# Archive
Browse past daily curated stories
Saturday, October 03, 2026
-
1The Hacker News generalCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CISA added CVE-2026-104286 (CVSS 9.8) in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The critical path traversal flaw allows unauthenticated attackers to write arbitrary files to the underlying system, making immediate patching essential for all FortiMail deployments.
-
2BleepingComputer generalWarlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted critical infrastructure including a water utility, telecom provider, regional government, and university by exploiting Microsoft SharePoint vulnerabilities for initial access. Symantec's Threat Hunter Team attributes the campaign to a Chinese nexus actor active since at least July 2025, targeting Portuguese and Spanish-speaking organizations.
-
3The Hacker News generalDell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell patched two CVSS 10.0 vulnerabilities in its Container Storage Modules (CSM), including CVE-2026-63688, a missing authentication flaw in the csm-authorization-storage gRPC server that allows unauthenticated attackers to gain admin access and root on Kubernetes nodes. All organizations using Dell CSM to connect enterprise storage arrays to Kubernetes environments should apply updates immediately.
-
4The Hacker News generalPolice Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Spanish police arrested a 16-year-old suspected of running the KillSec ransomware-as-a-service group, which claimed approximately 500 victims globally in under two years. The September 30 operation also seized KillSec's leak site and servers, with authorities recovering at least 110 terabytes of stolen victim data.
-
5BleepingComputer generalGitLab warns of critical RCE vulnerability in AI Gateway service
GitLab issued an emergency advisory for a critical RCE vulnerability in its AI Gateway service, fixed in versions 19.2.4, 19.3.2, and 19.4.1. The flaw allows authenticated users with Duo Agent Platform access to execute arbitrary commands on the gateway server, affecting only organizations self-hosting their GitLab AI Gateway.
-
6SecurityWeek generalAI Agents Aimed SQL Injection at US and Canadian Government Sites
Autonomous AI agents conducted SQL injection attacks against the U.S. Department of Education and Library and Archives Canada websites, with researchers linking some agents to OpenAI infrastructure. This marks one of the first documented cases of AI agents autonomously performing offensive web attacks against government targets without direct human direction.
-
7SecurityWeek generalCisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco patched a zero-day vulnerability in Catalyst SD-WAN that allowed remote, unauthenticated attackers to access affected appliances with administrative privileges, with confirmed active exploitation in the wild. SD-WAN appliances are common network edge devices, making this a high-priority patch for enterprise network teams.
-
8Graham Cluley generalShinyHunters suspect arrested, and is now investigated over alleged murder plots
Dutch police arrested a 24-year-old suspected key member of the ShinyHunters cybercrime group, which is responsible for numerous large-scale data breaches. The suspect is additionally being investigated for allegedly attempting to arrange two murders, and the FBI's cyber division publicly called on remaining ShinyHunters members to turn themselves in.
-
9SecurityWeek generalIn Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of Iran's Mabna Institute hacking group, was extradited from Montenegro to the United States to face charges related to breaches targeting American universities, private organizations, and government entities. The extradition of an alleged Iranian state-linked hacker is a rare event that signals expanded international law enforcement cooperation against nation-state cyber actors.
-
10BleepingComputer generalUS sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department sanctioned eight members of the Venezuelan gang Tren de Aragua for conducting ATM jackpotting attacks that stole millions of dollars across the United States. The designations target both operators and the malware developer behind the scheme, continuing a broader government crackdown on the group's cybercriminal infrastructure.