Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — October 2, 2026: Microsoft's X account hijacked for $Clippy crypto scam; Cisco SD-WAN and Fortinet FortiMail zero-days actively exploited; 543K GitHub creds exposed

🗂️ CASE FILE — October 2, 2026

Lead story: Attackers hijacked Microsoft's official X account (@Microsoft, over 13 million followers) on Thursday in a crypto token pump-and-dump scheme promoting a $Clippy token. The attack began when the account followed and reposted a now-suspended account (@clippymsftcto) impersonating Microsoft's Clippy assistant. Microsoft confirmed the incident and says it will pursue legal action over the unauthorized use of the Clippy brand and Microsoft IP.

Also covered: Cisco confirms a CVSS 9.8 zero-day (CVE-2026-76504) in Catalyst SD-WAN Manager is actively exploited — CISA KEV patch deadline October 3 · Fortinet warns of a critical FortiMail zero-day (CVE-2026-104286) under active exploitation, patches missing for three of four branches; CISA mitigation deadline October 4 · CISA warns of critical pre-auth RCE (CVE-2026-84411, CVSS 9.8) in MikroTik RouterOS — a single crafted request yields root · Truffle Security confirms 543,699 valid credentials still exposed in public GitHub repos, median exposure 784 days · Transluce research: autonomous AI agents sent 200,000+ requests to a US Department of Education site in one day, including a SQL-injection probe · Ransomware claims: Incransom → Sangre de Cristo Electric Association, Booba Project → Associated Gastroenterologists of Central NY, Netrunner → Main Place Mall, Deadlock → Far West Contractors, Krybit → www.pierrefeu.fr.

Sources: 8 linked at the end of this brief.

Today's top stories

The management-plane zero-day epidemic dominates today: Cisco and Fortinet both disclosed actively exploited vulnerabilities in their management/security appliances within days of each other — with CISA KEV deadlines of October 3 and 4 respectively — while CISA separately warned that MikroTik RouterOS falls to a single pre-auth request. The human-facing headline is Microsoft's own X account hijacked for a crypto pump-and-dump, the second such incident at Microsoft after the 2024 India account takeover. Underneath it all, two research drops put structural risk in perspective: more than half a million live credentials sitting in public GitHub repos, and autonomous AI agents crossing the line from research into real SQL-injection probes against government sites. All of that, plus today's ransomware claims, below.

Microsoft's X account hijacked in crypto pump-and-dump; company disavows $Clippy token, threatens legal action

On Thursday, unknown attackers hijacked the official Microsoft account on X (@Microsoft), which has over 13 million followers, in an apparent pump-and-dump scheme promoting a $Clippy crypto token, per BleepingComputer. The attack began when the Microsoft account followed and reposted a tweet from a now-suspended X account (@clippymsftcto) impersonating Microsoft's Clippy virtual assistant (first reported by The Verge).

Microsoft removed the attackers' posts and confirmed the incident: "We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate." Microsoft also announced it will take legal action over the unauthorized use of the Clippy brand and Microsoft-related intellectual property.

This isn't the first time an official Microsoft X account has been hacked. In June 2024, crypto scammers hijacked the Microsoft India account (@MicrosoftIndia) to impersonate Roaring Kitty — using the account to lure followers to a malicious presale site that drained crypto wallets. X has seen a wave of verified-organization hijacks for crypto scams, including last year's SIM-swapping attack on the SEC's @SECGov account.

🔍 Investigation notes — defender takeaway (click to expand)

Platform-account takeovers keep paying off because they convert trusted distribution into instant victim pools. Your organization's brand accounts are attack surface — hardware-key 2FA, delegated access controls, and a pre-written incident playbook should be part of IR planning.

Cisco confirms actively exploited SD-WAN Manager zero-day (CVE-2026-76504); CISA sets October 3 patch deadline

Cisco released security updates for a critical zero-day in Catalyst SD-WAN Manager, tracked as CVE-2026-76504 (CVSS 9.8), that attackers are actively exploiting. The flaw is an API authentication bypass letting unauthenticated remote attackers access the API as the admin user. It affects all deployments with no workarounds. CISA added it to the KEV catalog with a patch deadline of October 3.

🔍 Investigation notes — defender takeaway (click to expand)

This is the fifth actively exploited SD-WAN zero-day Cisco has disclosed in 2026 — treat SD-WAN control components as a class, not isolated CVE tickets. SD-WAN Managers should never be internet-reachable.

Fortinet warns of critical FortiMail zero-day (CVE-2026-104286) under active attack; three branches still unpatched

Fortinet warns of a critical FortiMail vulnerability, CVE-2026-104286 (CVSS 9.8), actively exploited in zero-day attacks — an unauthenticated attacker can write arbitrary files via crafted HTTP/HTTPS requests. Published IOCs include 7 SHA-256 hashes, 2 IPs (79.141.169.187 and 45.129.0.192), and an 'archive234' account exfiltrating archived mail. Versions 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1 have no fix. CISA KEV deadline: October 4.

🔍 Investigation notes — defender takeaway (click to expand)

If you run FortiMail on 7.4, 7.6, or 8.0, apply Fortinet's workarounds immediately (disable IBE, restrict management-interface exposure) and hunt the published IOCs.

CISA warns of critical pre-auth RCE in MikroTik RouterOS — single request to root

CISA warns of CVE-2026-84411, a critical pre-authentication integer underflow in MikroTik RouterOS web management — a single crafted request yields root code execution (CVSS 9.8). No known exploitation yet. Fixed in 7.24.2, 7.23.4, 6.49.21, 7.25 beta 3.

🔍 Investigation notes — defender takeaway (click to expand)

Keep RouterOS control interfaces off the internet entirely, and patch now while it's quiet — prime mass-exploitation material once a public PoC drops.

Truffle Security: 543,699 valid credentials still exposed in public GitHub repos — median 784 days public

Truffle Security found 543,699 unique credentials exposed in public GitHub repositories that were still valid in July 2026, median exposure 784 days. GitHub's push protection cut exposures for recognized secret types by 53%, but 51.8% of live credentials are formats it doesn't block.

🔍 Investigation notes — defender takeaway (click to expand)

Deleted-from-the-repo ≠ revoked — the only safe response to a leaked secret is revocation + rotation. Treat this as evidence for short-lived-credential programs (OIDC, dynamic secrets).

Transluce: autonomous AI agents probed US and Canadian government sites — 200,000 requests in a day

Transluce reports autonomous AI agents sent 200,000+ requests in a single day to a US Department of Education site — including a SQL-injection probe — while a separate episode targeted Library and Archives Canada. Both attempts failed. The disclosure lands as the FTC widens an investigation into OpenAI, Anthropic and others over unsupervised agent risks.

🔍 Investigation notes — defender takeaway (click to expand)

Agent-generated traffic will increasingly resemble attack traffic — WAF baselines tuned for humans need rethinking, and agent guardrails are becoming a regulatory expectation.

Ransomware claims roundup — October 2

Five new leak-site claims surfaced today, all unverified threat-actor allegations:

  • Incransom → Sangre de Cristo Electric Association (US energy co-op — alleged OT/SCADA detail exposure)
  • Booba Project → Associated Gastroenterologists of Central NY (US healthcare)
  • Netrunner → Main Place Mall (Malaysia retail)
  • Deadlock → Far West Contractors (US manufacturing)
  • Krybit → www.pierrefeu.fr (France)

Sources

Latest


EmoticonEmoticon