Bharat Threat FeedGlobal threats, decoded for Indian defenders
Nirad Bharat Threat Feed

India-first threat intelligence

Global threats, decoded for Indian defenders — weekly briefs, sector editions, and AI Threat Watch. Every claim source-attributed.

Weekly Latest Weekly Brief 2 October 2026 Open issue →

Weekly Brief — 2 October 2026

Three widely deployed products went under confirmed exploitation in the last week of September, and in each the flaw sat in the component that authenticates users or configures other devices. In all three, attackers were working the flaw before the advisory existed, so the patching window and the exposure window are not the same period.
1

Two NetScaler zero-days exploited before Citrix disclosed them — CVE-2026-88771 and CVE-2026-88772

India exposureBoth rate 9.5 on CVSS v4. CVE-2026-88771 gives unauthenticated command execution in the default configuration of NetScaler ADC and Gateway; CVE-2026-88772 is a memory overflow reachable wherever DTLS is on, the default for VPN virtual servers. NetScaler Gateway fronts remote access for Indian banking, insurance and IT services. Unit 42 traced version fingerprinting to 21 August and web shell drops through September, before the advisory on 27 September.
ActionMove to 14.1-73.37 or 13.1-64.23, and 13.1-37.279 on the FIPS and NDcPP lines. Where that cannot be immediate, reduce internet exposure. Web shells survive the upgrade, so hunt for them separately and rotate what the appliance held.
SourceCitrix security bulletin, reported by BleepingComputer, 27 September 2026; Palo Alto Networks Unit 42, 30 September 2026; CISA Known Exploited Vulnerabilities catalogue, 27 September 2026.
2

Cisco Catalyst SD-WAN Manager hands administrator access to one crafted request — CVE-2026-76504

India exposureRated 9.8. The API mishandles URL encoding, so a crafted request skips the rule guarding a protected endpoint and returns administrator privileges. Configuration does not alter the exposure and Cisco lists no workaround. The controller holds configuration for every branch beneath it, which in India means multi-branch banks, NBFCs, retail chains and providers running customer networks.
ActionUpgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1. Take the management interface off untrusted networks and review administrator activity for the weeks before the fix.
SourceCisco security advisory, 30 September 2026; Rapid7, 30 September 2026; CISA KEV catalogue, 30 September 2026, remediation date 3 October 2026.
3

Microsoft documents a running campaign against Zimbra mail servers — CVE-2026-73570

India exposureUnauthenticated command injection in the SNMP notification path, triggered by a crafted email with no user interaction, where the optional zimbra-snmp package is installed and notifications are enabled. Commands run as the zimbra service account. Zimbra carries mail for many Indian government departments, public sector undertakings, state bodies and universities on self-managed servers. Microsoft records web shells, stolen credentials and authentication keys, and mailbox data staged for exfiltration.
ActionThe fix shipped in 10.1.20 on 20 July. Until it is applied, remove zimbra-snmp or disable SNMP notifications. Rotate Zimbra authentication secrets and search application directories for JSP web shells.
SourceMicrosoft Threat Intelligence, 30 September 2026; CISA KEV catalogue, 21 August 2026.
4

Chinese espionage cluster names India among eight countries targeted — UAT-11587

India exposureCisco Talos assessed with moderate to high confidence that the campaign reached government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, with roughly 350 compromised endpoints. Antino, the backdoor, is compiled in Rust and takes its instructions from Outlook and OneDrive rather than attacker-registered infrastructure, so the command channel is ordinary Microsoft 365 traffic.
ActionEgress filtering will not separate this from legitimate use. Work from mailbox and OneDrive audit logs, unexpected Graph and EWS application activity, and execution of HTA, WSF and JScript files from user-writable paths.
SourceCisco Talos, 30 September 2026.
5

KillSec infrastructure seized in Europe while India leads the regional victim count

India exposureHamburg police, with Europol and Eurojust, took over KillSec's leak site on 30 September, securing at least 110 terabytes of stolen data along with five servers and five domains, and arresting three suspects in Spain, the United Kingdom and Romania. Investigators are examining about 1,000 suspected attacks. The group worked through software flaws and poorly secured cloud storage. Cyble separately reported that groups publicly claimed 24 Indian victims in August, the highest count in Asia-Pacific.
ActionOne operation has been removed, not the route it used. Audit cloud storage permissions, remote access without MFA, and the separation of backups from production credentials.
SourceEuropol and Hamburg police action, reported by The Hacker News, 1 October 2026; Cyble Research and Intelligence Labs, 30 September 2026. All three vulnerabilities above were exploited before the advisory that described them, and each gave the attacker reason to leave something behind: a web shell, a stolen key, a configuration already copied. Patching on advisory day answers the first question and not the second. The KillSec seizure makes the same point from the other direction, since the access those intrusions relied on was exposed storage and remote entry without MFA. — Nirad Threat Research
Sector Latest Sector Edition October 2026 Open issue →

