
The pay system needs a patch.
Military cyber personnel face pay cuts. A critical RCE threatens banking and government authentication systems. Dell patches a critical update flaw. A missed patch costs Accenture an FBI contract. Hackers hijack a fashion retailer’s push notifications. Insurers brace for rogue AI claims. Hackers breach a supertanker’s propulsion system. Denmark suffers a massive population data breach. And Japan extradites a suspected Qilin ransomware operator. Our guest is Steve Ryan, Founder and CEO of Trinity Cyber, on surviving first contact from a Frontier AI-enabled cyber threat. There’s no honor among Gentlemen.
Today is Tuesday October 6th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Some military cyber personnel face pace cuts.
The Pentagon’s new Cyber Mastery Incentive Pay program is supposed to reward military cyber personnel for developing advanced technical skills. But its rollout is proving rocky, with some troops facing substantial pay cuts.
C-MIP replaces service-specific incentives with a standardized system that pays more as personnel advance from basic to senior and master skill levels, with additional compensation for certain duties. Internal Army documents reviewed by DefenseScoop show many basic and senior cyber roles losing between $100 and $1,000 a month compared with the previous system. The Army is temporarily cushioning those losses with a yearlong pay-protection policy.
Critics warn the changes could hurt morale and retention just as military cyber capabilities are becoming increasingly important. Pentagon officials say C-MIP isn’t intended as a blanket retention bonus, but rather to encourage personnel to develop the military’s most sought-after cyber skills.
A critical RCE bug could expose banking and government authentication systems.
A critical remote code execution vulnerability in Thales’ SConnect browser extension could expose systems used for banking and government authentication. CVE-2026-18397, with a CVSS score of 9.4, stems from improper RSA signature validation and buffer handling. Attackers can exploit it through a malicious website or iframe, ultimately loading a malicious DLL and compromising the endpoint.
SConnect is used as authentication middleware in environments including SWIFT banking networks and government identity systems. Multiple researchers have reported drive-by attacks and observed endpoint compromises and session hijacking, though no unauthorized SWIFT transfers or identity-card signing events have been confirmed. CISA has not added the flaw to its Known Exploited Vulnerabilities catalog.
Chrome and Apple versions were patched in August, while the Edge version was removed from distribution in September. Organizations running older versions are urged to update or migrate to supported alternatives.
Dell patches a critical vulnerability in its System Update tool.
Dell is urging customers to patch a critical vulnerability in its System Update tool that could allow unauthenticated attackers to execute arbitrary code with root privileges on affected PowerEdge servers. CVE-2026-86360, rated 9.6, is a path traversal flaw affecting DSU versions before 2.3.0.0. Dell also patched four additional vulnerabilities that could enable privilege escalation or code execution. Customers should upgrade to DSU version 2.3.0.0 or later. Dell says it has not observed active exploitation.
A missed patch leads to a lost contract for Accenture.
The FBI has removed an Accenture contractor after determining that a missed security patch led to a breach exposing sensitive information on thousands of bureau employees. FBI cyber chief Brett Leatherman said the contractor failed to install a patch specifically issued to secure a third-party platform. Reuters identified that platform as Oracle PeopleSoft, which Accenture managed for the bureau.
The ShinyHunters cybercrime group claimed responsibility, saying it exploited PeopleSoft to compromise FBI recruitment infrastructure. The stolen information reportedly includes Social Security numbers, home addresses, assignments, family details, and sensitive medical records. Reuters partially verified some of the leaked data.
The FBI hasn’t confirmed all of ShinyHunters’ claims, including the scope of its access. But former bureau officials warn the exposed information could pose significant operational security risks to FBI personnel.
Hackers commandeer an online fashion retailer’s push notifications.
Online fashion retailer Asos is investigating a possible breach after thousands of customers received a push notification claiming hackers had “fully compromised” the company’s Snowflake cloud environment. The alert, titled “Asos hacked,” directed users to a Telegram channel associated with a previously unknown group calling itself Xuanye.
Asos hasn’t confirmed that a breach occurred, and its website and app remained operational Tuesday morning. But the incident rattled investors, sending the company’s shares down more than 14%.
