Floating servers breached by glowing cyan exploits in cyber diorama.

Daily Cybersecurity News – October 3, 2026

CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Ghost in the Wires by Kevin Mitnick

FortiMail Zero-Day CVE-2026-104286 Exploited for Arbitrary File Writes

Critical

Affected versions and workarounds

  • FortiMail 8.0.0-8.0.1: upgrade to 8.0.2+
  • FortiMail 7.6.0-7.6.6: upgrade to 7.6.7+
  • FortiMail 7.4.0-7.4.8: upgrade to 7.4.9+
  • FortiMail 7.2.0-7.2.9: move to 7.4 branch
  • Immediate: disable IBE and lock down management access

What happened

CISA added a critical Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog after confirmed active exploitation.

CVE-2026-104286 (CVSS 9.8) is a path traversal and NULL byte neutralization issue that lets unauthenticated attackers write arbitrary files via crafted HTTP or HTTPS requests. Fortinet acknowledged in-the-wild use and listed specific IOCs including IPs and modified files such as liblog.so and ld.so.preload.

Who is affected

FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

Organizations running these email security appliances, especially those with management interfaces or IBE exposed, face immediate risk. Federal agencies received a short remediation window.

Why it matters

Unauthenticated arbitrary file writes on a mail gateway can lead to full system compromise, malware persistence, and pivoting into internal networks.

Email infrastructure sits at the center of many organizations, so successful exploitation can enable widespread data theft or further ransomware deployment with high operational impact.

How it could have been prevented

Upgrade to the fixed versions once available (8.0.2+, 7.6.7+, 7.4.9+, or move 7.2.x to 7.4 branch).

Until then, disable IBE with the CLI command 'config system encryption ibe / set status disable / end' and restrict management interface access to trusted networks only. Monitor for the listed IOCs.

Relevant professional terms

Path traversal
A flaw that lets an attacker use special characters in a file path to reach directories outside the intended folder.
CISA KEV catalog
The U.S. government list of vulnerabilities confirmed as actively exploited in the wild, which triggers mandatory patching timelines for federal agencies.

Two Zero-Days Used in Agentic AI Attack on Dutch Institute

High

What happened

The Dutch Institute for Vulnerability Disclosure (DIVD) was compromised after attackers exploited two zero-day flaws in its Zammad helpdesk platform.

CVE-2026-102489 (session hijack leading to RCE as the zammad user) and CVE-2026-102490 (privilege escalation to root), both CVSS 9.8 and added to CISA KEV, were chained. Logs showed an AI agent justifying its own actions, confirming an agentic AI-powered attack that achieved root in seconds and enabled data exfiltration.

Who is affected

Users of Zammad versions 6.3.0 to 6.5.4 (and certain 7.x where conditions allow) plus DIVD volunteers whose email addresses and possible contact details were exposed.

Any organization running unpatched Zammad helpdesk instances is at risk of similar rapid compromise.

Why it matters

Agentic AI compressed the attack chain so privilege escalation and lateral movement happened almost instantly, outpacing traditional detection.

Even a well-defended non-profit suffered data exposure that raises impersonation risks. The incident shows how AI agents can turn zero-days into fully autonomous breaches.

How it could have been prevented

Update Zammad to version 7 or later immediately, or take instances offline until patched.

Enforce strong network segmentation, continuous monitoring, and rapid containment playbooks so the first hour of response isolates affected systems and credentials before machine-speed movement spreads further.

Relevant professional terms

Zero-day
A security flaw that is unknown to the vendor and has no patch available when attackers begin using it.
Agentic AI attack
An automated campaign in which an AI agent plans, justifies, and executes multi-step intrusion actions with minimal human oversight.

Warlock Ransomware Hits Critical Infrastructure via SharePoint Flaws

High

What happened

A China-linked group is deploying Warlock ransomware against critical infrastructure by exploiting multiple Microsoft SharePoint vulnerabilities.

