Security
Fortinet FortiMail zero-day exploited with no patch available
Fortinet scrambles as attackers backdoor FortiMail gateways via a 9.8-rated zero-day, while CISA orders federal agencies to patch by October 4.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Fortinet FortiMail zero-day lets attackers backdoor email gateways without a password
Attackers are actively exploiting CVE-2026-104286, a critical FortiMail zero-day rated 9.8 that lets unauthenticated attackers write arbitrary files to exposed appliances. CISA added it to the Known Exploited Vulnerabilities catalog on October 1, 2026, giving federal agencies until October 4 to remediate. The flaw chains path traversal (CWE-22) and NULL byte injection (CWE-158) in the IBE feature; a crafted HTTP request escapes its directory and plants files without credentials. No permanent fix exists: 8.0.2, 7.6.7 and 7.4.9 are forthcoming, while 7.2.x gets none. Fortinet advises disabling IBE and restricting management access. Attackers could plant web shells, read email archives, intercept messages or pivot deeper into networks.
Hackers Backdoor Fortinet FortiMail Email Gateways With No Password; Patches Unavailable →
Microsoft report confirms first fully automated AI ransomware attack
Microsoft’s 2026 Digital Defense Report, released October 1 and covering July 2025 through June 2026, confirms the first fully automated ransomware extortion attack. Sysdig documented JADEPUFFER in July 2026, with AI-orchestrated systems identifying targets and managing extortion with minimal human involvement; Microsoft has since seen similar low-volume intrusions. In tests, Anthropic Mythos Preview and OpenAI GPT-5.5 chained 32 attack steps to fully compromise an emulated network. The median time from vulnerability discovery to weaponization is now under 24 hours, while remediation takes 30 to 60 days. Nearly 40,000 CVEs were published in the first half of 2026, on track for 72,000. Phishing rose to 23% of investigated intrusions, and Microsoft recommends phishing-resistant MFA and passkeys.
Microsoft 2026 Security Report: Autonomous Ransomware Has Hacked Real Organizations →
Warlock ransomware hits water and telecom operators via SharePoint flaws
The China-linked Warlock ransomware group targeted a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities for initial access. Over two months the actor focused on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The gang emerged in June 2025 and gained notoriety after exploiting the ToolShell zero-day chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). In one intrusion starting July 22, a tool disabled protection on at least 40 hosts within two hours, then Warlock launched on at least 33 hosts. Attackers dropped a multi-version SharePoint web shell, used a signed vulnerable driver to kill AV/EDR, and staged the payload in SYSVOL for domain-wide execution.
Warlock ransomware breach SharePoint in water, telecom operator attacks →
RatHat Android malware uses AI to steal PINs and bank logins
Zimperium researchers discovered RatHat, an Android malware that uses generative AI to steal banking credentials, intercept authentication codes and reconstruct PINs or unlock patterns from raw touch coordinates. Because it reads touch data at a low level, screen-reader protections do not stop it. RatHat intercepts SMS and notifications for one-time passwords, displays fake overlays on financial apps, and targets banking and cryptocurrency apps, including payment services WeChat and Alipay. It spreads via SMS phishing, malicious ads and third-party download sites, posing as streaming apps or Chrome. Once installed, it abuses Accessibility Service to enable Wireless Debugging, reads the ADB pairing code and gains shell-level access. Google said Play Protect blocks known versions.
Android malware can steal your PIN and bank logins →
Secondhand CPU triggers Valorant hardware ban from previous owner
A German Valorant player was instantly banned after buying a used Ryzen 7 5800X3D CPU, according to a Reddit post. Riot’s Vanguard anti-cheat tags hardware components rather than only accounts or IP addresses, and the CPU carried a prior cheating ban. Riot support told the user nothing would lift the ban, and the motherboard and storage were also blacklisted in Vanguard. Vanguard requires Secure Boot and a Trusted Platform Module, which is why Valorant remains unavailable on Linux and SteamOS. Anti-cheat systems can flag CPUs, GPUs, motherboards, SSDs, network adapters or combinations, and Riot, Valve and Epic did not respond to questions about recourse for affected buyers. Such cases are rare but likely rising as used hardware sales thrive.
