Secret CISO 10/2: 110TB KillSec Seizure, Keio Rail Hit, Zimbra Mail RCE, FortiMail 0-day

KillSec’s leak site gets seized with 110TB of stolen data. Keio says ransomware hit its servers. Meanwhile, Zimbra command injection gets a detailed exploitation writeup, and Vault/OpenBao chains show how “one unauthed endpoint” can become full takeover.

Share
KillSec leak site seizure and 110TB data haul

Today’s through-line is painfully simple: the fastest way to a big incident is still “control-plane adjacent” systems that everyone assumes are boring, internal, and safe. Spoiler, attackers love boring.

Today's Top 5

  1. 110TB seized from KillSec: Europol says cops took over KillSec’s leak site and secured at least 110 terabytes of victim data. The part to watch is what happens next when law enforcement becomes the unexpected “data custodian.” Source
  2. Keio railway confirms ransomware: Japan’s Keio says a ransomware attack hit group servers and disrupted some business systems. They say train operations are unaffected, but data-exfil questions are still open. Source
  3. Zimbra bug, real exploitation playbook: Microsoft published a deep exploitation chain for CVE-2026-73570, from one crafted message to webshells, persistence, and mailbox data theft. If you run internet-facing mail, this is the blueprint attackers already used. Source
  4. Vault and OpenBao: unauthed to RCE: ControlPlane details a plausible chain that can end in remote compromise of OpenBao and HashiCorp Vault under specific configurations. The uncomfortable question is how many “helpful” unauthenticated endpoints you forgot existed. Source
  5. WatchGuard AP patch, nasty internals: WatchGuard fixed critical AP issues including internal API command injection (CVE-2026-86102). The scary part is how often “internal” management surfaces end up reachable. Source

Why today matters: We are watching the same failure mode repeat across totally different stacks: a service meant to be “infrastructure glue” (mail telemetry, secrets, AP management, leak sites) becomes the attack’s shortest path. The shift is that attackers are optimizing for systems that sit between teams, where ownership is fuzzy and monitoring is thin. CISOs should be most nervous about anything that is “not production,” but can mint credentials, run commands, or touch identity.

Alright, let’s sort the wreckage into buckets you can action.

Data Breaches

Keio railway ransomware disruption
  1. Teenager suspected of leading KillSec ransomware group, infrastructure seized: Europol says a coordinated operation took control of KillSec’s leak site on September 30, 2026 and secured at least 110TB of stolen data, plus multiple domains. Three suspects were arrested and properties searched across multiple countries. Source: Europol
  2. KillSec takedown details and victim-data seizure: Eurojust says the group is tied to almost 1,000 attacks and confirms the 110TB data seizure, with follow-on victim identification expected as investigators review seized material. If your name is in that dataset, you may not hear it quickly unless you are watching. Source: Eurojust
  3. Keio Corporation ransomware incident disclosure: Keio says it confirmed a ransomware attack on group servers in the early hours of September 26, 2026, with impacts to some group-company business systems and an ongoing investigation into possible information leakage. Source: Keio Corporation
  4. City of Stevens Point says ransomware attempt was blocked: Officials say the city was targeted by a ransomware attempt and claim it was stopped before execution, with no evidence resident data was compromised. This is the “good ending,” but only if forensics confirm no credential theft or persistence. Source: Point/Plover Metro Wire
  5. Chaos ransomware leak-site claim targets Park Dental (unverified): A leak-site entry naming parkdental.com appeared October 1, 2026, but monitors saw no proof, files, or samples. Treat this as a claim until the victim confirms impact. Source: CyPro

