Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
3 days ago

Tenable Security Intel Brief: OpenAI model got into an Australian gov portal

Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.

But first: Citrix fixed another exploited NetScaler flaw, CVE-2026-88779, on October 3. This one is a denial-of-service bug that only affects appliances set up for SAML sign-in, and the September 27 builds don't cover it. Our FAQ has the details.

This week, OpenAI says one of its internal models got non-public access to an Australian Medicare statistics reporting service in June, pulling internal files and credentials. The brief also covers Warlock ransomware's developers hitting a water utility and a telecom, JADEPUFFER's 7-minute Azure deletion run, and Cisco's fifth exploited SD-WAN zero-day of 2026, by BleepingComputer's count.

Internal OpenAI model got into an Australian Medicare stats portal →

Brief: OpenAI says an internal model gained non-public access to Services Australia's Medicare Statistics Reporting Service in June, pulling internal files and credentials and writing files.

Intel: Australia's Prime Minister Anthony Albanese said the agent hit repeated blocks and "found a way around those blocks," though "no personal information is believed to have been accessed at this stage" and investigations are ongoing. The company found the activity in mid-August, along with activity at three more Australian agencies, including an exposed access key its agents used at the Victorian Department of Health. Albanese called the way it notified the government on September 10 "unacceptable": "an email sent to just the public mailbox."

Why it matters: The assignment was research into per-person government spending on skin-condition medicines in Victorian communities. When that data proved hard to find, OpenAI says the model "took actions that we had not authorised it to take."

Longlegs keeps using SharePoint flaws, now against water and telecom →

Brief: Symantec says Longlegs, a China-nexus group that develops Warlock ransomware, attacked a water utility and a telecom provider in Portuguese- and Spanish-speaking countries over the past two months.

Intel: The group is also tracked as Storm-2603. It usually gets in through on-premises SharePoint servers. The 2025 ToolShell flaws, including CVE-2025-53770, likely remain in its kit alongside newer SharePoint flaws CISA flagged in July 2026. At one critical infrastructure operator, the attackers sent a security-tool killer to at least 40 machines in about two hours. Warlock then reached at least 33 machines through SYSVOL. Windows copies that shared folder to every domain controller, and every computer on the domain can read it.

Why it matters: Symantec reads the victims' locations as a sign of either deliberate tasking or opportunistic picks driven by which SharePoint servers were exposed and vulnerable. If it was the second, a water utility landed on the list for the same reason as a university Symantec also names. Both would have run one of those servers.

JADEPUFFER deletes Azure storage in 7 minutes, then takes the keys →

Brief: Microsoft documented JADEPUFFER, which it calls Storm-3168, using two hijacked service principals (accounts that software uses to act in Azure) to map and then delete one organization's cloud resources.

Intel: In early June, one account read through the environment for about 15.5 hours; the other listed virtual machines in two subscriptions within five seconds. A 7-minute run tried 100+ storage account deletions and most succeeded. It also deleted an app, along with a hosting plan and Key Vault linked to that app. Sysdig, which found JADEPUFFER in July, assessed it to be "the first documented case of agentic ransomware," while Microsoft says the timing and split of work "strongly indicates automated or scripted execution."

Why it matters: The account's attempts to delete SQL databases failed because each request used an unsupported version of Azure's interface. About half an hour later, it successfully requested access keys more than 30 times, including for storage accounts used for disaster recovery. The account did all of this with permissions it already had.

Attackers break into Cisco SD-WAN Manager with one encoded character →

Brief: Cisco fixed CVE-2026-76504, an actively exploited flaw that gives attackers admin access to Catalyst SD-WAN Manager, its console for network gear linking company sites, without logging in.

Intel: The software mishandles encoded characters in web addresses, so a crafted request slips past a rule meant to restrict access. Cisco's warning signs show requests to the j_security_check address with one character encoded, such as %6a for "j," and Cisco says any single encoded character works. SD-WAN Manager is affected regardless of setup, though Cisco says its cloud-managed release is already fixed. There's no workaround. CISA added it to its list of exploited vulnerabilities September 30, with an October 3 federal deadline.

Why it matters: By BleepingComputer's count, this is the fifth exploited Cisco SD-WAN zero-day of 2026, and watchTowr's Jake Knott tallies eight 2026 SD-WAN CVEs on CISA's exploited list this year, a wider count that includes three added in April. The February zero-day, CVE-2026-20127, had been exploited since at least 2023.

Stat of the week: 543,699

The number of credentials found in 224 million public GitHub repositories that still worked when tested this July, including nearly 200,000 pushed after GitHub began blocking recognized secrets by default, according to Truffle Security.

Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.

No RepliesBe the first to reply