DAILY BRIEFING
Microsoft plans to deprecate Windows Deployment Services
Today's briefing covers Bitget losing $351.6 million in a suspected North Korean backend compromise and how AI tools are lowering the cost of privilege escalation retries.
5 stories2 min read

Suspected North Korean threat actors compromised cryptocurrency exchange Bitget on September 24, 2026, stealing $351.6 million from hot and warm wallets. The platform suspended withdrawals while retaining Mandiant and SlowMist for a third-party security investigation. Bitget stated customer balances remain accurate and cold wallets were unaffected.
Meanwhile, threat reporting shows attackers using generative AI to automate troubleshooting and script debugging. AI adoption lowers the friction of failed intrusion attempts, allowing adversaries to quickly retry privilege escalation steps across cloud accounts.
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
The SOC Doesn't Need to Start Over with Every Alert
Threat actors are using generative AI to lower operational costs and rapidly iterate through failed intrusion attempts, such as troubleshooting privilege escalation scripts in cloud environments.
- Why it matters
- Attacker efficiency is increased, allowing lower-skilled adversaries to quickly overcome roadblocks during active intrusions.
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release.
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates.
Key takeaways
- Bitget reported a $351.6M loss from hot and warm wallets following a September 24, 2026 backend breach.
- Bitget suspended withdrawals and hired Mandiant and SlowMist to investigate the breach.
- Threat actors are using generative AI for translation, scripting, and troubleshooting failed intrusion steps.