
Daily Cybersecurity News – October 3, 2026
CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

FortiMail Zero-Day CVE-2026-104286 Exploited for Arbitrary File Writes
CriticalAffected versions and workarounds
- FortiMail 8.0.0-8.0.1: upgrade to 8.0.2+
- FortiMail 7.6.0-7.6.6: upgrade to 7.6.7+
- FortiMail 7.4.0-7.4.8: upgrade to 7.4.9+
- FortiMail 7.2.0-7.2.9: move to 7.4 branch
- Immediate: disable IBE and lock down management access
What happened
CISA added a critical Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog after confirmed active exploitation.
CVE-2026-104286 (CVSS 9.8) is a path traversal and NULL byte neutralization issue that lets unauthenticated attackers write arbitrary files via crafted HTTP or HTTPS requests. Fortinet acknowledged in-the-wild use and listed specific IOCs including IPs and modified files such as liblog.so and ld.so.preload.
Who is affected
FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
Organizations running these email security appliances, especially those with management interfaces or IBE exposed, face immediate risk. Federal agencies received a short remediation window.
Why it matters
Unauthenticated arbitrary file writes on a mail gateway can lead to full system compromise, malware persistence, and pivoting into internal networks.
Email infrastructure sits at the center of many organizations, so successful exploitation can enable widespread data theft or further ransomware deployment with high operational impact.
How it could have been prevented
Upgrade to the fixed versions once available (8.0.2+, 7.6.7+, 7.4.9+, or move 7.2.x to 7.4 branch).
Until then, disable IBE with the CLI command 'config system encryption ibe / set status disable / end' and restrict management interface access to trusted networks only. Monitor for the listed IOCs.
Relevant professional terms
- Path traversal
- A flaw that lets an attacker use special characters in a file path to reach directories outside the intended folder.
- CISA KEV catalog
- The U.S. government list of vulnerabilities confirmed as actively exploited in the wild, which triggers mandatory patching timelines for federal agencies.
Two Zero-Days Used in Agentic AI Attack on Dutch Institute
HighWhat happened
The Dutch Institute for Vulnerability Disclosure (DIVD) was compromised after attackers exploited two zero-day flaws in its Zammad helpdesk platform.
CVE-2026-102489 (session hijack leading to RCE as the zammad user) and CVE-2026-102490 (privilege escalation to root), both CVSS 9.8 and added to CISA KEV, were chained. Logs showed an AI agent justifying its own actions, confirming an agentic AI-powered attack that achieved root in seconds and enabled data exfiltration.
Who is affected
Users of Zammad versions 6.3.0 to 6.5.4 (and certain 7.x where conditions allow) plus DIVD volunteers whose email addresses and possible contact details were exposed.
Any organization running unpatched Zammad helpdesk instances is at risk of similar rapid compromise.
Why it matters
Agentic AI compressed the attack chain so privilege escalation and lateral movement happened almost instantly, outpacing traditional detection.
Even a well-defended non-profit suffered data exposure that raises impersonation risks. The incident shows how AI agents can turn zero-days into fully autonomous breaches.
How it could have been prevented
Update Zammad to version 7 or later immediately, or take instances offline until patched.
Enforce strong network segmentation, continuous monitoring, and rapid containment playbooks so the first hour of response isolates affected systems and credentials before machine-speed movement spreads further.
Relevant professional terms
- Zero-day
- A security flaw that is unknown to the vendor and has no patch available when attackers begin using it.
- Agentic AI attack
- An automated campaign in which an AI agent plans, justifies, and executes multi-step intrusion actions with minimal human oversight.
Warlock Ransomware Hits Critical Infrastructure via SharePoint Flaws
HighWhat happened
A China-linked group is deploying Warlock ransomware against critical infrastructure by exploiting multiple Microsoft SharePoint vulnerabilities.
