# Today's Top Stories

October 04, 2026

  1. 1
    0
    SecurityWeek general Oct 02
    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    CVE-2026-104286, a critical-severity path traversal zero-day in Fortinet FortiMail, is being actively exploited in the wild, allowing attackers to write arbitrary files to affected systems. Security teams running FortiMail should treat this as a priority patch given Fortinet's history as a high-value target for nation-state actors. Urgent action is required as exploitation is confirmed prior to widespread patching.

  2. 2
    0
    The Hacker News general Oct 03
    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    The China-linked threat actor 'Warlock' is actively exploiting Microsoft SharePoint vulnerabilities — both old and new — to disable security tools and deploy ransomware against critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries. Symantec and Carbon Black Threat Hunter Team observed the campaign, which has been ongoing since at least July 2025. Organizations running on-premises SharePoint should audit exposure and apply all available patches immediately.

  3. 3
    0
    The Hacker News general Oct 02
    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    A previously undocumented backdoor dubbed 'Antino,' attributed to a China-nexus threat actor by Cisco Talos, is targeting government and policy organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. Antino uses Microsoft Outlook and OneDrive for command-and-control communications, a living-off-the-land technique designed to blend into legitimate cloud traffic and evade detection. The campaign represents a significant espionage threat against Asian government entities.

  4. 4
    0
    The Hacker News general Oct 02
    GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

    GitLab patched a critical 9.9 CVSS vulnerability in its AI Gateway component that could allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers. Fixed versions are 19.2.4, 19.3.2, and 19.4.1; only organizations self-hosting the AI Gateway are affected and must apply patches immediately. The flaw sits at the intersection of AI infrastructure and privilege escalation — a growing attack surface as enterprises deploy AI-integrated DevOps pipelines.

  5. 5
    0
    BleepingComputer general Oct 03
    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    A suspected member of the ShinyHunters hacking group, known online as 'Rey,' has been detained in Jordan and is reportedly cooperating with the FBI to identify other members of the group responsible for a string of high-profile data breaches and extortion campaigns. ShinyHunters is linked to major incidents including the Ticketmaster and Santander breaches. This arrest represents a significant law enforcement development against one of the most prolific cybercriminal groups of recent years.

  6. 6
    0
    The Hacker News general Oct 02
    Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    Android 17's Advanced Protection mode now restricts access to Android's accessibility services API exclusively to applications verified as Accessibility Tools, blocking a major malware attack vector widely abused by banking trojans and stalkerware. Google identified accessibility API abuse as a primary conduit for financial fraud on Android. This change has significant implications for both legitimate accessibility app developers seeking verification and threat actors who have relied on this API for years.

  7. 7
    0
    BleepingComputer general Oct 02
    Dell asks admins to patch max severity CSM flaws as soon as possible

    Dell has released patches for two maximum-severity vulnerabilities in its Container Storage Modules (CSM), which integrate Dell enterprise storage arrays with Kubernetes environments, and is urging administrators to patch immediately. The flaws could allow attackers to compromise storage infrastructure in enterprise Kubernetes deployments. Given CSM's role in enterprise storage orchestration, exploitation could result in data loss or full storage cluster compromise.

  8. 8
    0
    BleepingComputer general Oct 02
    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Unknown attackers hijacked Microsoft's official X account — which has over 13 million followers — and used it to promote a Clippy-themed cryptocurrency token in what appears to be a coordinated pump-and-dump scheme. The incident demonstrates the continued risk of high-profile social media account compromise for amplifying crypto fraud at scale. Microsoft has not publicly disclosed the attack vector used to gain access to the account.

  9. 9
    0
    BleepingComputer general Oct 02
    Frontline Education breach exposes school district employee data

    Frontline Education, a major software provider for K-12 school districts, is notifying districts of a data breach in which attackers exploited a vulnerability in third-party software to access employee data including Social Security numbers. The breach potentially affects employees across numerous U.S. school districts that rely on Frontline's platform for HR and administrative functions. The use of a third-party software vulnerability underscores supply chain risk in the education sector.

  10. 10
    0
    BleepingComputer general Oct 03
    Danish university DTU breach exposes data of up to 200,000 people

    Denmark's Technical University (DTU) disclosed a breach of its identity and access management system, with hackers downloading data belonging to up to 200,000 users. The attack targeted DTU's IAM infrastructure — a high-value target that could expose credentials and access controls across the institution. The breach is particularly significant given DTU's role in sensitive research and its international academic collaborations.