Article Read Time

1. Fortinet Warns of Critical FortiMail Zero-Day Under Active Attack
Fortinet disclosed CVE-2026-104286, a critical path traversal flaw in FortiMail that lets an unauthenticated attacker write arbitrary files to a vulnerable system. The company confirmed the bug is already being exploited in the wild, which puts it squarely in the “patch now” category for any organization running FortiMail as its mail security gateway. Edge appliances remain a favorite entry point for attackers, and this one is no exception.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
2. Warlock Ransomware Crew Expands SharePoint Attacks on Critical Infrastructure
The China-linked Warlock group is exploiting SharePoint vulnerabilities to disable security tools and deploy ransomware, with government and critical infrastructure targets in Portuguese and Spanish-speaking regions. Researchers say the group has been leaning on SharePoint flaws since mid-2025 and keeps broadening its reach. Defenders should confirm SharePoint servers are fully patched and that endpoint protection cannot be switched off by a compromised service account.
Source: SecurityWeek URL: https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/
3. Police Take Down KillSec Ransomware and Arrest Alleged 16-Year-Old Leader
Spanish and German authorities arrested a 16-year-old suspected of administering the KillSec ransomware group and seized its leak site and infrastructure. Reporting indicates investigators recovered more than 110 terabytes of stolen data in the operation. It is a notable win for law enforcement, and a reminder of how young some of today’s most disruptive cybercriminals are.
Source: The Hacker News URL: https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
4. Technical University of Denmark Breach Exposes Data of Up to 200,000 People
The Technical University of Denmark (DTU) confirmed a breach after attackers compromised its identity and access management systems and exfiltrated a substantial amount of user data. Up to 200,000 people may be affected. Because the attackers reached the systems that control who gets access to what, the incident is a pointed lesson in why identity infrastructure deserves the same protection as any crown jewel.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
5. GitLab Patches Critical 9.9 Flaw in Self-Hosted AI Gateway
GitLab released fixes for CVE-2026-90970, a critical vulnerability rated 9.9 in its AI Gateway that allows an authenticated user to execute commands on self-hosted instances. Organizations running the gateway on their own infrastructure need to update promptly. As AI components get bolted onto development platforms, they are quickly becoming part of the attack surface.
Source: The Hacker News URL: https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
