Secret CISO 9/12: Novo Nordisk's 1.3TB Extortion, 800K Hospice Patients Exposed, Conti Hacker Gets 4 Years, Windows Zero-Days Under Attack
Novo Nordisk lost 1.3TB to a token left in public JavaScript, a hospice pharmacy breach hits 800,000 patients, a Conti affiliate is off to prison, and two Windows zero-days are being exploited right now. Today's Secret CISO.
Today's theme is doors: one propped open by a token in public JavaScript, one closing behind a Conti affiliate for four years, and two in Windows that attackers found before the patches did.
Today's Top 5
- Novo Nordisk's 1.3TB extortion: FulcrumSec spent two months inside the Ozempic maker's network and wants $25 million. The way they got in is the embarrassing part.
- 800,000 hospice patients exposed: OnePoint Patient Care confirmed the breach, and the group behind it picked perhaps the cruelest target category of the year.
- Two Windows zero-days under active attack: Microsoft's record September patch fixes 974 flaws, but two elevation bugs were already being used. Details in Top CVEs.
- PaperCut exploitation goes live: those zero-days from two weeks ago are now being exploited pre-auth. If you run print servers, today is the day.
- A Conti hacker gets 4 years: a US court closes one chapter of the ransomware era, and the sentence is shorter than some victims' recovery time.
Full stories, CVEs, and today's listening are below. Let's get to it.
Data Breaches

- Novo Nordisk Extorted After 1.3TB Theft Rooted in Public JavaScript: The FulcrumSec extortion group stole more than 700,000 files from the pharmaceutical giant and demanded $25 million. Initial access came from a GitHub personal access token and Azure credentials sitting in client-side JavaScript on two public Novo Nordisk subdomains, which unlocked hundreds of private repositories full of further secrets. The attackers stayed inside for over two months, and kept finding fresh credentials even after the company knew about the breach. Source: Dark Reading, BankInfoSecurity
- OnePoint Patient Care Breach Reaches 800,000 Hospice Patients: The Arizona-based hospice pharmacy disclosed that as many as 800,000 individuals are affected by its data breach, with the INC Ransom group claiming responsibility. Hospice patient records combine medical, insurance, and identity data, which makes this one of the more damaging healthcare breaches of the month. Source: Tech.co
- Ukrainian Conti Affiliate Sentenced to Four Years in US Prison: A US court sentenced a Ukrainian national for his role in Conti ransomware attacks, one of the few concrete convictions tied to the gang that extorted hundreds of organizations before imploding in 2022. Prosecutors framed the sentence as proof that ransomware affiliates remain reachable years after the fact. Source: DataBreachToday
Security Research

- Darktrace: 87% of Security Professionals See More AI-Driven Threats, Few Feel Ready: The State of AI Cybersecurity 2026 report finds a surge in the volume and impact of AI-driven attacks, while most defenders admit they are not prepared to stop them. The gap between awareness and readiness is becoming the defining number of this year's security budgets. Source: Darktrace
- Proofpoint: More CVEs, Same Playbook: Proofpoint's analysis of 2026 in-the-wild exploitation shows attackers burning through record numbers of CVEs while reusing the same handful of intrusion patterns. The lesson for defenders: chasing every CVE is losing strategy, closing the shared playbook steps is not. Source: Proofpoint
- How Novo Nordisk Was Actually Breached: What the Coverage Got Wrong: CybelAngel's teardown separates fact from noise in the Novo Nordisk story: the problem was not GitHub itself but secrets shipped to every visitor's browser in front-end code bundles. A useful checklist follows for auditing your own client-side JavaScript for tokens. Source: CybelAngel
- PaperCut Zero-Days Now Exploited Pre-Auth in the Wild: Huntress confirms active exploitation of the recently disclosed PaperCut flaws, including a pre-authentication remote code execution chain against exposed NG and MF servers. Given PaperCut's ransomware history, treat unpatched print servers as compromised until proven otherwise. Source: Huntress
Top CVEs
- CVE-2026-85880: A heap buffer overflow in Windows Advanced Local Procedure Call (ALPC) that lets a local attacker gain SYSTEM privileges, CVSS 7.8. Exploited in the wild as a zero-day before this week's record 974-fix Patch Tuesday. Source.
- CVE-2026-81963: An improper link resolution flaw in the Windows Update Stack, also exploited as a zero-day for elevation of privilege, CVSS 7.8. Attackers abusing the update mechanism itself is exactly as bad as it sounds. Source.
- CVE-2026-82078: The PaperCut NG/MF zero-day has moved from disclosure to confirmed pre-auth remote code execution in the wild. Patch immediately and hunt for indicators on any internet-exposed print server. Source.
Podcasts & Talks

- SANS Internet Storm Center Stormcast, September Patch Tuesday Special: The daily 5-minute briefing walks through Microsoft's record 974-CVE release, the Adobe bulletins, and the Ivanti Neurons for ITSM advisory in the time it takes to make coffee. A CISO-friendly way to brief your team before the patching argument starts. Listen: SANS ISC Stormcast
Final Words
The Novo Nordisk breach will be taught in security training for years, and not because the attackers were brilliant. A token pasted into client-side JavaScript is the digital version of taping your office key to the front door. Every organization has a developer who has done this at least once; the difference is whether anyone looks before an extortion group does.
Add the two exploited Windows zero-days and live PaperCut attacks, and this is a patching week, not a planning week. The hospice breach is a reminder of who ultimately absorbs the damage when the patching argument is lost.
If today's edition saved you a scramble, forward it to a colleague who is still scrambling. And if someone forwarded this to you, you can get your own copy every morning: subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!