Government & Defence Sector Edition — October 2026

Between 22 September and 4 October, exploitation was confirmed in an SD-WAN manager, an SD-WAN orchestrator, a firewall management server, a secure mail gateway and a remote-access appliance. Each is a place where one unauthenticated request yields control of an estate rather than a single host. In the same weeks a State Data Centre in India carried active malware for five days and took departmental portals down with it, and a state department's website was defaced while sitting on a commercial hosting account. For Indian government and defence estates the thread is consistent: the systems that administer other systems are now the target, and most of them are not on anyone's patch calendar.

1. Sector snapshot

September pushed the exposure up a layer. CISA catalogued Check Point, Arista VeloCloud and F5 entries on 22 September, a Cisco Catalyst SD-WAN Manager authentication bypass on 30 September, Fortinet FortiMail on 1 October and a Citrix NetScaler flaw on 4 October. All of these products administer or front other systems, so a successful request buys policy control, mail flow or remote access across a department. For scale on the Indian backdrop, Seqrite's India Cyber Threat Report 2026 recorded 265.52 million detections across its own India telemetry for October 2024 to September 2025, with trojans at 88.4 million and file infectors at 71.1 million. That is Seqrite's telemetry, cited as theirs.

Source (with date): Seqrite India Cyber Threat Report 2026; CISA KEV (22 Sep, 30 Sep, 01 Oct and 04 Oct 2026).

2. Threats targeting government & defence

Cisco Catalyst SD-WAN Manager authentication bypass, CVE-2026-76504 (CVSS 9.8). Improper handling of hex and URI encoding lets an unauthenticated attacker send a crafted HTTP request to the API and obtain administrator access to vManage. Catalogued 30 September 2026 with a 3 October federal date, the eighth Cisco SD-WAN flaw added during 2026.Exposed:departments and PSUs using Catalyst SD-WAN for district and field connectivity, where the manager holds every branch configuration.Action:patch, then review service proxy and vManage logs for POST requests to /j_security_check, especially with usernames beginning viptela-reserved-.

Source (with date): CISA KEV (30 Sep 2026); The Hacker News (01 Oct 2026).

Fortinet FortiMail unauthenticated file write, CVE-2026-104286 (CVSS 9.8). Path traversal combined with improper handling of a NULL byte, allowing arbitrary file writes through crafted HTTP or HTTPS requests. Fortinet confirmed exploitation without stating when attacks began. Affected: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. Fixes are 8.0.2, 7.6.7 and 7.4.9, unreleased when this was reported, so mitigations are the control for now: disable identity-based encryption and take the management interface off the internet. The 7.2 branch has no listed fixed build, which makes migration the real remediation there.

Source (with date): Fortinet PSIRT; CISA KEV (01 Oct 2026); Help Net Security (02 Oct 2026).

Check Point pre-authentication code execution and management traversal, CVE-2026-85102 and CVE-2026-93616 (both CVSS 9.8). The first is improper certificate validation during VPN negotiation on Security Gateway and Spark firewalls: a crafted certificate presented before authentication completes gives code execution without credentials, and Check Point states exploitation began 12 September 2026 against Spark customers globally. The second is a pre-authentication path traversal in the Security Management web service allowing a script to be uploaded and run on the management server, with pinpointed attacks detected 23 July 2026.Action:patch both, then review logs for unusual certificate-based Mobile Access logins and for uploads to the management server.

Source (with date): Check Point advisory (22 Sep 2026); CISA KEV (22 Sep 2026).

A State Data Centre carried malware for five days. Reporting on the West Bengal State Data Centre states malware was active on the main server from 9 to 13 September 2026. Websites of several departments, including Public Works, Housing, Municipal Affairs and Urban Development, and the State Police, went down, with backend operations blocked for some. Forensic examiners were reported to fear that documents from four departments including Finance had been taken and destroyed. Treat the loss as reported and feared rather than established; the investigation was continuing and the main server had not returned to normal. The structural point: a State Data Centre is shared tenancy for dozens of departments, so one intrusion is a multi-department outage, and recovery rests on restore paths nobody rehearsed.

Source (with date): UNI India (22 Sep 2026); The Statesman (Sep 2026).

