside the intended web root. This flaw enables remote code execution (RCE) through webshell deployment, potential credential theft from mailboxes, and subsequent lateral movement within corporate networks.
PyJWT: Asymmetric-PEM Detection Bypass via Whitespace/Line-Ending Mutated Public Keys
PyJWT versions prior to 2.8.0 insufficiently validate PEM‑encoded asymmetric public keys, allowing whitespace or line‑ending variations to evade the HS/asymmetric confusion guard. When such a mutated key is supplied with an HS256/HS384/HS512 algorithm, the library treats it as an HMAC secret, enabling an attacker who possesses the victim’s private asymmetric key to forge valid tokens. This flaw impacts any service that accepts user‑provided public keys for JWT verification or signing and can lead to authentication bypass, privilege escalation, and unauthorized API access. The issue was resolved in PyJWT 2.8.0 by replacing the custom is_pem_format() check with a try/except around cryptography.hazmat.primitives.serialization.load_pem_public_key().
Storm-3168: Rapid Azure Resource Deletion Campaign Targeting Microsoft Azure Subscriptions
Threat actor JADEPUFFER (Storm-3168) conducted a highly automated, destructive campaign against Microsoft Azure tenants using compromised service principals. Initial access was achieved through service principal secrets exposed in public GitHub issue histories. Following a 15-hour reconnaissance phase involving ~300 read-only API calls, the actor executed a seven-minute burst of over 150 destructive operations. This included deleting >100 storage accounts, Azure Key Vaults, SQL databases, and removing Azure Site Recovery and backup protection locks. Post-destruction, the actor attempted credential harvesting via storageAccount/listKeys calls. The attack pattern—combining rapid resource destruction with recovery-impairment tactics—suggests an extortion-focused methodology designed to pressure victims through immediate operational paralysis.
NVIDIA Open Agent Safety Platform OASP HardwareBased Agent Governance
NVIDIA unveiled the Open Agent Safety Platform (OASP) in September 2026, coupling the open‑source OpenShell runtime with the Sentry watchdog reference design that runs on BlueField‑4 DPUs. OpenShell provides kernel‑level isolation, sandboxed execution, and per‑outbound‑request policy checks, while Sentry monitors agent behavior out‑of‑band and can quarantine or halt malicious agents within milliseconds. The platform targets governance of agents on enterprise‑controlled infrastructure, aiming to move enforcement outside the model and into hardware. Analysts estimate it addresses less than 25% of enterprise agentic risk, leaving SaaS, third‑party, and attacker‑introduced agents ungoverned.