INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Pentagon Data Breach Exposed via Unpatched Citrix Vulnerability
| 2026-10-05 01:55 CRITICAL HIGH DATA BREACH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A Pentagon personnel data breach occurred on 2026-10-05, affecting over three million people. The attack is attributed to the US Cybersecurity and Infrastructure Security Agency (CISA) as a Known Exploited Vulnerability (KEV). The breach was actively exploited using zero-days in Apple CoreGraphics and Fortinet FortiMail, while two still-unpatched Citrix NetScaler RCE flaws were also reported. This incident is categorized under the MITRE ATT&CK Technique T1588.006 - Vulnerabilities. As of February 2026, over 270,000 systems remained exposed to CVE-2020-0796, a vulnerability that has been known for six years.
Technical Mitigations AI-generated
• • Fortinet FortiMail: Apply the latest patch for CVE-2022-10100 to prevent exploitation of the vulnerability.
• • Citrix NetScaler RCE flaws (unpatched): Prioritize remediation and apply patches for the identified vulnerabilities as soon as possible.
• • Apple CoreGraphics 0-day: Regularly update systems with the latest version of macOS or iOS that includes a patch for this vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
co•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2020-0796CVE-2020-0796
Target & Sectors
Global Scope
Incident Timeline
February 2026
CVE-2020-0796 vulnerability remained unpatched on approximately 270,000 systems as of February 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2020-0796
Separately, more than 270,000 systems remained exposed to CVE-2020-0796 as of February 2026, six years after its disclosure.
general_metric
270,000 systems
Separately, more than 270,000 systems remained exposed to CVE-2020-0796 as of February 2026, six years after its disclosure.
Q2 2026
Disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before.
Click on any entity below to view its context and source!
organisation
Beazley Security’s
Beazley Security’s Q2 2026
analysis found
disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before.
general_metric
36 %
Beazley Security’s Q2 2026
analysis found
disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before.
general_metric
18.5 %
Beazley Security’s Q2 2026
analysis found
disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before.
July 2026
Tenable Vulnerability Management integrated its platform with Automox in a limited beta release starting July 2026.
Click on any entity below to view its context and source!
organisation
Tenable Vulnerability Management
In July 2026, Automox placed an integration with Tenable Vulnerability Management into limited beta.
2026/10/05
Vulnerabilities confirmed as actively exploited and added to CISA's catalog rose 10% over the same period.
Click on any entity below to view its context and source!
organisation
IBM
IBM’s Cost of a Data Breach Report 2026 found 50% of organizations now deploy AI agents somewhere in the security operations center, but
only 18% apply them
to vulnerability scanning and management.
organisation
Sophos’s State of Ransomware
Sophos’s State of Ransomware 2026 reported that compromised identities featured in 79% of ransomware attacks, while malicious email (26%) and phishing (24%) were the two most commonly reported root causes.
victims
2,158 organizations
Sophos surveyed 2,158 organizations that had experienced ransomware during the previous year, all with 100 to 5,000 employees, while Verizon analyzed confirmed breaches across a much broader dataset.
victims
5,000 employees
Sophos surveyed 2,158 organizations that had experienced ransomware during the previous year, all with 100 to 5,000 employees, while Verizon analyzed confirmed breaches across a much broader dataset.
organisation
The Access Route Got Older
The Access Route Got Older, Not Smarter
Much of the current security discussion centres on
AI-related threats
, but Verizon’s data shows that known and unpatched vulnerabilities remain a common entry point.
organisation
Securing AI
Securing AI systems matters, but organizations are still being breached through weaknesses for which fixes already exist.
organisation
Automox
“Manual work is the new attack surface,” says Ryan Braunstein, Security Manager at Automox.
organisation
MTTP
Roughly 1 in 10 reported an MTTP of under a day.
organisation
the Reason Triage Stopped Working
Volume Is the Reason Triage Stopped Working
The prioritization bottleneck is a volume problem before it’s a judgment problem.
organisation
CVE
The same analysis notes that NIST no longer enriches every new CVE, which quietly removes a triage input a lot of programs were built on.
organisation
Mitigation Worklet
In September, the company introduced an AI-drafted
Mitigation Worklet pipeline
that produces configuration changes and temporary workarounds.
organisation
Verizon’s
These figures are not directly comparable with Verizon’s breach-wide findings.
organisation
The Boring Investment
The Boring Investment Is the Defensible One
The most defensible security spending of the AI era may be the least interesting.
Tactical Metrics
Metrics
victims
2,158
Organizations
Click for context!
Sophos surveyed 2,158 organizations that had experienced ransomware during the previous year, all with 100 to 5,000 employees, while Verizon analyzed confirmed breaches across a much broader dataset.
Metrics
victims
5,000
Employees
Sophos surveyed 2,158 organizations that had experienced ransomware during the previous year, all with 100 to 5,000 employees, while Verizon analyzed confirmed breaches across a much broader dataset.
Intelligence Sources
HackRead
2026-09-25
AlienVault OTX
2026-10-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:49
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
general metric
%
13
%
13x
organisation
Identified Entity
Sophos’s State of Ransomware
entity
6x
timeline
Temporal Reference
2026
date
3x
tactic
Cyber Operation Type
Data Breach
tactic
2x
attribution
Attributing Entity
Detected CISA Known Exploited
authority
Contextual Telemetry
Context Block
7 METRICS
general metric
Developments
26
developments
victims
Organizations
2,158
organizations
victims
Employees
5,000
employees
vulnerability
Exploited CVE
CVE-2020-0796
cve
general metric
Systems
270,000
systems
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Entities
1
entities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.