A departmental portal defaced on someone else's hosting account. The Kerala General Administration Department website was defaced on 27 September 2026, with a claim of responsibility by a group calling itself Team Blackleets, described in reporting as suspected Pakistan-based. That claim is the claimant's, not an attribution. The hosting provider suspended the account, officials said a cyber team was checking for any data breach, and the portal was still unavailable on 30 September 2026. Defacement is unsophisticated; the control gap is not. A departmental site on a commercial shared-hosting account sits outside the department's own monitoring, patching and incident-response path.

Source (with date): The Print (27 Sep 2026); Organiser (30 Sep 2026).

3. Sector tech & exposures

- The SD-WAN and access control planes, twice over. Arista VeloCloud Orchestrator CVE-2026-93952, improper input validation rated CVSS 10.0 and confirmed exploited, announced 22 September 2026 and catalogued the same day with a 25 September federal date. An attacker needs network access to the on-premises orchestrator web interface and the public portion of the VeloCloud Edge authentication certificate, but no tenant or operator credentials. Affected builds are 6.1.3.7 and below and 7.0.0.2 and below, with fixes in 5.2.3.16 and 6.4.2.8; confirm your branch has a build to move to. Alongside it, F5 BIG-IP APM CVE-2026-94127 is a heap-based buffer overflow rated CVSS 9.8 giving unauthenticated remote code execution, published 22 September 2026 with exploitation confirmed. It is not reachable in a default build: the virtual server must carry both an APM access policy and an OAuth profile, which makes this a configuration audit rather than a version check. Source (with date): CISA KEV (22 Sep 2026); BleepingComputer (23 Sep 2026). - Citrix NetScaler CVE-2026-88779, where the patch did not end the matter. A memory overflow in NetScaler ADC and Gateway rated CVSS 8.7, reachable where a customer-managed appliance is configured as a SAML service provider or identity provider. Citrix published the bulletin and fixed builds on 3 October 2026 after targeted exploitation had been observed, and CISA catalogued it on 4 October with a 7 October date. Documented impact is denial of service and repeated restart, and administrators reported crashes on appliances patched days earlier for the August and September NetScaler flaws. There is no broadly documented public proof of reliable remote code execution, so do not escalate it to that in a board paper. In government estates SAML is the single sign-on path into departmental portals, so an outage here is an authentication outage. Source (with date): Citrix security bulletin (03 Oct 2026); CISA KEV (04 Oct 2026). - Helpdesk software holds citizen data and is rarely on the patch calendar. Zammad CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, catalogued 2 October 2026 with a 5 October federal date. Chained, session fixation gives code execution as the zammad service account and improper privilege management escalates to root. The Dutch Institute for Vulnerability Disclosure states its own systems were reached on 21 September 2026 and characterises the intrusion as driven by an agentic AI system executing each step automatically. Reported version scope varies between sources, with upgrade to version 7 the recommendation carried in that reporting, so take the affected range from the vendor rather than a summary. Government service desks and grievance-redressal portals run exactly this class of software. Source (with date): CISA KEV (02 Oct 2026); SecurityWeek (01 Oct 2026). - A shared whole-of-government platform, breached through a known medium-severity flaw. Japan's Digital Agency disclosed that roughly 246,000 record rows of government personnel data were exposed after attackers exploited a known, medium-severity VPN device vulnerability attached to the shared platform used across its ministries. India is not a victim and nothing is reproduced here. It earns its place because the architecture is ours too: on a platform shared by every department, a medium-severity rating on one appliance is not a medium-severity exposure, and severity scores should not be the thing that sets the patch queue. Source (with date): Japan Digital Agency disclosure (11 Sep 2026); TechNadu (14 Sep 2026).

4. Regulatory & compliance watch

- CERT-In's clock read against this month's catalogue. The May 2026 AI-exploitation guidance CISG-2026-02 sets an indicative expectation of 12 hours to remediate known exploited vulnerabilities on internet-exposed systems, 24 hours for critical externally exposed flaws not yet exploited, three days for critical internal high-value systems and five days for high-severity issues. This is guidance with indicative timelines, not a binding mandate, and should not be briefed as one. The binding instrument remains the directions of 28 April 2022: initial intimation within six hours, 180-day log retention within Indian jurisdiction, and clock synchronisation to NPL. A department carrying the Cisco, Fortinet, Check Point, VeloCloud or F5 entries into the second week of October is well outside that window. Source (with date): CERT-In CISG-2026-02 (May 2026); CERT-In directions (28 Apr 2022). - DPDP: one date is settled, the other is a proposal. The DPDP Rules were notified on 13 November 2025. Rule 4 applies from 13 November 2026, when registration with the Data Protection Board becomes mandatory for anyone operating as a Consent Manager in India. Separately, MeitY has proposed compressing the Significant Data Fiduciary runway from eighteen months to twelve, which would pull those obligations, including an India-based Data Protection Officer, impact assessments for high-risk processing and third-party audits, forward to 13 November 2026. That compression is a proposal discussed with stakeholders, not notified law; the baseline date for the substantive obligations remains 13 May 2027. Departments and PSUs processing citizen data are data fiduciaries, so plan against both and do not brief the proposal as settled. Source (with date): MeitY DPDP Rules (13 Nov 2025). - NCIIPC runs a second clock in parallel. NCIIPC sits under NTRO with its mandate from section 70A of the IT Act 2000 as amended in 2008, and the Central Government notifies a computer resource as a protected system under section 70(1). Each notified system needs a named system owner, a CISO and a defined nodal officer for NCIIPC coordination. Where a department operates one, NCIIPC reporting runs alongside CERT-In's six-hour path and both clocks start together, which is the detail that fails during an out-of-hours incident. Source (with date): NCIIPC guidelines; IT Act 2000 section 70A, as amended 2008.