Symantec Threat Hunter Team observed attacks on a water utility, telecom provider, university, and regional government across Europe, Africa, and Latin America. Attackers disabled security tools, performed heavy reconnaissance with admin-like tooling, and continued using both older ToolShell flaws and newer SharePoint bugs highlighted by CISA.

Who is affected

Organizations in Portuguese- and Spanish-speaking countries running unpatched on-premises SharePoint, especially critical infrastructure operators.

SharePoint's deep integration with Microsoft authentication makes any foothold valuable for broader network access. Prior global campaigns already hit hundreds of entities including U.S. government agencies.

Why it matters

Successful ransomware on water, telecom, or government systems can disrupt essential services and create real-world safety risks beyond data encryption.

The campaign proves that even after high-profile 2025 SharePoint waves, many deployments remain unpatched and attractive to both criminal and state-aligned actors.

How it could have been prevented

Patch all SharePoint servers for the full set of recently disclosed vulnerabilities and apply Microsoft's latest security updates without delay.

Restrict external access, enable advanced logging and EDR that can detect security-tool disablement, segment SharePoint from critical OT/IT assets, and maintain offline backups tested for rapid recovery.

Relevant professional terms

Ransomware
Malware that encrypts an organization's files and demands payment for the decryption key.
ToolShell
A colloquial name for a cluster of SharePoint vulnerabilities that attackers chain for initial access and code execution.
Source: The Record

GitLab Patches Critical 9.9 AI Gateway RCE on Self-Hosted Servers

High

Fixed gateway versions

In useFirst fixed
18.1.6+ before 19.2.419.2.4
19.3 before 19.3.219.3.2
19.4 before 19.4.119.4.1

What happened

GitLab fixed a critical flaw in its AI Gateway that could allow command execution on self-hosted instances.

CVE-2026-90970 (CVSS 9.9) lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox of a custom flow and run arbitrary commands on the gateway. CISA assessed exploitation as none at disclosure. Fixes shipped in gateway versions 19.2.4, 19.3.2, and 19.4.1.

Who is affected

Only self-managed customers who host their own AI Gateway (Docker or Helm). GitLab.com, Dedicated, and GitLab-hosted gateway users are already protected.

Affected range covers gateway releases from 18.1.6 onward until the fixed versions in the 19.2, 19.3, and 19.4 lines.

Why it matters

The AI Gateway handles prompts and model traffic. Compromising it can expose sensitive code, credentials, or internal data and turn an AI feature into a server foothold.

As more teams adopt self-hosted AI tooling for data residency, this class of sandbox-escape bug becomes a high-value target for insider or compromised-account attacks.

How it could have been prevented

Self-hosted gateway operators must update immediately to 19.2.4, 19.3.2, or 19.4.1 using the matching Docker image tag or Helm chart setting.

Stop and replace running containers with the new image. No workaround is provided, so prioritize the upgrade and review Duo Agent Platform access controls.

Relevant professional terms

Remote code execution (RCE)
A vulnerability that lets an attacker run their own commands on a target system as if they were a legitimate user.
Prompt template sandbox
An isolation boundary intended to keep user-controlled AI workflow configurations from escaping into the underlying host environment.

Microsoft Warns AI Compresses Cyber Attack Lifecycles to Minutes

Medium

What to watch

  • Rise of fully autonomous AI attack campaigns
  • Phishing volume and personalization quality
  • Speed of post-compromise lateral movement
  • Adoption of AI-powered defensive tooling and phishing-resistant MFA
  • Targeting shifts toward government, IT, and research sectors

What happened

Microsoft's Digital Defense Report 2026 states that AI, especially agentic models, is shrinking the cyber-attack lifecycle from days to minutes.

Attackers use AI for faster vulnerability discovery, scaled personalized phishing, bespoke malware generation, and post-compromise tasks such as credential hunting and lateral movement. Phishing rose from 7% to 23% of incidents. Autonomous campaigns like JadePuffer illustrate the trend.

