Secret CISO 10/11: DexCom Extortion Claim, IDCF Cloud Ransomware, Cisco NX-API RCE, Exchange Mailbox Bug
Today’s thread: attackers keep skipping “endpoints” and going straight for the control plane, identity flows, and notification rails. Extortion crews name-name-shame, while exploited network and mail server bugs keep giving them an easy on-ramp.
The attacker playbook is getting boring in the most expensive way: hit the control plane, abuse an auth flow, then weaponize your own comms channel against you. If that sounds familiar, it is because it keeps working.
Today's Top 5
- DexCom named by extortion crew: A new leak-site post claims DexCom is the latest victim of the Redact operation, but there is no independent confirmation yet. The pressure tactic is the story. Source
- IDCF Cloud ransomware outage: Japan’s IDC Frontier says ransomware disrupted its IDCF Cloud environment, impacting a data center cluster and customer access. The detail to watch is how they got in so fast. Source
- Cisco Nexus NX-API RCE: Cisco shipped a critical fix for CVE-2026-76471 in NX-OS NX-API. If NX-API is exposed or reachable, this is a “today” patch, not a “sprint” patch. Source
- Exchange mailbox-read bug: A newly fixed Exchange Server issue can enable attackers to read mailboxes across an org, and Microsoft says the key delta is the fix for CVE-2026-96940. This is the kind of bug that turns “one login” into “every inbox.” Source
- Hermes Agent PKCE session takeover: Tenable disclosed a high-severity auth issue in Hermes Agent where redirect parsing can enable PKCE session takeover. The nasty part is how “looks like loopback” becomes “actually attacker-controlled.” Source
Why today matters: Extortion crews are treating brand damage as the product, while defenders are still treating “notification systems,” OAuth redirects, and admin APIs as boring plumbing. The pattern says attacks are converging on trust primitives: identity callbacks, management interfaces, and shared cloud consoles. If you run anything that can broadcast to customers or administer fleets, you should be nervous.
Alright. Let’s get into what you can actually action this week.
Data Breaches

- DexCom listed on Redact leak site (claim): Leak-site monitoring shows a new Redact post naming DexCom dated October 10, 2026. Treat it as an unverified claim until DexCom confirms, but assume PR pressure will spike fast once files appear. Source: RansomLook
- National Life Insurance Company breach notice filed (Vermont): A breach filing indicates National Life began notifying individuals around October 8, 2026. If you are in financial services, this is another reminder that downstream identity fraud outlives the incident timeline. Source: DataBreachClassActions
- Advantest America data breach notice (Massachusetts filing): A Massachusetts breach notice PDF states Advantest identified unauthorized access and data extraction earlier in 2026, with notifications dated October 6, 2026. Watch for vendor and supply chain ripple effects if customer data is implicated. Source: Mass.gov
- Community Teamwork, Inc. office breach notice (Massachusetts filing): A breach notice dated October 5, 2026 reports a September 18 incident at a Lowell, MA office. Physical-world security incidents keep turning into digital identity exposure the hard way. Source: Mass.gov
Security Research

- Cisco NX-OS NX-API RCE (CVE-2026-76471): Cisco published a critical advisory for NX-API in NX-OS with a 9.8 base score. If management features are reachable from untrusted networks, you are playing on hard mode. Source: Cisco
- Hermes Agent PKCE redirect parser confusion (TRA-2026-65): Tenable describes an auth-flow bug that can lead to session takeover via redirect URI parsing and PKCE token exchange behavior. This is the modern class of “browser went there, app thought it didn’t.” Source: Tenable
- Exchange Server mailbox-read risk (CVE-2026-96940 fix noted): Reporting highlights that Microsoft’s later 2026 Exchange updates include a key fix for CVE-2026-96940. If you rely on the Extended Security Updates program, validate you actually applied the version that includes the delta. Source: TechRadar
- Rejetto HFS exploitation wave (admin forgery to RCE): VulnCheck observed exploitation attempts soon after public write-ups and PoCs, highlighting how fast “one-day” bugs become mass scanned. If HFS is still in your estate, assume it is already being probed. Source: The Hacker News
- AI safety timeline after Hugging Face attack: AP’s timeline pulls together how fast “AI security” has moved from theoretical to operational, with real-world incidents and policy reactions. For CISOs, it reads like a risk register that keeps writing itself. Source: AP News
Top CVEs

- CVE-2026-76471: Critical heap-based buffer overflow in Cisco NX-OS NX-API that can allow remote code execution. Inventory Nexus devices, confirm NX-API exposure, and patch to the fixed NX-OS releases. Source
- CVE-2026-96940: Microsoft Exchange Server issue addressed in later 2026 security updates, with reporting warning it can enable mailbox access across an organization. Confirm you are on the updated build, not just “patched in September.” Source
- CVE-2026-104286: Fortinet FortiMail flaw described as critical and discussed widely as actively exploited. If FortiMail sits anywhere near inbound mail flows, treat compromise checks and emergency patching as a fire drill. Source
- CVE-2026-102489: Zammad vulnerability reported as actively exploited and cited as added to CISA KEV in community tracking. If Zammad is Internet-facing, prioritize patching and review for suspicious auth and admin activity. Source
- CVE-2026-102490: Companion Zammad issue also discussed as exploited in the wild in community tracking, suggesting chained or parallel attack paths. Patch both and validate no lingering exposed endpoints remain. Source
Podcasts & Talks

- Darknet Diaries: EP 180 “Conti”: A tight, human-scale retelling of how a top-tier ransomware brand scaled, imploded, and left a blueprint that smaller crews still copy. Useful for executive briefings because it makes “ransomware ops” feel uncomfortably real. Listen: Darknet Diaries
- CISO Series Podcast: “Data Is the New Oil…” (Oct 6, 2026): A pragmatic conversation about data value, visibility, and why most orgs do not actually know what they are protecting until the incident forces the inventory. Good prompt for your own “what data do we monetize?” discussion. Listen: CISO Series
Final Words
The underlying pattern today is trust surface expansion. Every new admin API, OAuth callback, cloud console, and notification rail becomes an attacker shortcut because it is “supposed to work” when everything else is on fire. The uncomfortable implication is that many orgs have better malware detection than they do control-plane visibility, so they learn about the compromise when the extortion post goes live.
This week, do three things:
- Patch Cisco NX-OS for CVE-2026-76471, and explicitly verify whether NX-API is enabled and reachable from any non-admin network segment.
- Validate your Microsoft Exchange Server build includes the CVE-2026-96940 fix, then run a mailbox access review focusing on unusual cross-mailbox reads and delegate assignments.
- If you run OAuth or PKCE flows in desktop or agent apps, add test cases for redirect URI parsing and loopback handling, using Tenable’s Hermes Agent findings as the template.
Your turn: If an extortion crew named your company on a leak site tonight, do you have a pre-approved decision on what you will publicly confirm in the first 6 hours, and who signs it? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.
Know someone in medtech whose brand would not survive a “DexCom-style” leak-site claim even if it is unverified? Forward them this issue, it takes 30 seconds and the alternative takes months. If you’re reading this from a forward or the web, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!