Critical Infrastructure, Cyber News

What’s Going on in Cyber (01 OCT 2026)

The Human Take

Critical Infrastructure. Operations Technology / Information Technology. PLC and HMI exploits.

This is… Well… This is Cyber… And A Whole Lot More!

  • Water Plants
  • Manufacturing
  • Powergrid
  • E911 and Emergency Response
  • Pipelines
  • Transportation

Nation States actively target critical infrastructure on an hourly basis. Critical infrastructure brings in another area of Cybersecurity protection, Operations Technology. Not as well-known as its close relation, Information Technology. But every bit as vital and carries the well-earned label “critical”.

Operations Technology is

“Programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building management systems, fire control systems, and physical access control mechanisms.” Risk Management Framework for Information Systems and Organizations A NIST System Life Cycle Approach for Security and Privacy, 2018.

Yesterday, record rainfall fell in the Omaha, Bellevue, and Lincoln Nebraska area. Emergency response, water and sanitation, pipelines, transportation (trains, interstate, and metro) and manufacturing were all stressed by the flooding. Protecting Critical Infrastructure and OT matters at all times, severe weather magnifies the importance.

Bellevue University Cybersecurity actively supports and are members of InfraGard – a thirty-year collaboration among the US FBI, affiliated law enforcement agencies, business, critical infrastructure practitioners and educators. Protecting critical infrastructure is a shared responsibility.

Our Weekly Summary for October 1, 2026, highlights State Sponsored Threats and Zero-Day Exploits. Dig in. If this is an area that you want to learn more about, engage in, reach out to us. Interested in InfraGard? Watch the video below and explore membership via the link.

Welcome to InfraGard — site


Weekly Cyber News Summary October 1, 2026

This week in cyber:
  • Nation-states actively target critical infrastructure and civilian networks globally.
  • Cisco’s SD-WAN and Citrix NetScaler suffer critical zero-day exploits.

State-Sponsored Attacks

Active Zero-Day Exploits in Cisco SD-WAN Manager

A critical zero-day vulnerability, tracked as CVE-2026-76504, has been found in the Catalyst SD-WAN Manager from Cisco. This flaw allows attackers to bypass authentication mechanisms and escalate their privileges to administrative levels within the network.

Security briefings confirm that this vulnerability is not theoretical; attackers are actively exploiting it in the wild. Cisco has released necessary security updates, urging organizations to patch their devices immediately to mitigate the risk of unauthorized access and network takeover.

Sources:
InfosecNexus Live Brief: https://infosecnexus.com/live-cybersecurity-brief/
BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/

Zero-Day Exploits/CVEs

Cisco SD-WAN Zero-Day is Actively Exploited in Attacks

A critical zero-day vulnerability, CVE-2026-76504, has been identified in Cisco’s Catalyst SD-WAN Manager. This flaw is an authentication bypass that allows attackers to escalate their privileges to full administrative rights.

Security analysts confirm that this exploit is not just theoretical; it is being actively leveraged in the wild. Cisco has issued immediate security updates, making prompt patching essential for organizations running this infrastructure.

Sources:
BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
InfosecNexus Live Brief: https://infosecnexus.com/live-cybersecurity-brief/
Citrix NetScaler Zero-Days Enable Remote Code Execution

Two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affect Citrix NetScaler devices. These flaws allow for Remote Code Execution (RCE), meaning an attacker can run arbitrary code on the server.

Unit 42 and other sources confirm these flaws are being exploited in real-world attacks. Citrix has issued fixes, and these CVEs were added to the CISA KEV catalog, signaling their immediate threat level.

Sources:
Cybersecurity News: https://cybersecuritynews.com/citrix-netscaler-0-day-rce-2/
Unit 42 Palo Alto Networks: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
Artificial Intelligence, Cyber News, Security Assessments, Security Management

What’s Going on in Cyber (20 AUG 2026)

The Human Take

AI Governance Frameworks attempt to tame and navigate the rapidly changing nature of AI integration and adoption. Rebecca put AI integration under her keen flashlight this week.

