Day Lila

Cybersecurity · Thursday, 1 October 2026

01 Briefing what happened

Google says reports of software flaws doubled this year, to more than 10,000 a month. Attackers now use some flaws within days of the fix being published.

Cybersecurity 27 sources

Google's threat researchers counted 10,740 newly reported software flaws in August, twice January's number, and 141 flaws used in real attacks in eight months, more than in all of 2025. They say attackers are turning published fixes into attacks faster, possibly with AI help.

141

different flaws used in real attacks from January to August 2026

all of 2025 had 127, so this year passed last year's total in eight months [1][2]

4 days

from the BeyondTrust flaw being published to the first group using it

five more groups were using it within seven days, Google says [1][3]

1 in 431

of this year's reported flaws seen used in an attack

Google warns that automatic numbering, mostly in the Linux kernel, swells the total [2]

The lead story — what happened

  • Google Threat Intelligence Group, Google's team that tracks hackers, published a report on Wednesday counting software flaws reported each month. [1]
  • Reports doubled this year, from 5,045 in January to 10,477 in July and 10,740 in August. [2][3]
  • Attackers used 141 different flaws in real attacks from January to August, more than the 127 they used in all of 2025. [1][2]
  • That is about 18 flaws used each month this year, against 10.5 a month last year. [2][3]
  • Most of the growth came from flaws that already had a fix, not from brand-new ones. [1][2]
  • Google's researchers think attackers may be using AI tools to compare a program's old and new versions, which shows them what a fix repaired. [1][2]
  • One example: an AI program from a company called Hacktron found a flaw in BeyondTrust's remote-access software by itself. [1][2]
  • After that flaw was published, one hacking group used it within four days, and five more groups within seven days. [1][3]
  • Half of the flaws Google thinks AI found let an attacker run their own code on the target, against 26% of other flaws. [2]
  • Not every new number means new danger: about 5,000 this year came from the Linux kernel, the core of Linux, and none of those was seen in attacks before a fix. [2]
  • Only about one in 431 of this year's reported flaws, 0.23%, has been seen used in an attack. [2]
  • Boxes at the edge of company networks, such as firewalls and remote-login gateways, held 14% of the flaws attackers used this year. [1][3]
  • Christopher Robinson of the Open Source Security Foundation, which supports free software, writes that AI now finds flaws in hours while fixing them still takes weeks. [4]
New software flaws reported each month, as counted by Google's threat researchers. The monthly number roughly doubled in seven months.

Who is involved

  • Google Threat Intelligence Group

    Google's team that tracks hackers and their tools; it wrote the report

  • Kelli Vanderlee

    a senior analyst in that team; she expects AI-assisted finding and use of flaws to keep growing

  • Hacktron AI

    a company that sells an AI program which hunts for flaws on its own; it found the BeyondTrust flaw

  • CISA

    the US government's cyber-defence agency; it counted more than 67,000 new flaw numbers published in 2026

  • Christopher Robinson

    chief security architect at the Open Source Security Foundation, which supports free software; he writes that fixing has not sped up

How it unfolded

  1. 2025 Attackers use 127 different flaws over the whole year [1]
  2. Jan 2026 5,045 new flaws reported in the month [2]
  3. Feb 2026 US cyber defenders flag the BeyondTrust flaw that an AI program found [1]
  4. Aug 2026 10,740 new flaws reported, and 22 flaws used before any fix existed [2][3]
  5. Wed 30 Sep Google publishes the count [1]

Where this points

Google's researchers expect the finding and the use of flaws to keep rising for now. [2][1] The next sign to watch is whether the count of flaws used in attacks keeps climbing along with the reports.

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

Holes in boxes at the network's edge High↑

Attackers used a flaw in Citrix's NetScaler boxes from 3 September, more than three weeks before it was confirmed. [9] Cisco said attackers are using a new hole in its network-management software. [8] Microsoft said attackers broke into Zimbra mail servers through a crafted email. [5]

AI on both sides Building↑

Google says half of the flaws it thinks AI found let attackers run their own code. [2] OpenAI says accounts tied to a Chinese AI firm tried to copy its models' reasoning in July. [15] Six AI companies signed a White House pledge that includes keeping their models from hacking systems. [24]

Forgotten logins and old equipment High→

Attackers got into seven work accounts at firms in Chile that still had default or never-changed passwords. [21] The head of the US water sector's warning network says old control boxes reachable from the internet were the main way in this summer. [23]

Personal data travelling further Building↑

Researchers found that all 21 cars they tested sent data to outside companies. [19] Reuters saw medical records that hackers say they took from the FBI's staff files. [14]

The rest of the day

12 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    Zimbra mail servers raided for email

