NeoShield Security logo NeoShield Security Quantum X
AUTONOMOUS AI · ONLINE LAST SCAN 49m ago STORE DB SYNC 10:51:16 ALERTS 0

AI-assisted threat intelligence

Live critical cyber signals

A Claude-powered agent continuously scans official global threat feeds, triages the most dangerous activity, and maps each one to concrete defensive action — automatically.

AI analyst live situational brief

6 critical flaws under active exploitation: FortiMail zero-day, edge/VPN devices, WordPress backdoors—patch immediately

Threat level GUARDED (5/5). Six critical vulnerabilities are actively exploited across mail, edge, and web infrastructure; zero-days in FortiMail and unpatched devices dominate the landscape. Ransomware and authentication attacks remain secondary but persistent threats. Defenders must prioritize perimeter and mail-server hardening within 24 hours.

Do this today: Isolate and patch FortiMail instances; block unauthenticated access to edge/VPN devices; scan WordPress for backdoors and rebuild from clean backups.

EdgeVPN Critical Sweep 4 Zero-Day Active Exploit Chain 2 FortiMail Unauthenticated Write 2 CMS Persistent Backdoor 1 Identity & Access Abuse 3 Ransomware Staging Activity 2
AI-triaged Priority One

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News · threat news ·

CVE-2026-104286 is a critical FortiMail vulnerability (CVSS 9.8) allowing unauthenticated arbitrary file writes and is actively exploited in the wild. Immediate patching and network segmentation of FortiMail instances are required.

  • Immediately patch all FortiMail instances to the latest patched version
  • Isolate FortiMail servers on restricted network segments with strict ingress controls
  • Monitor FortiMail logs for suspicious file write operations and authentication anomalies
  • Implement network-based detection for CVE-2026-104286 exploitation attempts
Open source advisory →
5
Critical
11
High
26
Tracked

Triaged intelligence feed

refreshes automatically · severity-first
CRITICAL The Hacker News

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

CVE-2026-104286 is a critical FortiMail vulnerability (CVSS 9.8) allowing unauthenticated arbitrary file writes and is actively exploited in the wild. Immediate patching and network segmentation of FortiMail instances are required.

▸ countermeasure Immediately patch all FortiMail instances to the latest patched version
ArrayArrayArray
Claude triage
Open source advisory →
CRITICAL The Hacker News

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

WordPress backdoor 'SC' uses multi-layered persistence mechanisms (files, database, shared memory) to automatically rebuild itself after cleanup attempts. Organizations must implement comprehensive removal procedures targeting all persistence vectors simultaneously.

▸ countermeasure Perform full WordPress core, theme, and plugin audit for unauthorized modifications and SC_ markers
ArrayArrayArrayArray
Claude triage
Open source advisory →
CRITICAL BleepingComputer

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet FortiMail CVE-2026-104286 is a critical vulnerability actively exploited in zero-day attacks enabling remote code execution. Immediate patching and network segmentation of mail infrastructure is required.

▸ countermeasure Apply Fortinet security patches immediately to all FortiMail instances
ArrayArrayArray
Claude triage
Open source advisory →
CRITICAL The Hacker News

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Citrix NetScaler ADC/Gateway systems are being actively exploited via pre-authentication command injection to deploy web shells and exfiltrate configuration data. Immediate patching and network segmentation are required.

▸ countermeasure Patch all Citrix NetScaler ADC and Gateway instances to latest security updates immediately
ArrayArrayArrayArray
Claude triage
Open source advisory →
CRITICAL CISA News

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based o

▸ countermeasure Confirm exposure, apply vendor patches, add temporary WAF/IPS rules, and run post-patch vulnerability validation.
heuristic
Open source advisory →
HIGH CISA News

Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
HIGH CISA News

Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vuln

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
HIGH CISA News

Meari IoT Cloud Platform OpenAPI Service

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service ver

▸ countermeasure Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.
heuristic
Open source advisory →
HIGH CISA News

Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592,

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
HIGH BleepingComputer

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
HIGH BleepingComputer

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

▸ countermeasure Verify immutable backups, block known IOCs, isolate affected hosts, and review EDR detections for lateral movement.
heuristic
Open source advisory →
HIGH BleepingComputer

Microsoft says threat actors are ahead in the early AI race

Threat actors are leveraging AI for accelerated vulnerability discovery, malware development, and post-compromise activities faster than defenders can respond. Security teams face capability gaps in AI-driven threat detection and response.

