Secret CISO 9/30: 3M Military PII Exposed, 270K Court Files Stolen, BTR Spectre-v2, ChatGPT ClickFix RAT
A year of quiet access beats a loud ransom note. Today’s stories rhyme: identity systems, file-sharing corners, and “trusted” UX surfaces turning into attacker-controlled funnels. Also, Spectre is not dead, it just took a long nap.
Attackers keep picking the same low-drama chokepoints: file sharing, identity plumbing, and user trust surfaces. You do not get a ransom note. You just get a letter six months later.
Today's Top 5
- 3 million military identities: A Pentagon personnel data system exposure ran for months, and the scary part is what was unencrypted. The breach window alone should make every legacy file-share owner sweat. Source
- 270,000 Arizona court records: Arizona’s courts say hackers copied sensitive case documents, including protective order and foster care records. The entry point detail is the part you should be training on this week. Source
- BTR Spectre-v2 returns: New research shows Branch Target Reuse can turn JIT engines into a memory-leaking machine, even with defenses enabled. Two fresh CVEs landed for Linux BPF JIT mitigation work. Source
- ChatGPT Custom GPTs abused: Huntress shows attackers using a Custom GPT as the “trusted front door,” then a ClickFix PowerShell paste to drop a RAT. The most dangerous part is how normal it looks to smart users. Source
- Waterford hotel-group exposure: A hotel management group says an intruder viewed or downloaded data after suspicious activity in May. Username and password fields showing up in breach notices should change your containment playbook. Source
Why today matters: Three very different incidents all share one operational truth: “data systems” and “control systems” are the same system now. File-sharing platforms, court document stores, and AI-driven user journeys are becoming the new perimeter. If you cannot inventory where sensitive files live and who can touch them, you are already negotiating with the calendar, not the attacker.
Alright, let’s get into the receipts.
Data Breaches

- Defense Manpower Data Center breach affects 3M+: The Defense Manpower Data Center exposure impacted over three million people with ties to the U.S. military. Reporting says a small number of unauthorized users accessed unencrypted PII, with access spanning roughly October 2025 through July 2026, tied to a file-sharing system flaw that was patched in July. Source: Federal News Network
- Arizona courts cyberattack, protective-order and foster-care records exposed: Arizona’s court system disclosed a cyberattack and ongoing notification effort. Local reporting cites theft of more than 270,000 records and says the incident began after an employee clicked a malicious link in a phishing email, with sensitive protective-order data among the affected documents. Source: AZFamily
- Waterford Hotel Group issues data event notice: Waterford says it found suspicious activity May 5, 2026, investigated, and determined an unknown actor accessed systems and could view or download data. Data types may include SSNs, passport numbers, payment card data, and usernames and passwords, which raises the immediate question of credential reuse and MFA coverage for downstream systems. Source: PR Newswire
- Upbound Group cloud-files incident disclosure: Upbound’s notice says an unauthorized party obtained certain files stored in cloud applications, with access occurring July 3 to July 6, 2026, and discovery on July 13. The potentially exposed data varies by person but can include SSNs, government IDs, and payment card info, which is the exact combo that makes fraud teams miserable for quarters. Source: Upbound
- Restorative Therapies breach posted to Vermont AG trackers: Vermont-facing reporting indicates Restorative Therapies, Inc. reported a breach on September 25, 2026. The public takeaway is small counts can still mean high sensitivity when health data is in scope, and these notices are often the first externally visible signal of a deeper third-party or endpoint issue. Source: DataBreachClassActions
Security Research

