A CVSS 9.8 pre-authentication RCE in Cisco Catalyst SD-WAN Manager is actively exploited, with CISA adding CVE-2026-76504 to the Known Exploited Vulnerabilities catalog. No workaround exists - patching is the only remediation. In other developments, the Pentagon confirmed a year-old breach that exposed 3 million military personnel records, and Talos published its full technical report on a China-nexus group tunneling C2 through the Microsoft 365 Graph API.
In the News
Cisco Catalyst SD-WAN Manager Zero-Day Exploited - CVE-2026-76504
CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog on October 1, confirming active exploitation of a critical pre-authentication remote code execution flaw in Cisco Catalyst SD-WAN Manager. The vulnerability carries a CVSS score of 9.8 and requires no user interaction - an unauthenticated attacker can access the management API with full administrative privileges, achieving complete management-plane compromise.
The attack surface is significant. Catalyst SD-WAN Manager is the centralized orchestration platform for Cisco’s SD-WAN fabric. Compromising it gives an attacker the ability to modify routing policies, push configuration changes to edge routers, and pivot into the underlying network infrastructure. There is no workaround; the only remediation is applying the patch from Cisco’s advisory.
For federal agencies, the KEV listing triggers mandatory remediation timelines under BOD 22-01. For everyone else, the combination of pre-auth access, CVSS 9.8, and confirmed exploitation means this is a patch-today priority. Organizations should confirm their SD-WAN Manager version, apply the update, and review management-plane access logs for anomalous API activity during the exposure window.
What defenders should do: Patch Cisco Catalyst SD-WAN Manager immediately. Audit management-plane access logs for unauthorized API calls. Restrict management interface exposure to trusted networks if not already segmented.
Pentagon Confirms DMDC Breach - 3 Million Military Personnel Records Exposed
The Department of Defense publicly confirmed that the Defense Manpower Data Center (DMDC) was breached in October 2025, with the compromise going undetected for approximately 365 days. The breach exposed records belonging to roughly 3 million military personnel, DoD contractors, and individuals holding security clearances. The specific attack mechanism targeting the HR management system has not been publicly disclosed.
A full year of dwell time in a military HR system is a visibility failure of the first order. The records at stake - names, service details, clearance status - are exactly the data a threat actor needs for targeted phishing, social engineering against cleared personnel, and identity fraud. For organizations in the defense industrial base, the risk extends beyond the primary breach: compromised personnel data enables convincing impersonation in follow-on attacks against contractors and suppliers.
The BleepingComputer report notes that notification of affected individuals is underway. Defense-adjacent organizations should anticipate an uptick in targeted phishing and credential-harvesting campaigns leveraging the stolen data.
What defenders should do: Organizations with DoD, military, or cleared-contractor customers should flag elevated phishing risk. Deploy phishing-resistant MFA on all personnel and HR systems. Implement identity analytics to detect anomalous access patterns.
Mandia’s Armadin Raises $255M at $2.5B Valuation
Kevin Mandia’s Armadin, an AI-powered offensive security startup, closed a $255 million Series B at a $2.5 billion valuation - just seven months after launch. The company builds autonomous AI agents for red teaming and attack simulation, positioning itself in the emerging category of AI-driven offensive security tooling.
The valuation reflects VC confidence that autonomous offense tools are a standalone market category, not a feature bolted onto existing BAS platforms. For security teams, this signals that Q4 2026 budget conversations will increasingly include questions about AI red team agents, continuous attack simulation, and how defensive controls perform against automated adversary emulation. The competitive landscape includes Google’s Gemini 4 Argon for vulnerability research and a growing set of AI-augmented penetration testing tools. SecurityWeek coverage.
What defenders should do: Evaluate whether current breach-and-attack simulation tooling includes AI-driven adversary emulation. Ensure defensive detection stacks are validated against automated attack patterns, not just known-signature playbooks.
China-Nexus UAT-11587 Deploys Antino Backdoor via M365 Graph API
Cisco Talos published the full technical report on UAT-11587, a China-nexus threat actor that has compromised 16 government and policy organizations across eight Asian countries. The group deploys a custom Rust-based backdoor called Antino, with all command and control traffic routed exclusively through the Microsoft 365 Graph API - making C2 communications indistinguishable from legitimate cloud application traffic at the network perimeter.
The use of Graph API as a C2 channel is operationally significant. Traditional network-layer detection that keys on known-bad IPs or unusual protocol usage will miss this entirely. The detection opportunity lies in identifying endpoints making anomalous Graph API calls - volume, timing, and the specific API endpoints accessed. Defenders should baseline normal Graph API usage and alert on deviations, particularly from endpoints that do not typically interact with M365 programmatically. Full Talos report.
What defenders should do: Baseline outbound Graph API usage. Alert on endpoints making Graph API calls outside normal patterns. Ingest Talos IOCs for Antino into EDR and network detection platforms. MITRE ATT&CK: T1102.002 (Web Service: Bidirectional Communication), T1071.001 (Application Layer Protocol: Web Protocols).
Today’s Deep Dive - C2 Over Legitimate Cloud APIs
The UAT-11587 campaign is the latest example of a trend that has been accelerating since at least 2023: threat actors routing command and control traffic through legitimate cloud service APIs. The technique - mapped to MITRE ATT&CK T1102.002 (Web Service: Bidirectional Communication) - exploits the fundamental trust that organizations place in traffic to Microsoft, Google, and AWS endpoints.
The mechanism is straightforward. The Antino backdoor authenticates to the Microsoft 365 Graph API using stolen or attacker-registered OAuth tokens, then reads commands from and writes exfiltrated data to cloud resources (mailbox drafts, OneDrive files, or SharePoint lists). From a network perspective, the traffic is HTTPS to graph.microsoft.com - a destination that virtually every enterprise allowlists. Traditional IOC-based detection fails because there are no malicious IPs or domains to block.
Detection requires a shift from destination-based to behavior-based analysis. The key signals are: endpoints that suddenly begin making Graph API calls when they historically have not; API call volumes that exceed the baseline for a given user or machine; calls to specific Graph API endpoints (e.g., /me/messages, /me/drive/root/children) from processes that are not Outlook or OneDrive; and OAuth token usage from unexpected client IDs. Organizations running Microsoft Sentinel or Splunk can query the OfficeActivity and AzureADSignIn log sources for these anomalies.
The defensive response is layered. First, enforce Conditional Access policies that restrict Graph API OAuth grants to known application IDs. Second, deploy cloud-aware network detection that can inspect API call metadata within TLS-decrypted traffic. Third, integrate cloud telemetry into XDR or SIEM correlation - the signal is not in any single log source but in the cross-correlation of endpoint process execution, identity authentication events, and cloud API access logs.
Detection Spotlight
The following Splunk SPL query identifies endpoints making unusual volumes of outbound connections to the Microsoft Graph API. Tune the threshold to your environment’s baseline. This detection catches the pattern used by Antino and similar cloud-API C2 frameworks.
index=proxy OR index=firewall
dest="graph.microsoft.com" OR dest="graph.microsoft.us"
| stats count dc(uri_path) as unique_paths values(uri_path) as paths by src_ip, src_host, user
| where count > 50 AND unique_paths > 5
| sort -count
| table src_ip, src_host, user, count, unique_paths, paths
Adjust the count > 50 threshold based on your organization’s normal Graph API traffic volume. False positives will include legitimate automation accounts (e.g., Power Automate flows, backup agents). Correlate hits against known service accounts and application registrations in Azure AD to filter noise.
For Microsoft Sentinel environments, the equivalent KQL:
OfficeActivity
| where TimeGenerated > ago(24h)
| where RecordType == "AzureActiveDirectory"
| summarize CallCount = count(), UniqueOps = dcount(Operation) by UserId, ClientIP
| where CallCount > 50 and UniqueOps > 5
| sort by CallCount desc
Defender Action Items
- Patch CVE-2026-76504 on Cisco Catalyst SD-WAN Manager immediately - no workaround exists. Confirm version, apply the update, and audit management-plane API logs for the exposure window.
- Patch CVE-2026-73570 on internet-facing Zimbra Collaboration Suite instances. Check for web shells in the SNMP handler path as documented in the Microsoft Threat Intelligence report.
- Schedule CVE-2026-0307 patching for Palo Alto GlobalProtect client - local privilege escalation, lower urgency but relevant for managed endpoint estates.
- Baseline Graph API usage in your environment and deploy the detection queries above. Ingest Talos UAT-11587 IOCs into EDR and NDR platforms.
- Alert defense and cleared-contractor accounts to elevated phishing risk following the DMDC breach disclosure. Enforce phishing-resistant MFA on all personnel and HR systems.
References
- CISA adds exploited Cisco Catalyst SD-WAN Manager flaw to KEV - The Hacker News
- Pentagon DMDC breach exposes 3 million personnel records - BleepingComputer
- Kevin Mandia’s Armadin raises $255M at $2.5B valuation - SecurityWeek
- Talos: UAT-11587 targets Asian governments with Antino backdoor - Cisco Talos
- Microsoft Threat Intelligence: CVE-2026-73570 Zimbra command injection - Microsoft
- Palo Alto Networks advisory: CVE-2026-0307 GlobalProtect - Palo Alto Networks
- Google launches Gemini 4 Argon for security researchers - SecurityWeek
- DIVD confirms Zammad zero-days enabled AI-driven breach - BleepingComputer
- Star Blizzard adopts RedFlick technique for CosmicPulse backdoor - BleepingComputer
Related Briefs
- Entra ID Script Injection Blocked - October Rollout
- NetScaler Zero-Day CVE-2026-88772 - Web Shells Live
- Apple CoreGraphics Zero-Day CVE-2026-86950 Patched
- Storm-3168 Deleted Azure via Service Principals
- NetScaler Zero-Days CVE-2026-88771 and 88772 Exploited
Subscribe to it-learn Brief
Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.