New: AI Workspace – Secure AI for Organizations With Sensitive Data. Learn more.
SECURITY INSIGHTS | Oktober 2, 2026
Myra's monthly security highlights provide IT executives and security professionals with the most relevant topics from the world of cybersecurity. Current trends, defense strategies, and reports on cyberattacks, attack campaigns, and more are presented here in a clear and concise format.
Artificial intelligence continues to dominate cybersecurity headlines. In Germany, the newly established German AI Safety Institute (AISI) is set to evaluate AI-related security risks. At the same time, an autonomous AI agent's unauthorized intrusion into an Australian government portal and an AI-driven attack campaign detailed by tech outlet Heise highlight the serious risks posed by self-directed agentic systems.
Meanwhile, new reporting and oversight requirements are ramping up regulatory pressure on organizations across Europe. The first mandatory reporting rules under the Cyber Resilience Act took effect on September 11. In addition, Austria is introducing new incident-reporting obligations starting in October, while Switzerland is drafting standalone cybersecurity legislation. Concurrently, the European Court of Auditors warned of significant shortcomings in cross-border threat intelligence sharing and incident response.
The tangible impact of cyberattacks on organizations is underscored by recent incidents affecting public institutions, utilities, and healthcare providers: consequences range from encrypted systems and stolen personal data to compromised websites.
Germany Establishes Institute to Assess AI Security Risks
In Berlin, the German AI Safety Institute (AISI Deutschland) has commenced operations to evaluate both the benefits and risks of AI systems and strengthen resilience against emerging threats. At launch, the Federal Office for Information Security (BSI) oversees cybersecurity aspects, while the Federal Network Agency manages systemic safety. The institute's launch comes in response to incidents where AI models from Anthropic and OpenAI independently accessed third-party systems without authorization.
German Government Abandons Constitutional Amendment to Expand BSI Mandate
The German federal government has dropped its plans to amend the Basic Law to turn the Federal Office for Information Security (BSI) into a central federal agency. The Federal Ministry of the Interior pointed to the existing legal framework, established cooperation agreements with the federal states, and the BSI's expanded powers under national NIS 2 implementation.
European Court of Auditors Highlights Gaps in EU Cyber Defense
In a recent special report, the European Court of Auditors concluded that current EU measures to detect and mitigate severe cyber incidents remain inadequate. The auditors primarily criticized the lack of information sharing among member states and underutilized reporting channels during cross-border incidents—despite 1.4 billion euros allocated through the Digital Europe Programme. As an example, the report cites a ransomware attack on a service provider for several European airports that was never officially reported to ENISA by any affected member state.
Austria Introduces Mandatory IT Incident Reporting Starting in October
Through the Network and Information System Security Act 2026 (NISG 2026), Austria is transposing the EU's NIS 2 Directive effective October 1, establishing a new Federal Office for Cybersecurity. The agency receives registration and oversight powers over companies and public bodies, coordinates major security incidents, and will operate the civilian GovCERT. The former CIO of transmission system operator Austrian Power Grid will lead the agency.
Swiss Federal Council Drafts Standalone Cybersecurity Law
The Swiss Federal Council has instructed the Federal Department of Defence, Civil Protection and Sport to draft a standalone Cybersecurity Act by June 2027. The bill will merge three separate parliamentary initiatives covering product resilience, data protection, and cloud/hosting provider obligations, which were initially planned as piecemeal revisions to the Information Security Act. The draft aligns closely with the EU's Cyber Resilience Act and incorporates existing mandatory incident-reporting rules for critical infrastructure to minimize compliance overhead for businesses.
BSI Warns of Targeted Phishing Following Berlin Data Leak
Following a cyberattack on Berlin's municipal government network, the Rhysida ransomware group leaked around 1.4 million files totaling 5.8 terabytes on the dark web. The leak occurred after the Berlin Senate refused to pay a ransom demand of 30 Bitcoin. The BSI raised the threat level to elevated and issued warnings regarding follow-up spear-phishing attacks. The exposed data includes HR files, login credentials, and sensitive records concerning critical municipal infrastructure.
Ransomware Attack Paralyzes IT Systems at Landsberg Municipal Utility
A cyberattack on the municipal utility Stadtwerke Landsberg encrypted core IT systems overnight on September 1. In response, the utility severed all external internet connections, shut down affected infrastructure, and retained incident-response specialists. According to the company, regional electricity, water, and district heating supplies remained operational. Potential data exfiltration remains under investigation.
Fresenius Medical Care Reports Cyberattack on Internal Systems
Fresenius Medical Care detected unauthorized access to a limited number of internal systems, Hessian public broadcaster hr reported on September 23. Medical equipment, patient care, production lines, and business continuity were not impacted, according to the dialysis care provider. The company engaged third-party cybersecurity experts and notified law enforcement. It remains unconfirmed whether sensitive data was exfiltrated; the exact breach date was not disclosed.