5. Actor in focus — APT36 (Transparent Tribe), Operation RapidRust

Zscaler ThreatLabz published this on 16 September 2026. The Pakistan-nexus actor APT36 ran a campaign through August 2026 against government and defence organisations in India and Afghanistan, with most post-compromise activity between 20 August and 1 September 2026. Delivery used typosquatted domains impersonating Indian news outlets, hosting malicious PowerShell. RUSTYSHADE is a 64-bit Windows backdoor written in Rust whose command and control runs through attacker-controlled private GitHub repositories over the GitHub REST API, with AES-256-GCM encryption keyed from the SHA-256 hash of the GitHub personal access token; it handles screenshots, webcam access, file transfer and command execution. RUSTYMOVE watches for removable media and propagates. PSNATCH on Windows and BASHNATCH on Linux collect documents and archives modified within the last 120 days and exfiltrate to GitHub. Payloads were staged through Backblaze cloud storage, and command and control ran only on weekdays, roughly 04:00 to 11:00 UTC.

Three details should change a defender's configuration. GitHub REST API traffic and commercial cloud-storage downloads are allow-listed on most government networks, so this channel resembles developer activity rather than exfiltration. The removable-media component means an air gap is a control to be monitored, not a boundary to be assumed. The 120-day filter shows collection aimed at current working documents. APT36 and the aligned SideCopy cluster remain the standing espionage pressure on Indian government and defence networks, with spear-phishing delivering weaponised LNK, HTA, PPAM and ELF files; keep those detections live irrespective of this campaign.

Source (with date): Zscaler ThreatLabz (16 Sep 2026); Seqrite (2026).

6. IOC pack

Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural leads; the Type column says which, and the leads need tuning against your own baseline.

IndicatorTypeContextSource
theprints[.]org, indiatodays[.]org, officialinfo[.]orgDomainsAPT36 delivery, impersonating Indian news outletsZscaler ThreatLabz
C:\Users\Public\Documents\DriverInstaller.zipFile pathRapidRust stagingZscaler ThreatLabz
StandAloneOneDriveUpdater-2626Scheduled taskRapidRust persistenceZscaler ThreatLabz
GitHub REST API calls to private repositories from non-developer hostsDetection leadRUSTYSHADE command and controlZscaler ThreatLabz
Backblaze downloads followed by PowerShell executionDetection leadRapidRust payload stagingZscaler ThreatLabz
Process creation shortly after removable-media insertionDetection leadRUSTYMOVE propagationZscaler ThreatLabz
POST requests to /j_security_check, usernames beginning viptela-reserved-Log patternCisco Catalyst SD-WAN Manager exploitationCISA KEV; The Hacker News
Certificate-based Mobile Access logins with unusual certificate subjectsDetection leadCheck Point CVE-2026-85102 exploitationCheck Point
CVE-2026-76504CVECisco Catalyst SD-WAN Manager bypass, exploitedCISA KEV
CVE-2026-104286CVEFortiMail unauthenticated file write, exploitedCISA KEV
CVE-2026-85102, CVE-2026-93616CVECheck Point gateway and management flaws, exploitedCISA KEV
CVE-2026-93952CVEArista VeloCloud Orchestrator, exploitedArista; CISA KEV
CVE-2026-94127CVEF5 BIG-IP APM, exploitedF5; CISA KEV
CVE-2026-88779CVECitrix NetScaler SAML memory overflow, exploitedCitrix; CISA KEV
CVE-2026-102489, CVE-2026-102490CVEZammad chain to root, exploitedCISA KEV

7. Tiered actions

Board. Ask for one page listing which systems administer other systems and who patches each: the SD-WAN manager, the firewall management server, the mail gateway, the remote-access appliance, the helpdesk platform. Ask who owns the department's dependency on the State Data Centre and what the tested restore path is if it is unavailable for a week. Ask which departmental websites run on commercial hosting and who monitors them. Confirm the six-hour CERT-In path has been exercised out of hours and that NCIIPC reporting runs in parallel for any notified protected system. Ask for a DPDP position separating the settled 13 November 2026 Consent Manager date from MeitY's proposed compression.

