Secret CISO 10/1: 13,000 GitHub Screenshots, Cisco SD-WAN Bypass, MikroTik RCE, TeamViewer Bugs
AI agents quietly turned dev laptops into public leak pipelines. Plus: Cisco SD-WAN Manager auth bypass hits KEV, CISA flags a MikroTik pre-auth root RCE, OpenSSL DTLS bug, and TeamViewer’s “patch now” moment.
Today’s theme is “invisible publishing.” Not exfiltration to some sketchy FTP server, but your own tooling doing the leaking in plain sight.
Today's Top 5
- 13,000 internal screenshots leaked: AI coding agents trying to “share the screenshot” reportedly created public GitHub repos under dev personal accounts, leaving corporate billing and ops screens downloadable by anyone. Source
- Cisco SD-WAN admin auth bypass: Cisco says attackers are actively exploiting CVE-2026-76504 to reach the SD-WAN Manager API as admin via crafted, URI-encoded requests. If vManage is internet reachable, you already know how this ends. Source
- MikroTik pre-auth root RCE: CISA warns a single crafted HTTP request can trigger root code execution or DoS in RouterOS web management (tracked as CVE-2026-84411). Versions and guidance appear messy, which is how outages get scheduled for you. Source
- TeamViewer: patch “as soon as possible”: TeamViewer shipped fixes for multiple issues, including local-to-remote code execution and privilege escalation paths. This is the kind of thing attackers pair with “helpdesk” social engineering and a bored intern. Source
- OpenSSL DTLS memory exposure bug: OpenSSL’s Sept. 29 advisory includes CVE-2026-84782, a DTLS retransmission flaw that can expose heap fragments or crash apps. If you run DTLS at scale, this is not a “later” patch. Source
Why today matters: Security programs keep modeling “the attacker” as the only publisher of sensitive data. But today’s leaks are created by your own agents, your own management planes, and your own remote support stack. That shifts the winning move from catching exfil to preventing accidental public distribution, and it makes identity and egress guardrails the new perimeter.
Ok, coffee down. Pager on.
Data Breaches

- AI coding agents exposed internal images on GitHub: Researchers say more than 13,000 sensitive screenshots from 300+ organizations were posted into public GitHub repos created by AI agents under developers’ personal accounts. The ugly twist is visibility: the leak lives outside the corporate org, so normal repo monitoring can miss it. Source: The Hacker News
- Astrana Health reports material social engineering incident (8-K): The company disclosed a campaign where threat actors impersonated personnel and spoofed the corporate phone number to pressure employees and gain access. Treat this as a blueprint for voice-driven initial access against your own service desk. Source: SEC (8-K submission text)
- Poca Valley Bank listed by Storm ransomware group (unverified claim): Threat intel trackers show Storm posted Poca Valley Bank as a victim, with pressure for contact and threatened leaks. No independent confirmation yet, but it is an early warning to look for access broker indicators and outbound staging. Source: GalaxyWarden
- Century Management Services listed by Storm ransomware group (unverified claim): Another Storm leak-site listing, with no victim confirmation or regulator filing tied to it at publish time. Use it as a trigger for third-party access review and privileged account audit, not as courtroom truth. Source: GalaxyWarden
Security Research

- Cisco SD-WAN Manager API authentication bypass: Cisco published details and indicators of compromise for CVE-2026-76504, including suspicious requests using URI-encoded characters (example: %6a for “j”) to bypass auth rules and hit j_security_check. If your SD-WAN Manager is reachable from the internet, assume scan traffic is already looking for you. Source: Cisco
- CISA warning on MikroTik RouterOS pre-auth RCE: CVE-2026-84411 is described as a pre-auth integer underflow in RouterOS web-management HTTP request handling, with root code execution possible via a single crafted request. The practical takeaway is to treat RouterOS web management exposure like an emergency, not a configuration preference. Source: BleepingComputer
- OpenSSL DTLS retransmission bug: OpenSSL’s Sept. 29 security advisory includes a DTLS stale buffer offset issue (CVE-2026-84782) that can leak heap fragments or crash DTLS apps. This hits the long tail of embedded, VPN, and edge deployments that love DTLS. Source: oss-sec (seclists.org)
- Mozilla ships Thunderbird security updates: Mozilla published advisories for Thunderbird versions released on Sept. 30, with multiple security vulnerabilities fixed. Email clients stay a soft target because they are parsers with a UI and a user who clicks. Source: Mozilla (MFSA 2026-103)
- TeamViewer patches multiple high-impact bugs: TeamViewer pushed fixes including path traversal, heap-based overflow, TOCTOU race condition, and path validation issues with potential code execution or privilege escalation outcomes. This is classic “remote support becomes remote access” risk if you are behind on updates. Source: BleepingComputer
- Poper Blocker extension described as spyware: Research alleges the popular pop-up/ad blocker collects sensitive browsing data, including AI chat content, and remains live in the Chrome Web Store. If you do not control extensions, you do not control data egress. Source: Dark Reading
Top CVEs

