Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Source summary · The RegisterNo login required, exploitation underway, and some admins are still waiting for patches
3 reporting groups · Read the storyGathering the saved reports for your topic and time period.
See what happened while you were away.
Sep 27, 2026 – Oct 4, 2026 · Rolling 7 days · UTC
From our saved archive, collecting since Oct 4, 2026. This covers reports we captured, not every event. The selected period starts before collection began; earlier coverage is limited to reports captured later. How catch-ups work
No login required, exploitation underway, and some admins are still waiting for patches
3 reporting groups · Read the story
The AdGuard Family Plan lifetime subscription, which normally costs $169.99, is available for $11 until October 4. The plan protects up to nine devices from advertisements and tracking elements. [1][2]
2 reporting groups · Read the story
Amid the rapid rise in AI agents requesting “Full Disk Access” to your Mac, Apple says it is making changes to macOS to protect user privacy. While the company hasn’t shared specifics, Apple says users should understand what it means to give an app such “extraordinary” access to their Mac.
2 reporting groups · Read the story
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
2 reporting groups · Read the story
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.
2 reporting groups · Read the story
NVIDIA is taking on agentic AI security with the new Open Agent Safety Platform and OpenShell 0.1.0 frameworks
2 reporting groups · Read the storyChained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds
As reported by 404 Media, Magnet Forensics says it has found a way to bypass the iPhone security feature that automatically reboots devices if they haven’t been unlocked for 72 hours. Here are the details.
No login required, exploitation underway, and some admins are still waiting for patches
It’s a good month to reassess old accounts and retake control of your data and privacy.
The AdGuard Family Plan lifetime subscription, which normally costs $169.99, is available for $11 until October 4. The plan protects up to nine devices from advertisements and tracking elements. [1][2]
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
As enterprises push AI out of pilots and into production, FlexPod, the converged infrastructure franchise built by NetApp Inc. and Cisco Systems Inc., is being recast as a pretested answer to AI’s complexity. Customers want a trusted platform, not a pile of parts to integrate themselves. That pitch lands as NetApp works to tie its…
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.
The company's GrayKey Preserve device and a new Evidence Preservation Mode for existing GrayKey systems are designed to prevent an iPhone from losing its After First Unlock, or AFU, status, according to an instructional video 404 Media obtained. That puts the tools in direct conflict with an Apple security feature...
As open-weight models close in on the performance of proprietary frontier systems, enterprises are gaining a credible way to run generative AI on hardware they own. That shift puts the data already sitting in corporate storage at the center of the private AI conversation. Many organizations are now moving AI out of pilot projects and…
Operation KillSwitch takes over leak site holding at least 110 TB of stolen data
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account.
Envoy Gateway has released v1.9.1, a maintenance release that focuses heavily on security, upgrade reliability, and operational correctness following the broader v1.9 release. By Craig Risi
OpenAI unveiled several flashy new features during its annual developer’s conference Tuesday, from the always-on “Dot” work agent to a new, cloud-based security system that keeps constant watch for cyber threats. But one of the biggest — and to many ChatGPT users, the most infuriating — headlines from DevDay wasn’t announced on stage.
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
U.S. cities consider deploying Flock drones that automatically respond to emergency calls. However, other jurisdictions are pushing back against the service due to privacy and other concerns.
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap.
How quickly things change in the artificial intelligence era. Just a few months after everyone was scrambling to infuse AI into every enterprise operation — and frankly they still are, as agents have captured the enterprise imagination — everyone now is saying, “Whoa, where’s the brake pedal?” That’s why controlling agents is the next infrastructure…
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws.
Prosecutors claim Greg Lui helped China procure advanced hardware to develop, ahem, 'super intelligence’
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States.
Here’s some exciting news for those using a UniFi Network Video Recorder (UNVR) from Ubiquiti: The company today announced the release candidate of UniFi Protect 7.3 with major improvements that, among other things, ease the pain of storage costs. The official 7.3 version is set to come out as soon...