CISO. Emergency-patch Cisco Catalyst SD-WAN Manager, Check Point gateway and management, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Citrix NetScaler and the helpdesk estate. On FortiMail apply the mitigations now and plan branch migration where no fixed build exists. Make compromise assessment, not patch completion, the closure criterion on every internet-facing system in that list: rotate credentials, tokens and certificates, and look for administrative accounts and scheduled jobs created before the fix. Audit the F5 estate by configuration rather than version. Bring departmental sites on third-party hosting under managed hosting with logging. On defence estates, block sideloaded packages, enforce device enrolment, and monitor removable-media use on isolated networks instead of treating the air gap as sufficient.

SOC. Hunt the section 6 indicators. On the perimeter, alert on POST requests to /j_security_check with reserved-prefix usernames, on certificate-based Mobile Access logins with unexpected subjects, on file writes outside expected paths on FortiMail, and on unexplained NetScaler restarts. Inside the estate, alert on GitHub REST API traffic to private repositories from hosts with no development function, on cloud-storage downloads followed closely by PowerShell, on process creation after USB insertion, and on new administrative accounts or tokens on any management platform. Baseline administrative logins to the SD-WAN manager and orchestrator now rather than during an incident. Keep the APT36 and SideCopy lure and loader detections active.

8. Source index

Arista · BleepingComputer · CERT-In (CISG-2026-02 and directions of 28 Apr 2022) · Check Point · CISA Known Exploited Vulnerabilities catalogue · Cisco · Citrix · Dutch Institute for Vulnerability Disclosure · F5 · Fortinet PSIRT · Help Net Security · Japan Digital Agency · MeitY (DPDP Rules) · NCIIPC · Organiser · SecurityWeek · Seqrite · TechNadu · The Hacker News · The Print · The Statesman · UNI India · Zscaler ThreatLabz

9. Byline

1

Nirad Threat Research

NBTF — Government & Defence Sector Edition | 7 October 2026

AI Watch Latest AI Threat Watch 8 October 2026 Open issue →

AI Threat Watch — 8 October 2026

Two of this week's disclosures turn on the same question, which is who supplied the input that an automated system then acted on using somebody else's authority. A coding agent read a developer's production secrets and sent them out, and the vendor's position is that the user asked for it. An enterprise CRM agent acted on instructions a stranger had typed into a public lead form weeks earlier. Google's new measurement sets out the queue all of this now sits in: vulnerability disclosures roughly doubled over the first eight months of 2026, and the flaws research agents find are about twice as likely to end in remote code execution as those found by other means. The fourth item is the one closest to Indian customers, because a government-backed awareness campaign launched in Mumbai on Monday names voice cloning and real-time deepfakes as mainstream fraud, which is an acknowledgement that the technique has already reached ordinary people.
1

Google's threat intelligence group has measured what AI is doing to vulnerability discovery, and the finding that matters is not the volume but the profile: flaws found by research agents are roughly twice as likely to end in remote code execution

The Google Threat Intelligence Group published "Vulnerability Discovery and Exploitation Trends in the AI Era" on 30 September 2026, covering January 2025 to August 2026. Monthly disclosures roughly doubled over the period, from 5,045 in January 2026 to 10,740 by August, and those rated high risk rose 167 percent, from 131 to 350. Of the vulnerabilities GTIG assesses as likely discovered by AI, about half lead to remote code execution against 26 percent across the wider CVE set, and they cluster in the medium-risk band rather than the low-risk one, 58 percent against 28 percent. GTIG reads this as autonomous research agents being aimed at consequential software rather than swept broadly across everything. Two numbers cut in the opposite direction, and they are the ones that make triage defensible. Observed in-the-wild exploitation rose from an average of 10.5 vulnerabilities a month in 2025 to 18 a month over January to August 2026, which is 141 distinct exploited vulnerabilities against 127 in the whole of 2025. But only 0.23 percent of disclosures, roughly one in 431, were seen exploited at all. Volume is rising faster than exploitation, so patching by severity score alone spends effort that the compressed timelines now require elsewhere. GTIG's worked example is CVE-2026-1731, an unauthenticated operating-system command injection in BeyondTrust Remote Support and Privileged Remote Access, found autonomously by the Hacktron AI research agent. BeyondTrust published advisory BT26-02 on 6 February 2026, rating it 9.9 under CVSS version 4, affecting Remote Support 25.3.1 and earlier and Privileged Remote Access 24.3.4 and earlier, with fixes in Remote Support 25.3.2 and Privileged Remote Access 25.1.1 and later. One threat cluster exploited it within four days of disclosure and five more followed inside seven days; CISA added it to the Known Exploited Vulnerabilities catalogue on 13 February 2026. Separately, GTIG counts 2,076 AI-related CVE disclosures since January 2025, with agent orchestration and agent frameworks the largest category at 782 and up 347 percent in 2026, naming Flowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, Semantic Kernel, Letta, MCP and Pydantic-AI among them.

