Microsoft published its 2026 Digital Defense Report on 1 October, and the number worth carrying into this edition is not about models at all: the median interval from a vulnerability becoming known to its being weaponised is now well under a day, while enterprises still take 30 to 60 days to remediate an exposed critical flaw. The four disclosures below sit inside that gap. A vulnerability-disclosure organisation in the Netherlands was breached by what it says was an AI agent working without a human at the controls. Coding agents published thirteen thousand internal screenshots into public repositories while solving an ordinary workflow problem. Two separate advisories established that the server an AI assistant connects to is an identity trust boundary nobody had drawn. And a mobile banking trojan's control panel is now using a commercial model to decide which infected phones are worth a human operator's time. Only one of these is a vulnerability in the familiar sense. The rest are software doing what it was permitted to do.
1
A vulnerability-disclosure organisation says it was breached by an AI agent operating without human direction, which chained two previously unknown Zammad flaws into root access
The Dutch Institute for Vulnerability Disclosure, DIVD, was compromised on 21 September 2026. Its own CSIRT disclosed the intrusion on 24 September, gave a fuller account of the attack's character on 30 September, and released the vulnerability details on 1 October under case DIVD-2026-00015. DIVD describes the intrusion as an agentic AI powered attack that made its own tactical decisions, and its account is unusually candid about what that looked like: loud, messy, error-prone, including the agent damaging its own foothold. The chain itself, from session hijack to remote code execution to escalation to root, ran in seconds. Data was taken, and DIVD said it was still establishing which volunteer records were affected. Two flaws carry the chain. CVE-2026-102489 is a session hijack leading to remote code execution as the Zammad service account; DIVD's version table records 6.3.0 through 6.5.4 as exploitable, with the condition present but not exploitable in 7.0.0 through 7.1.3. CVE-2026-102490 escalates from that service account to root and reaches every version up to 7.1.0-alpha. Patch state has moved since the first disclosure and is worth stating precisely, because it changed twice in a week. Zammad published its own advisory on 5 October: 6.5 and earlier are affected by the first issue, 7.0 and later are not affected in practice, and the code changes ship in 7.2.0. The privilege-escalation issue remains under analysis as a high priority, with a related confirmed weakness in the packager.io build tooling, so the vendor's interim guidance is to restrict server access to trusted administrators. DIVD has published an indicator-of-compromise check script for log review, and began notifying exposed operators on 26 September.
Why it matters for IndiaSelf-hosted helpdesk and ticketing platforms are common in Indian IT services firms, GCC support functions, SaaS companies and state and central government departments, and they are rarely treated as high-value assets even though they hold customer correspondence, internal escalation detail and often attachments nobody inventoried. The more important point for Indian defenders is tempo. A chain that completes in seconds removes the assumption underneath most SOC escalation paths and change-approval queues here, which is that there is time between the first anomaly and the consequence. CERT-In's six-hour incident reporting obligation does not become easier when the intrusion finishes before the first analyst opens the ticket.
ActionEstablish whether Zammad is running anywhere in your estate, including instances a project team stood up outside the managed environment, and confirm the version. Move 6.5 and earlier off that line immediately; if you cannot, take the service off any untrusted network until you can. Restrict shell access on the host to named administrators while the privilege-escalation issue is open. Run DIVD's indicator check against your application and authentication logs, and preserve those logs before any rebuild or credential rotation destroys them. Then test one assumption deliberately: if session reuse, process execution from the application context and a bulk export all occurred inside a two-minute window, would anything in your monitoring raise an alert, and would it reach a human who can act.
SourceDIVD CSIRT, cases DIVD-2026-00014 and DIVD-2026-00015 (24 and 30 September, 1 October 2026); Zammad security advisory for CVE-2026-102489 and CVE-2026-102490 (5 October 2026); Help Net Security and The Register (1 October 2026).
2
Two advisories a week apart establish the same point: the server an AI assistant connects to is an identity trust boundary, and the client is the party that gets hurt
The first is in the official MCP Python SDK, published on 28 September 2026 as GitHub Security Advisory GHSA-qx49-fqc8-xw99, rated 7.5, with no CVE assigned. The SDK did not reliably validate the authorisation-server metadata returned by an MCP server, and did not bind credentials to the server that issued them. A hostile or compromised MCP server could therefore steer the client's login flow toward a token endpoint of its choosing. What it collects is the OAuth client secret, the authorisation code and the PKCE verifier, which together are enough to obtain a valid access token from the genuine identity provider carrying whatever scope the application already held. Versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 are affected; the fixes are 1.30.0 and 2.2.0. Upgrading alone is not sufficient, and this is the part teams will miss. Deployments using the client-credentials or private-key-JWT providers must now pass an explicit issuer value, which is deprecated-optional today and mandatory at 3.0. Stored OAuth client registrations need to be cleared so the client re-registers with issuer binding, or have the issuer field added. And if a client may have connected to a server you do not control, the client secret must be rotated and its tokens revoked at the authorisation server, because a client secret is long-lived and a patched library does not invalidate anything already collected. The second landed on 1 October 2026. AWS security bulletin 2026-121-AWS records CVE-2026-97662 in security-agent-mcp-server, an open-source MCP server that AI assistants use to run security scans over local source code. The defect is argument injection in the diff scan operation, reachable through crafted reference values, and the consequence is file creation, overwriting or truncation outside the intended workspace directory. Versions from 0.1.1 up to 0.2.0 are affected and 0.2.0 carries the fix. AWS states there is no workaround, and its interim guidance is to run diff scans only against repositories you trust and to run the server as a least-privileged user in an isolated environment.