Your used CPU might come with someone else’s Valorant ban →
LiteLLM authentication bypass allows full admin account takeover
OX Security found that a legitimately signed login token can authenticate as another LiteLLM user, including an admin, in CVE-2026-93355, rated 8.8. LiteLLM, an open-source gateway managing access to OpenAI, Anthropic and other LLM APIs, matches JWT-bearing requests by user_id or sso_user_id, then falls back to the token’s email claim without checking email_verified. On a match, the account is returned as the authenticated caller and a background write permanently rebinds its sso_user_id to the attacker’s token subject. No victim credentials or interaction are needed. The flaw is unpatched through version 1.100.1, disclosed September 14, 2026, after roughly 120 days without vendor response. Mitigations include requiring email_verified at the IdP and pinning identity to a stable subject claim.
CVE-2026-93355: Account Takeover in LiteLLM | OX Security →
Asus patches router flaws allowing command execution via VPN configs
Asus has patched two vulnerabilities, CVE-2026-14157 and CVE-2026-13313, scoring 9.4 and 8.9 on the CVSS 4.0 scale, that could let attackers run commands on affected routers. A crafted VPN client configuration file uploaded through the web management interface can enable arbitrary command execution. A second bug uses debug code left active to bypass security checks and enable Telnet, potentially allowing root-level commands and affecting connected devices. Asus names firmware series rather than models: 3.0.0.6_102 fixes both bugs, while the 3.0.0.4_386 and 3.0.0.4_388 series are also affected by the Telnet flaw. Asus recommends importing VPN client configuration files only from trusted sources.
Malicious VPN config files can let attackers run commands on Asus routers →
Federal judge rules warrantless Flock search unconstitutional
A federal judge ruled that a Tulsa, Oklahoma sheriff’s deputy violated a woman’s Fourth Amendment rights by searching Flock Safety for her license plate without a warrant. Judge Sara Hill said the deputy had no apparent reason for the search other than the vehicle’s California license plate, and ordered all evidence obtained afterward suppressed as fruit of the poisonous tree. The deputy allegedly found 91 pounds of meth. Hill called the system a type of indiscriminate mass surveillance that passively catalogs all vehicles passing network-connected cameras. The ruling is not binding precedent but is among the first federal decisions finding a Flock search unconstitutional. Florida, Texas and other governments have said they will stop using the technology, and Senator Bernie Sanders introduced the Block Flock Act.
Federal judge calls Flock ‘indiscriminate mass surveillance’ →
Chainalysis traces $387M Bitget hack to North Korea using AI
Chainalysis attributed the $387 million Bitget exchange hack to North Korea-linked actors, saying the September 24 breach pushed total crypto stolen by such groups in 2026 past $1 billion. In the first three hours, $387 million left Bitget across 23 transfers to Ethereum (49.7%), XRP (40.8%), Zcash (7.6%) and Tron (1.8%), then moved through cross-chain protocols and laundering services. Chainalysis used in-house AI automation that compressed an estimated 20-plus hours of manual bridge reconciliation into under 10 minutes, with humans still directing the work. Bitget CEO Gracy Chen and Elliptic had already pointed to North Korea. Near Intents rejected over $50 million in swaps; Circle and Tether froze roughly $318,000 in stablecoins.
Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea →
FBI arrests first cyber fugitive on Top 10 Most Wanted list
Anibal Alexander Canelon Aguirre, 50, a Venezuelan national known as Prometheus, was returned to the United States after capture in Venezuela and pleaded not guilty Friday in a Nebraska courtroom to four federal conspiracy charges. A grand jury indicted him in December 2025 on charges including bank fraud conspiracy (up to 30 years), money laundering, providing material support to terrorists, and computer fraud. Authorities describe him as an alleged leader of an ATM jackpotting conspiracy tied to Tren de Aragua, using Ploutus malware to force ATMs to dispense cash. The FBI added him to its Ten Most Wanted list in March 2026, the first cybercriminal ever designated. The conspiracy is linked to attacks in 47 states and roughly $5.4 million in losses.
