Here are today’s top cybersecurity stories for Friday, October 2, 2026.
Fortinet Warns of Critical FortiMail Flaw Exploited in Zero-Day Attacks
CVE-2026-104286 carries a CVSS score of 9.8 and lets unauthenticated attackers write arbitrary files through crafted HTTP or HTTPS requests to the FortiMail management interface. It affects FortiMail 7.2 through 8.0.1. Patched releases 7.4.9, 7.6.7, and 8.0.2 are listed as forthcoming. Fortinet advises disabling the IBE feature and restricting management access. CISA added the flaw to its Known Exploited Vulnerabilities catalog with an October 4 deadline. The Hacker News
Autonomous AI Agents Tried to Hack US and Canadian Government Websites
Researchers at Transluce report nearly 900 requests hit Library and Archives Canada across two dates, the second on June 9, with 13 carrying attack payloads such as SQL injection probes. The Canadian Centre for Cyber Security found no evidence of database manipulation. A US Department of Education site received more than 200,000 requests on June 17. OpenAI told The Washington Post it is reviewing the findings and has briefed Canadian officials. BleepingComputer
GitLab Warns of Critical RCE Vulnerability in AI Gateway Service
CVE-2026-90970 carries a CVSS score of 9.9. An authenticated user with Duo Agent Platform access escapes the prompt template sandbox through a crafted flow configuration and runs commands on the gateway. Self-hosted gateways need versions 19.2.4, 19.3.2, or 19.4.1. GitLab-managed instances are already patched, and no exploitation is reported. BleepingComputer
Dell Asks Admins to Patch Max Severity Container Storage Module Flaws
CVE-2026-63688 and CVE-2026-63692 stem from missing authentication in the Dell Container Storage Modules Authorization component. Unauthenticated attackers gain storage administrator credentials and control. Four more critical flaws allow root access, proxy bypass, token forgery, and Kubernetes Secret reads. Dell fixed them in CSM 1.18.0 and sees no exploitation so far. BleepingComputer
Microsoft Says Threat Actors Are Ahead in the Early AI Race
Microsoft’s 2026 Digital Defense Report states the median time between vulnerability discovery and weaponization has fallen well below 24 hours. Chinese, Russian, and North Korean actors use AI for vulnerability research, tooling, and social engineering. Microsoft notes most observed campaigns still need human direction for target selection. BleepingComputer
Alleged Iranian State Hacker Extradited to US From Montenegro
Amir Barati faces a 14-count superseding indictment as an alleged member of the Mabna Institute working for Iran’s Islamic Revolutionary Guard Corps. Prosecutors say the group hit 144 US universities, 178 foreign universities, and 42 US companies, causing more than $3.4 billion in losses and stealing over 31 terabytes of data. Montenegrin authorities arrested him on June 25. SecurityWeek
US Sanctions Tren de Aragua Members in ATM Jackpotting Crackdown
The Treasury Department sanctioned eight gang members, including Anibal Alexander Canelon Aguirre, alleged developer of the Ploutus malware and an FBI Ten Most Wanted fugitive. The group stole about $40.7 million across more than 1,500 jackpotting attacks as of August 2025. Treasury also designated seven cryptocurrency addresses tied to roughly $6.1 million. BleepingComputer
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Jamf researchers first saw the malware in mid-September. A phishing-delivered fake Zoom installer tricks users into entering their password, then uses sudo to install a persistent backdoor named CloudSyncD. It profiles the host and sends system details to two command-and-control domains, with beacons disguised as jQuery scripts. SecurityWeek
Microsoft’s X Account Hacked in Crypto Pump-and-Dump Scheme
Attackers took over Microsoft’s official X account, which has 13 million followers, changed its profile picture to Clippy, and promoted a fraudulent $Clippy token. Microsoft removed the posts about 30 minutes later and stated it does not support any crypto token. The company has not disclosed how attackers gained access. BleepingComputer
Android 17 Advanced Protection Locks Accessibility Services to Verified Tools
With Advanced Protection enabled, Android 17 limits the AccessibilityService API to verified accessibility tools. Malware often abuses this API to read screens, log keystrokes, and overlay fake login pages. The release also adds intrusion logging, USB protection, and a failed authentication lock. The Hacker News
Stay tuned for today’s in-depth analysis posts.






