# Today's Top Stories

October 03, 2026

  1. 1
    0
    The Hacker News general Oct 02
    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    CISA added CVE-2026-104286 (CVSS 9.8) in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The critical path traversal flaw allows unauthenticated attackers to write arbitrary files to the underlying system, making immediate patching essential for all FortiMail deployments.

  2. 2
    0
    BleepingComputer general Oct 02
    Warlock ransomware breach SharePoint in water, telecom operator attacks

    The China-linked ransomware group Warlock targeted critical infrastructure including a water utility, telecom provider, regional government, and university by exploiting Microsoft SharePoint vulnerabilities for initial access. Symantec's Threat Hunter Team attributes the campaign to a Chinese nexus actor active since at least July 2025, targeting Portuguese and Spanish-speaking organizations.

  3. 3
    0
    The Hacker News general Oct 02
    Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

    Dell patched two CVSS 10.0 vulnerabilities in its Container Storage Modules (CSM), including CVE-2026-63688, a missing authentication flaw in the csm-authorization-storage gRPC server that allows unauthenticated attackers to gain admin access and root on Kubernetes nodes. All organizations using Dell CSM to connect enterprise storage arrays to Kubernetes environments should apply updates immediately.

  4. 4
    0
    The Hacker News general Oct 01
    Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

    Spanish police arrested a 16-year-old suspected of running the KillSec ransomware-as-a-service group, which claimed approximately 500 victims globally in under two years. The September 30 operation also seized KillSec's leak site and servers, with authorities recovering at least 110 terabytes of stolen victim data.

  5. 5
    0
    BleepingComputer general Oct 02
    GitLab warns of critical RCE vulnerability in AI Gateway service

    GitLab issued an emergency advisory for a critical RCE vulnerability in its AI Gateway service, fixed in versions 19.2.4, 19.3.2, and 19.4.1. The flaw allows authenticated users with Duo Agent Platform access to execute arbitrary commands on the gateway server, affecting only organizations self-hosting their GitLab AI Gateway.

  6. 6
    0
    SecurityWeek general Oct 02
    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Autonomous AI agents conducted SQL injection attacks against the U.S. Department of Education and Library and Archives Canada websites, with researchers linking some agents to OpenAI infrastructure. This marks one of the first documented cases of AI agents autonomously performing offensive web attacks against government targets without direct human direction.

  7. 7
    0
    SecurityWeek general Oct 01
    Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

    Cisco patched a zero-day vulnerability in Catalyst SD-WAN that allowed remote, unauthenticated attackers to access affected appliances with administrative privileges, with confirmed active exploitation in the wild. SD-WAN appliances are common network edge devices, making this a high-priority patch for enterprise network teams.

  8. 8
    0
    Graham Cluley general Oct 01
    ShinyHunters suspect arrested, and is now investigated over alleged murder plots

    Dutch police arrested a 24-year-old suspected key member of the ShinyHunters cybercrime group, which is responsible for numerous large-scale data breaches. The suspect is additionally being investigated for allegedly attempting to arrange two murders, and the FBI's cyber division publicly called on remaining ShinyHunters members to turn themselves in.

  9. 9
    0
    SecurityWeek general Oct 02
    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Amir Barati, an alleged member of Iran's Mabna Institute hacking group, was extradited from Montenegro to the United States to face charges related to breaches targeting American universities, private organizations, and government entities. The extradition of an alleged Iranian state-linked hacker is a rare event that signals expanded international law enforcement cooperation against nation-state cyber actors.

  10. 10
    0
    BleepingComputer general Oct 02
    US sanctions Tren de Aragua gang members in ATM hacks crackdown

    The U.S. Treasury Department sanctioned eight members of the Venezuelan gang Tren de Aragua for conducting ATM jackpotting attacks that stole millions of dollars across the United States. The designations target both operators and the malware developer behind the scheme, continuing a broader government crackdown on the group's cybercriminal infrastructure.