Why it matters for IndiaNothing in this research is directed at India, but the exposure categories it ranks are the ones Indian estates are built on. Edge and security appliances account for 14 percent of exploited vulnerabilities and enterprise directory and collaboration services for 11 percent, and remote-access and privileged-access products of exactly the BeyondTrust type sit in front of government departments, banks, managed service providers and critical-infrastructure operators here, very often operated by a third party under contract. CERT-In's advisory line through 2026 has been that the interval between disclosure and exploitation has collapsed, and this research puts a measured figure behind that argument rather than an assertion. The practical consequence for an Indian CISO is that a monthly patch cycle cannot be reconciled with a four-day exploitation interval on an internet-facing appliance, and the gap has to be closed by triage, because no Indian security team is going to be given enough people to patch everything quickly.
ActionRun a separate daily queue for internet-facing appliances, remote and privileged access products, identity providers and collaboration platforms, driven by known exploitation rather than by severity scores. Confirm in writing that BeyondTrust Remote Support is at 25.3.2 or later and Privileged Remote Access at 25.1.1 or later, including instances a managed service provider runs on your behalf. Where an appliance ran unpatched while exploitation was public, review administrative activity, new accounts, changed access policies and outbound connections from that host, and preserve the logs before rebuilding. For the AI estate, inventory the orchestration frameworks GTIG names, establish which hold production credentials, and separate the ones that do not need them. Then take GTIG's structural recommendation seriously: sandbox autonomous agentic workloads so that code execution inside them is contained rather than assumed benign.
SourceGoogle Threat Intelligence Group, "Vulnerability Discovery and Exploitation Trends in the AI Era" (30 September 2026); Infosecurity Magazine and SiliconANGLE (30 September 2026); Help Net Security (1 October 2026); BeyondTrust advisory BT26-02 for CVE-2026-1731 (6 February 2026); CISA Known Exploited Vulnerabilities catalogue addition (13 February 2026); Rapid7 analysis of CVE-2026-1731.
2

A coding agent was made to read a developer's production secrets and send them to an external endpoint, and the vendor's position is that this is not a vulnerability because the user asked for the content and had granted the agent autonomy

Adversa AI published research on 6 October 2026 describing a technique it calls Cryptographic Context Injection against GitHub Copilot CLI. The defensive point sits above the mechanism, which this brief will not reproduce. A guardrail that inspects fetched content as it arrives can pass material that is not yet in an executable form; the agent then transforms that material inside its own tool runtime as an ordinary coding task, and treats the result as its own trusted context rather than as something an outsider supplied. In the demonstration the agent was in autopilot mode and was asked to look at one attacker-controlled web page. It went on to read local files, including a production environment file holding secrets, and send the contents to an external endpoint, with no visible indication on screen that a file had left the machine. The disclosure history is as much of the story as the technique. Adversa says it reported the finding to GitHub through its bug bounty programme on 17 September 2026, and that GitHub declined to classify it as a product vulnerability, on the reasoning that the user had asked for the attacker-controlled content and had granted autonomous permissions. No CVE has been assigned. Reasonable people can disagree about where product responsibility ends, but an enterprise security team cannot adopt that reasoning, because the user who approved a broad task did not approve the specific resolved actions that followed, and no approval record in that organisation will show otherwise. Two other recent pieces of work point the same way. Salt Labs published research on 1 October 2026 showing that a single email could hijack the agentic platform Manus and reach the email, cloud storage and code repository accounts a user had connected to it; the platform's guardrail did detect the activity, but the warning arrived after the code had already run, and Salt Labs' conclusion is that a control which fires one step late has not fired. That issue has been fixed. Academic work published on 18 September 2026 by Szczepaniak, Feldman, Viner and Nassi found that conditional payloads which stay dormant until a later trigger succeeded in 43 to 83 percent of trials across nine production agents, against at most 3 percent for a direct instruction, and proposes detection at the point content is ingested.