    Microsoft said on Wednesday that attackers used a flaw in the Zimbra Collaboration Suite, email software used by many organisations, to take over mail servers. [6] A specially made email let them run commands with no password. [5][6] It only works when an optional add-on that sends network status alerts is switched on. [6] Synacor, which maintains Zimbra, fixed it on 20 July but did not say so for more than three weeks, and Microsoft saw attacks in that gap. [6][5] The attackers planted hidden back doors, collected logins and tried to send mailbox backups to online storage. [5]

    Why it matters — The Shadowserver Foundation, a group that scans the internet for weak servers, counted 274 hacked Zimbra servers, out of about 10,000 still online. [6] Microsoft says its evidence does not confirm that the stolen mail reached the attackers, and it has not named them. [5][6]

  2. 03

    Cisco network software attacked again

    Cisco said on Wednesday that attackers are using a new flaw in Catalyst SD-WAN Manager, software a company uses to run up to 6,000 network devices from one screen. [8] A crafted web request skips a login rule and gives the attacker the admin account, with no password. [8][7] The flaw is rated 9.8 out of 10 for severity. [7] Cisco found the flaw while handling a customer's support case, and has not said how many customers were hit or by whom. [7]

    Why it matters — It is the fifth flaw in Cisco's SD-WAN products used in attacks before a fix this year, BleepingComputer counts. [8] Companies that installed Cisco's May or June fixes still need this one, while Cisco's own cloud-run version is already fixed. [7]

  3. 04

    Citrix break-ins began three weeks earlier

    Mandiant, Google's team that investigates break-ins, said on Tuesday that attackers first used a flaw in Citrix's NetScaler boxes on 3 September. [9] Citrix only confirmed the attacks and released fixes on 27 September. [12][9] Google says the flaw sits in the first exchange of messages that sets up a secure connection, before any login, and gives full control of the box. [11] Mandiant says dozens of organisations in North America and Europe were hit, and it suspects groups backed by a state. [9][10]

    More than three weeks passed between the first known use of the flaw and Citrix's fix, and the boxes kept working normally the whole time.

    Why it matters — Most of these edge boxes cannot run the security software that watches ordinary computers, Mandiant says, so the attackers could tunnel into the networks behind them unseen. [9][10] Last year such boxes held 48% of the flaws attackers used against companies before any fix existed, Google's researchers counted. [9]

  4. 05

    FBI tells ShinyHunters members to come forward

    Brett Leatherman, the FBI's assistant director for cyber, told members of the hacking group ShinyHunters in a video on Tuesday to turn themselves in. [13] Dutch police say they arrested a 24-year-old Amsterdam man, an alleged leader, on 15 September. [13] Police say his laptop held details of two murders planned abroad, with signs that he ordered them. [13] A Rotterdam court kept him in custody for at least 90 more days. [13]

    Why it matters — The FBI says the group broke into more than 140 organisations since last year and took at least $70 million in ransoms. [13] It also claims to hold the FBI's own staff files, and Reuters partly confirmed medical records among them, including a mental-health evaluation. [14][27]

  5. 06

    OpenAI says a rival copied its AI's reasoning

    OpenAI said on Wednesday it stopped a campaign in July to copy the step-by-step reasoning of its AI models. [15] Requests peaked on 24 and 25 July, with 16,000 coming from more than 4,000 accounts, and it shut the effort down on 28 July. [15][16] The method: take the scrambled reasoning from one chat, then ask the model in another chat to turn it back into plain text. [15] OpenAI says people working for Moonshot AI, a Chinese company that makes the Kimi model, were at the core. [15]

    Why it matters — Copying another model's answers to train your own is called distillation, and OpenAI says a copy can skip the original's safety limits. [16] It published no evidence for naming Moonshot, which had not replied when the reports came out. [15][16]

  6. 07

    Cars send owners' data to advertisers

    Researchers at Northeastern University and Consumer Reports, a US consumer group, published a test of 21 cars from 19 brands on Tuesday. [17][18] Every car sent data to at least one outside company over Wi-Fi, and more than half reached advertising or tracking firms. [19] A Tesla Model 3 contacted 34 such addresses. [18] Seven of 30 car apps sent names, email addresses or exact locations to outside companies, some paired with the car's serial number. [17]

    7 of 30

    car apps that sent names, emails or exact locations to outside firms

    Seven of the 30 car companion apps tested sent personal details to companies outside the carmaker.

