top of page

Cybersecurity weekly news (September 28–October 4): 1.1 Billion personal data records, Cisco SD-WAN Zero-day and the race to control AI agents

1 hour ago
7 min read

Cybersecurity weekly news September 28–October 4, 2026 highlighted growing risks around personal data, digital identity, online fraud, network management infrastructure and AI Agents. In Vietnam, major developments included a case in which suspects were accused of purchasing approximately 1.1 billion personal data records to target more than 5,400 elderly victims, alongside new warnings about online-shopping scams and changes to VNeID account protection.

Internationally, Cisco disclosed critical vulnerability CVE-2026-76504 in Catalyst SD-WAN Manager under active exploitation, NVIDIA introduced tools designed to contain AI Agents that move beyond their intended scope, and Europol dismantled infrastructure linked to KillSec in an international operation involving roughly 1,000 suspected attacks.

Businesses can continue following new developments through the IPSIP Vietnamcybersecurity news section.

cybersecurity-weekly-news-september-28-october-4-2026
Cybersecurity weekly news September 28–October 4, 2026

I. Cybersecurity news in Vietnam

1. Suspects allegedly purchased 1.1 billion personal data records to target more than 5,400 elderly victims

On October 2, 2026, VnExpress reported that Vietnam’s Supreme People’s Procuracy had completed an indictment in a case where Tran Quang Dao was accused of spending money to purchase approximately 1.1 billion personal data records for fraudulent activities.

T he data was allegedly used to target more than 5,400 elderly people, with the group accused of stealing approximately VND 39.6 billion. A total of 181 defendants were prosecuted in the case, while the alleged mastermind faced charges related to both fraud and the illegal use of computer and telecommunications network information.

For businesses, a data leak does not end when information is copied. Stolen data may continue to be sold, combined with other datasets and reused in phishing, impersonation and fraud campaigns for months or years.

Recommended action: Businesses should maintain a data inventory, restrict large-scale exports, monitor unusual access behavior, deploy Data Loss Prevention where appropriate and strictly control accounts with access to customer databases. Sensitive information should also be protected through suitable enterprise data encryption.

2. VNeID accounts can be automatically locked when the registered phone number is no longer under the same owner

From September 28, 2026, a new condition applies to electronic identity accounts: when the phone number used to register a VNeID account changes and is no longer registered to the same owner, the account may be automatically locked.

The provision forms part of Decree 320/2026 on electronic identification and authentication. Electronic identity accounts may also be locked or unlocked in line with the status of the associated electronic ID.

From a cybersecurity perspective, the change is relevant because phone numbers often function as an identity factor for account recovery, OTPs and other authentication workflows.

Recommended action: Review account-recovery workflows, deploy stronger MFA for critical accounts, reduce dependence on SMS OTP alone and require additional verification when users change phone numbers or recovery information.

3. New online-shopping scam uses accurate order information to gain victims’ trust

On September 28, 2026, Vietnam’s Ministry of Public Security warned about a scam targeting online shoppers.

According to the Ministry of Public Security advisory, scammers impersonate e-commerce platforms, brands or delivery companies and claim that a recently delivered product is defective, prohibited or subject to recall. Critically, attackers may provide correct information about the buyer, product and delivery timing to appear legitimate.

After establishing trust, victims are encouraged to move the conversation to Zalo, Telegram or Facebook, access a fraudulent link, scan a QR code or perform actions on their phones for a supposed “refund verification.” This can lead to theft of banking credentials, authentication codes or device access.

Recommended action: E-commerce, retail and logistics companies should clearly communicate official contact channels, minimize unnecessary exposure of order information and monitor access to CRM and order-management systems. Employees and customers should also be reminded never to provide passwords, OTPs or scan QR codes simply because a caller knows accurate order details.

4. Ministry of Public Security strengthens detection of AI-generated images and videos with signs of violations

On October 1, 2026, during a press briefing on third-quarter policing results, Vietnam’s Cybersecurity Department discussed measures to detect and handle AI-generated information, images and videos showing signs of violations. The Ministry of Public Security published details of the initiative.

The rapid development of generative AI has made deepfakes, cloned voices and impersonation content more accessible. For businesses, the risk is not limited to misinformation on social media. It can also appear in highly targeted scenarios such as fake executive voices, manipulated video calls, fraudulent transfer requests or brand impersonation.

Recommended action: Businesses should establish out-of-band verification for unusual financial requests, require dual approval for high-value transactions and train employees to recognize deepfake and AI-assisted impersonation scenarios. Organizations that are frequently impersonated should combine brand monitoring with takedown procedures for fake domains and accounts.

II. International cybersecurity News

5. NVIDIA introduces tools designed to contain AI Agents that exceed their intended scope

On September 28, 2026, NVIDIA introduced a set of AI-safety tools as concerns continued to grow around Agents being granted system access and performing actions outside their intended boundaries.

