The Human Take
This week there’s a few interesting stories, but the write up in the Incident Reports section from Tech Insider collecting the information around the spring breach of Ernst and Young (EY), one of the Big 4 accounting firms. What really caught my eye was the timeline:
| Date | Event |
|---|---|
| March 26–28, 2026 | Unauthorized access to the ITSM platform begins |
| April 12, 2026 | Unauthorized access window ends; documents already downloaded |
| April 23, 2026 | EY detects anomalous activity on the platform |
| July 13, 2026 | Date listed on EY’s client notification letter |
| July 15, 2026 | EY files breach notification with the California Attorney General |
| July 17, 2026 | Breach becomes public via multiple outlets |
| Late July 2026 | ShinyHunters publicly claims responsibility for the intrusion |
| Late September 2026 | New letters confirm Goldman Sachs and Man Group client exposure |
The incident occurred sometime in March (and I question the dates there, because finding when something “started” is always a bit of… hypothesis), the adversary either got out or lost access on 12 APR, then they were detected by EY security in 23 APR. That may seem like a long time, but this is what it looks like when Cybersecurity takes a loss, a slick bad actor can root around for as long as they want. Then between detection and client notification was nearly… 3… months…
Cyber investigations can take a long while, but incident notifications of this potential criticality should normally be out within 24 hours of suspected breach. If you’re really conservative, maybe 3 days to really lock in the scope of the attack. 3 months? That’s public relations and legal teams filtering the security output into serious-but-dismissive notifications to the officially-mandated channels. This is the nature of things more than a condemnation of any particular business, but this whole incident highlights a very real problem in Cybersecurity, and it is not solvable by AI (and is slightly aggravated by it).
For the love of everything good and right about security, stop giving your critical data to third parties. Especially unencrypted data. There was a golden age in the late 2000s where PCs were still the daily driver, and we all learned how cool cloud storage was. Over time we – people and businesses – have moved out entire infrastructure to the cloud. The promise of lower maintenance, better security (which at one time was better than the petri dishes that were the PCs and local server farms of 2009) and lower overall cost made everyone rush to the cloud. Cloud providers found a way to encourage businesses to outsource their infrastructure and people to rent digital storage lockers to put all their junk in. Cost will always be debated, it really depends on how you want to categorize the numbers in an accounting ledger, but I think it’s fair to say that the security promise of the cloud have not delivered.
Cloud breaches started happening as people moved there, but more often than not, that could be chalked up to old IT being duplicated in the cloud and just getting compromised there. In 2014, a hacker breached the icloud accounts of numerous celebrities and posted their private data on the Internet. It was a huge scandal and pushed people into thinking about their personal security, but it also highlighted that putting all of your very private eggs in someone else’s basket may not be the best approach. In the dozen years since, cloud compromises are so common, no one bats an eye anymore.
In this case, EY – as I’ve gathered from reading the articles – was not directly breached, or was not initially breached. Instead, their IT Service Management tool (one of the surely 10 that they use), provided by a third party in the cloud, was breached. Was the whole product breached, or just EY’s instance? I’m not sure. Are they sure? The ITSM – and this has been verified – had client tax records, audit information, and a treasure trove of privacy information and financial data. So, let’s state that clearly. Ernst and Young – one of the largest accounting firms on the entirety of planet earth – is outsourcing… Something… That includes vital and critical records of their clients. And there’s the rub. Company A hires EY as a third party. EY hires ITSM company to handle critical data. Company A has now assumed the risk for ITSM company. If ITSM company hires Company X to process some of that data, Company A also gets to assume the risk of Company X.
If you’re getting someone to make the cake for the company Christmas party, it’s fine if the bakery uses a shady janitorial service. But if you handle the financial records for fortune 500 companies, do you really want to just believe that the service you hand your data to isn’t also hiring a shady janitorial company? I’d bet that EY has a Third-party Risk Management department – if it’s not contracted out – that is understaffed and woefully unable to handle the thousands of vendors that EY uses on a regular basis. But the wheel must turn, the spice must flow, and the vendors are used. That 3 month lag in reporting? That is – at least in part – the vendor being analyzed to figure out where EY liability stops and ITSM company X begins.
There is no good solution for this other than finding vendors who are doing it all themselves (good luck) or – to set up systems and procedures to ensure that third parties never have your critical data, unless it’s encrypted (by you or a method you understand and trust). I’m not made of stone – or time – so I use cloud storage, but if my data is important, I encrypt it at rest so if someone breaches my cloud accounts, they get a bunch of photos of my kids and gigabytes and gigabytes of encrypted nonsense data that they can’t do anything with without a key. And a password. And another key. You get the idea.