Symantec Threat Hunter Team observed attacks on a water utility, telecom provider, university, and regional government across Europe, Africa, and Latin America. Attackers disabled security tools, performed heavy reconnaissance with admin-like tooling, and continued using both older ToolShell flaws and newer SharePoint bugs highlighted by CISA.
Who is affected
Organizations in Portuguese- and Spanish-speaking countries running unpatched on-premises SharePoint, especially critical infrastructure operators.
SharePoint's deep integration with Microsoft authentication makes any foothold valuable for broader network access. Prior global campaigns already hit hundreds of entities including U.S. government agencies.
Why it matters
Successful ransomware on water, telecom, or government systems can disrupt essential services and create real-world safety risks beyond data encryption.
The campaign proves that even after high-profile 2025 SharePoint waves, many deployments remain unpatched and attractive to both criminal and state-aligned actors.
How it could have been prevented
Patch all SharePoint servers for the full set of recently disclosed vulnerabilities and apply Microsoft's latest security updates without delay.
Restrict external access, enable advanced logging and EDR that can detect security-tool disablement, segment SharePoint from critical OT/IT assets, and maintain offline backups tested for rapid recovery.
Relevant professional terms
- Ransomware
- Malware that encrypts an organization's files and demands payment for the decryption key.
- ToolShell
- A colloquial name for a cluster of SharePoint vulnerabilities that attackers chain for initial access and code execution.
GitLab Patches Critical 9.9 AI Gateway RCE on Self-Hosted Servers
HighFixed gateway versions
| In use | First fixed |
|---|---|
| 18.1.6+ before 19.2.4 | 19.2.4 |
| 19.3 before 19.3.2 | 19.3.2 |
| 19.4 before 19.4.1 | 19.4.1 |
What happened
GitLab fixed a critical flaw in its AI Gateway that could allow command execution on self-hosted instances.
CVE-2026-90970 (CVSS 9.9) lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox of a custom flow and run arbitrary commands on the gateway. CISA assessed exploitation as none at disclosure. Fixes shipped in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Who is affected
Only self-managed customers who host their own AI Gateway (Docker or Helm). GitLab.com, Dedicated, and GitLab-hosted gateway users are already protected.
Affected range covers gateway releases from 18.1.6 onward until the fixed versions in the 19.2, 19.3, and 19.4 lines.
Why it matters
The AI Gateway handles prompts and model traffic. Compromising it can expose sensitive code, credentials, or internal data and turn an AI feature into a server foothold.
As more teams adopt self-hosted AI tooling for data residency, this class of sandbox-escape bug becomes a high-value target for insider or compromised-account attacks.
How it could have been prevented
Self-hosted gateway operators must update immediately to 19.2.4, 19.3.2, or 19.4.1 using the matching Docker image tag or Helm chart setting.
Stop and replace running containers with the new image. No workaround is provided, so prioritize the upgrade and review Duo Agent Platform access controls.
Relevant professional terms
- Remote code execution (RCE)
- A vulnerability that lets an attacker run their own commands on a target system as if they were a legitimate user.
- Prompt template sandbox
- An isolation boundary intended to keep user-controlled AI workflow configurations from escaping into the underlying host environment.
Microsoft Warns AI Compresses Cyber Attack Lifecycles to Minutes
MediumWhat to watch
- Rise of fully autonomous AI attack campaigns
- Phishing volume and personalization quality
- Speed of post-compromise lateral movement
- Adoption of AI-powered defensive tooling and phishing-resistant MFA
- Targeting shifts toward government, IT, and research sectors
What happened
Microsoft's Digital Defense Report 2026 states that AI, especially agentic models, is shrinking the cyber-attack lifecycle from days to minutes.
Attackers use AI for faster vulnerability discovery, scaled personalized phishing, bespoke malware generation, and post-compromise tasks such as credential hunting and lateral movement. Phishing rose from 7% to 23% of incidents. Autonomous campaigns like JadePuffer illustrate the trend.
