
Weekly Axis Of Easy #470
Last Week’s Quote was: “Wonder is the feeling of the philosopher, and philosophy begins in wonder.” — by Plato. Nobody got it — no winner this week, so the prize carries forward.
This Week’s Quote: “There is no pleasure in having nothing to do; the fun is having lots to do and not doing it.” By ???
THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.
This is your easyDNS #AxisOfEasy Briefing for the week of September 28th, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.
To Listen/watch this podcast edition with commentary and insight from Joey and Len the Legend click here.
In this issue:
- Apple Patches A Zero-Day Used In An “Extremely Sophisticated” Spyware-Style Attack
- Citrix’s NetScaler Zero-Days Were Exploited For Weeks Before Anyone Patched
- A Pentagon Personnel Database Was Quietly Open For Nine Months
- An AI Agent Broke Into A Vulnerability-Disclosure Nonprofit, And Was Bad At It
- Mark E. Jeftovic: What’s Really Behind The AI Panic
Elsewhere Online:
- OpenAI Shelves Its Next Model After Safety Tests Found It Lying About Its Own Actions
- ShinyHunters’ FBI Breach Claim Is Still Unconfirmed, And The Jobs Portal Is Still Down
- A 16-Year-Old Found A Microsoft Bug Reachable To 17 Trillion Database Rows
- A Japanese Car-Sharing Breach Exposed 6.6 Million Accounts, Including License Images
- F5 Patches A Critical BIG-IP Zero-Day Already Being Exploited On OAuth Servers

easyHermes Is Here
We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform. It’s a Nous Hermes–powered conversational agent that sits on the same private VPS and control panel as easyClaw, but is built for natural, steerable conversation — assistants, knowledge bases, and chat workflows — rather than shell access and autonomous ops.
Now you can finally settle the “openClaw vs. Hermes” argument for yourself, or just run both and let them fight it out.
Check it out today, and get your first month on us when you use promo code:
AXISOFEASY ⇒ https://easynode.ai
Apple Patches A Zero-Day Used In An “Extremely Sophisticated” Spyware-Style Attack
Apple shipped emergency updates for iOS, iPadOS, and macOS on September 29 to fix CVE-2026-86950, a CoreGraphics flaw the company says was exploited in “an extremely sophisticated attack against specific targeted individuals” running iOS versions before iOS 27. The bug was reported by Meta’s own product security team, a detail Apple’s advisory doesn’t elaborate on. CISA added it to the Known Exploited Vulnerabilities catalog the same day and gave federal agencies until October 2 to patch.
Apple’s language here — “specific targeted individuals,” “extremely sophisticated” — is its standard shorthand for commercial spyware or nation-state activity rather than opportunistic crime, and it’s the same phrasing it’s used for prior mercenary-spyware disclosures. If you’re not personally in that target profile, the practical advice is simply to update promptly; if you are — a journalist, dissident, or anyone handling sensitive negotiations — this is worth treating as confirmation that whatever protections you have in place were tested against a real, working exploit, not a hypothetical one.
More via The Hacker News
Citrix’s NetScaler Zero-Days Were Exploited For Weeks Before Anyone Patched
Citrix disclosed two critical NetScaler ADC/Gateway zero-days on September 27 — CVE-2026-88771 (CVSS 9.5), an unauthenticated remote code execution bug from improper input validation that hits every default configuration, and CVE-2026-88772 (also CVSS 9.5), a memory overflow triggered by malformed DTLS packets. Researchers are calling the pair “PitScaler.” Google’s Threat Intelligence Group says the campaign was running since at least early September — nearly three weeks before Citrix’s public disclosure — with GreyNoise catching exploitation attempts as early as September 24, and Mandiant tracing attackers installing PHP web shells disguised as non-executable files, then setting the setuid bit on /bin/sh to keep root-level access even after a reboot. Palo Alto’s Cortex Xpanse counted more than 50,000 internet-exposed NetScaler instances still potentially vulnerable as of September 27.
The uncomfortable part for defenders: patching closes the hole but doesn’t evict anyone already inside. If an attacker planted a web shell before you updated, the update doesn’t remove it — you need to assume compromise on any internet-facing NetScaler appliance running an affected version from before the patch, and hunt for the specific indicators Mandiant and Citrix have published rather than just confirming the version number and moving on. NetScaler devices sit at the network edge without the endpoint monitoring a typical server gets, which is exactly why they keep showing up at the top of exploited-vulnerability lists.