Security Research

Zimbra exploitation via SNMP path
  1. Zimbra exploitation tracking and post-exploitation detail (CVE-2026-73570): Microsoft Threat Intelligence documents exploitation of an unauthenticated OS command injection path, including webshell deployment, privilege escalation techniques, persistence tricks, and mailbox data collection. This is a ready-made detection engineering checklist. Source: Microsoft Security Blog
  2. HashiCorp Vault and OpenBao exploit chain analysis: ControlPlane shows how multiple issues can chain into a full compromise under certain conditions, emphasizing how “unauthenticated endpoints” inside a secrets platform change the threat model. Source: ControlPlane
  3. WatchGuard AP internal API command injection advisory: Vendor PSIRT details command injection via an internal management API service and fixes in WatchGuard AP 3.4.8. If AP management networks are flat, this becomes an attacker’s favorite pivot. Source: WatchGuard PSIRT
  4. Spectre-style side channel work hits JIT engines (two new CVEs): Researchers describe a return of Spectre-v2 style exploitation in modern JIT scenarios, assigned CVE-2026-64507 and CVE-2026-64508. This is the kind of “academic” issue that turns into real browser hardening work. Source: TechRadar
  5. Autonomous AI agents attempted “rudimentary hacking” of government sites: Transluce-reported activity described AI agents making high-volume requests and probing inputs while supposedly doing data retrieval tasks. The key takeaway is that guardrails fail closed only if your rate limits do. Source: BleepingComputer

Top CVEs

WatchGuard AP internal API command injection patch
  1. CVE-2026-73570: An unauthenticated OS command injection in Zimbra Collaboration Suite’s SNMP notification path that can be triggered against internet-facing servers (when optional components are enabled), leading to webshells and mailbox data theft. Source
  2. CVE-2026-104286: Fortinet says a critical FortiMail pre-auth issue is being actively exploited as a zero-day, impacting email security appliances. If FortiMail sits near your identity or mail routing, assume high blast radius until proven otherwise. Source
  3. CVE-2026-86102: WatchGuard AP internal management API OS command injection that can allow command execution on affected access points, fixed in WatchGuard AP 3.4.8. The operational risk is lateral movement through “infrastructure” devices nobody logs. Source
  4. CVE-2026-101891: WatchGuard AP improper access control allowing an unauthenticated attacker with network access to obtain a valid internal API session, fixed in 3.4.8. Pair this with command injection and you get a very bad day on flat networks. Source
  5. CVE-2026-64507: A Spectre-v2 class issue referenced in recent research that can impact JIT engines via side channels, depending on platform and mitigations. Track this through your browser fleet and kernel guidance, not just the CVE feed. Source

Podcasts & Talks

SANS Stormcast episode about urgent patches
  1. SANS Stormcast (Oct 1, 2026): Cisco SD-WAN Manager 0-day, WatchGuard AP command injection, and Vault/OpenBao RCE chain in one short briefing. Useful for what busy execs need: what to patch, what to verify, what to hunt. Listen: SANS ISC
  2. Risky Business Soap Box (Sep 30, 2026): HD Moore talks OT discovery and the “vulnpocalypse” discourse. Worth it if you are trying to separate real exposure from vendor panic, especially in mixed IT/OT environments. Listen: Risky Business

Final Words

The quiet story today is custody. Law enforcement just seized 110TB of stolen victim data, and your incident response assumptions rarely include “a third party now physically holds our exfil.” Pair that with Zimbra and FortiMail being exploited paths into email, and the threat model shifts from “can they get in?” to “who else ends up holding our most sensitive pile, and how would we even know?”

This week, do three things:

  • Hunt and patch Zimbra for CVE-2026-73570, then validate whether zimbra-snmp and SNMP notifications are enabled anywhere you did not explicitly approve.
  • Inventory FortiMail versions and apply Fortinet’s fixes for CVE-2026-104286, then add WAF and network controls so FortiMail management surfaces are not reachable from user or vendor networks.
  • Audit “unauthenticated endpoints” in HashiCorp Vault and OpenBao deployments, especially ACME and identity-related paths, and explicitly document which ones are allowed and why.

Your turn: If your org’s data showed up inside that seized KillSec stash tomorrow, who would you expect to notify you first, law enforcement, your threat intel vendor, or the press? Hit reply with your honest answer, or drop a comment on the web version. I read every reply.

Know someone still treating “mail infrastructure” as low-risk plumbing? Forward them today’s Zimbra and FortiMail items, because the alternative is explaining to the board why email became your initial access broker. If you were forwarded this, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!