FBI Arrests First Ever Cyber Fugitive on Top 10 Most Wanted List →
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix released emergency updates for CVE-2026-88779, a memory buffer flaw rated 8.7 in NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality. The flaw has been exploited in targeted attacks causing denial-of-service conditions; repeated triggering may leave the service unavailable. Early Sunday, Citrix released NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28, with FIPS deployments directed to 14.1-73.41 FIPS. Attacks were first reported Thursday after administrators saw recently patched appliances unexpectedly rebooting, and one saw crafted authentication usernames downloading a payload from 213.209.159[.]55. CISA added the flaw to its Known Exploited Vulnerabilities catalog Sunday, giving federal agencies until October 7 to mitigate.
Citrix patches NetScaler SAML zero-day exploited in attacks →
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international operation dubbed Operation KillSwitch seized KillSec’s data leak site and servers, led to three arrests and identified a 16-year-old as the group’s alleged administrator. The September 30 action involved authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland and the United Kingdom, with Europol, Eurojust, Bitdefender and Group-IB. The German-led investigation examined around 1,000 suspected attacks worldwide and identified suspects described as administrator, developer, negotiator and affiliate. Three suspects were arrested and eight properties searched in Greece, Romania, Spain and the United Kingdom. Five servers were shut down, including KillSec’s main server, and at least 110 terabytes of stolen data seized. Around 500 attacks were successful.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old →
China-aligned TA419 impersonates Anthropic staff to target AI policy experts
Proofpoint reported that a China-aligned hacking group tracked as TA419 impersonated Anthropic researchers and former government officials to obtain information on American AI development. The group targeted AI policy experts at US think tanks, universities and law firms, sending introductory emails inviting them to a fictitious AI Policy Advisory Committee or a fabricated Senate Committee on Foreign Relations report. After a few exchanges, the hackers sent malware-laced documents to gain access to cloud accounts. One email impersonating a senior Anthropic staffer carried the subject line Request for Feedback on Military Integration of Claude. Proofpoint assessed that TA419 will likely continue targeting think tanks and policy experts and spoofing real subject-matter experts.
Chinese Hackers Impersonate Anthropic Employee to Extract AI Secrets →
MacSync malware hides commands in public iCloud calendar events
Kaspersky researchers identified a new MacSync variant that uses a public iCloud calendar event in its infection chain. A downloader connects to the calendar and feeds the event description into the Mac’s zsh shell; malicious instructions placed after the description field execute, downloading an archive containing another malicious app. The attack begins when a user downloads and runs a malicious app, not through a calendar invitation. MacSync, first seen on the dark web in 2025 and operating as malware-as-a-service, steals browser history, cookies, saved logins, crypto wallet data, Telegram information and Keychain files, and searches for SSH, ZSH, AWS, Kubernetes and Git configuration files. It persists via a LaunchAgent, .zshrc changes and global Git hooks.
Mac malware can hide commands in your iCloud calendar →
Iranian national extradited to US over alleged $3.4 billion hacking scheme
Amir Barati, an Iranian-Turkish national, was extradited from Montenegro to the United States on October 1 over alleged involvement in a $3.4 billion hacking scheme targeting universities and companies across the country. Montenegrin police arrested Barati in June at the FBI’s request. Barati and 16 other Iranians were indicted on wire and computer fraud charges in August and are expected to face the charges in the US Southern District of New York. According to the indictment, the 17 defendants are members of Mabna Institute, an Iran-based company known for state-backed global hacking activities. The extradition is a rare move involving an individual accused of state-sponsored attacks.