I’m speaking mostly to business here, but as an individual, you are just as much at risk as a company, if not more. If you’re interested in encrypting and have a little bit of time to learn something new, I recommend you look at Veracrypt, a free and open-source software for encrypting files, drives, volumes, creating hidden (and encrypted) drives, the works.
As AI dominates the Cyber news cycle, you may hear us back here yelling as loud as we can about the fundamentals. The AI monsters can’t get you if there’s no way in. If you trust someone else to handle your most holy of holies, you may be giving them a direct path to under your bed.

Weekly Cyber News Summary October 8, 2026
This week in cyber:State-Sponsored Attacks
Google’s Threat Analysis Group and Mandiant have attributed a coordinated series of cyber operations targeting the global defense industrial base to four nation-state actors: China, Iran, Russia, and North Korea. Unlike previous years where each country operated in isolation, these state-sponsored groups are now working in tandem across multiple vectors, striking defense contractors, supply chain vendors, and military technology firms simultaneously. The campaign leverages shared infrastructure, coordinated timing, and complementary toolsets to overwhelm defenders who traditionally track each actor independently. This convergence marks a structural shift in cyber warfare, where geopolitical allies pool resources to create multi-vector sieges that are harder to attribute, contain, or predict. For security teams, this means threat intelligence programs must now account for cross-actor collaboration rather than treating each nation-state campaign as a separate entity.
This development is significant because it compresses the attack surface across industries and geographies, forcing organizations to defend against a unified threat rather than isolated campaigns. The defense industrial base is particularly vulnerable because it sits at the intersection of government contracts, commercial technology, and export-controlled systems. A breach in one vendor can cascade through multiple prime contractors, making supply chain visibility more critical than ever. The coordinated nature of these attacks also suggests deeper intelligence sharing between the four nations, potentially including early warning of defensive measures and shared exploit libraries.
Sources:
ITBriefcase: https://itbriefcase.net/top-10-cybersecurity-stories-this-week-october-2-2026/
LinkedIn/Google TAG: https://www.linkedin.com/posts/automated-news-automator-solutions_google-links-china-iran-russia-north-korea-activity-7428151089306198017-U3Az
Regional Campaigns
ANY.RUN’s analysis of September 2026 threat activity reveals a multi-stage phishing ecosystem targeting US and EU organizations across technology, manufacturing, healthcare, and government sectors. Five distinct campaigns—CSuite, N0va, IronToll, Wazza, and TerminalFix—each exploit different attack surfaces: Microsoft 365 session theft, Device Code authentication flows, real-time payment card interception, anti-bot routing filters, and multi-stage payload delivery through compromised WordPress sites. The campaigns share a common pattern of using trusted cloud services and familiar authentication flows to blend malicious activity with legitimate business workflows, making detection increasingly dependent on behavioral analysis rather than static indicators.
The significance of these campaigns lies in their layered complexity. No single indicator tells the full story; a compromised session, a suspicious device registration, and an unusual outbound connection may all stem from the same initial lure. For SOC teams, this means investigation speed and context matter more than ever. The campaigns also highlight how attackers are moving beyond simple credential theft toward persistent access through token manipulation and remote management tool abuse, requiring defenders to monitor not just login events but the full authentication lifecycle across identity, browser, endpoint, and network layers.
Sources:
ANY.RUN: https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/
AI Integration
Cynet’s 2026 analysis documents a fundamental shift in how artificial intelligence drives cyber operations: AI has moved from assisting attackers to orchestrating entire attack chains autonomously. The report identifies hyper-personalized phishing, self-evolving malware, and AI-powered vulnerability discovery as the defining threats of the year. Machine-speed cyber warfare is now the norm, with attacks adapting in real time to defensive measures, creating feedback loops where both attackers and defenders deploy AI simultaneously. The report notes that 94% of organizations view AI as the biggest cybersecurity force shaping 2026, and 82.6% of analyzed phishing emails now contain AI-generated elements, fundamentally changing the scale and sophistication of social engineering campaigns.
What makes this year’s AI-driven threats particularly dangerous is the compression of the vulnerability lifecycle. AI can scan codebases, identify weaknesses, and generate exploits in minutes rather than weeks, narrowing the window between discovery and exploitation. Defenders must now rely on behavioral detection, automated response, and unified platforms to keep pace. The rise of dual-use AI models—systems that can both discover vulnerabilities and develop exploits—means that even restricted models will eventually find their way into attacker toolkits. The industry is shifting from signature-based detection to an assume- compromise posture, where continuous validation and intelligence-driven defense are the only viable strategies.