Why it matters for IndiaCoding agents and agentic developer tooling are in routine use across Indian product companies, GCC engineering functions, fintechs and services firms, on machines holding source code, cloud tokens, repository credentials, CI secrets and, in services work, access into a customer's environment rather than only your own. The pattern these three pieces of research share fits Indian delivery work closely, because engineers here routinely pull external tickets, vendor documentation, customer logs and third-party pages into an agent's context and then let it act. The governance problem is the sharper one. If a vendor treats an agent action as authorised because the user approved the overall task, and no CVE is issued, then this exposure never reaches your vulnerability management process at all. Where a leaked credential reaches customer personal data, the obligation under the Digital Personal Data Protection Act does not soften because the action was technically permitted.
ActionTurn off autopilot or equivalent autonomous modes whenever an agent is handling content from outside the organisation, including web pages, email, tickets, pull requests and customer-supplied files. Require explicit confirmation for reads outside the working directory, for any action touching secret-bearing files, and for outbound connections to destinations not on an allowlist. Log tool calls with their resolved arguments rather than the agent's own description of what it did, because that summary is written by the component you are trying to supervise. Build the detection Adversa recommends: untrusted content entering context, then code execution, then an outbound request. Run coding agents under least-privilege identities in workspaces holding no production credentials, and rotate what those machines have already held. Extend your vulnerability intake beyond CVE feeds to vendor and research-lab advisories, because this item has no CVE and would otherwise be invisible to you.
SourceAdversa AI, "Cryptographic Context Injection" research on GitHub Copilot CLI (6 October 2026); CSO Online; Salt Labs research on the Manus agentic platform (1 October 2026), reported first by Dark Reading; Szczepaniak, Feldman, Viner and Nassi, "Defusing Explosive Prompts", arXiv 2609.22510 (18 September 2026).
3

Three flaws in Salesforce Agentforce allowed a stranger who filled in a public lead form to have a company's own AI agent query CRM records and carry selected values out, with no click from any employee

Zenity Labs published the research, which it calls SalesBleed, on 24 September 2026, authored by Alex Apostolov, João Donato, Avishai Efrat and Ayush RoyChowdhury. The first weakness is a question of timing and trust rather than of code: instructions submitted through a public Web-to-Lead form sat in Salesforce as ordinary data until an employee later asked the agent to review recent leads, at which point the agent acted on them. The second is that Salesforce's Trusted URLs redaction, the control meant to stop an agent sending data to an unapproved destination, had two parsing failures that let an attacker-controlled destination through. The third is separate and concerns the Slack integration, where the agent could post messages without reliably recording who had triggered the action and without the confirmation step Salesforce normally requires, which would let an insider send phishing under the agent's trusted identity while remaining unidentified. The remediation timeline is complete, which is why this is an architectural lesson rather than a live emergency. Zenity reported to Salesforce on 1 June 2026; Salesforce confirmed the Trusted URLs fix on 18 August 2026 and Zenity verified it on 19 August; the Slack-path fixes, which added proper attribution and changed insecure defaults, were confirmed and tested on 21 September 2026. No CVE was assigned to any of the three. What outlives the patches is the researchers' own generalisation: prompt injection stops being a content-safety problem and becomes an access-control problem the moment an agent combines three properties, which are ingesting untrusted external input, rendering rich content, and holding access to sensitive backend data. Agentforce happened to be the product examined. The three properties are not specific to it.

Why it matters for IndiaIndian BFSI, telecom, healthcare, education technology, IT services and public-sector organisations run CRM and collaboration platforms with public lead intake, partner portals and messaging integrations, and many are now piloting agents on top of exactly those systems. A public form is reachable by anyone by design; if the agent that later reads those records also holds access to accounts, contacts, opportunities and cases, the boundary between a stranger's input and your customer data is thinner than the architecture diagram suggests. CRM records in Indian BFSI contain personal and financial data, so an agent-mediated leak is a data leak for the purposes of incident response, client notification and DPDP Act governance, whatever the agent was configured to do. Most of these deployments are assembled by an integrator, so the controls in question were chosen by a third party and are rarely written down anywhere the security team can read them.
ActionTreat every agent as a privileged non-human identity with its own inventory entry, owner and access review. Establish which agents can read leads, accounts, contacts, opportunities and cases, and separate those that process public submissions from those that can query sensitive objects, because combining both jobs in one identity is the condition this research turns on. Require confirmation and recorded attribution for any agent write into a collaboration tool, and verify your Slack or Teams integration now shows who triggered a message. Confirm with Salesforce or your integrator that the Trusted URLs hardening and the Slack attribution defaults are active in your own tenant rather than merely released. Monitor outbound DNS and HTTP from CRM and collaboration surfaces for destinations with no business relationship. Then ask the general-form question of every agent you run: does it read anything a stranger can write, and can it reach anything you would have to report losing.
SourceZenity Labs, "SalesBleed: 0-click data exfiltration on Agentforce" and the companion research on the Agentforce Slack integration (24 September 2026); Infosecurity Magazine (25 September 2026); SecurityWeek.
4