There are three frameworks helpful to guide your use of AI.

  • EU AI Act
  • NIST AI RMF
  • ISO / IEC 42001

Let me share a bit of my experience with preparing the EU AI Act for a leading global payment processor in 2025-6. It was a significant lift – over 1,000 hours from our team. The EU AI Act sets the requirements for AI uses. Our bank payments and fraud fell into a higher risk category. They’re not excluded, but require policies, inspection and due diligence. We accomplished the attestation and the effort was well worth it.

What I discovered. Preparing for AI adoption is a daunting task, begin with ensuring the essentials:

  • Identify where the human-in-the-loop occurs
  • Ensure explainability of your AI use
  • Ensure traceability of your AI use
  • Document and learn.

Now enjoy what Rebecca has for you. She’s our most trusted AI partner!

Bonus. This is a wonderful article that addresses all three frameworks Global AI Governance Comparison 2026: EU AI Act vs NIST AI RMF vs ISO/IEC 42001

– David Kohrell, GRC Professor

Rebecca’s Intelligence Gathering – 20AUG2026


  • Shadow Campaigns are hitting ministries and suppliers across Europe and Asia-Pacific.
  • AI is rapidly being integrated into both offensive attack techniques and defensive detection systems.
  • A surge of 44 zero-day exploits in one week overwhelms enterprise defenses worldwide.


Regional Campaigns

Global espionage operation “Shadow Campaigns” breaches 70 …

The “Shadow Campaigns” are a coordinated and deliberate espionage operation that has successfully breached numerous organizations across dozens of countries.

The campaign’s targets include critical ministries such as finance, foreign affairs, trade, and interior, alongside national law enforcement bodies and parliaments.

These targeted attacks demonstrate a clear focus on specific regions and economic partnerships.
Victims span Europe, the Americas, Asia-Pacific, and Africa, with one notable victim being a major Taiwanese power equipment supplier, illustrating how these campaigns prioritize strategic geopolitical interests.


Sources:
Cyberinsider (Shadow Campaigns): https://cyberinsider.com/global-espionage-operation-shadow-campaigns-breaches-70-orgs-in-37-countries/
Unit42 (Shadow Campaigns): https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/

AI Integration

Guide to AI in Cybersecurity: 7 Use Cases of AI Automation

AI agents are revolutionizing cybersecurity by optimizing SecOps workflows and maximizing return on investment across various functions.

Use cases include automating threat hunting, classifying vulnerabilities, and integrating human intelligence with machine learning to handle complex security tasks.

In defense applications, AI is crucial for real-time monitoring and detection; one specific example involves the Automated Indicator Sharing (AIS) service using an AI decision tree to assign a Confidence Score to incoming cyber threat indicators.
Offensively, attackers are leveraging AI at unprecedented speed to bypass traditional security measures.


Sources:
Swimlane (AI Use Cases): https://swimlane.com/blog/how-is-ai-used-in-cybersecurity/
CISA (AI Use Cases): https://www.cisa.gov/ai/cisa-use-cases

Zero-Day Exploits/CVEs

44 Zero-Days in One Week: The Exploitation Surge Overwhelming Enterprise Defenses

A massive surge of vulnerabilities has hit the industry, with 44 zero-day exploits being reported in a single week.

These flaws affect widely used enterprise software, including Microsoft Defender, VMware vCenter, and SAP Commerce Cloud, putting organizations under intense pressure to patch.

One specific critical finding involves Windows vulnerability CVE-2024-43461, which was exploited using the Atlantida info-stealer.
This exploit allows attackers to infect devices by abusing braille “spaces,” stealing passwords and authentication cookies from infected systems.


Sources:
Defend Edge (Exploit Surge): https://www.defendedge.com/zero-day-exploit-surge-2026-enterprise-defenses-overwhelmed/
BleepingComputer (Windows Zero-Day): https://www.bleepingcomputer.com/news/security/windows-vulnerability-abused-braille-spaces-in-zero-day-attacks/