Sources:
Cynet: https://www.cynet.com/security-foundations/ai-machine-learning/ai-cyberattacks/
AI Policy and Posture Adaptation
September 2026 marks a critical inflection point for AI governance, with the EU AI Act’s first wave of high-risk system audits beginning across France, Germany, and Spain. The European AI Office is inspecting automated resume screening tools, algorithmic credit assessment systems, and AI triaging tools in healthcare, requiring providers to submit technical documentation on system architecture, training data provenance, and human oversight mechanisms. Simultaneously, California faces a September 30 deadline for Governor Newsom to sign or veto SB 1047, the Frontier AI Safety Act, which imposes strict obligations on developers training models exceeding 10^26 FLOPs, including mandatory pre-training safety protocols, full shutdown capabilities, and annual independent audits. Brazil’s Senate also voted on Bill 2338/2023 on September 16, establishing a comprehensive AI framework influenced by the EU model.
The convergence of these regulatory milestones reveals a global shift from voluntary AI governance to binding enforcement. Organizations operating across jurisdictions must now reconcile overlapping requirements: EU Article 11 technical files, California’s whistleblower protections and third-party audits, Colorado’s consumer-facing risk management programs, and China’s algorithm registry with mandatory watermarking. The compliance burden is no longer theoretical—it requires immutable audit logging, training data copyright opt-out verification, and automated red-teaming pipelines. For enterprises, the challenge is building a governance program that satisfies multiple frameworks without duplicating effort, with ISO/IEC 42001 certification emerging as a practical compliance passport for multinational operations.
Sources:
Cubbbix: https://cubbbix.com/blog/ai-regulation-september-2026-global-update/
Zero-Day Exploits/CVEs
Fortinet disclosed CVE-2026-104286, a critical CVSS 9.8 zero-day in its FortiMail secure email gateway, on October 1, 2026. The vulnerability combines path traversal (CWE-22) with improper NULL byte handling (CWE-158) in the Identity-Based Encryption GUI component, allowing unauthenticated remote attackers to write arbitrary files to the appliance via crafted HTTP or HTTPS requests. Fortinet confirmed active exploitation in the wild and published detailed indicators of compromise, including planted shared libraries (/data/lib/liblog.so), modified dynamic linker preload directives (/data/etc/ld.so.preload), and outbound connections to 79.141.169.187 and 45.129.0.192. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day and issued Binding Operational Directive 26-04, giving federal civilian agencies just three days to remediate—a compressed deadline that signals the severity of confirmed exploitation evidence.
The vulnerability is particularly dangerous because it requires no authentication, no user interaction, and no prior foothold—any internet-facing FortiMail appliance is a potential target. The patch gap compounds the risk: permanent firmware fixes are still pending for the 8.0, 7.6, and 7.4 branches, leaving administrators to rely on interim workarounds like disabling IBE and restricting management interface access. This is at least the second FortiMail-specific flaw tied to the IBE subsystem to land on CISA’s KEV catalog since 2025, suggesting a recurring architectural weakness. For security teams, the lesson is clear: email gateways are high-value targets that sit at the intersection of defensive control and attack surface, and a single compromise can silently disable anti-malware scanning, suppress phishing detection, and exfiltrate sensitive communications without raising downstream alerts.
Sources:
The CyberSec Guru: https://thecybersecguru.com/exploits/fortimail-cve-2026-104286-zero-day/
Tech Insider: https://tech-insider.org/fortimail-zero-day-cve-2026-104286-cisa-deadline-2026/
Incident Reports
Ernst & Young disclosed a supply chain breach that exposed personal and financial information belonging to clients of Goldman Sachs and Man Group. The incident affected a third-party IT service management platform used by EY’s tax services, where support tickets included attachments containing sensitive client tax information. An unauthorized third party accessed the platform between March 28 and April 12, 2026, downloading documents that included names, addresses, tax identification numbers, email addresses, and financial details. EY detected unusual activity on April 23 and, working with an independent cybersecurity firm, confirmed the data theft window. The breach was attributed to a vulnerability in Checkmarx software, though no specific CVE or affected version has been identified, limiting the technical depth of current assessments.
This incident is significant because it illustrates how third-party support systems can become a route to sensitive client data without requiring a direct attack on the client’s own infrastructure. Goldman Sachs confirmed its systems were unaffected and client assets safe, while Man Group described the incident as involving software used by EY rather than a direct compromise of its own systems. The delay between the last unauthorized access and EY’s detection—eleven days—means the theft occurred before any response was triggered. For organizations, the takeaway is that vendor risk management must extend beyond the primary supply chain to include every platform that touches client data, and that access monitoring should be continuous rather than periodic.
Sources:
Tech Insider: https://tech-insider.org/ey-breach-goldman-sachs-man-group-data-2026/
Cyber Security News: https://cybersecuritynews.com/ey-data-breach-exposed/







