Intelligence in Cyber Intelligence Weekly

Cyber Intelligence Weekly (October 4, 2026): Our Take on Three Things You Need to Know

By Dan Desko
Posted on Oct 04 / 2026
Cyber Intelligence Weekly Echelon

Welcome to our weekly newsletter where we share some of the major developments on the future of cybersecurity that you need to know about. Make sure to follow my LinkedIn page as well as Echelon’s LinkedIn page to receive updates on the future of cybersecurity!

To receive these and other curated updates to your inbox on a regular basis, please sign up for our email list here: https://echeloncyber.com/ciw-subscribe

Echelon Events & Thought Leadership Highlight

Echelon Events & Thought Leadership Highlight

Ransomware attacks against healthcare organizations rose roughly 14% in the first half of 2026 compared to the second half of 2025.

That’s more than two incidents a day.

For hospitals and clinics, the cost of downtime is more than revenue. It delays diagnoses, disrupts care, and puts patients at risk while systems are down.

Our very own @Drew Foley explained exactly why healthcare organizations are targeted, why the usual fixes fall short, and what actually works.

Read the article: https://lnkd.in/eq7D9BUg

https://echeloncyber.com/images/content/healthcare_vciso_ciw.png

Away we go!

1.  ShinyHunters Breaches FBI Job Site as Authorities Close In on the Group

The cybercrime group ShinyHunters is drawing renewed attention after an unusually aggressive series of attacks that coincided with the arrest of a suspected member in the Netherlands. Dutch authorities confirmed the arrest of a 24-year-old man connected to their ShinyHunters investigation. Sources identified him as Pepijn van der Stap, a previously convicted cybercriminal who operated under the alias "Umbreon." Van der Stap was convicted in 2023 for data theft and extortion, served time in prison and later publicly portrayed himself as a reformed hacker working professionally in offensive security. He was reportedly arrested again around September 16.

Just days later, ShinyHunters claimed responsibility for a brazen compromise of the FBI's employment website, apply.fbijobs.gov. According to reporting cited by KrebsOnSecurity, the stolen information included Social Security numbers and personal data belonging to more than 5,000 officials. The exposed records reportedly identified people's roles and teams, including special agents, cybercrime personnel and employees investigating foreign state-backed threats. Some of the stolen material also contained sensitive psychiatric and medical information. The FBI confirmed the breach, turning what could have been dismissed as another data-theft campaign into a serious example of how compromised human resources systems can expose highly sensitive information about the people working inside an organization.

The attack also carries an important vulnerability-management lesson. ShinyHunters said it gained access by exploiting CVE-2026-35273, a recently patched vulnerability affecting Oracle PeopleSoft, technology widely used for functions such as recruiting, payroll, benefits and human resources. According to the reporting, attackers had been exploiting the vulnerability as a zero-day since June. Mandiant and Google's threat intelligence team later concluded that ShinyHunters had mass-exploited the flaw against dozens of systems spanning government, healthcare, higher education, technology, transportation, agriculture and other sectors. Even more concerning, the attackers reportedly found a URL-encoding technique capable of bypassing web application firewall rules that had been provided as a temporary mitigation.

For security leaders, that last detail may be the most important part of the story. A compensating control is not the same thing as a patch. WAF rules, intrusion-prevention signatures and other mitigations can buy valuable time, but sophisticated attackers will look for ways around them. Organizations running internet-accessible enterprise applications should identify vulnerable PeopleSoft systems, apply Oracle's security update as quickly as possible and hunt for evidence of compromise rather than assuming patching today proves the environment was safe yesterday. The FBI incident is also a reminder that attackers do not need to compromise the systems an organization considers most mission-critical to obtain extremely valuable information. HR and recruiting platforms can contain identity data, employment history, medical information and details about an organization's personnel and structure. For an adversary, that can be an intelligence collection opportunity hiding in plain sight.

Google Patches Critical Cloud Integration Flaws

Google disclosed three vulnerabilities in its Application Integration service this week, including two rated Critical that highlight the risk created when cloud automation operates with powerful backend identities. The most serious issues could have allowed authenticated users to execute arbitrary code on Google's shared production infrastructure or make internal requests using a privileged identity. Google says all three vulnerabilities were patched before their public disclosure on September 28 and that no customer action is required.

