Weekly Wire #12: The Expanding Attack Surface
This week, the security landscape once again shows how quickly attackers can weaponize new vulnerabilities. From targeted ransomware campaigns to forensic investigations, the common thread is the pressure on defenders to keep pace with a rapidly shifting attack surface.

In brief
- Vulnerabilities under fire: Exploits and disclosures continue to drive many of this week’s most notable incidents.
- Ransomware evolution: Threat actors are refining their tactics and targeting critical sectors.
- Privacy in focus: Surveillance and data protection concerns remain high on the agenda.
- Policy momentum: Regulatory frameworks continue to evolve globally.
- Tools for defenders: New research and open-source tools offer practical insights for security teams.
Digital forensics & DFIR
- September 2026 Cyber Attacks Timeline — A live, continuously updated timeline of the cyber attacks reported in September 2026
- The importance of digital forensics examiner training — Ongoing training helps digital forensic examiners maintain expertise, adapt to emerging technologies
- Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF — A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles
Threat intelligence & APT
- Warlock ransomware breach SharePoint in water, telecom operator attacks — The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body
- SilverFox: Tracking the Distribution of a Domestic Variant of a Malicious Installation File Posing as KakaoTalk — The threat actor used SEO poisoning, a technique that exploits search results to redirect users to fake sites
- Microsoft says threat actors are ahead in the early AI race — Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders
Privacy & surveillance
-
Unidentified Flock Cameras in Florida — St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify
-
Critical Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerabilities — Threat Summary On September 27th 2026, Citrix disclosed multiple vulnerabilities affecting NetScaler ADC and NetScaler G…
Policy & legislation
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code — A malicious file could trigger the vulnerability. Apple says it may already have been used against iPhone users.
- Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited — Here’s an overview of some of last week’s most interesting news, articles, interviews and videos
Tools & research
- Frontline Education breach exposes school district employee data — Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability
- GitLab warns of critical RCE vulnerability in AI Gateway service — GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary code
-
**[How a vulnerability scanner creates an illusion of protection Kaspersky official blog](https://www.kaspersky.com/blog/scanner-vs-real-security/56481/)** — We break down the full vulnerability management cycle: from IT asset inventory and threat prioritization
Extra
- I Want Better Reporting on AI Genie Behavior — AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing…
My pick of the week is Warlock ransomware breach SharePoint in water, telecom operator attacks, which stands out for its timely insight into this week’s evolving threats. As attackers continue to adapt, defenders will need to stay equally agile in the weeks ahead.
FAQ
- What are the main security trends this week? This week saw continued focus on vulnerabilities, ransomware activity, and policy developments from 2026-09-27 to 2026-10-04.
- What are the most important cybersecurity events of the week of {DATE_START}? Key events include new vulnerability disclosures, threat actor campaigns, and updates to privacy and policy frameworks.
- How are articles selected for the Weekly Wire? Articles are curated from a fixed set of RSS feeds weighted by source reliability and relevance to DFIR, threat intelligence, privacy, policy, and security research. Vendor marketing and press releases are discarded.