Secret CISO 10/6: 8.8M Denmark IDs Exposed, Nikkei Phish Blitz, UIC Ransomware, Citrix SAML Zero-Day

Identity data keeps leaking through “trusted access” and “trusted login” paths: Denmark’s CPR registry, Nikkei’s M365 mailbox, and a medical school ransomware case. Plus: Citrix SAML DoS zero-day, Rejetto HFS RCE scanning, and Google pauses OSS bug bounties due to AI spam.

Share
Denmark CPR registry breach affecting 8.8M people

Today’s theme is “trust is the attack surface.” When a registry partner login, a journalist’s mailbox, or a SAML edge box becomes the control plane, attackers do not need novel malware. They just need your weakest permission.

Today's Top 5

  1. 8.8M Denmark IDs exposed: Denmark’s CPR registry says attackers abused a private company’s legitimate access and pulled names, addresses, and CPR numbers at national scale. The partner angle is the scary part. Source
  2. Nikkei’s 9,000 impersonation emails: A compromised Microsoft 365 account was used to spray phishing at prior contacts, including journalistic sources. Your “known sender” model just got weaker. Source
  3. UIC med school ransomware, data stolen: University of Illinois Chicago says attackers hit the College of Medicine, restored systems, and are investigating whether personal or research data was taken. The leak site claim is the breadcrumb. Source
  4. Citrix SAML deployments targeted: Citrix shipped fixes for a NetScaler memory overflow DoS bug that only matters if you run SAML SP or IdP configurations. The precondition list is your incident triage list. Source
  5. Rejetto HFS RCE scanning begins: Honeypots saw probes for a weak session signing key issue that can become admin takeover and RCE. If HFS exists in your environment, it is probably unloved and Internet reachable. Source

Why today matters: Three different org types got hit the same way: attackers piggybacked on a trusted path, not a noisy exploit chain. Partner access into a national registry, a single Microsoft 365 mailbox into a media org’s relationship graph, and SAML edge appliances as a fragile “front door” all point to the same shift: identity plumbing is now your highest-value data lake. If you run critical workflows on credentials and federation alone, you should be nervous, especially if you cannot prove least privilege and session integrity end-to-end.

Quick palate cleanser: the bots are coming for your triage queue too.

Data Breaches

Nikkei Microsoft 365 account compromise and phishing blast
  1. Denmark population registry data breach affects 8.8 million people: Denmark’s Central Population Register (CPR) disclosed that threat actors misused a private company’s legitimate access to extract CPR numbers and related personal data. Danish authorities said the activity involved brute forcing or enumeration to pull records at scale, and the partner’s access has been blocked. Source: BleepingComputer
  2. Nikkei discloses employee account intrusions, phishing sent to sources: Nikkei said an attacker compromised an employee Microsoft 365 account and used it to send roughly 9,000 phishing emails to internal and external recipients, including journalistic sources. Nikkei also disclosed an earlier Google Workspace account intrusion that could have exposed information on 1,646 people. Source: The Record
  3. University of Illinois Chicago medical school hit by ransomware: UIC said a ransomware incident limited access to some College of Medicine systems and that hackers stole some information from servers. The university reported systems restored and no impact to patient care delivery at UI Health, with notifications planned as scope is confirmed. Source: The Record
  4. iRhythm begins notifications after June 2026 cyber incident review: iRhythm said a forensic investigation found data accessed and downloaded between June 3 and June 8, 2026 from third-party-hosted business applications. The company said notifications to impacted individuals began October 2, 2026. Source: TechIntelPro

