CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-03 12:15 UTC · REPORT BRIEF-20261003-121547
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
17
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Fortra Patches Critical Vulnerabilities in BoKS
The bugs could lead to authentication bypass, shell command execution, and memory corruption.
The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 03 Oct 2026 11:34:00 +0000
https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/
02
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authentica
SRC: Security Affairs
Sat, 03 Oct 2026 10:43:39 +0000
https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html
03
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The fi
SRC: Security Affairs
Fri, 02 Oct 2026 22:46:18 +0000
https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html
04
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
SRC: DarkReading
Fri, 02 Oct 2026 16:56:30 GMT
https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response
05
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring:
Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility,
SRC: The Hacker News
Sat, 03 Oct 2026 16:30:00 +0530
https://thehackernews.com/2026/10/the-state-of-cybersecurity-in-2026key.html
06
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. […]
SRC: BleepingComputer
Fri, 02 Oct 2026 14:33:01 -0400
https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
07
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government
SRC: Security Affairs
Sat, 03 Oct 2026 09:26:04 +0000
https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html
08
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
SRC: DarkReading
Fri, 02 Oct 2026 20:18:37 GMT
https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail
09
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
SRC: DarkReading
Fri, 02 Oct 2026 13:00:00 GMT
https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security
10
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deploy
SRC: The Hacker News
Fri, 02 Oct 2026 23:03:16 +0530
https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
11
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. […]
SRC: BleepingComputer
Fri, 02 Oct 2026 15:01:40 -0400
https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/
12
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.
"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a s
SRC: The Hacker News
Fri, 02 Oct 2026 17:53:15 +0530
https://thehackernews.com/2026/10/openai-parts-ways-with-three-safety.html
13
Is It Fair to Blame 'Rogue' AI for Security Failures?
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
SRC: DarkReading
Fri, 02 Oct 2026 15:51:33 GMT
https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
14
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.
The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 03 Oct 2026 11:45:00 +0000
https://www.securityweek.com/doxx-net-raises-38-million-to-prevent-ai-agent-on-the-internet-misadventures/
15
Is Your Organization Ready for 2027's AI Accountability Era?
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.
SRC: DarkReading
Fri, 02 Oct 2026 16:01:22 GMT
https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-
16
Vulnerability Backlogs Are an Ownership Problem
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
SRC: DarkReading
Fri, 02 Oct 2026 14:00:00 GMT
https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem
17
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’ files, messages, mail, and browsing history riskier.
SRC: TechCrunch Security
Fri, 02 Oct 2026 18:11:27 +0000
https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