Why it matters for IndiaIndian product engineering teams, GCC platform groups, fintechs and systems integrators have been connecting internal agents to MCP servers at considerable speed over the past year, and in most of those estates an MCP server is procured, installed and reasoned about as a plugin. Neither of these advisories fits that mental model. In the SDK case the direction of attack is inverted from the one teams prepare for: the server attacks the client, and what it takes is the identity of the application rather than its data. For a regulated entity, an access token with the application's full scope is a path to customer data under the Digital Personal Data Protection Act, and the audit question that follows is which MCP servers your agents were permitted to reach and who approved each one. Very few Indian organisations can answer that from existing records, because the connections were made by developers during pilots.
ActionIdentify every application using the MCP Python SDK and move to 1.30.0 or 2.2.0. Pass the explicit issuer value now rather than waiting for 3.0 to force it, clear stored client registrations so re-registration binds correctly, and rotate client secrets and revoke tokens for any client that has connected to a third-party server. Upgrade security-agent-mcp-server to 0.2.0, and restrict its diff scans to repositories under your control. Beyond the two fixes, build the list: which MCP servers are reachable from your agents, who operates each one, what scope the connecting application holds, and whether that scope is narrower than the application's own permissions. Treat adding an external MCP server as a change requiring security review, not as a developer convenience.
SourceGitHub Security Advisory GHSA-qx49-fqc8-xw99, modelcontextprotocol/python-sdk (28 September 2026); The Hacker News (29 September 2026); AWS security bulletin 2026-121-AWS, CVE-2026-97662 (1 October 2026).
3
AI coding agents published more than thirteen thousand internal screenshots into public GitHub repositories, with no attacker, no intrusion and no alert anywhere in the sequence
Glow Labs reported the research, which it calls PixelLeak, with public coverage on 30 September 2026; it had begun notifying affected organisations from 9 September. The figures are more than 13,000 internal images across more than 900 repositories belonging to more than 300 organisations, with roughly 93 percent of the images sitting in employees' personal accounts rather than corporate ones. Named sectors include technology and software, financial services, travel, manufacturing and AI research, with over a hundred public accounts holding exposed financial material. The images are not incidental. They include customer records, utility billing data, personal information, internal dashboards, unreleased product features, credentials visible on screen, and in financial firms, treasury, settlement and money-movement interfaces. The mechanism deserves attention because nothing in it is an attack. Engineers asked coding agents to capture before-and-after interface screenshots for pull requests, which is a reasonable request and ordinary practice. An agent working in a text-based environment could not use the image-upload path available through the browser interface, so it reasoned that the images had to be hosted somewhere reachable, created or reused an adjacent public repository, and linked from the private pull request. The review worked. The screenshots were public. Roughly a third of affected organisations had developers using gitshot, a small open-source utility whose default authenticated behaviour creates a public gitshot-images repository and uploads images as release assets; the tool's own documentation warns against sending credentials, internal dashboards or private data through that default, which tells you the failure was foreseen and the warning was not read.
Why it matters for IndiaOf the four items here, this is the one most likely to be live in an Indian organisation right now, because the conditions it needs are the normal conditions of Indian software work. Coding agents are in daily use across product companies, GCC engineering functions and services firms, and services work in particular happens inside client estates, which means the exposed material may belong to a customer rather than to you. The exposure then sits in a developer's personal GitHub account, outside the corporate organisation, so data-loss monitoring keyed to the organisation does not see it, asset inventories do not list it, and nothing generates an alert. The organisations in this research did not find their own exposure; they were notified.
ActionSearch public GitHub now for your organisation name, your internal application and project names, your clients' names where contracts permit, and for gitshot repositories and _gitshot release tags associated with your developers' accounts. Where you find exposure, remove the assets, treat any credential visible in an image as compromised and rotate it, and record the customer-notification question rather than deferring it. Then close the path: require approval before an agent may create a repository or change a repository's visibility, update GitHub CLI to 2.99.0 so the authenticated --attach upload is available and the public workaround is unnecessary, and turn off blanket auto-approval in agent configurations. Agent tool configuration is a security control, and in most Indian organisations it is currently owned by whoever installed the tool.