The first critical vulnerability, CVE-2026-81867, affected the JavaScript Task used by Application Integration. An authenticated user with standard permissions could submit a specially crafted script that resulted in arbitrary code execution on shared production servers. A second critical flaw, CVE-2026-19759, involved improper authorization in task configuration. It could allow an authenticated user to invoke an internal-only task and execute arbitrary RPCs from Google's internal production network under a privileged identity. Google also disclosed CVE-2026-81375, a High-severity confused-deputy vulnerability in the Email Task that could have been abused to read and exfiltrate arbitrary Google-internal files through a crafted attachment path.

There is nothing for customers to patch. Google fixed the vulnerabilities on June 17, June 28 and June 30, respectively, before publishing the bulletins. But Application Integration customers should still review who has permission to create and modify integrations, what service accounts those workflows can use, and whether those identities have accumulated unnecessary access. Google is separately changing Application Integration so every integration run has an explicit identity, either the triggering user or a configured run-as service account. Beginning October 15, new scheduled or event-triggered integrations will require a run-as service account. That makes now a good time to review those identities and apply least privilege.

Why it matters: Think about an automated integration that pulls information from one SaaS platform, processes it and writes the results into another cloud system. The integration itself may look harmless, but the service identity behind it could have access to databases, APIs, secrets and other internal resources. Cloud automation should therefore be treated like privileged software, not plumbing. Know what identity every workflow runs as, restrict what that identity can reach, and assume that every integration point can eventually become part of an attack path.

2.  Pentagon Data Breach Exposes Personal Information of More Than 3 Million People

A major data breach involving the U.S. Department of Defense has exposed sensitive personal information belonging to more than 3 million people with ties to the military. The incident affected a Defense Manpower Data Center information system and exposed records belonging to nearly 2.8 million living people and another 294,000 deceased individuals. The compromised information varied by person but included names, contact information, dates of birth, Social Security numbers, military job specialties and other records. Particularly concerning, the Pentagon confirmed that at least some of the exposed information was stored unencrypted.

The breach was not a quick intrusion that security teams caught within hours or days. According to a Pentagon official, a small number of unauthorized users may have had access to the information for nearly a year, from October 2025 until July 2026. A breach notification received by at least one affected individual said officials discovered a vulnerability in a file-sharing system on July 16 and immediately patched it. The Pentagon has not publicly identified who accessed the system, explained whether the intrusion was intentional or disclosed why the sensitive information was stored without encryption. Officials said there was no evidence at the time of reporting that the stolen personal information had been misused, and affected individuals are being offered 12 months of credit monitoring.

The organization involved makes the incident especially significant. The Defense Manpower Data Center plays a central role in identity verification for Department of Defense ID card holders and maintains records covering more than 60 million service members, veterans, civilian employees, contractors and military family members. Information such as Social Security numbers, military occupations and contact details can have value far beyond conventional identity theft. Depending on whose information was accessed and by whom, personnel data can potentially support highly targeted phishing, impersonation and social engineering campaigns. The Pentagon has not disclosed enough about the affected population or the unauthorized users to determine whether those risks have materialized, but organizations should consider the long-term usefulness of exposed identity information when evaluating an incident like this.

For security leaders, there are two lessons worth emphasizing. Sensitive information should be protected as if an attacker will eventually reach the system storing it, and organizations must be able to detect unauthorized access much faster than a year. Encryption of sensitive data at rest, aggressive patching of internet-facing and file-sharing infrastructure, least-privilege access, meaningful logging, behavioral monitoring and strong data-retention practices all matter. But this breach also highlights a larger national security issue. The people who serve in the military, work for the government and support the defense industrial base are themselves valuable intelligence targets. Protecting their personal information is not simply a privacy obligation. Protecting the identities of America's military community is part of protecting the mission.

GitLab Patches CVSS 9.9 AI Gateway Flaw

GitLab released an urgent security update this week for a CVSS 9.9 vulnerability in its AI Gateway that could allow an authenticated user to escape an AI prompt-template sandbox and execute arbitrary commands on the underlying server. Tracked as CVE-2026-90970, the vulnerability affects organizations operating GitLab's Self-Hosted AI Gateway, which supports GitLab Duo's AI capabilities. GitLab says customers using its hosted AI Gateway are already protected.