Data Breach Strikes Ludwig Maximilian University of Munich
Attackers gained unauthorized access to an administrative database at LMU Munich, compromising master enrollment records. The exfiltrated records include names and personal information of approximately 600,000 current and former students spanning roughly five decades. The Bavarian State Criminal Police Office (LKA) launched a formal investigation.
AI-Driven Campaign Compromises at Least 27 Organizations
At least 27 organizations were compromised across 105 attack projects between September 10 and 15, Heise reported, citing findings from Gambit Security. A threat actor leveraged three open-source AI agents to automate vulnerability scanning, payload execution, and campaign orchestration. Security researchers analyzed threat tooling, stolen databases, and operational logs recovered from a staging server, corroborating parts of the findings. The investigation remains ongoing; traces of the campaign extend back to July.
Malicious Code Injected into Kassel Transport Authority Websites
Threat actors injected malicious scripts across several public portals of the Kassel Transport and Utility Group (KVV), prompting site visitors to download fake update installers. KVV promptly removed the code upon detection and temporarily deployed a stripped-down emergency website. Current findings indicate that internal enterprise systems and customer databases were not breached.
Autonomous AI Agent Breaches Australian Government Portal
During what was intended as a routine research query on public health statistics, an autonomous OpenAI-based agent gained unauthorized access to an internal Medicare database after its initial API queries were blocked. The Prime Minister called the breach "unacceptable" while voicing sharp concern that OpenAI waited nearly three months—until September—to disclose the June incident. A comprehensive forensic audit is underway to determine whether personal records were exposed.
FBI Puts Government Impersonation Losses at $1.6 Billion
The FBI reported a sharp spike in social engineering schemes where criminals pose as federal agents or law enforcement officers to coerce victims into transferring funds or handing over credentials. Federal authorities estimate direct financial losses at approximately $1.6 billion. The schemes disproportionately target consumers, relying on false legal authority and fabricated enforcement threats to induce panic.
Cyber Resilience Act: 24-Hour Incident Reporting Rules Take Effect
Starting September 11, hardware and software manufacturers must report actively exploited vulnerabilities and severe security incidents within 24 hours, B2B Cyber Security reported. Detailed supplemental technical analyses are required within 72 hours, followed by comprehensive final incident reports. According to a Bitkom survey of 1,003 enterprises cited in the report, only 29 percent of companies understand what the CRA requires of them. A centralized EU platform will handle secure communications between manufacturers and national authorities.
BSI Issues Critical Alert for Active Exploitation of GitLab Vulnerability
On September 14, Germany's BSI warned of active exploitation attempts targeting self-managed GitLab instances. The alert focuses on CVE-2026-85706, a critical path-traversal flaw carrying a maximum CVSS rating of 10.0 that allows unauthenticated actors to read arbitrary files under certain conditions. With public exploit code circulating, the agency urges administrators to apply vendor security updates immediately and audit logs for indicators of compromise.
Law Enforcement Dismantles NightmareStresser DDoS-for-Hire Service
US law enforcement agencies seized infrastructure and domain assets belonging to NightmareStresser, a major booter service boasting over 566,000 registered users and an attack infrastructure capable of delivering 200 Gbps volumetric floods. Active since 2022, the platform facilitated hundreds of thousands of distributed denial-of-service attacks worldwide. The takedown represents the latest milestone in Operation PowerOFF, an ongoing international crackdown on commercial DDoS platforms.
OWASP Maps 51 AI Security Risks Across 25 Regulatory Frameworks
The OWASP GenAI Security Project released an open-source Crosswalk mapping tool on September 1, Heise reported. The resource cross-references 51 AI risk vectors across four core OWASP taxonomies with security controls from 25 leading regulatory and compliance frameworks. The matrix helps security and compliance teams identify coverage gaps, structure audit workflows, and document safeguards—though OWASP stresses that the resource is not a substitute for formal certification or case-by-case architectural reviews.
What Is the Best AI Model? It All Depends on the Task
Organizations face mounting pressure to deploy generative AI quickly across their business units—often hoping for a single, straightforward choice that solves every use case. However, that simplified view ignores how widely business tasks differ in everyday workflows and how differently specialized foundation models perform when handling specific operational requirements.
Stefan Bordel
Senior Editor
Stefan Bordel has been working as Editor and Technical Writer at Myra Security since 2020. He is responsible for the strategic development and editorial management of all content formats – from website content and specialist publications to whitepapers, social media communication, and technical documentation. In this role, he combines solid expertise from IT journalism with in-depth technical understanding in the field of cybersecurity. As a long-time Linux enthusiast, he closely follows developments in the IT industry both professionally and personally.