▸ countermeasure Implement AI-assisted security tools for vulnerability scanning and threat detection to close the capability gap
ArrayArrayArrayArray
Claude triage
Open source advisory →
HIGH CISA KEV

CVE-2026-104286 · Fortinet FortiMail

Fortinet FortiMail contains a path traversal vulnerability being actively exploited in the wild. Attackers can access unauthorized files and directories on affected systems.

▸ countermeasure Immediately patch FortiMail instances to the latest patched version
ArrayArrayArray
Claude triage
Open source advisory →
HIGH The Hacker News

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

Multiple attack vectors identified including AI model inspection RCE, credential exposure (543K secrets), and cache/compilation-based exploitation. Organizations must audit model inspection endpoints, rotate exposed credentials, and review caching mechanisms.

▸ countermeasure Audit all AI model inspection/debugging endpoints for code execution capabilities and restrict access
ArrayArrayArrayArray
Claude triage
Open source advisory →
HIGH BleepingComputer

Metamask discloses security incident affecting its infrastructure

MetaMask infrastructure compromise may expose user data and wallet interactions. Immediate credential rotation and transaction monitoring recommended for affected users.

▸ countermeasure Rotate MetaMask passwords and security keys immediately
ArrayArrayArray
Claude triage
Open source advisory →
HIGH SANS ISC

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

ScreenConnect client is being abused by threat actors as a legitimate tool for unauthorized access and lateral movement. Organizations must restrict and monitor this remote access software to prevent compromise.

▸ countermeasure Inventory all ScreenConnect installations across the environment
ArrayArrayArray
Claude triage
Open source advisory →
MEDIUM The Hacker News

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Android 17's Advanced Protection restricts accessibility service access to verified tools, blocking a major malware attack vector. Organizations should enable Advanced Protection on high-risk devices and audit existing accessibility app permissions.

▸ countermeasure Enable Advanced Protection on Android 17+ devices for high-risk users
ArrayArray
Claude triage
Open source advisory →
MEDIUM The Hacker News

How Financial Services Companies Can Modernize Their Software Supply Chain

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
MEDIUM The Hacker News

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

KillSec ransomware group operator arrested; leak site and infrastructure seized by Spanish police. Organizations previously targeted should verify data exposure and implement incident response protocols.

▸ countermeasure Check if your organization was targeted by KillSec; search public breach databases and news archives for your company name
ArrayArrayArray
Claude triage
Open source advisory →
MEDIUM The Hacker News

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google released Gemini 4 Argon AI model to trusted cybersecurity professionals via Fairwind Program. Organizations should evaluate AI model integration into defensive workflows and establish governance controls for AI-assisted security tools.

▸ countermeasure Assess organizational readiness for AI-assisted cybersecurity tools and establish acceptable use policies
Array
Claude triage
Open source advisory →
LOW SANS ISC

ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)

ISC Stormcast is a daily cybersecurity podcast providing threat intelligence updates and defensive guidance. This is a routine security awareness resource for defenders.

▸ countermeasure Subscribe to ISC Stormcast for daily threat briefings
Array
Claude triage
Open source advisory →
LOW The Hacker News

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
LOW BleepingComputer

Autonomous AI agents tried to hack US, Canadian government websites

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
LOW SANS ISC

ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic
Open source advisory →
Feeds: CISA KEV · NVD · CISA News · SANS ISC · The Hacker News · BleepingComputer · Krebs on Security · triaged by NeoShield's AI agent Full defense feed →
How to use Threat Live Manual & worked example — inputs, output, limits, what it does not do, and a worked example. Open the reference →