Secret CISO 10/9: 20M Cerner Patients, 400K Utility Accounts, TP-Link Lawsuits, SonicWall SSRF
Credential theft is back on top: Oracle Health’s Cerner blast radius jumps to nearly 20M, utilities lose 400K accounts via a portal, and ASOS gets popped by straight-up impersonation. Plus: Atlassian file-read scans, FortiBleed lockouts, and a CVSS 10 SonicWall SSRF.
Today’s pattern is painfully old-school: attackers are not outsmarting your crypto, they are outsmarting your people and your “trusted” access paths. The blast radius is measured in customers, not packets.
Today's Top 5
- 20M Cerner patients at risk: Oracle Health’s legacy Cerner incident keeps growing, and the newest tally is big enough to reshape your third-party exposure math. The real question is which “old server” still exists in your estate. Source
- 400,000 utility accounts exposed: Georgia Power and Alabama Power say an intruder accessed customer portal data including contact info and SSN last-fours. If your billing portal is “not core,” attackers love you. Source
- Atlassian bug hit within hours: A critical Atlassian Data Center file access flaw started drawing real exploitation attempts shortly after public PoC details dropped. Patch speed just became a competitive advantage again. Source
- FortiBleed lockouts escalate: Fortinet device owners are getting locked out as actors create accounts, delete accounts, and rotate passwords to strand responders. This is access monetization, not “just scanning.” Source
- SonicWall SMA1000 pre-auth SSRF: SonicWall shipped fixes for a CVSS 10 pre-auth SSRF in SMA1000, and Splunk patched multiple critical issues too. Patch windows are now measured in hours, not change boards. Source
Why today matters: We are watching “identity plus legacy” become the dominant breach formula. Stolen credentials, alternate access paths, and forgotten servers are consistently beating best-in-class tooling. CISOs who still treat portals, SaaS admin accounts, and remote access appliances as separate risk buckets should be nervous, because attackers already merged them into one kill chain.
Alright, let’s get specific.
Data Breaches

- Oracle Health Data Breach Tally Climbs to Nearly 20 Million: Reporting says the Oracle Health legacy Cerner incident may have exposed personal and medical data for nearly 20 million people, far above earlier state filings and notifications. The detail that should haunt every CISO is the phrase “old legacy server not yet migrated,” because that is how most mega-incidents start. Source: SecurityWeek
- Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts: Southern Company says an unauthorized party accessed limited utility account information via its online customer portal affecting roughly 400,000 customers. Exposed data includes names and contact details, and in some cases SSN last four digits and basic account details. Source: SecurityWeek
- ASOS links data breach to social engineering attack, credential theft: ASOS says an attacker impersonated a trusted contact to steal an employee’s login credentials, then used them to access third-party platforms with customer data. ASOS says names and contact details were exposed, but not card data or passwords. Source: BleepingComputer
- Hasbro data breach exposed personal information of 600 RI residents: A Rhode Island filing indicates more than 600 Rhode Island residents may have been impacted, tied to earlier 2026 breach activity and a later review of accessed files. The practical takeaway is that breach scope accounting is now a months-long process, not an incident-day event. Source: Rhode Island Current
- Holland & Knight, LLP breach notice filed in Vermont: Vermont’s AGO listing shows Holland & Knight, LLP filed a security breach notice on October 8, 2026, with Social Security numbers implicated. Law firms remain high value because they concentrate client data and privileged material behind “normal business access.” Source: Vermont AGO
Security Research

- Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication: SecurityWeek reports threat actors began targeting CVE-2026-21589 soon after public technical details. If you run Jira, Confluence, Bitbucket, or other Atlassian Data Center products, assume you are already in someone’s scan queue. Source: SecurityWeek
- Atlassian Data Center flaw exploitation attempts (timeline confirmation): The Hacker News reports exploitation activity being observed around the Atlassian Data Center file access flaw and quotes watchTowr confirming in-the-wild exploitation. The key operational point is that public detail release is the new starting gun. Source: The Hacker News
- FortiBleed attackers locking victims out: SecurityWeek summarizes guidance tied to FortiBleed operations and the move to lockout tactics. Expect this to become a standard playbook for edge-device intrusions because it buys attackers time while you argue about ownership. Source: SecurityWeek
- TP-Link faces state lawsuits and new scrutiny over ISP router flaws: SecurityWeek covers multi-state lawsuits and notes SEC Consult technical detail publication tied to reported flaws. Even if you are not a router shop, this will increase supplier questionnaires and board questions about consumer and branch network gear. Source: SecurityWeek
- SonicWall and Splunk patch critical vulnerabilities: SecurityWeek details SonicWall SMA1000 fixes including a CVSS 10 pre-auth SSRF and critical Splunk Enterprise issues. This is a reminder that “infrastructure tooling” is now an attacker’s first-choice pivot point. Source: SecurityWeek
- Formula predicts when AI chatbots are at risk of turning bad: SecurityWeek covers research from George Washington University proposing a model for “tipping” from good to bad outputs. CISOs should care because guardrail failure is increasingly a measurable engineering property, not just a policy issue. Source: SecurityWeek
Top CVEs

- CVE-2026-21589: Critical arbitrary file access in Atlassian Data Center products. Attack activity followed quickly after public technical details, so exposed instances should be treated as urgent even if you think “nobody knows the path.” Source
- CVE-2026-102255: CVSS 10 pre-auth SSRF in SonicWall SMA1000 due to an unintended alternate access path, potentially enabling unauthorized operations via server-side requests. Patch SMA1000 fast, and review exposure and admin surfaces. Source
- CVE-2026-76485: One of Cisco Nexus 3000/9000 NX-OS NGOAM RCE issues, rated critical, that can allow unauthenticated remote code execution in affected conditions. This is squarely in “network fabric control plane” territory. Source
- CVE-2026-76486: Additional Cisco Nexus 3000/9000 NX-OS NGOAM RCE issue in the same advisory set, also rated critical, with no workarounds listed. If Nexus runs anything customer-facing, this is a weekend patch. Source
- CVE-2026-76501: Third Cisco NX-OS NGOAM RCE CVE from the same bulletin; impact is remote code execution risk in a core switching environment. Your “internal only” assumptions do not survive lateral movement. Source
Podcasts & Talks

- SANS Stormcast, Thursday October 8th 2026: The episode threads together Atlassian exploitation scanning, ccTLD registry compromise response, Cisco Nexus RCE advisories, and Outlook attachment hardening. Worth a listen because it mirrors what your SOC is about to see in logs. Listen: Apple Podcasts
Final Words
The uncomfortable pattern today is that breach scale is now created by normal business plumbing: portals, third-party platforms, and legacy systems that stayed online because “migration.” Attackers do not need exotic malware when your environment already contains everything they need to move, persist, and monetize. The miss in most coverage is that the first compromise is rarely the worst day, the worst day is when you discover how many systems trusted that first identity.
This week, do three things:
- Patch and externally validate Atlassian Data Center exposure for CVE-2026-21589, then confirm your WAF and reverse proxy logs can identify exploitation attempts against the /s/ path patterns.
- For SonicWall SMA1000, apply the fixed versions for CVE-2026-102255 and immediately inventory any alternate access paths and management interfaces exposed to the internet.
- Run a Fortinet access integrity sweep: rotate all FortiGate VPN and admin credentials, enforce phishing-resistant MFA where supported, and audit for new accounts or deleted admins consistent with FortiBleed lockout behavior.
Your turn: If your org got the “Cerner legacy server” email tomorrow, could you name the top five legacy systems still holding regulated data, with owners, in under 30 minutes? Hit reply with your honest answer, or drop a comment on the web version. I read every reply.
Know someone who still treats customer portals and “old servers” as low risk because they are not “core”? Forward them this issue, it costs 30 seconds and the alternative costs months. For forwarded and web readers: subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!