Secret CISO 10/4: 200K Uni IDs Exposed, KillSec Teen Arrest, ShinyHunters Flips, GitLab AI RCE
Identity systems keep failing loud and wide: a Danish university IAM breach hits 200,000, K-12 staff SSNs spill via a vendor flaw, and a hospice manager loses PHI for 35,916 Texans. Meanwhile, law enforcement squeezes extortion crews, and AI features ship with command execution footguns.
Today’s vibe is “the directory is the breach.” IAM databases, HR systems, and vendor APIs are where attackers go when they want maximum leverage with minimum noise.
Today's Top 5
- 200,000 DTU identities exposed: Attackers used stolen creds to get into DTU’s IAM system and pull decades of user data, including national IDs and next-of-kin details. What else sits behind your “just identity” database? Source
- KillSec takedown, teen operator: Operation KillSwitch seized infrastructure and data, made arrests, and says the alleged main operator is 16. RaaS is industrialized enough that kids can run it. Source
- ShinyHunters “Rey” detained: A key ShinyHunters member was reportedly detained in Jordan and is cooperating with the FBI. The interesting part is what seized chats and devices can reveal about token theft, affiliates, and SaaS access paths. Source
- GitLab AI Gateway command exec: GitLab patched a critical sandbox escape in self-hosted AI Gateway. If your “AI sidecar” runs with real network reach, treat it like prod, not a plugin. Source
- Rejetto HFS under exploit: VulnCheck says exploitation activity began for a new HFS unauth RCE via predictable session signing. File servers keep getting popped because everyone forgets they are internet software. Source
Why today matters: The attacker playbook is converging on control planes that were never meant to be high-value targets: IAM directories, “helpdesk” tools, AI gateways, and mail appliances. The pattern signals faster pivots from low-priv footholds into systems that mint trust. Anyone running self-hosted AI features, ticketing, or edge appliances should be nervous, especially if those components can reach secrets, runners, or identity stores.
Alright, let’s get into the receipts.
Data Breaches

- Technical University of Denmark (DTU) IAM breach may impact up to 200,000 people: DTU says attackers accessed its identity and access management system (DTUBasen) using compromised credentials and downloaded a large amount of data. Exposed fields may include Danish civil registration numbers (CPR), addresses, employment data, profile photos, and some next-of-kin contact details; records go back to 2003. Source: DTU
- Frontline Education breach impacts school district employee data: Frontline Education began notifying districts after attackers exploited a vulnerability in a third-party software product to access part of its environment. The stolen employee data can include Social Security numbers and other sensitive HR information, and districts can opt out of Frontline-managed notifications. Source: BleepingComputer
- AngMar Management Services incident affects 35,916 Texas residents: A Texas hospice management company reported unauthorized access discovered in July 2026; exposed data may include SSNs plus extensive health and insurance details. Reporting indicates ransomware involvement and leak-site pressure. Source: HIPAA Journal
- L&Q housing cyberattack exposed correspondence for ~12,000 residents: UK housing association L&Q said an attacker accessed emails or webform messages for about 12,000 residents; regulators were informed and online services were disrupted. Even “just messages” can be gold for targeted fraud. Source: Inside Housing
Security Research

- GitLab fixes critical AI Gateway sandbox escape (self-hosted): GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address CVE-2026-90970. The bug could allow an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a crafted flow configuration and execute commands on the AI Gateway host. Source: GitLab
- Fortinet warns FortiMail zero-day exploited, patch pending: Fortinet disclosed active exploitation of CVE-2026-104286 in FortiMail, advising immediate mitigations while fixes are not yet available. Treat any exposed management surface like it is already being scanned. Source: BleepingComputer
- DIVD details Zammad zero-day chain used in “agentic” attack: DIVD published a case timeline for vulnerabilities found while investigating its own breach. The chain includes CVE-2026-102489 and CVE-2026-102490, and DIVD scanned for vulnerable Zammad instances and began notifying owners. Source: DIVD
- Rejetto HFS exploitation observed for new unauth RCE: VulnCheck reports exploitation activity for CVE-2026-61500 and describes a predictable session signing key that lets attackers forge an admin session on affected HFS 3.x versions. If HFS is internet-facing, assume it is on a list. Source: VulnCheck
- Warlock ransomware leverages SharePoint flaws for initial access: Reporting links Warlock intrusions to SharePoint exploitation and follow-on ransomware activity across multiple sectors. This is the operational reminder: edge collaboration stacks are still a favorite door. Source: BleepingComputer
Top CVEs

- CVE-2026-90970: GitLab AI Gateway sandbox escape leading to arbitrary command execution on self-hosted AI Gateway under certain conditions (authenticated user with Duo Agent Platform access, crafted flow configuration). Fixed in 19.2.4, 19.3.2, and 19.4.1. Source
- CVE-2026-104286: Fortinet FortiMail critical path traversal and NULL byte handling issue that can enable unauthenticated arbitrary file write, with active exploitation reported and mitigations recommended pending patches. Source
- CVE-2026-61500: Rejetto HFS 3.x predictable session-cookie signing key enabling admin session forgery and unauthenticated RCE, with exploitation activity observed. Source
- CVE-2026-102489: Zammad session fixation leading to session hijack and potential remote code execution in affected versions, published via DIVD reporting and tracked in NVD. Source
- CVE-2026-102490: Zammad local privilege escalation affecting versions listed in the CVE record, enabling escalation from the local zammad user to root when chained post-compromise. Source
Podcasts & Talks

- SANS Stormcast (Oct 2, 2026): ScreenConnect abuse and ClickFix delivery: A tight listen for CISOs because it’s not a “new malware” story, it’s abuse of legitimate remote support workflows and user nudges that bypass normal controls. If your helpdesk model relies on users doing the right thing quickly, you’re in the blast radius. Listen: SANS ISC
- Risky Business #854: “We’re Jevpilled”: Useful context on where the industry is taking AI agents and deception, and why “agents doing crimes” is becoming an operational problem, not a lab demo. Listen: Risky Business
Final Words
The uncomfortable through-line today is that “support systems” have become primary attack surfaces. Identity directories, ticket queues, AI gateways, and mail appliances all sit on the trust boundary, and they tend to have quiet, long-lived access to secrets. That changes the threat model from perimeter break-ins to trust minting. The part most coverage misses is the second-order damage: once identity and correspondence spill, fraud and social engineering scale faster than your comms team can type.
This week, do three things:
- Patch GitLab Self-Hosted AI Gateway to 19.2.4, 19.3.2, or 19.4.1 to address CVE-2026-90970, and restrict Duo Agent Platform access to a smallest-possible group.
- For FortiMail, apply Fortinet’s mitigations for CVE-2026-104286 immediately, and take the management interface off the public internet while you triage for compromise.
- Inventory and remove any internet-facing Rejetto HFS, and if you must keep it, prioritize remediation for CVE-2026-61500 plus harden session and admin exposure paths.
Your turn: If an attacker pulled your IAM directory tomorrow, could you answer in one hour which downstream systems they can now convincingly impersonate, and which helpdesk workflows they can now socially engineer? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.
Know someone running self-hosted GitLab Duo features because “it’s just an AI helper”? Forward them this issue. It costs 30 seconds, and the alternative costs a weekend. For forwarded and web readers, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!