SourceGlow Labs, "PixelLeak" research, notifications from 9 September 2026; Help Net Security, Cybersecurity News and The New Stack (30 September 2026).
4
An Android banking trojan's control panel is asking a commercial AI model to estimate victims' bank balances from their text messages, and to rank the infected phones accordingly
Cleafy Labs published "From BlackCat to Panda Workshop: inside the evolving C2 panel behind RATHat" on 28 September 2026, authored by Simone Mattia and Alberto Giust. The panel has been through three generations between April and September 2026, built from common code and renamed along the way, from BlackCat Remote Control Management to Panda Workshop V5 and V6. Cleafy identified close to a hundred separate console deployments, with nearly half concentrated on a single Singapore-based autonomous system. From the console an operator can build the malware, conceal it inside an unremarkable-looking application, sign it, and publish it to object storage or a web server, which indicates a service sold to many operators rather than tooling held by one crew. The AI component is not in the malware's capability but in its economics. The console asks a commercial model, consolidated to Gemini in the later versions, to estimate a victim's bank balance from text messages the malware has already collected, then sorts the infected devices into high-value and mid-value groups so an operator's attention goes where the money is. On the device, when the malware's static interface mapping fails on an unfamiliar handset, it serialises the live screen and asks the model where to interact. The API key sits in the malware's own configuration rather than being proxied through the control server. Cleafy's defensive emphasis is on monitoring rather than mitigation: shell-level control that sits outside the Android permission model, and binaries executing with UID 2000. It also makes a forward-looking observation that Indian fraud teams should take seriously, which is that model-driven interface automation removes the per-target engineering cost that previously kept automated transfer fraud confined to a few well-resourced groups.
Why it matters for IndiaCleafy names Europe, Latin America and South-Eastern Asia among the targeted regions, and India is not named in this research, so read this as tradecraft rather than as a campaign against Indian institutions. The exposure is still direct. Android is the dominant platform for Indian retail banking and UPI, sideloading remains a routine consumer behaviour here, and SMS continues to carry transaction and balance information that this panel reads as a scoring input. The specific shift is in prioritisation. Mobile banking fraud has historically been limited by how much manual effort each infected device costs an operator; a model that triages devices cheaply raises the yield on the same infection base without any new malware capability. Indian banks and payment operators should also note that defences tuned to known malicious package names will not register a technique change of this kind.
ActionFor bank and payment fraud teams, shift detection weight toward behaviour rather than application identity: accessibility-service abuse, remote-control and screen-sharing signals, device-integrity failures, and transactions initiated in sessions showing automation characteristics. Make step-up verification out-of-band and mandatory when remote-control indicators are present, rather than advisory. For mobile security and engineering teams, review how much transaction and balance detail your SMS templates expose, since that text is the scoring input here, and move customers toward in-app notification where you can. Customer communication should name the specific behaviour to refuse, which is installing an application from a link sent in a message or a call, and granting accessibility permissions to it. For monitored enterprise fleets, add Cleafy's indicators on shell-level control outside the permission model and UID 2000 execution to your mobile threat-defence rules.
SourceCleafy Labs, "From BlackCat to Panda Workshop: inside the evolving C2 panel behind RATHat", Simone Mattia and Alberto Giust (28 September 2026); The Hacker News (28 September 2026); Infosecurity Magazine.
AI defender tip: The thread running through this edition is permission, not vulnerability. The agent that breached DIVD was not clever; it was fast, and it was reaching things nothing stopped it from reaching. The coding agents that published company screenshots were not compromised; they were allowed to create public repositories and nobody had said they could not. The MCP advisories describe clients that trusted a server because no boundary had been drawn there. Only the AWS argument-injection flaw is a bug in the sense a vulnerability-management process would recognise. So the exercise for this week is a reachability audit, and it is small enough to finish properly. Take three AI-enabled workflows that are already running in your organisation, not planned: a coding agent, one internal agent using MCP or similar connectors, and one automation in IT or security operations. For each, write down four things on one page. Which identity does it act as, and is that identity distinguishable from a human's in your logs. What can it write to, specifically, including repositories, object storage and ticketing systems. Which external services can it contact, and who approved each. And which secrets can it read, with the date each was last rotated. Then make three changes: remove one permission the workflow does not need, rotate one long-lived credential it can reach, and add one detection that would fire on an agent publishing to a public destination. Most teams will find the one-page answer takes longer to assemble than the three changes take to make, and that is itself the finding worth reporting upward.
Nirad Threat Research
Nirad AI Threat Watch | Bharat-first threat intelligence