More via BleepingComputer
A Pentagon Personnel Database Was Quietly Open For Nine Months
The Defense Manpower Data Center — the Pentagon’s central repository for more than 60 million personnel records — began notifying people on September 18 that unauthorized users had access to one of its file-sharing systems from October 2025 through mid-July 2026, roughly nine months, before anyone caught it. The exposed data varied by individual but included unencrypted Social Security numbers, names, dates of birth, contact information, demographic data, and military occupational specialties. A defense official put the total at 2.76 million living people and 294,000 deceased individuals — family members, veterans, and former personnel whose records the agency still holds.
DMDC says there’s no evidence the data has been misused and is offering a year of free credit monitoring, which is the standard response and not much comfort against a nine-month window. Occupational specialty data tied to a real name and Social Security number is exactly the kind of thing that turns a routine breach into a foreign-intelligence targeting list, and the “small number of unauthorized users” framing doesn’t tell you whether this was a bored insider or something considerably more patient. If your organization runs internal file-sharing systems that predate your current access-review process, this is as good a prompt as any to check who actually still has access to what.
More via SecurityWeek
An AI Agent Broke Into A Vulnerability-Disclosure Nonprofit, And Was Bad At It
The Dutch Institute for Vulnerability Disclosure — volunteer ethical hackers who’ve run coordinated disclosure programs since 2019 without incident — disclosed its first breach in seven years, and said the intrusion itself was carried out autonomously by an AI agent after an attacker exploited an undisclosed technical vulnerability (DIVD specifically says it wasn’t Citrix NetScaler). What followed, in DIVD’s own words, was “loud and very, very messy”: the agent decided each next step on its own, at machine speed, with what DIVD called sloppy logic, including fumbling its own credential-stuffing attempt by interfering with its own adversary-in-the-middle setup mid-attack.
The agent’s incompetence is the useful part of this story, not an asterisk on it — DIVD says the sloppiness left an unusually rich forensic trail that’s letting them reconstruct the whole intrusion in detail, which is exactly the trade-off you’d expect from autonomous tooling that optimizes for speed over stealth. DIVD has notified Dutch police, the national data protection authority, and the NCSC, and plans to warn other organizations that may share the same unpatched vulnerability once its investigation wraps. Treat this as an early data point, not a trend line: the first publicly disclosed agentic intrusion against a security nonprofit was also badly executed, but “badly executed and still got in” is not a reassuring combination.
More via BleepingComputer
What was really behind the “AI doom” panic?
(from the desk of Mark E. Jeftovic)
The sudden outbreak of AI-doomer panic earlier in the month seemed rather odd on its surface, everything from the initial tweet from an obscure, new X account that ignited it, to the incumbent frontier labs who took time out from their IPO road shows to beg for government regulations over themselves.
It all seemed rather, concocted, and motivated from a desire to create an AI cartel more so than an altruistic (pun intended) desire to save humanity from being exterminated by their own product.
Last weekend I wrote it all up on my personal blog, where I ring-fence my more unfiltered thoughts. I covered the Effective Altruists, a messianic doomer cult with adherents in the upper echelons of Anthropic and OpenAI, the mechanics of regulatory capture, and my own experience having the playbook laid out for me firsthand.
Read it here: https://bombthrower.com/whats-really-behind-the-ai-panic/
Also on AxisOfEasy this week: Nothing new in Curated Posts since our last check — still nothing since May. We’re not going to pad this section with filler just to fill space; when something worth your time crosses our desk, it’ll be here.
Elsewhere Online:
OpenAI Shelves Its Next Model After Safety Tests Found It Lying About Its Own Actions
Read: https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html
ShinyHunters’ FBI Breach Claim Is Still Unconfirmed, And The Jobs Portal Is Still Down
Read: https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
A 16-Year-Old Found A Microsoft Bug Reachable To 17 Trillion Database Rows
Read: https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
A Japanese Car-Sharing Breach Exposed 6.6 Million Accounts, Including License Images
Read: https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
F5 Patches A Critical BIG-IP Zero-Day Already Being Exploited On OAuth Servers
Read: https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
Previously on #AxisOfEasy
If you missed the previous issues, they can be read online here:
- September 25, 2026: #AxisOfEasy 469: Google Confirms Gemini Broke Into Three Real Companies During A Security Test
- September 18, 2026: #AxisOfEasy 468: A Compromised HBO Max Account Became A Malware Storefront
- September 11, 2026: #AxisOfEasy 467: Your LG TV Is Listening Even When It Is Off
- September 4, 2026: #AxisOfEasy 466: You Handed Over Your Licence At The Counter, Now 153 Million Scans Are For Sale
- August 28, 2026: #AxisOfEasy 465: DOJ and FBI Seize Chinese State-Backed Hacking Platforms That Hit NASA, the Fed, and the Senate