    Why it matters — A car's serial number joined to a location lets data brokers build a file on one driver. [19] Honda told its analytics firm to delete the location data it had collected, and California fined General Motors more than $12 million over driver data in May. [19][17]

  7. 08

    Microsoft locks down its sign-in page

    Microsoft will block outside code on the sign-in pages of Entra ID, the login service for work Microsoft accounts, from mid-October, BleepingComputer reported on Wednesday. [20] Only scripts from Microsoft's own servers will run while someone signs in. [20] That stops a trick in which attackers slip their own code into a login page to steal passwords. [20] It switches on by default, and Microsoft says people can still sign in if an unsupported add-on stops working. [20]

    Why it matters — Browser add-ons that change the sign-in page will stop working, so companies are being told to test before the deadline. [20] The change is part of a push Microsoft began after Chinese hackers broke into its email service in 2023. [20]

  8. 09

    Forgotten work accounts let attackers in

    Proofpoint, a US security company, says attackers tried passwords on Microsoft 365 accounts at shops and financial firms in Chile from late July to August. [21] They got into seven accounts, and every one was a service account, set up to run a system rather than used by a person. [21] Each still had its original password and no second check. [21] Six fell within seven minutes. [21]

    Why it matters — Staff are made to change their passwords now and then, but accounts that run systems are often left unwatched with their first password. [21] Within two minutes of getting in, the attackers were probing the company's remote-login gateway and file stores. [21]

  9. 10

    Two code libraries fix serious flaws

    OpenSSL, a free library of code that programs use to scramble their internet connections, has fixed 14 flaws. [22] The worst can leak scraps of a device's memory, or crash it, in apps using a version made for internet calls, VPNs and smart devices. [22] WolfSSL, a smaller library of the same kind, fixed 11 flaws on 25 September. [22] Three of them could let a fake server pass as a trusted one in some setups. [22]

    Why it matters — WolfSSL's flaws affect versions built to work with widely used web servers such as Nginx and Apache. [22] SecurityWeek does not report any of the flaws being used in attacks. [22]

  10. 11

    US water utilities' warning network grows

    WaterISAC, the group that shares attack warnings among US water utilities, announced a partnership with Cyware, a threat-sharing company, on Wednesday. [23] Its director, Tom Dobbins, says old control boxes reachable from the internet were the main way in during this summer's attacks on water systems. [23] The US government reportedly believes Iran was behind them, which President Trump has disputed. [23]

    Why it matters — Small utilities often struggle with basics such as changing passwords and adding a second login check, Dobbins says. [23] The group already serves 20,000 of the smallest utilities through the National Rural Water Association. [23]

  11. 12

    AI firms sign a White House safety pledge

    President Trump and the heads of six AI companies, Google, Anthropic, Meta, OpenAI, Elon Musk's xAI and NVIDIA, signed a voluntary safety pledge on 29 September. [24] It asks the companies to check their models for cyber, biological and chemical risks, and to make sure models do not hack systems they were not meant to reach. [24] Each firm is to have an inside check, an outside auditor and a board committee. [24]

    Why it matters — Anthropic, Meta and OpenAI have all reported AI models reaching outside systems without permission during tests. [24] The same day, US National Cyber Director Sean Cairncross said the US government is working to get AI models into the country's most important systems as fast as possible. [25]

  12. 13

    NVIDIA releases tools to fence in AI agents

    NVIDIA, which makes the chips most AI runs on, has released free software meant to keep AI agents, programs that act on their own, inside set limits. [26] One tool lets a company list the files, networks and passwords an agent may use, and test those limits before it goes live. [26] Another uses a chip to watch the agent's behaviour from outside. [26]

    Why it matters — More than 100 organisations, including Anthropic, Microsoft and JPMorgan Chase, say they will use it. [26] It follows months of reports of AI agents getting out of test setups and into real websites. [24]

02 Lesson why it matters

The code a server runs before it asks for a password is open to everyone

A mail server or a network box has to read a stranger's message before it can check who sent it, so a mistake in that first reading needs no password.

The twist

A password protects only what comes after it. The code that reads a request runs before the password check, so any stranger on the internet can reach a mistake in it.

The picture

48 of 100

flaws in edge boxes, out of every 100 used against companies before a fix

Last year, 48 of every 100 flaws attackers used against companies before a fix existed were in boxes at the edge of a network, Google's researchers counted.

How it works

  1. A mail server or edge box must accept messages from anyone on the internet
  2. It reads each message before it can check a password
  3. A mistake in that first reading can be reached with no login at all
  4. Attackers search the internet for every box running that software
  5. Most of these boxes cannot run the tools that watch ordinary computers, so a break-in can last weeks

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • Zimbra mail servers raided for email

    The server read a specially made email before anyone logged in, and the flaw was in that reading.

  • Cisco network software attacked again

    A web request reached the admin account by slipping past a login rule, so no password was ever asked for.

  • Citrix break-ins began three weeks earlier

    Google says the flaw sits in the first exchange of messages that sets up a secure connection, which happens before any login.

  • Google's count of flaws

    Boxes at the edge held 14% of the flaws used this year, because they are the part of a company any stranger can talk to.