According to Reuters, the package includes OpenShell, designed to isolate and restrict what Agents can access, as well as Sentry, a monitoring mechanism capable of disabling an Agent when it detects behavior outside defined boundaries.

For organizations integrating AI Agents into DevOps, IT automation, customer support or security operations, the risk is not just whether the model produces an incorrect answer. An Agent with access to terminals, APIs, cloud consoles or secrets can create real operational impact if surrounding controls are weak.

Recommended action: Treat AI Agents as identities with system access. Apply Least Privilege, restrict egress traffic, separate credentials by task, monitor Agent activity and maintain an emergency shutdown mechanism.

Businesses can also refer to IPSIP Vietnam’s article on cybersecurity risk management in the AI era.

6. Cisco warns that CVE-2026-76504 in Catalyst SD-WAN Manager is under active exploitation

On September 30, 2026, Cisco released a fix for CVE-2026-76504, a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager.

According to the official Cisco Security Advisory, CVE-2026-76504 received a CVSS score of 9.8/10 and allows an unauthenticated remote attacker to access the system with administrator-level privileges through specially crafted HTTP requests. Cisco PSIRT also confirmed active exploitation during September 2026.

The risk is especially significant because SD-WAN Manager belongs to the management plane. If attackers compromise a central management system, they may be able to affect configurations, policies and multiple downstream network components.

Recommended action: Do more than patch. Organizations should collect diagnostic data, upgrade immediately and review admin-tech output for signs of compromise. If compromise is confirmed, remediation should continue beyond the version upgrade.

7. Europol dismantles KillSec infrastructure and secures at least 110 TB of data

On September 30, 2026, international law-enforcement agencies seized KillSec’s leak site as part of Operation KillSwitch. Europol announced the results on October 1.

According to Europol, the campaign was linked to approximately 1,000 suspected attacks worldwide, around 500 of which have so far been identified as successful. Three suspects were provisionally arrested, eight locations across four countries were searched and five core servers were brought under law-enforcement control. At least 110 TB of data was also secured against unauthorized access.

Recommended action: Review exposed cloud storage, eliminate weak access points, enforce MFA on administrative accounts and ensure backups cannot be modified or deleted using the same credentials as production systems.

8. Visa opens part of its AI-powered cyber-defense technology as automated threats increase

On September 29, 2026, Visa disclosed part of its AI-based cyber-defense technology amid growing concern that attackers may increasingly use Agents to automate reconnaissance, adaptation and execution.

According to Reuters, Visa argued that future defensive systems may also need to become increasingly agentic, as human-operated security processes may struggle to keep pace with attackers operating at machine speed.

On one side, Agents may support reconnaissance, exploitation and fraud. On the other, Agents can help analyze telemetry, detect anomalies and automate response.

However, defensive automation also creates risk if an Agent is allowed to isolate systems, lock accounts or alter security policies without sufficient guardrails.

Recommended action: When applying AI to SOC or automated response, organizations should clearly separate actions that the system may only recommend from actions it can execute automatically. High-impact actions should remain behind human approval or appropriate policy gates.

III. What should businesses prioritize after cybersecurity weekly news September 28 – October 4, 2026?

This week’s developments highlight four major trends.

  • Personal data is increasingly becoming fuel for highly personalized fraud campaigns. The 1.1 billion-record case and the new online-shopping scam show that Social Engineering becomes far more convincing when attackers possess real contextual information.

  • Identity remains a core security layer. Changes involving VNeID demonstrate the relationship between phone numbers, digital identity and account recovery. The same logic applies inside businesses to MFA, service accounts, privileged accounts and credential-reset workflows.

  • Management infrastructure remains a high-value target. CVE-2026-76504 shows that attackers do not need to compromise every endpoint if they can seize control of a central management system.

  • AI is becoming an operational layer for both attackers and defenders. NVIDIA is building containment tools, Visa is investing in agentic defense and Europol says KillSec used AI in its ransomware operations.

IPSIP Vietnam's expert perspective

Cybersecurity developments during September 28–October 4, 2026 show that risk is increasingly interconnected across data, identity, privileged infrastructure and AI-driven automation.

A dataset sold on the underground market can become fuel for phishing. A compromised network-management system can provide access to multiple downstream assets. An AI Agent with excessive privileges can turn a control failure into a real operational action.

ipsip-viet-nam-cybersecurity-solutions
IPSIP Vietnam cybersecurity solutions
For businesses, the priority should not simply be deploying more security tools. The more important objective is to control the right data, identities and privileges while maintaining the ability to detect and respond quickly as attackers gain access to increasingly powerful automation.

References

Ministry of Public Security – Warning on a new online-shopping scam

follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page