Security Research

Google pauses OSS VRP product vulnerability submissions due to AI spam
  1. Google pauses OSS VRP product vulnerability submissions due to AI spam: Google suspended product vulnerability submissions to its OSS VRP, citing a significant rise in automated reports that are mostly invalid. Supply chain reports and existing submissions are not impacted, and Google says it will update the program in Q1 2027. Source: BleepingComputer
  2. Rejetto HFS CVE-2026-61500 shifts from writeup to scanning: VulnCheck observed probes for CVE-2026-61500, a session-cookie signing key weakness that can lead to admin session forgery and RCE. The story also highlights AI-assisted discovery and exploit chaining, which means more “weird but real” bug classes will hit prod faster. Source: BleepingComputer
  3. Dell System Update CLI path traversal lets attackers reach root: Dell warned that DSU versions prior to 2.3.0.0 are affected by a path traversal issue enabling code execution with root privileges. If you use DSU in automation, assume it is broadly deployed and quietly privileged. Source: BleepingComputer
  4. Citrix publishes guidance and builds for CVE-2026-88779 (SAML preconditions): Citrix states the bug affects NetScaler ADC and Gateway when configured as SAML SP or SAML IdP, and provides specific fixed builds. Treat this as a configuration-led emergency, not a blanket appliance patch. Source: Citrix
  5. GTIG: vulnerability volume rising in the AI era: Google Threat Intelligence Group research argues AI is already measurably changing vulnerability discovery velocity and the vulnerability landscape. If your org’s remediation throughput has not changed, you are losing by default. Source: TechRadar

Top CVEs

Citrix NetScaler SAML vulnerability CVE-2026-88779
  1. CVE-2026-88779: Citrix NetScaler ADC and NetScaler Gateway memory overflow leading to denial of service, with preconditions tied to SAML SP or SAML IdP configurations. Citrix urges upgrades to specific fixed builds across 14.1 and 13.1 lines, including FIPS variants. Source
  2. CVE-2026-61500: Rejetto HFS session-cookie signing weakness and leakage that enables session forgery, admin takeover, and remote code execution via server-side configuration features. Public technical details plus observed scanning means this one is moving from theory to incident response. Source
  3. CVE-2026-86360: Dell System Update (DSU) path traversal enabling code execution with root privileges on affected systems. Dell’s advisory targets DSU versions prior to 2.3.0.0, which matters because DSU often runs inside privileged enterprise update workflows. Source
  4. CVE-2026-104286: Fortinet FortiMail unauthenticated arbitrary file write via path traversal and NULL byte handling, with confirmed active exploitation and KEV inclusion discussed widely by defenders. If FortiMail is Internet exposed, treat the workaround as an emergency change window, not a backlog item. Source
  5. CVE-2026-94127: F5 BIG-IP APM heap-based buffer overflow in OAuth configurations, reported as exploited in the wild as a zero-day with hotfixes available. The pattern matches what keeps happening at the edge: auth and policy components are attackers’ favorite choke points. Source

Podcasts & Talks

SANS Stormcast daily briefing episode
  1. SANS Stormcast (Mon, Oct 5, 2026): FortiMail 0-day and other rapid response items. Useful as a daily executive briefing input when your team is triaging KEV and “patch now” edge appliance issues. Listen: https://isc.sans.edu/diary.html?date=2026-10-05
  2. Risky Business: Weekly show hiatus notice and recent episodes index. Worth noting if your comms plan assumes a weekly external news digest, this one is on break and returns Oct 14, 2026, so plan alternate listening for leadership briefings this week. Listen: https://www.risky.biz/risky-business/

Final Words

The uncomfortable pattern today is that the biggest damage is happening in the “it is supposed to be allowed” layer. A partner with legitimate registry access. A real employee mailbox. A correctly configured SAML box that is still exploitable. Your threat model cannot stop at authentication, it has to include what authenticated or federated access is allowed to do at speed and at scale.

This week, do three things:

  • Hunt for Citrix NetScaler SAML configurations and upgrade any appliances meeting Citrix’s SAML SP or IdP preconditions for CVE-2026-88779, then add a regression check to your change pipeline.
  • Inventory Rejetto HFS and Dell DSU usage in your estate, upgrade HFS to at least 3.2.1 and DSU to 2.3.0.0 or later, and block Internet exposure for any “utility servers” by default.
  • Run an “identity blast radius” tabletop: assume one Microsoft 365 mailbox is compromised, then validate your anti-phishing controls for known-sender abuse, plus your incident playbook for notifying external contacts fast.

Your turn: If one of your journalists, execs, or deal teams had their Microsoft 365 mailbox hijacked tomorrow, do you know exactly which external relationships would get phished within the first hour? Hit reply with your real answer, or drop a comment on the web version. I read every reply.

Know someone who still thinks “partner access” is lower risk than Internet exposure? Forward them the Denmark CPR story, it costs 30 seconds and the alternative costs a lot more. For forwarded and web readers: subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!