Secret CISO 9/29: Apple iOS 0-day, 400K Medicaid leak, AI wallet-drain, WSO2 KEV

Zero-days are back in the quietest place possible: your endpoints’ file parsers, your ERP edge, and your “harmless” public reports. Today’s common thread is control-plane trust being treated as data-plane reality, and attackers cashing that check.

Share
Apple iOS CoreGraphics zero-day (CVE-2026-86950)

Today’s lesson is rude but useful: the easiest place to hide an incident is inside something everyone assumes is boring, like a PDF renderer, a stats report, or an auth token algorithm nobody reads twice.

Today's Top 5

  1. 400,000 Medicaid leak: DC Health Care Finance says hidden fields in website reports exposed beneficiary attributes over a long window. The scary part is how few logs you keep for “public” pages. Source
  2. Apple iOS zero-day: Apple patched CVE-2026-86950 after a report from Meta, and hints at a targeted campaign. CoreGraphics plus crafted files is never a relaxing combo. Source
  3. ShinyHunters retools PeopleSoft: Google says the crew modified exploitation of CVE-2026-35273 to slip past WAF rules using URL encoding. The phrase “we blocked that endpoint” is doing a lot of work here. Source
  4. AI credits as DDoS target: A Windows botnet called x47.c uses xAI Grok prompts to pick persistence actions and can drain AI provider credits using stolen API keys. Denial-of-wallet is real, and finance will notice before security does. Source
  5. WSO2 auth bypass exploited: CISA warned active exploitation for CVE-2026-5430 in WSO2, plus exploitation of Adobe Commerce, SharePoint, and MikroTik RouterOS bugs. The “boring middleware” tier is still a frontline. Source

Why today matters: We are watching attackers win by exploiting trust boundaries that defenders mentally label as “not a security surface”: reporting layers, rendering libraries, and identity middleware. The next wave is not just ransomware, it is silent control-plane compromise that makes every downstream alert look like normal app traffic. CISOs who cannot prove control effectiveness continuously, not quarterly, should be nervous.

Alright, let’s get into the receipts.

Data Breaches

DC DHCF Medicaid report data exposure
  1. DC Health Care Finance exposes 399,086 beneficiaries: The District of Columbia’s Department of Health Care Finance says two web reports contained hidden personal data, potentially reachable from 2023 to July 2026. Impacted fields include Medicaid IDs and demographics, with no SSNs or financial data listed. Source: SecurityWeek
  2. Astrana Health discloses social-engineering driven intrusion: In an 8-K, Astrana Health says threat actors spoofed the company’s main phone number and impersonated personnel to gain unauthorized access attempts, with ongoing assessment of what patient, employee, provider, and business data may have been accessed or exfiltrated. Source: SEC (Form 8-K)
  3. LMU Munich enrollment system breach impacts student data: SANS reports Ludwig Maximilian University of Munich said intruders accessed a system containing enrollment information, and the university assumes data was retrieved. Detection was September 16, 2026, with the initial access time still unknown. Source: SANS NewsBites
  4. Emperador ransomware claims attack on SitePro Rentals: Monitoring reports Emperador listed SitePro Rentals as a victim on September 28, 2026. Treat as an extortion claim until the victim confirms, but it is a useful signal for suppliers and partners to start asking questions. Source: DeXpose

