Secret CISO 10/3: 6.6M Times Car IDs Stolen, K-12 SSNs Leaked, M365 C2, Dell K8s Storage Keys

Big breaches keep landing in the “verification” layer: identity docs and SSNs on one side, and enterprise cloud control planes on the other. Today’s thread is trust reuse, attackers hiding in systems you already allow.

Share
Times Car breach affecting 6.6 million accounts

Today’s damage pattern is not exotic malware. It is attackers cashing in on the two things we keep reusing: identity proofing artifacts and trusted platforms.

Today's Top 5

  1. 6.6M Times Car accounts hit: Japan’s biggest car share confirms a breach impacting 6.6 million accounts, including identity document images for a large subset. The cleanup is the easy part, the downstream fraud is the nightmare. Source
  2. Frontline K-12 staff data exposed: Frontline Education tells districts attackers exploited a third-party software bug and stole employee info including Social Security numbers. If you run K-12, this lands directly on your HR and payroll inbox. Source
  3. Warlock hits water and telecom: A China-linked ransomware crew is again using on-prem SharePoint exposure as its front door, then fanning out across victims including a water utility and telecom provider. The part to watch is what they disable before they encrypt. Source
  4. Outlook and OneDrive as C2: The Antino backdoor blends command traffic into Microsoft 365, turning your “trusted” SaaS egress into an attacker transport. If you only hunt by destination, you will not see this. Source
  5. Dell Kubernetes storage takeover bugs: Two max severity flaws let unauthenticated attackers grab backend admin creds and seize control of Dell’s Container Storage Modules used in Kubernetes environments. Storage plus Kubernetes is a spicy combo. Source

Why today matters: Identity and trust are the new blast radius multipliers. Times Car and Frontline show how long-lived “proof” data (IDs, SSNs) turns into years of fraud. Antino and Dell CSM show the other half, attackers now ride inside platforms your controls already whitelist, from Microsoft 365 to Kubernetes storage control planes. CISOs who should be nervous are the ones who still treat egress allowlists, third-party SaaS, and cluster admin endpoints as “out of scope” for continuous detection.

Okay, now the receipts and the sharp edges.

Data Breaches

Frontline Education breach affecting school employees
  1. Times Car confirms breach affecting 6.6 million accounts: Park24 says attackers accessed member data tied to roughly 6.6M current and former Times Car accounts, including sensitive identity verification artifacts such as driver’s license images for a reported subset. Expect high-conviction phishing and identity fraud because the dataset includes contact details plus verification-grade documents. Source: Japan Cyber Watch
  2. Frontline Education breach exposes school district employee data: Frontline is notifying districts that attackers exploited a vulnerability in a third-party application to access part of its environment and steal employee PII, including Social Security numbers. Districts should assume this becomes targeted payroll redirect attempts within days. Source: BleepingComputer
  3. Warlock ransomware breaches via SharePoint: Reporting says Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities for initial access. If you still have internet-facing SharePoint, treat this as “already being scanned,” not “might be scanned.” Source: BleepingComputer
  4. Microsoft’s X account hijacked for token shill: Attackers took over Microsoft’s official X account and used it to boost a Clippy-themed crypto token, a reminder that brand accounts are now a direct fraud vector. Your comms team is part of incident response whether they like it or not. Source: BleepingComputer

