Daily Briefing
Today's outlook
Fortinet FortiMail zero-day under active attack as CISA flags fresh exploited flaws
Good morning. The Register reported that Fortinet sounded the alarm over an actively exploited FortiMail zero-day, stating that no login is required, exploitation is underway, and some admins are still waiting for patches. Treat internet-facing FortiMail as a priority: confirm your version against Fortinet's advisory, apply the fix as soon as it is available for your build, and review mail-gateway logs and admin accounts for signs of access.
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation, both in Zammad: a session fixation flaw and an improper privilege management flaw. CISA states that Binding Operational Directive 26-04 requires federal agencies to prioritise rapid remediation of catalog entries; organisations running Zammad should patch to the vendor's fixed release.
On the exploited edge, CISA's KEV catalog lists CVE-2026-88771 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8) and CVE-2026-88772 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 8.1) in Citrix NetScaler ADC and Gateway, affecting 13.1 up to the fix in 13.1-64.23 — upgrade to 13.1-64.23 per Citrix's bulletin. CISA's KEV catalog also lists CVE-2026-86950 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8) in Apple macOS up to the fix in 15.8.1; apply 15.8.1 per Apple's advisory. For federal agencies and anyone following CISA's guidance, apply mitigations in accordance with vendor instructions and BOD 26-04.
Google's Chrome advisory lists three flaws fixed in 154.0.8037.92 — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309, each with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and base score 9.6; update Chrome to 154.0.8037.92. These are not on CISA's KEV catalog.
Two critical server-side fixes landed. BleepingComputer and The Hacker News reported that GitLab warned customers to immediately patch a critical AI Gateway flaw; The Hacker News said a logged-in user with Duo Agent Platform access could run commands on the gateway under certain conditions. The Hacker News also reported that Dell released updates for multiple critical flaws in Dell Container Storage Modules that could allow unauthenticated admin access and root on Kubernetes nodes.
On threat activity, BleepingComputer reported that the China-linked Warlock ransomware group breached a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities for initial access. The Hacker News reported that a China-nexus actor deployed the Antino backdoor, which uses Outlook and OneDrive for command-and-control, against government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.
In other incidents, BleepingComputer reported that Frontline Education is notifying school districts of a breach after attackers exploited a vulnerability in third-party software and stole employee data including Social Security numbers, and that the U.S. Treasury sanctioned eight Tren de Aragua members over ATM jackpotting attacks. The Record reported that ransomware forced Vicksburg, Mississippi to shut down systems, with Mayor Willis Thompson saying the FBI is investigating, and that a California judge dismissed the Pegasus spyware case brought by El Faro journalists for lack of jurisdiction.
Zoom out: Help Net Security reports that Microsoft's 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap.
Vulnerability in focus
CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- The Record: Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus Read it
- BleepingComputer: Frontline Education breach exposes school district employee data Read it
- The Hacker News: GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers Read it
- SecurityWeek: In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats Read it
Sources
- Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus The Record
- Frontline Education breach exposes school district employee data BleepingComputer
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News
- In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats SecurityWeek
- AI is giving attackers a head start, Microsoft warns Help Net Security
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA
- How American Political Campaigns Are Using AI—and What They’re Spending on the Tools Schneier on Security
- Fortinet sounds the alarm over actively exploited FortiMail zero-day The Register
- Warlock ransomware breach SharePoint in water, telecom operator attacks BleepingComputer
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign The Hacker News
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes The Hacker News
- GitLab warns of critical RCE vulnerability in AI Gateway service BleepingComputer
- US sanctions Tren de Aragua gang members in ATM hacks crackdown BleepingComputer
- Mississippi mayor says ransomware incident led city to shut down systems The Record
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.