INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Pentagon Data Breach Exposed via Unpatched Citrix Vulnerability

| 2026-10-05 01:55 CRITICAL HIGH DATA BREACH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A Pentagon personnel data breach occurred on 2026-10-05, affecting over three million people. The attack is attributed to the US Cybersecurity and Infrastructure Security Agency (CISA) as a Known Exploited Vulnerability (KEV). The breach was actively exploited using zero-days in Apple CoreGraphics and Fortinet FortiMail, while two still-unpatched Citrix NetScaler RCE flaws were also reported. This incident is categorized under the MITRE ATT&CK Technique T1588.006 - Vulnerabilities. As of February 2026, over 270,000 systems remained exposed to CVE-2020-0796, a vulnerability that has been known for six years.
Technical Mitigations AI-generated
• • Fortinet FortiMail: Apply the latest patch for CVE-2022-10100 to prevent exploitation of the vulnerability. • • Citrix NetScaler RCE flaws (unpatched): Prioritize remediation and apply patches for the identified vulnerabilities as soon as possible. • • Apple CoreGraphics 0-day: Regularly update systems with the latest version of macOS or iOS that includes a patch for this vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

co•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2020-0796CVE-2020-0796
Target & Sectors
Global Scope
Incident Timeline
‎February 2026
CVE-2020-0796 vulnerability remained unpatched on approximately 270,000 systems as of February 2026.
vulnerability CVE-2020-0796
general_metric 270,000 systems
‎Q2 2026
Disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before.
organisation Beazley Security’s
general_metric 36 %
general_metric 18.5 %
‎July 2026
Tenable Vulnerability Management integrated its platform with Automox in a limited beta release starting July 2026.
organisation Tenable Vulnerability Management
‎2026/10/05
Vulnerabilities confirmed as actively exploited and added to CISA's catalog rose 10% over the same period.
organisation IBM
organisation Sophos’s State of Ransomware
victims 2,158 organizations
victims 5,000 employees
organisation The Access Route Got Older
organisation Securing AI
organisation Automox
organisation MTTP
organisation the Reason Triage Stopped Working
organisation CVE
organisation Mitigation Worklet
organisation Verizon’s
organisation The Boring Investment
Tactical Metrics
Metrics
victims
2,158
Organizations
Metrics
victims
5,000
Employees