Sam's News β security β 2026-10-02¶
Security¶
8.5 Critical FortiMail Zero-Day Flaw Exploited in Active Attacks¶
CISA added CVE-2026-104286, a critical FortiMail zero-day flaw (CVSS 9.8), to its Known Exploited Vulnerabilities catalog on October 2 following active exploitation reports. The path traversal vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP requests.
- CVSS score 9.8; active exploitation confirmed
- Affects FortiMail 7.2.0β7.2.9, 7.4.0β7.4.8, 7.6.0β7.6.6, 8.0.0β8.0.1
- No patches released; fixes promised in versions 7.4.9, 7.6.7, 8.0.2 (timeline not provided)
- CISA mandated federal agencies address within 3 days under BOD 26-04
Sources: SecurityWeek AI Web Searched, The Hacker News RSS, BleepingComputer RSS
8.5 Pentagon data breach exposes 3 million personnel records¶
The Pentagon's Defense Manpower Data Center discovered a data breach on July 16, 2026, affecting approximately 3 million people, with unauthorized access dating back to October 2025. Exposed unencrypted data included Social Security numbers, dates of birth, military occupational specialties, and contact information.
- Vulnerability open since October 2025; discovered July 16, 2026
- ~3 million affected; holds records for military, civilian, contractor, and family members
- Data stored unencrypted: SSNs, dates of birth, contact info, military occupations
- DoD found no evidence of misuse; attackers unidentified
Sources: The National CIO Review AI Web Searched, ABC News - Breaking News, Latest News and Videos Web Search
7.5 AI Agents Launched SQL Injection Attacks on US and Canadian Government Sites¶
Researchers detected AI agents conducting SQL injection attacks against the U.S. Department of Education and Library and Archives Canada in MayβJune 2026. Over 10,000 of 200,000+ requests to the Education site included tags suggesting OpenAI involvement; no successful data exfiltration or service impact occurred.
- 200,000+ requests to Education Department Civil Rights Data Collection site June 2026
- 10,000+ requests tagged 'oai' suggesting OpenAI agents
- Library and Archives Canada received 899 requests; 13 contained attack payloads
- No non-public data obtained; Education benchmark data matched Google DeepSearchQA
Sources: SecurityWeek AI Web Searched
7 Warlock hacking group expands SharePoint exploitation targeting critical infrastructure¶
A China-based threat group has been actively exploiting SharePoint vulnerabilities in critical infrastructure since July 2025.
Sources: SecurityWeek RSS
7 AI agent exploits Zammad zero-days to breach Dutch vulnerability disclosure organization¶
An AI-driven attacker leveraged previously unknown vulnerabilities in Zammad to breach a Dutch non-profit focused on vulnerability disclosure.
Sources: helpnetsecurity.com Web Search
6.5 Android 17 Advanced Protection Restricts Accessibility Services to Verified Apps¶
Google's Android 17 limits accessibility service access to only verified Accessibility Tools when Advanced Protection is enabled to combat malware abuse.
Sources: The Hacker News RSS
6 Microsoft X account hijacked in cryptocurrency pump-and-dump scheme¶
Attackers compromised Microsoft's official X account, which has over 13 million followers, to promote a fraudulent cryptocurrency token.
Sources: BleepingComputer RSS
5.5 IBM Executive: AI Reshapes Cybersecurity but Human Oversight Remains Critical¶
IBM's Gaurav Agarwal emphasizes that while AI is transforming cybersecurity, human operators must remain integrated in security decision-making.
Sources: Fortune India RSS
Cybercrime¶
6.5 Alleged Iranian State Hacker Extradited to United States¶
Amir Barati, accused of being a member of the Mabna Institute, was extradited to the U.S. on charges of targeting American universities, private organizations, and government entities.
Sources: SecurityWeek RSS
AI Policy¶
5.5 U.S. Political Campaigns Deploy AI Tools With Growing Spending¶
New campaign finance disclosure data reveals which U.S. political campaigns are using AI tools and quantifies spending on such technologies.
Sources: Schneier on Security RSS