- Branch Target Reuse (BTR) Spectre-v2 attack disclosed: VUSec and collaborators disclosed BTR, a Spectre-v2 style technique that abuses stale branch prediction entries across JIT engines. The writeup highlights Linux kernel cBPF JIT as a practical target and ships with paper and code, which means defenders should expect noisy “security research” exploitation attempts in cloud multi-tenant environments. Source: VUSec
- Two new Linux CVEs tied to BTR mitigations: The oss-sec thread documents the Linux mitigation work and CVE assignments, including IBPB flush behavior for BPF JIT allocation and additional hardening support. This is the kind of subtle platform change that breaks assumptions in container-heavy fleets where “unprivileged” is not as unprivileged as people think. Source: oss-sec
- Huntress: ChatGPT Custom GPT to ClickFix PowerShell RAT chain: Huntress details a campaign that uses a Custom GPT as a lure, then redirects to a malicious page that prompts users to paste PowerShell, ultimately installing malware via MSI and DLL sideloading. This is a real-world example of brand trust becoming an initial access vector, not just a phishing theme. Source: Huntress
- Mozilla ships Firefox 157 and ESR fixes (multiple CVEs): Mozilla’s September 29 advisory set includes Firefox 157 and ESR updates with multiple high-impact CVEs across components. For CISOs, the point is less the individual bug list and more the reality that browser patch latency is now an enterprise risk lever, not a helpdesk hygiene issue. Source: Mozilla
- Kiteworks lifts shutdown after patching critical flaw: Kiteworks told customers to shut down systems as a precaution, then lifted the advisory after patching a critical issue in Advanced Forms and reporting no evidence of compromise. Regardless of whether exploitation occurred, this is a reminder that “secure file sharing” is frequently a high-value choke point in regulated environments. Source: BleepingComputer
- Citrix NetScaler CVE-2026-88771 exploitation goes mass: Reporting indicates exploitation moved from targeted activity into widespread scanning after technical details and PoC became available. If you run NetScaler internet-facing, the detection question is now “when did someone try” not “will someone try.” Source: Help Net Security
Top CVEs

- CVE-2026-64507: Linux kernel mitigation work for BPF JIT allocation to reduce BTR-style risk includes IBPB flush behavior. If you have high-density Linux fleets running containers and seccomp-heavy profiles, treat kernel update rollouts as a confidentiality control, not a stability chore. Source
- CVE-2026-64508: Additional Linux BPF hardening support tied to Branch Target Reuse defense-in-depth. The practical impact is that speculative side channels keep finding “we assumed this was safe” corners, especially where JIT and packet filtering meet. Source
- CVE-2026-88771: Citrix NetScaler ADC and Gateway bug used as a zero-day and then commoditized once PoC appeared, driving mass exploitation attempts. Internet-exposed appliances should be treated like endpoints with emergency patch SLAs and post-patch compromise checks. Source
- CVE-2026-88772: A second Citrix NetScaler issue cited alongside CVE-2026-88771 in active exploitation reporting. Even without a public PoC, defenders should assume parallel tradecraft exists and hunt for suspicious appliance behavior and config changes. Source
- CVE-2026-100757: Mozilla lists multiple high-impact CVEs in Firefox ESR 115.42, including a use-after-free in the Widget component. In enterprise reality, this is “patch browsers fast” because browsers are now the default document viewer, auth client, and admin console. Source
Podcasts & Talks

- SANS Stormcast (Sep 29): Apple 0-day patch, macOS priv-esc PoC, file notification attacks: Ullrich’s rundown is a useful triage list for security leaders. The “file notification attacks” segment is a quiet reminder that side-channels show up in places nobody is monitoring, like dev workstations and build hosts. Listen: SANS ISC
- Risky Business #854 (Sep 23): AI agents doing crimes, plus the week’s chaos: Not within 48 hours, but still relevant if you are aligning policy on agentic tools, internal sandboxes, and what counts as authorized testing. It is a good prompt for your legal and security teams to agree on guardrails before the next “oops.” Listen: Risky Business
Final Words
The pattern underneath today is not “more breaches.” It’s where they happen: places we treat as boring infrastructure. File-sharing systems, court document repositories, and trusted AI interfaces are all acting like identity providers now. And when those layers crack, the blast radius is people, not servers.
This week, do three things:
- Find every internet-reachable file-transfer and content portal you own (Kiteworks, legacy shares, custom upload apps), and validate patch level plus access logs retention, then run a targeted compromise assessment.
- Patch and verify Citrix NetScaler ADC/Gateway for CVE-2026-88771 and CVE-2026-88772, then hunt for new admin accounts, unexpected config changes, and outbound connections from the appliance.
- Update Linux kernels where feasible for CVE-2026-64507 and CVE-2026-64508, and review whether unprivileged cBPF JIT is enabled in your fleet baselines, especially on shared compute nodes.
Your turn: If a DMDC-style letter landed in your employees’ mailboxes tomorrow, could you answer one question in one hour: exactly which file-sharing system leaked it, and exactly who accessed it? Hit reply with your honest answer, or drop a comment on the web version. I read every reply.
Know someone running a “secure file-sharing” server that has never been treated like a tier-0 system? Forward them this issue, because the alternative is sending credit-monitoring codes for the next year. For everyone else, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!