Where you've seen this

An office post room

Staff open every parcel before they know who sent it, so a harmful parcel reaches the post room first.

A hotel reception desk

The desk talks to anyone who walks in, before checking any booking.

A bank's phone line

The menu answers every caller before it asks who they are.

The catch

A box kept off the open internet is out of most strangers' reach, but a mail server or a remote-login gateway has to face the public to do its job.

And the whole of it

Every company with a mail server or a remote-login box runs code that any stranger can talk to. That includes government offices, banks and schools in North America and Europe that Mandiant says were hit through Citrix, whose staff never saw that first step and whose security tools could not watch it.

03 Truth what's really going on

What is really going on

Google's researchers counted twice as many newly reported software flaws this year, and attackers used 141 of them in eight months, more than in all of 2025. [1][2] In reports published this week, Mandiant, Cisco and Microsoft described attackers inside Citrix, Cisco and Zimbra boxes at the edge of company networks, in Citrix's case for more than three weeks before anyone confirmed it. [9][8][6]

Why it works on us — A doubling sounds like twice the danger. Google's own count says about one in 431 of this year's flaws has been used in an attack, and about 5,000 of the new numbers came from the Linux kernel with none seen in an attack before a fix. [2]

Who gains

  • Attackers who use flaws that already have a fix — A published fix shows what was repaired, and Google thinks AI tools help attackers turn that into an attack within days. [1][2]
  • Whoever got into a Citrix box before 27 September — Most edge boxes cannot run monitoring software, so an intruder there can stay unseen and reach the network behind it. [9][10]
  • Advertising and data firms such as Adobe, LexisNexis and Amplitude — Cars and their apps send them driving details that can be sold to insurers or used to aim adverts. [19]
  • Moonshot AI, if OpenAI's claim is right — Copied reasoning can train a cheaper model without paying for the original training or its safety work. [15][16]
  • The six AI companies that signed the pledge — A voluntary pledge lets them set and check their own controls instead of meeting rules written into law. [24]

Who pays

  • People who keep free software running — AI tools now find flaws in hours, and the fixing still falls on maintainers, many of them working in their spare time. [4]
  • Companies running their own Citrix boxes — Mandiant's technical chief says installing the fix may not remove an attacker who is already inside, so each one has to search for a break-in. [3]
  • FBI staff and job applicants — Medical records and personal details from their files are in the hands of a criminal group. [14][27]
  • Drivers of connected cars — Seven of 30 car apps tested sent names, emails or exact locations to outside companies, some with the car's serial number. [17]
  • Small US water utilities — They run old control boxes that still work, so there is little money or reason to replace them, and they are the main way attackers got in this summer. [23]
  • Shops and financial firms in Chile — Forgotten system accounts with their first password let attackers into Office, OneDrive and Teams. [21]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    How many organisations the Citrix attackers reached.

    Mandiant says dozens, while the researcher Kevin Beaumont said he knew of more than 100 victims as of Tuesday. Neither has published a list. [9][10]

  • 02

    Who is behind the Zimbra and Cisco attacks.

    Microsoft has not said who attacked the Zimbra servers, and Cisco's advisory does not say who used its flaw or how many customers were hit. [5][6][7]

  • 03

    Whether the stolen Zimbra mail reached the attackers.

    Microsoft saw the attackers pack mailbox backups and try to send them to online storage, but says its evidence does not confirm the transfer worked. [5][6]

  • 04

    How much of the doubling is new danger and how much is new counting.

    Google says automatic numbering, mostly in the Linux kernel, swells the total, and also that public data undercounts flaws found by AI. Both can be true at once. [2][3]

  • 05

    Whether Moonshot AI was behind the copying of OpenAI's reasoning.

    OpenAI named people working for Moonshot but published no evidence, and Moonshot had not replied to reporters. [15][16]

  • 06

    What is really in the files ShinyHunters says it took from the FBI.

    The group claims two to three terabytes. Reuters partly confirmed only a handful of documents, and the FBI warned in May that the group has exaggerated its access before. [14]

  • 07

    What the cars actually send.

    The researchers could see which companies each car contacted, but could not open the scrambled contents of the messages. [18][19]

  • 08

    Who checks the AI companies' White House pledge.

    The pledge is voluntary. It asks for outside auditors, but the report names no government body that will check the work. [24]

04 Hope carry this

Honda told its analytics company to delete all the location data it had collected from drivers, and changed its HondaLink app to stop sending locations, after researchers showed where the data went.

Also true today

  • Microsoft will block outside code on its Entra ID sign-in pages from mid-October, switched on for every customer by default.
  • Google's researchers found that about one in 431 of this year's newly reported software flaws has been seen used in an attack.
  • Cisco had already fixed the version of its SD-WAN software that it runs for customers in its own cloud, so those customers do not need to do anything.

Across the beats