Pentagon HR Breach Hits Over 3 Million People (10/01/2026)
- › The Defense Manpower Data Center says attackers breached its HR management system in October 2025 through a file-sharing vulnerability, and the breach was found in July 2026.
- › About 2.8 million living people and 294,000 deceased people had data taken, including Social Security numbers and military personnel details.
- › Kiteworks fixed 126 vulnerabilities, including CVE-2026-54154, a maximum-severity flaw that gives unauthenticated attackers root on its Email Protection Gateway.
- › Proofpoint says China-aligned TA419 impersonated a senior Anthropic employee and a former White House official to phish AI policy experts' Microsoft 365 accounts.
- › Police in ten countries took down KillSec, which claimed about 500 successful attacks, and identified a 16-year-old as its alleged administrator.
The Pentagon’s personnel breach has the worst kind of timeline: attackers got in through a file-sharing vulnerability in October 2025, and nobody noticed until July 2026. For nine months, somebody had access to Social Security numbers and service records for millions of current and former service members. The notification letters are going out now, nearly a year after the data left.
Top 5 Critical Security Alerts
1. Pentagon HR System Breach Exposes More Than 3 Million People
The Defense Manpower Data Center is notifying service members that attackers breached the Pentagon’s human resources management system in October 2025, exploiting a vulnerability in its file-sharing systems, and that the breach was discovered in July 2026, per BleepingComputer. Data on about 2.8 million living people and 294,000 deceased people was taken, varying by person but including Social Security numbers, names, dates of birth, contact information, and military personnel details. No group has been identified, and affected people are offered 12 months of credit monitoring.
Operator Note: If you employ veterans or reservists, expect targeted phishing that uses service details to sound official. Tell staff that a message quoting their own military record is a warning sign, not a credential.
2. Kiteworks Fixes 126 Flaws, One at Maximum Severity
Kiteworks released fixes for 126 vulnerabilities, including CVE-2026-54154 in its Email Protection Gateway, which chains path traversal, code injection, and missing authentication so that a remote unauthenticated attacker can run code and escalate to root on the appliance, per BleepingComputer. All Email Protection Gateway releases before 9.4.1 are affected, and 11 other critical flaws cover authentication bypass and account takeover. There is no evidence of exploitation, and it is not yet clear whether this is the flaw behind the shutdown we covered in our September 29 briefing.
Operator Note: One hundred and twenty-six fixes in a release means a lot of new attack paths are now documented in public. Apply it this week, and if your gateway was reachable from the internet before the patch, review its logs for unexpected processes.
3. TA419 Impersonates an Anthropic Employee to Phish AI Policy Experts
Proofpoint says the China-aligned group TA419 impersonated a senior Anthropic employee, former White House science policy official Lynne Edwards Parker, and economist Heidi Crebo-Rediker to invite AI policy experts at universities, think tanks, and law firms onto a fake AI policy advisory committee, per The Register and Infosecurity Magazine. The links led through fake OneDrive pages to adversary-in-the-middle phishing that captured Microsoft 365 credentials and sessions, mostly in July.
Operator Note: An invitation that flatters the recipient’s expertise is the oldest lure in espionage. Passkeys, which are bound to the real sign-in site, defeat the session theft this campaign depended on.
4. Police Take Down KillSec and Identify a 16-Year-Old Administrator
Operation KillSwitch, led by German investigators with authorities from nine other countries, seized KillSec’s leak site and five servers, arrested three suspects, and identified a 16-year-old as the group’s alleged administrator, per BleepingComputer and The Record. Investigators link the group to about 1,000 suspected attacks and about 500 successful ones since around 2024, and seized at least 110 terabytes of stolen data.
5. MetaMask Reports an Ongoing Infrastructure Incident
MetaMask disclosed an ongoing security incident affecting part of its infrastructure, said there is no immediate threat to wallets, and began exiting affected Ethereum validators from its staking operations as a precaution, per BleepingComputer and The Hacker News. It has not said which systems were affected.
Additional Security Alerts
Vulnerabilities & Patches
- CISA adds the exploited Cisco SD-WAN Manager flaw to its catalog: CVE-2026-76504, which we covered yesterday, is now on the Known Exploited Vulnerabilities list. The Hacker News
- A public proof of concept appears for the Apple CoreGraphics flaw: A malicious PDF with a crafted font crashes unpatched iPhones and Macs, and WhatsApp’s PDF handling hints at a delivery path. The Hacker News
- A Citrix NetScaler payload creates a superuser and hides web shells behind CSS-like URLs: LevelBlue documented the post-exploitation activity and attempts to steal configuration data. The Hacker News
Threat Intelligence
- A WordPress backdoor rebuilds itself after cleanup: The SC backdoor uses files, the database, and shared memory so the payload returns without reinfection. The Hacker News
- CloudSyncD hides behind a fake Zoom installer: The macOS backdoor phishes the user’s password and launches in two stages. Infosecurity Magazine
- MI5 warns UK academics their work may have aided Chinese intelligence: More than 100 academics contributed to a Chinese research institute, and universities are told to trace who funds their work. Infosecurity Magazine
- Treasury sanctions 10 over an ATM jackpotting scheme: OFAC targeted Venezuelan nationals and companies laundering money stolen from dozens of ATMs, tied to Tren de Aragua. The Record
Security Breaches & Incidents
- A major Polish invoicing platform is breached: The attack may have exposed data on users and their customers and business partners. The Record
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.