Security experts say the notification itself suggests attackers may have gained access to systems capable of sending messages through the Asos app, while the claimed Snowflake compromise could potentially expose sensitive customer information. Researchers also warn that publicity surrounding the incident could fuel follow-on phishing campaigns impersonating Asos and targeting concerned customers.
Insurers brace for autonomous AI claims.
Insurers are preparing for potentially multimillion-dollar claims arising from autonomous AI agents, including the possibility that executives could face liability when their models cause harm, The Financial Times reports. The concern follows incidents in which AI agents have escaped their developers’ controls, including OpenAI’s reported hacking of Hugging Face.
Insurance brokerage and risk management firm Aon reviewed more than 300 AI-related legal cases and found potential exposure across cyber, crime, intellectual property, media liability, and technology errors and omissions policies. Some experts say directors and officers insurance could also come into play if executives are accused of failing to adequately govern AI risks.
But the legal landscape remains largely untested. Potential claims against AI companies could involve product liability, discrimination, privacy, copyright, and wrongful death. Lawyers suggest future litigation could even borrow from environmental, tobacco, and pharmaceutical cases to establish responsibility for damage caused by autonomous AI systems.
The FBI and Coast Guard investigate a breach of a supertanker propulsion system.
FBI and Coast Guard investigators have found evidence that hackers gained temporary access to the propulsion system of the VL Prosperity, an oil supertanker approaching the Texas coast this summer. Officials are still investigating how the breach occurred, who was responsible, how long access lasted, and what the attackers could have controlled.
Authorities boarded the fully loaded tanker in August after it lost communications and showed signs of a network compromise. The FBI says there were no reported operational disruptions, danger to the crew, vessel instability, or environmental impacts.
The incident highlights the potential physical consequences of maritime cyberattacks as ships increasingly depend on network-connected operational technology. By September, U.S. agencies were reportedly tracking cyber threats against nearly 20 vessels worldwide. The VL Prosperity remains anchored off Galveston.
Denmark’s Central Person Register suffers a data breach.
Denmark’s Central Person Register is notifying roughly 8.8 million people after hackers stole personal information through a private company with legitimate access to the national database. The attackers obtained names, addresses, and CPR numbers, Denmark’s equivalent of Social Security numbers, during September. People enrolled in name and address protection weren’t affected. CPR has terminated the company’s access, notified regulators and police, and launched an investigation. Officials haven’t identified the attackers and are warning people to watch for phishing and other suspicious communications.
Japanese authorities extradite a suspected key member of the Qilin ransomware operation to Germany.
Japanese authorities have arrested a suspected key member of the Qilin ransomware operation and extradited him to Germany. The 28-year-old Russian man was detained in Osaka in May and transferred to German authorities this month. He’s accused of breaching a German logistics company in 2024, stealing data, and demanding $165,000 in Bitcoin.
Active since 2022, Qilin operates a ransomware-as-a-service model, providing infrastructure and malware to affiliates who conduct attacks and share ransom proceeds. The group has become one of the world’s most active ransomware operations, particularly following law enforcement’s disruption of LockBit.
Qilin has also claimed several attacks against Japanese organizations. Its activity comes amid a broader surge in ransomware incidents in Japan, where authorities recorded 123 cases during the first half of this year, with small and midsized businesses accounting for most victims.
There’s no honor among Gentlemen.
A Russian-speaking ransomware affiliate apparently decided that extorting victims wasn’t quite enough and allegedly double-crossed his criminal partners as well. CloudSEK says an operator known as “Azazel,” affiliated with The Gentlemen ransomware-as-a-service operation, secretly ran his own Leakned leak site and kept extortion payments for himself.
Researchers discovered exposed servers containing several terabytes of data stolen from more than two dozen victims across six countries. Azazel’s methods included mining old GitLab commits for credentials and exploiting an SSRF vulnerability in an unauthenticated AI medical-imaging API. One weeks-long intrusion ultimately compromised six terabytes of data.
CloudSEK says Azazel also used an AI coding assistant connected through MCP to issue commands on a compromised system. And rather than relying on disposable cloud infrastructure, he maintained more than 50 terabytes of dedicated storage. Apparently, even ransomware has an expense-account tier.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

