CRITICAL
The Hacker News
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CVE-2026-104286 is a critical FortiMail vulnerability (CVSS 9.8) allowing unauthenticated arbitrary file writes and is actively exploited in the wild. Immediate patching and network segmentation of FortiMail instances are required.
▸ countermeasure Immediately patch all FortiMail instances to the latest patched version
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
WordPress backdoor 'SC' uses multi-layered persistence mechanisms (files, database, shared memory) to automatically rebuild itself after cleanup attempts. Organizations must implement comprehensive removal procedures targeting all persistence vectors simultaneously.
▸ countermeasure Perform full WordPress core, theme, and plugin audit for unauthorized modifications and SC_ markers
ArrayArrayArrayArray
Open source advisory →
CRITICAL
BleepingComputer
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet FortiMail CVE-2026-104286 is a critical vulnerability actively exploited in zero-day attacks enabling remote code execution. Immediate patching and network segmentation of mail infrastructure is required.
▸ countermeasure Apply Fortinet security patches immediately to all FortiMail instances
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Citrix NetScaler ADC/Gateway systems are being actively exploited via pre-authentication command injection to deploy web shells and exfiltrate configuration data. Immediate patching and network segmentation are required.
▸ countermeasure Patch all Citrix NetScaler ADC and Gateway instances to latest security updates immediately
ArrayArrayArrayArray
Open source advisory →
CRITICAL
CISA News
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based o
▸ countermeasure Confirm exposure, apply vendor patches, add temporary WAF/IPS rules, and run post-patch vulnerability validation.
Open source advisory →
HIGH
CISA News
Johnson Controls EasyIO Neo Series EC and CW Controllers
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Monta monta.app
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vuln
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Meari IoT Cloud Platform OpenAPI Service
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service ver
▸ countermeasure Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.
Open source advisory →
HIGH
CISA News
Armatura LLC Armatura One
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592,
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
BleepingComputer
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
BleepingComputer
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
▸ countermeasure Verify immutable backups, block known IOCs, isolate affected hosts, and review EDR detections for lateral movement.
Open source advisory →
HIGH
BleepingComputer
Microsoft says threat actors are ahead in the early AI race
Threat actors are leveraging AI for accelerated vulnerability discovery, malware development, and post-compromise activities faster than defenders can respond. Security teams face capability gaps in AI-driven threat detection and response.
▸ countermeasure Implement AI-assisted security tools for vulnerability scanning and threat detection to close the capability gap
ArrayArrayArrayArray
Open source advisory →
HIGH
CISA KEV
CVE-2026-104286 · Fortinet FortiMail
Fortinet FortiMail contains a path traversal vulnerability being actively exploited in the wild. Attackers can access unauthorized files and directories on affected systems.
▸ countermeasure Immediately patch FortiMail instances to the latest patched version
ArrayArrayArray
Open source advisory →
HIGH
The Hacker News
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
Multiple attack vectors identified including AI model inspection RCE, credential exposure (543K secrets), and cache/compilation-based exploitation. Organizations must audit model inspection endpoints, rotate exposed credentials, and review caching mechanisms.
▸ countermeasure Audit all AI model inspection/debugging endpoints for code execution capabilities and restrict access
ArrayArrayArrayArray
Open source advisory →
HIGH
BleepingComputer
Metamask discloses security incident affecting its infrastructure
MetaMask infrastructure compromise may expose user data and wallet interactions. Immediate credential rotation and transaction monitoring recommended for affected users.
▸ countermeasure Rotate MetaMask passwords and security keys immediately
ArrayArrayArray
Open source advisory →
HIGH
SANS ISC
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
ScreenConnect client is being abused by threat actors as a legitimate tool for unauthorized access and lateral movement. Organizations must restrict and monitor this remote access software to prevent compromise.
▸ countermeasure Inventory all ScreenConnect installations across the environment
ArrayArrayArray
Open source advisory →
MEDIUM
The Hacker News
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Android 17's Advanced Protection restricts accessibility service access to verified tools, blocking a major malware attack vector. Organizations should enable Advanced Protection on high-risk devices and audit existing accessibility app permissions.
▸ countermeasure Enable Advanced Protection on Android 17+ devices for high-risk users
ArrayArray
Open source advisory →
MEDIUM
The Hacker News
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
MEDIUM
The Hacker News
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
KillSec ransomware group operator arrested; leak site and infrastructure seized by Spanish police. Organizations previously targeted should verify data exposure and implement incident response protocols.
▸ countermeasure Check if your organization was targeted by KillSec; search public breach databases and news archives for your company name
ArrayArrayArray
Open source advisory →
MEDIUM
The Hacker News
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google released Gemini 4 Argon AI model to trusted cybersecurity professionals via Fairwind Program. Organizations should evaluate AI model integration into defensive workflows and establish governance controls for AI-assisted security tools.
▸ countermeasure Assess organizational readiness for AI-assisted cybersecurity tools and establish acceptable use policies
Array
Open source advisory →
LOW
SANS ISC
ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)
ISC Stormcast is a daily cybersecurity podcast providing threat intelligence updates and defensive guidance. This is a routine security awareness resource for defenders.
▸ countermeasure Subscribe to ISC Stormcast for daily threat briefings
Array
Open source advisory →
LOW
The Hacker News
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
LOW
BleepingComputer
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
LOW
SANS ISC
ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →