SecurityWeek reports that the Defense Manpower Data Center, which holds Pentagon personnel records, has begun notifying roughly 2.76 million living individuals and 294,000 deceased individuals that their files were exposed. A notification letter dated September 18 traces the cause to a vulnerability in a DMDC file-sharing system. "Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII," the letter says, according to SecurityWeek, which obtained and published its contents. The exposure window ran roughly nine months, from October 2025 until the vulnerability's discovery the following July. The compromised data included Social Security numbers, names, dates of birth, contact information, demographic details and military occupational specialties. DMDC says it has no indication the information was misused, and no group has claimed responsibility. The agency is offering a year of credit monitoring and identity-restoration services to those notified.
Citrix customers got a rougher week. Cybersecurity Dive reports that two critical NetScaler ADC and NetScaler Gateway flaws, tracked as CVE-2026-88771 and CVE-2026-88772 and both scored 9.5 of 10 for severity, were already under active exploitation before Citrix or the government had issued public guidance. Some security teams instead got phone calls over a weekend warning them to disconnect exposed servers immediately. The Shadowserver Foundation counted more than 20,000 exposed NetScaler instances, though confirmed compromises remain limited. "The urgency stemmed from the discovery that two previously unknown vulnerabilities were being actively exploited in the wild," Yordan Ganchev, a principal threat intelligence specialist at watchTowr, told Cybersecurity Dive. Citrix's own bulletin addressed eight vulnerabilities in total, though it said some require specific preconditions, such as an active DTLS configuration, before they can be exploited.
A third report points at infrastructure rather than enterprise IT. Security.com reports that Symantec's threat hunters are tracking a China-linked group, which they call Longlegs and others track as Storm-2603, still breaking in through Microsoft SharePoint flaws more than a year after those flaws first surfaced. Longlegs has hit at least four organizations in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body and a university, deploying Warlock ransomware each time. In one intrusion, the group disabled security tooling on more than 40 hosts within two hours using a vulnerable signed driver, then staged its ransomware inside a compromised domain's SYSVOL share, a folder that servers replicate automatically, so the malware spread itself to more than 30 machines without further action from the attackers. The group has also abused Visual Studio Code's remote-tunneling feature to maintain covert access once inside.
None of the three incidents required a new technique. A known file-sharing bug, a disclosed zero-day and a SharePoint flaw already a year old were each sufficient on their own.





Leave a Reply