ITsecurity Daily
Daily Briefing
Fortinet FortiMail zero-day under active attack tops a heavy patch day for Citrix, Apple and Chrome
Good morning. Fortinet is warning customers of a critical FortiMail vulnerability that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices, BleepingComputer reported. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 1 October, describing it as a "Fortinet FortiMail Path Traversal Vulnerability" and citing evidence of active exploitation. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of KEV-listed vulnerabilities on publicly exposed assets. If you run FortiMail, follow Fortinet's advisory and treat any internet-facing instance as the priority.
Three more actively exploited flaws carry fixes. CISA's KEV catalog lists CVE-2026-88771 in Citrix NetScaler ADC, scored 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), affecting version 13.1 and fixed in 13.1-64.23, and CVE-2026-88772, scored 8.1, in the same product and fix. Both are known to be exploited. CISA's KEV catalog also lists CVE-2026-86950 in Apple macOS, scored 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), affecting releases up to the fix in macOS 15.8.1 and known to be exploited. Citrix's security bulletin and Apple's advisory cover the fixed releases.
Google's Chrome stable channel update fixes three flaws each scored 9.6 — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) — in Chrome up to the fix in 154.0.8037.92, per Google's advisory. CISA does not list these three as exploited.
Zoom out: Microsoft says cyberattackers are currently benefiting from AI faster than defenders, speeding up vulnerability discovery, malware development and post-compromise activity, BleepingComputer reported.
Vulnerability in focus
CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- The Hacker News: Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Read it
- Help Net Security: Criminal recruiters want people on your payroll Read it
- Help Net Security: Android 17 makes it harder for spyware to cover its tracks Read it
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks Read it
- The Register: AI agents hacked the hackers, stealing email addresses from security research org Read it
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog Read it
- BleepingComputer: Autonomous AI agents tried to hack US, Canadian government websites Read it
- SecurityWeek: Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks Read it
- The Register: EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank Read it
- SecurityWeek: Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains Read it
- The Hacker News: ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Read it
- The Register: Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing Read it
Sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks BleepingComputer
- AI agents hacked the hackers, stealing email addresses from security research org The Register
- Iranian accused of hacking American universities extradited from Montenegro The Record
- Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks SecurityWeek
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers The Hacker News
- 16-year-old suspected leader of KillSec ransomware group arrested Help Net Security
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- Connected Cars Are a Surveillance Platform Schneier on Security
- Autonomous AI agents tried to hack US, Canadian government websites BleepingComputer
- Microsoft says threat actors are ahead in the early AI race BleepingComputer
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments The Record
- EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank The Register
- Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains SecurityWeek
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings