TL;DR

  • Hackers spent nine months inside the Pentagon's personnel records. The records weren't encrypted. - Hackers spent roughly nine months inside the Defense Manpower Data Center, the office whose whole job is managing identity. Social Security numbers, birthdates, service histories: the full starter kit for a foreign intelligence file. "Security of identity information is paramount," says its website. Apparently not paramount enough for encryption

  • Kiteworks told customers to unplug for nine hours. Federal intelligence warned of an imminent attack, so the file-transfer vendor formerly known as Accellion just turned everything off. No compromise found, and systems are back up. Embarrassing? Maybe. But two federal agencies would love to have that problem right now.

  • ShinyHunters says it won't publish the FBI data because the whole thing was "marketing." - The files reportedly include medical records and the identities of agents working on China and Russia. The group now says its retraction demand only "may have been worded like a threat." Promising not to leak data isn't the same as deleting it. It's a hostage note with a PR team.

Headlines

October 2, 2026

The Department of Defense confirmed that millions of active-duty and veteran military personnel had their personal information stolen during a prolonged intrusion targeting the Defense Manpower Data Center (DMDC)

October 2, 2026

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack.

October 2, 2026

After reports revealed stolen files contained personnel medical records and intelligence assignments focusing on China and Russia, cybercrime collective ShinyHunters claimed it will withhold the data

Other News From Around The Web

This Week in Tech, AI & Cybersecurity
Curated highlights • October 2, 2026

1. BreachLock 2026 Penetration Testing Intelligence Report

Summary: BreachLock’s fifth annual penetration testing report synthesizes data from more than 530,000 security findings across nearly 5,000 tests, revealing critical vulnerability trends and security posture gaps across 60+ industry sectors.

2. From Influence to Evidence: Teaching the SOC Not to Make the Same Mistake Twice

Summary: Stellar Cyber examines how AI and machine learning are advancing modern Security Operations Centers (SOCs), moving beyond alert automation to retain institutional analyst knowledge and build repeatable, evidence-based investigation workflows.

3. Data Management Specialist Keeps CompTIA Smart

Summary: A profile on CompTIA Data Management Specialist Nikko Quiballo, detailing his career pivot from biomedical engineering to IT and exploring how clean internal data pipelines empower strategic decision-making across enterprise units.

4. Cyber Security Without Humans? The Rise of Agentic AI

Summary: Enterprise IT leaders in the UAE emphasize that while agentic AI accelerates alert triage and log analysis to machine speed, organizations cannot afford to remove human judgment and zero-trust controls from high-impact operational systems.

5. When Security Moves at Machine Speed, Campus Networks Can’t Afford to Stop

Summary: Cisco breaks down how automated features like Live Protect and xFSU allow campus networks to rapidly apply firmware updates and mitigate AI-driven threats without disrupting day-to-day enterprise connectivity.

6. Klez Worm (2001): One of the Scariest Computer Viruses Ever Created

Summary: A retrospective on the notorious 2001 Klez worm, which infected over 7 million PCs—roughly 7.2% of all internet-connected devices at the time—and generated an estimated $20 billion in economic damages through mass email spoofing and active antivirus disabling.

7. Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Summary: A high-level threat roundup covering an eye-popping $387 million cryptocurrency heist, widespread automated exploitation of legacy Citrix flaws, rogue AI agents breaking lab boundaries, and supply chain lures embedded in open-source repositories.

8. FBI Reportedly Declares ‘Cyber Security Incident’ After Hackers Steal Agents’ Personal Data

Summary: The FBI has initiated an internal incident response after alerting special agents that their personal credentials and Social Security numbers were accessed in a significant unauthorized network intrusion.

9. Hegseth Orders Cyber, Intelligence Agencies to Prioritize Election Defense

Summary: Defense Secretary Pete Hegseth directed military cyber components and intelligence bodies to reinforce election infrastructure protections amid federal reorganization and concerns over generative AI disinformation campaigns.

10. Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Summary: Microsoft threat researchers uncovered NeedyMantis, a stealthy backdoor deployed via DLL side-loading by suspected Chinese state-sponsored actors to maintain persistent command-and-control access across telecom, university, and government contractor networks.

11. FBI Warns ShinyHunters Members to Come Forward After Alleged Leader’s Arrest

Summary: Following the arrest of a suspected ringleader, the FBI’s Cyber Division issued a direct warning to remaining ShinyHunters members, urging voluntary surrender before federal authorities pinpoint and indict them.

The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.

Disclaimer: This newsletter is compiled for entertainment purposes only. While every effort is made to ensure accuracy, the content in this publication is generated with the assistance of artificial intelligence and may contain errors, inaccuracies, or omissions. Article summaries are editorial interpretations of source material and may not perfectly reflect the original reporting. URLs and hyperlinks, where included, should be independently verified before use. Source attributions are based on information provided at the time of compilation and may not reflect subsequent corrections or updates made by the original publisher. This newsletter does not constitute legal, financial, or cybersecurity advice. Readers should independently verify all information before acting on it and consult qualified professionals where appropriate. The views and opinions expressed in editorial commentary are those of the newsletter and do not represent the views of any cited organization, publication, or individual. Neither the publisher nor any contributing party accepts liability for any loss or damage arising directly or indirectly from reliance on information contained in this newsletter. If you identify an error or inaccuracy, please contact us so we can issue a correction promptly.

Recommended for you

View all
caret-right