The vulnerability sits inside GitLab Duo's custom flows, which allow organizations to create AI-powered workflows for multistep tasks. Under certain conditions, a user with access to the Duo Agent Platform could submit a specially crafted flow configuration, break out of the prompt-template sandbox and execute commands on the AI Gateway itself. That is a significant escalation. The gateway connects GitLab to AI model providers and sits inside the organization's development environment. A successful compromise could therefore put sensitive infrastructure and credentials within reach.

Organizations running a Self-Hosted AI Gateway should upgrade immediately to AI Gateway 19.2.4, 19.3.2 or 19.4.1, depending on their current release branch. Versions from 18.1.6 through 19.2.3, versions 19.3.0 and 19.3.1, and version 19.4.0 are affected. Importantly, teams need to verify the AI Gateway version, not simply assume that updating the connected GitLab application has addressed the issue. GitLab says it contacted potentially affected customers before publicly disclosing the vulnerability.

Why it matters: AI infrastructure is quickly becoming privileged infrastructure. AI gateways, agents and orchestration platforms increasingly connect to source code, model providers, APIs, credentials and internal systems. That makes the sandbox around an AI workflow a genuine security boundary. Organizations should inventory self-hosted AI infrastructure, tightly restrict who can create or modify agentic workflows, isolate AI execution environments and keep the identities used by those systems narrowly scoped. We should stop thinking of AI security as simply protecting prompts and models. Once AI can execute actions, AI infrastructure needs the same hardening, segmentation, patching and monitoring we expect from any other privileged system.

3.  Labcorp Settlement Sends a $2.3 Million Warning About Third-Party Cyber Risk

A data breach that occurred more than six years ago is still creating consequences for Labcorp. A bipartisan coalition of 44 state attorneys general reached a $2.3 million settlement with the medical testing company over cybersecurity and data protection failures connected to the massive 2019 American Medical Collection Agency breach. That incident ultimately affected approximately 27.5 million people nationwide, including 10.2 million Labcorp customers. While the intrusion occurred at AMCA, a debt collection company used by Labcorp, regulators argued that Labcorp did not do enough to oversee how its vendor protected sensitive customer information.

The settlement is significant because it goes well beyond a financial penalty. Labcorp has agreed to overhaul how it manages third-party cybersecurity risk, including establishing an incident response plan specifically addressing vendor security failures, limiting the amount of information shared with vendors and building out a risk management function responsible for monitoring vendor security practices. Cybersecurity requirements must also be incorporated into vendor contracts, and certain data collectors will be required to provide audits demonstrating compliance. Labcorp must retain an independent expert to perform information security assessments and take steps to segregate data handled by collection agencies rather than allowing information from multiple clients to be aggregated together.

There is an important lesson here for any organization that entrusts sensitive information to outside providers. Outsourcing a business process does not outsource the underlying cyber risk. Sending customer information to a collection agency, SaaS provider, payroll company or other third party may move the data outside your network, but it does not necessarily move the accountability with it. Vendor due diligence also cannot be reduced to collecting a security questionnaire once a year. Organizations need to understand what information each vendor receives, why the vendor needs it, how long it retains that information, what security controls protect it and how quickly the organization will learn when something goes wrong.

The Labcorp settlement provides a useful blueprint for what mature third-party risk management increasingly looks like. Collect less data, share less data, contractually establish security expectations, validate those expectations through evidence and audits, continuously reassess critical vendors, and build incident response plans that assume the breach may happen somewhere outside your own environment. The fact that regulators are imposing these requirements years after the original breach should get the attention of executives and boards. Your cybersecurity perimeter increasingly includes every third party trusted with your data, and regulators appear increasingly willing to hold organizations accountable for what happens there.

 

Thanks for reading!

About us: Echelon is a full-service cybersecurity consultancy that offers wholistic cybersecurity program building through vCISO or more specific solutions like penetration testing, red teaming, security engineering, cybersecurity compliance, and much more! Learn more about Echelon here: https://echeloncyber.com/about

Are you ready to get started?