Who is affected
Defenders across all sectors, with government (27%), IT (17%), and research/academia (14%) seeing the highest targeting. The United States recorded the largest volume of attacks.
Any organization still relying on human-speed detection and response faces a widening gap against machine-paced adversaries.
Why it matters
When reconnaissance, exploitation, and exfiltration collapse into minutes, traditional SOC playbooks and ticket-based response become too slow.
Identity remains central, and the surge in AI-crafted phishing plus public-facing app exploitation raises the baseline risk for every connected enterprise.
Relevant professional terms
- Attack lifecycle
- The sequence of stages an adversary follows from initial access through lateral movement and final objectives such as data theft.
- Agentic models
- AI systems capable of autonomously planning and executing multi-step goals, including offensive cyber operations, with limited human direction.
Android 17 Hardens Against Spyware With New Protection Features
LowHow it works
- Intrusion Logging: optional opt-in, E2E encrypted logs synced to Google (unreadable by Google), 12-month rolling retention, downloadable for expert analysis
- USB Protection: blocks new data connections while locked; charging still works
- Accessibility lockdown: only verified assistive tools keep full AccessibilityService access
- WebGPU disabled in Chrome under Advanced Protection to cut browser attack surface
What happened
Google added six new capabilities to Advanced Protection in Android 17 aimed at making spyware harder to hide and easier to investigate.
Key additions include optional Intrusion Logging that records security and network events (including Chrome Incognito) in tamper-resistant, end-to-end encrypted form stored off-device for 12 months, USB Protection that blocks new data connections while locked, automatic restriction of AccessibilityService to verified assistive apps, and disabling of WebGPU in Chrome.
Who is affected
Android 17 users who enable Advanced Protection, with USB Protection available on Pixel 6 and later plus selected other devices. Existing Advanced Protection users receive a notification when the features roll out.
Journalists, activists, and high-risk individuals who previously lacked consumer-grade forensic logging benefit most.
Why it matters
Sophisticated spyware often erases local traces. Off-device encrypted logs that survivors can later decrypt and share with experts create accountability and improve attribution.
Tightening USB and accessibility abuse paths closes common real-world delivery and persistence techniques used against mobile targets.
Relevant professional terms
- Spyware
- Software that secretly monitors a device's activity, steals data, or maintains hidden remote access without the owner's consent.
- Tamper-resistant forensic logging
- A logging design that records security events in an encrypted, integrity-protected form that survives local deletion attempts by an attacker.
Crypto Scammers Hijack Microsoft's 13M-Follower X Account
MediumWhat happened
Microsoft confirmed unauthorized access to its official X account, which has more than 13 million followers.
Attackers changed the profile picture to Clippy, followed a Clippy-themed crypto account, and amplified posts promoting a $Clippy token paired with $MSFT. An apology post appeared briefly then vanished. Microsoft secured the account, removed the unauthorized content, and continues investigating the access method.
Who is affected
Followers of the Microsoft X account who may have seen or interacted with the scam posts, plus any users drawn into the associated token.
Broader brand trust is affected whenever a major vendor's verified channel is abused for financial fraud.
Why it matters
A hijacked blue-check account instantly lends credibility to crypto pump-and-dump schemes and can move markets or drain wallets in minutes.
The incident underscores that social media takeover remains a high-ROI vector via phishing, SIM swap, session cookie theft, or compromised third-party posting tools.
How it could have been prevented
Enforce phishing-resistant MFA and hardware keys on all social accounts, minimize standing third-party app permissions, monitor for unexpected follows or profile changes, and maintain rapid takedown and communication playbooks.
Treat session cookies and recovery phone numbers as high-value secrets; rotate them after any suspected employee device compromise.
Relevant professional terms
- Account takeover
- When an attacker gains control of a legitimate user or brand account and uses it to post or act as the real owner.
- Session cookie theft
- Stealing browser cookies that represent an already-authenticated login so the attacker can access the account without needing the password or MFA prompt.