- CVE-2026-76504: A critical authentication bypass in Cisco Catalyst SD-WAN Manager where crafted HTTP requests with URI-encoded characters can bypass auth rules and grant admin-level API access. Cisco notes active exploitation and provides IOC guidance (log review for j_security_check abuse). Source
- CVE-2026-84411: CISA describes a pre-auth integer underflow in MikroTik RouterOS web management that can allow root code execution or denial of service via a single crafted request. If the web UI is exposed, treat this as “reachable equals risk.” Source
- CVE-2026-84782: OpenSSL DTLS retransmission bug involving a stale buffer offset that may let a remote peer obtain heap memory fragments or crash DTLS applications. Prioritize patches wherever DTLS terminates on internet-facing systems. Source
- CVE-2026-19743: A TeamViewer path traversal issue fixed in the latest release; TeamViewer urges rapid patching. Remote support software tends to be present on exactly the machines attackers want. Source
- CVE-2026-92369: A TeamViewer TOCTOU race condition fixed in the latest release, one of multiple bugs that can contribute to code execution or privilege escalation depending on context. If TeamViewer is allowed through the firewall, patch cadence matters. Source
Podcasts & Talks

- SANS Stormcast (Sep 30, 2026): This episode flags MikroTik RouterOS activity and the Poper Blocker spyware story, plus scanning patterns that show what is getting attacker attention right now. Useful for tuning your own “what’s being probed” dashboards. Listen: SANS ISC
- CIS podcast “Cybersecurity Where You Are” Episode 207 (published 09/29/2026): AI risk management framed as a trust and governance relationship, not a tooling checklist. Good material for aligning security, legal, and product on what “safe AI” actually means in your org. Listen: Center for Internet Security
- CISO Series Podcast (Sep 29, 2026): “Mirror, Mirror on the Wall, Who Has the Best Infrastructure of Them All?” A leadership-focused discussion worth forwarding to anyone who still thinks resilience is a vendor SKU. Listen: CISO Series
Final Words
The underlying pattern today is that security incidents are escaping the places we watch. Your SOC might be staring at the corporate GitHub org while sensitive screenshots leak from a personal repo. Your edge team might be patching routers while the real risk is that the management UI is still reachable. The uncomfortable implication is that “asset inventory” now includes workflows, agents, and default-sharing behaviors, not just devices and IPs.
This week, do three things:
- Hunt and patch Cisco Catalyst SD-WAN Manager for CVE-2026-76504, then review /var/log/nms/containers/service-proxy/serviceproxy-access.log and vmanage-server.log for suspicious j_security_check activity.
- Block or strictly restrict MikroTik RouterOS web management exposure, then validate RouterOS versions and mitigation status for CVE-2026-84411 across every site, including “small office” gear.
- Implement extension controls on managed browsers, then specifically detect and remove the Poper Blocker extension across endpoints where it is present.
Your turn: If an AI agent on a developer laptop can create a public GitHub repo without your security team noticing, what is your one control that would stop it tomorrow: endpoint policy, GitHub governance, egress filtering, or DLP? Hit reply with your take, or drop a comment on the web version. I read every reply.
Know a dev org that is rolling out coding agents fast and treating “share this screenshot” as harmless? Forward them this issue, because the leak path here is quiet and brutally simple. For everyone else, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!