Who is affected

Defenders across all sectors, with government (27%), IT (17%), and research/academia (14%) seeing the highest targeting. The United States recorded the largest volume of attacks.

Any organization still relying on human-speed detection and response faces a widening gap against machine-paced adversaries.

Why it matters

When reconnaissance, exploitation, and exfiltration collapse into minutes, traditional SOC playbooks and ticket-based response become too slow.

Identity remains central, and the surge in AI-crafted phishing plus public-facing app exploitation raises the baseline risk for every connected enterprise.

Relevant professional terms

Attack lifecycle
The sequence of stages an adversary follows from initial access through lateral movement and final objectives such as data theft.
Agentic models
AI systems capable of autonomously planning and executing multi-step goals, including offensive cyber operations, with limited human direction.
Source: SC Magazine

Android 17 Hardens Against Spyware With New Protection Features

Low

How it works

  • Intrusion Logging: optional opt-in, E2E encrypted logs synced to Google (unreadable by Google), 12-month rolling retention, downloadable for expert analysis
  • USB Protection: blocks new data connections while locked; charging still works
  • Accessibility lockdown: only verified assistive tools keep full AccessibilityService access
  • WebGPU disabled in Chrome under Advanced Protection to cut browser attack surface

What happened

Google added six new capabilities to Advanced Protection in Android 17 aimed at making spyware harder to hide and easier to investigate.

Key additions include optional Intrusion Logging that records security and network events (including Chrome Incognito) in tamper-resistant, end-to-end encrypted form stored off-device for 12 months, USB Protection that blocks new data connections while locked, automatic restriction of AccessibilityService to verified assistive apps, and disabling of WebGPU in Chrome.

Who is affected

Android 17 users who enable Advanced Protection, with USB Protection available on Pixel 6 and later plus selected other devices. Existing Advanced Protection users receive a notification when the features roll out.

Journalists, activists, and high-risk individuals who previously lacked consumer-grade forensic logging benefit most.

Why it matters

Sophisticated spyware often erases local traces. Off-device encrypted logs that survivors can later decrypt and share with experts create accountability and improve attribution.

Tightening USB and accessibility abuse paths closes common real-world delivery and persistence techniques used against mobile targets.

Relevant professional terms

Spyware
Software that secretly monitors a device's activity, steals data, or maintains hidden remote access without the owner's consent.
Tamper-resistant forensic logging
A logging design that records security events in an encrypted, integrity-protected form that survives local deletion attempts by an attacker.

Crypto Scammers Hijack Microsoft's 13M-Follower X Account

Medium

What happened

Microsoft confirmed unauthorized access to its official X account, which has more than 13 million followers.

Attackers changed the profile picture to Clippy, followed a Clippy-themed crypto account, and amplified posts promoting a $Clippy token paired with $MSFT. An apology post appeared briefly then vanished. Microsoft secured the account, removed the unauthorized content, and continues investigating the access method.

Who is affected

Followers of the Microsoft X account who may have seen or interacted with the scam posts, plus any users drawn into the associated token.

Broader brand trust is affected whenever a major vendor's verified channel is abused for financial fraud.

Why it matters

A hijacked blue-check account instantly lends credibility to crypto pump-and-dump schemes and can move markets or drain wallets in minutes.

The incident underscores that social media takeover remains a high-ROI vector via phishing, SIM swap, session cookie theft, or compromised third-party posting tools.

How it could have been prevented

Enforce phishing-resistant MFA and hardware keys on all social accounts, minimize standing third-party app permissions, monitor for unexpected follows or profile changes, and maintain rapid takedown and communication playbooks.

Treat session cookies and recovery phone numbers as high-value secrets; rotate them after any suspected employee device compromise.

Relevant professional terms

Account takeover
When an attacker gains control of a legitimate user or brand account and uses it to post or act as the real owner.
Session cookie theft
Stealing browser cookies that represent an already-authenticated login so the attacker can access the account without needing the password or MFA prompt.
Source: SecurityWeek