Security Research

Oracle PeopleSoft ShinyHunters WAF bypass
  1. Apple patches Meta-reported CoreGraphics zero-day: Apple shipped updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution via a crafted file. Apple says it may have been exploited in an “extremely sophisticated attack” against targeted individuals. Source: SecurityWeek
  2. Google: ShinyHunters refreshed PeopleSoft campaign, WAF bypass: Mandiant and Google’s GTIG say UNC6240 modified exploitation for CVE-2026-35273 to bypass WAF rules by URL-encoding the PSEMHUB path, then deployed web shells across affected systems. Source: Google Cloud Blog
  3. x47.c botnet uses Grok prompts and “AI API drain” mode: Qrator research (via reporting) describes a botnet-as-a-service that uses xAI Grok to select persistence actions and can run up costs against OpenAI, xAI, and compatible APIs using stolen keys. This is the cleanest example yet of AI billing as an attack surface. Source: SecurityWeek
  4. CISA warns active exploitation across WSO2, Adobe Commerce, SharePoint, MikroTik: CISA flagged exploitation of CVE-2026-5430 (WSO2 auth bypass) and CVE-2026-71362 (Adobe Commerce authorization), plus exploitation of SharePoint CVE-2026-65660 and MikroTik CVE-2026-67279. If you run any of these at the edge, assume scans are already in your logs. Source: BleepingComputer
  5. Roundcube pre-auth SQLi now exploited: BleepingComputer reports active exploitation of a Roundcube Webmail flaw patched in May, with Canada’s cyber center warning it is being used in the wild. This is the recurring pattern: “patched in May” is not “safe in September.” Source: BleepingComputer

Top CVEs

WSO2 JWT auth bypass CVE
  1. CVE-2026-86950: Apple CoreGraphics out-of-bounds write, patched in iOS and macOS point releases, with Apple warning of possible exploitation in targeted iOS attacks. Prioritize mobile fleets where attachment previews and messaging clients expand the blast radius. Source
  2. CVE-2026-5430: Critical WSO2 authentication bypass tied to JWT algorithm handling, with CISA warning of active exploitation. If WSO2 sits in front of APIs or identity flows, treat compromise as credential and secret exposure, not just “a web bug.” Source
  3. CVE-2026-71362: Critical incorrect authorization in Adobe Commerce and Magento, added to KEV and observed exploited in the wild. E-commerce apps tend to be over-privileged to payment, customer, and marketing stacks, so containment plans matter as much as patching. Source
  4. CVE-2026-65660: SharePoint code-injection flaw listed as actively exploited, with CISA deadlines already attached. The tactical fix is patching, the strategic fix is de-internet-facing legacy collaboration servers. Source
  5. CVE-2026-35273: Oracle PeopleSoft pre-auth RCE abused by ShinyHunters, with Google reporting a renewed campaign that bypasses WAF signatures using URL encoding. If PeopleSoft is exposed, assume it is being fingerprinted continuously. Source

Podcasts & Talks

SANS ISC Stormcast daily security briefing
  1. SANS Stormcast (Sep 29, 2026): macOS/iOS 0-day patch coverage: ISC is already threading Apple’s new patch cycle into operational guidance. Good listen for what to hunt for after you push updates, and what telemetry gaps you should admit out loud. Listen: SANS ISC

Final Words

Underneath today’s headlines is one pattern: defenders are still treating control planes as “admin-only” and therefore safe, while attackers treat them as the shortest path to authority. A hidden export field leaks quietly for years, a JWT algorithm edge case becomes a takeover, and a file renderer bug becomes a targeted implant. The uncomfortable implication is that your best detection may be the billing system, not the SIEM, once AI credits become a denial-of-wallet lever.

This week, do three things:

  • Patch Apple fleets for CVE-2026-86950 and temporarily disable high-risk preview behaviors where you can, then hunt for anomalous file rendering crashes on iOS devices.
  • Inventory every Internet-exposed WSO2 and Adobe Commerce instance, then validate remediation for CVE-2026-5430 and CVE-2026-71362 with external scanning plus real auth-flow tests.
  • Rotate and scope down AI provider API keys, add per-key spend limits, and alert on sudden token surges so x47.c-style “AI API drain” attempts trip alarms before Finance pings you first.

Your turn: If a crafted-file zero-day hits iOS again tomorrow, do you actually know which exec devices can be reached via attachment previews, and which can’t? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.

Know someone who still thinks AI key abuse is “just fraud,” not security? Forward them this issue and point them at the x47.c credit-drain angle, it will save them a bad quarter-end surprise. For everyone else, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!