India's national awareness campaign for this month names AI voice cloning and real-time deepfakes alongside malicious APKs and digital-arrest scams, which places synthetic impersonation in the mainstream fraud category rather than the emerging one

The Data Security Council of India launched "Be Cyber Street Smart" on 5 October 2026 at the Bombay Stock Exchange in Mumbai, inaugurated by Maharashtra's IT Minister Ashish Shelar and running through October for Cyber Security Awareness Month. It is supported by CERT-In, the Indian Cyber Crime Coordination Centre, MeitY and the Government of Maharashtra, with participants including Axis Bank, HDFC Bank, Punjab National Bank, CRED, PayPal, BSE, Thales, Veeam, 63SATS and ZS Associates. This is an awareness campaign and not a disclosure, and it is here for what the choice of topics indicates: when the national industry body, the CERT and the cybercrime coordination centre jointly put AI voice cloning and real-time deepfakes into a campaign aimed at ordinary citizens, the technique has stopped being a demonstration and become a volume fraud. The regulatory frame is already in force. The IT Rules amendments notified on 10 February 2026 and effective from 20 February brought synthetically generated information into scope, requiring prominent labelling and embedded provenance markers that platforms may not permit to be stripped, and compressing the window for acting on a government or court takedown order from 36 hours to three.

Why it matters for IndiaThe exposure is widest in BFSI, because voice cloning attacks the one authentication factor Indian banking operations have always treated as reliable, which is recognising the person on the call. That reaches past the customer. Contact centres, branch operations, help desks, treasury and vendor-onboarding teams all run processes where a familiar voice with a plausible reason has historically been enough to move a step forward. Government departments and public-facing services face the digital-arrest and official-impersonation themes directly, and defence suppliers and critical-infrastructure operators face executive impersonation aimed at payment diversion. For large intermediaries the three-hour window is an operational commitment that has to be staffed, not a policy position. No source here says any particular actor is targeting Indian institutions; what the campaign establishes is that the national bodies consider the technique common enough to warrant a public campaign.
ActionRemove "I recognised the voice" from every process that currently accepts it, and name the replacement: a callback on a number held in your own records, or an out-of-band confirmation, for payment instructions, vendor bank-detail changes, password and MFA resets, SIM changes, emergency procurement and privileged access requests. Test it rather than documenting it, by attempting a voice-led credential reset against your own help desk and recording what happens. Brief contact-centre and branch staff that detection by ear is not expected of them and that the process is the control. Align customer messaging with the campaign's four named techniques while the public attention is there. For intermediaries, confirm the takedown workflow can meet three hours outside business hours and on a public holiday, which is when it will be tested.
SourceData Security Council of India, "Be Cyber Street Smart" campaign launch, Bombay Stock Exchange, Mumbai (5 October 2026); APAC News Network, MediaBrief, Digital Terminal and India Education Diary launch coverage (5 to 6 October 2026); Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules on synthetically generated information, notified 10 February 2026, effective 20 February 2026.
AI defender tip: The phrase to distrust this week is "the user asked for it." GitHub's reasoning on the Copilot CLI research was that the developer requested the page and had granted the agent autonomy, so what followed was authorised. Salesforce's agent read a lead because an employee asked it to review recent leads, which it duly did, including the part a stranger had written. Manus detected the problem and said so, after the code had run. In each case something genuinely was approved, and in each case the thing that executed was not the thing the approver had in mind. That gap is where the whole category now lives, and it will not be closed by better model behaviour, because it is not a model failure. It is an authorisation design that collects consent for an intention and spends it on a sequence of concrete actions nobody reviewed.

The exercise for this week is small and produces an artefact you can show an auditor. Pick one agent already running in your organisation, in development, sales or support. Find a real session in the logs and write two columns. On the left, what the human approved, in the words they would have used. On the right, the resolved actions that executed: files read, records queried, hostnames contacted, messages sent. Most teams will find the right column cannot be reconstructed at all, because the logging captured the agent's summary of its work rather than its tool calls with arguments. That absence is itself the result, and worth reporting upward in those terms, because every control you might add afterwards depends on seeing that column first. If you can reconstruct it, compare the two sides and find the widest gap. That gap, not the model, is your next piece of work.

Nirad Threat Research

Nirad AI Threat Watch | Bharat-first threat intelligence