Security Research

Antino backdoor using Outlook and OneDrive for C2
  1. Antino backdoor uses Outlook and OneDrive for C2: Cisco Talos research, as covered here, documents a Rust backdoor that uses Microsoft 365 services as dead drops and command channels. For defenders, the key shift is from blocking destinations to validating which processes, tokens, and identities are talking to Graph and mailbox APIs. Source: The Hacker News
  2. Dell Container Storage Modules (CSM) critical flaws: Dell published advisories covering multiple issues in CSM Authorization, including missing authentication paths that can expose storage backend admin credentials and enable total compromise. If CSM is reachable from untrusted network segments, assume an attacker can turn storage into a ransomware accelerant. Source: Dell
  3. GitLab AI Gateway critical RCE: GitLab disclosed a critical issue in self-hosted AI Gateway deployments that can enable command execution in certain configurations, and shipped fixed releases. The immediate question is not “do we run GitLab,” it is “did anyone self-host the gateway to keep AI traffic in-house.” Source: BleepingComputer
  4. New Spectre v2 variant (BTR) targets JIT engines: Researchers disclosed Branch Target Reuse, a Spectre v2 technique targeting JIT compilers in browsers, runtimes, and kernels, with proof-of-concepts against Linux kernel paths. This is a reminder that “fully patched” does not mean “side-channel safe,” especially in multi-tenant and sandbox-heavy environments. Source: SecurityWeek
  5. ScreenConnect client abused via phishing: SANS ISC documents a phishing flow where the attachment is a legitimate, signed ScreenConnect client preconfigured to call back to an attacker-controlled instance. Your controls have to care about “legit remote admin tools in the wrong hands,” not just malware verdicts. Source: SANS ISC

Top CVEs

Dell Container Storage Modules critical auth bypass CVEs
  1. CVE-2026-63688: Dell Container Storage Modules (CSM) Authorization missing authentication for a critical function. An unauthenticated attacker could access storage backend administrator credentials for registered arrays, enabling full administrative takeover of the storage layer. Source
  2. CVE-2026-63692: Dell Container Storage Modules (CSM) Authorization missing authentication in the authorization proxy and tenant service. Successful exploitation can allow an attacker to bypass auth controls and gain admin privileges over the authorization service. Source
  3. CVE-2026-90970: GitLab AI Gateway vulnerability fixed in versions 19.2.4, 19.3.2, and 19.4.1, with impact described as critical command execution risk in self-hosted AI Gateway deployments under certain conditions. Treat as an urgent patch if you self-host the gateway. Source
  4. CVE-2026-93616: Check Point Security Management and Multi-Domain Management servers vulnerable to unauthenticated file write as root that can be turned into root code execution, with reporting noting in-the-wild exploitation. If you run Check Point management, patching is only step one, hunt for prior access. Source

Podcasts & Talks

SANS Stormcast episode on ScreenConnect abuse
  1. SANS Stormcast (Oct 2, 2026): This episode stitches together a very CISO-relevant theme, abuse of legitimate tooling and identity surfaces, including ScreenConnect client abuse and modern spoofing tricks. Good for briefing your SOC leads in under 10 minutes. Listen: SANS ISC
  2. CISO Insights Podcast (EP 579, Oct 2, 2026), “The Infostealer Trap”: Focuses on session cookie theft and how it bypasses passwords and MFA, which pairs uncomfortably well with today’s “trusted platform” stories. Listen: CISO Insights

Final Words

The uncomfortable throughline today is that attackers do not need your perimeter when they can borrow your trust. Identity docs and SSNs become permanent exploit kits for humans, while Microsoft 365 and Kubernetes control planes become permanent exploit kits for networks. The miss in most coverage is that these are the same problem: we keep granting long-lived power to artifacts and channels that were never designed to be safely reusable at internet scale.

This week, do three things:

  • Inventory and lock down Dell CSM exposure, then patch CSM to a fixed release and validate that CSM APIs are not reachable from untrusted segments, specifically addressing CVE-2026-63688 and CVE-2026-63692.
  • If you self-host GitLab AI Gateway, patch immediately for CVE-2026-90970 and confirm whether any teams deployed a separate gateway “quietly” to keep AI traffic internal.
  • Turn on hunting for Microsoft 365 abuse patterns, including anomalous Graph, Outlook, and OneDrive API usage by non-standard processes and identities, then baseline what “normal” looks like before Antino-like tradecraft lands in your tenant.

Your turn: If an attacker got a copy of your customers’ or employees’ identity documents tomorrow, do you have a plan that reduces fraud next week, not just a plan that mails letters next quarter? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.

Know someone who still has internet-facing SharePoint “because it has always been there”? Forward them this issue before Warlock turns their file shares into a weekend. If you got forwarded this, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!