THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • FortiMail exploitation is active and fixes remain unreleased; CISA has set an October 4, 2026 deadline for US federal civilian agencies to address the flaw.
  • The KillSec investigation secured at least 110 terabytes of stolen data; investigators will examine the evidence and trace financial proceeds.
  • Android 17’s optional Intrusion Logging preserves encrypted forensic records off-device, but users cannot delete them before the rolling 12-month retention period expires.
01

Fortinet reports active exploitation of critical FortiMail zero-day

Fortinet says attackers are exploiting CVE-2026-104286, a path-traversal and null-byte flaw that could let an unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests. It affects specified FortiMail 7.2, 7.4, 7.6 and 8.0 releases; fixes are not yet available, and Fortinet advises disabling identity-based encryption or restricting access to the management interface as temporary mitigations. The company has not disclosed when or where attacks occurred, how many systems were compromised, or who was responsible.

Why it matters FortiMail administrators face an interim operational trade-off: disable identity-based encryption or limit management access while waiting for a patch.

What to watch next US federal civilian agencies must address the vulnerability by October 4, 2026. That is a remediation deadline, not a promised patch-release date.

HelpNet Security ↗
02

Authorities arrest suspected 16-year-old operator of KillSec ransomware group

Eurojust says a 16-year-old is suspected of being KillSec’s main operator and administrator; the group has been active since 2024 and is linked to almost 1,000 attacks worldwide. Authorities made three arrests, searched eight homes across Spain, Greece, the United Kingdom and Romania, and seized five servers, domains and at least 110 terabytes of stolen data. Investigators are examining evidence and tracing financial proceeds, according to Eurojust.

What changed Infrastructure used to hold victim data has become an evidence source: authorities seized five storage servers and secured at least 110 terabytes of stolen material.

Why it matters For victim organizations, the documented harm extends beyond a system intrusion: KillSec used copied data as ransom leverage and published files when victims did not pay.

What to watch next Investigators will examine seized devices and data and trace financial proceeds. Identifying additional victims or participants is a possible outcome, not a confirmed finding.

HelpNet Security ↗
03

Pentagon data breach affects more than three million people

The Defense Manpower Data Center is notifying people after hackers accessed personal data, Help Net Security reports. A Defense Department official told CNN that the breach affects 2.76 million living individuals, including current and former defense personnel and dependents, as well as 294,000 deceased individuals. The supplied report does not specify when the breach occurred or what data was accessed.

Why it matters The privacy exposure reaches beyond serving personnel: the reported population can include former personnel and dependents, while records concerning 294,000 deceased people were also affected.

HelpNet Security ↗
04

CISA warns of flaws that could expose Monta EV charging stations to control

CISA says vulnerabilities in Monta’s monta.app could let attackers gain unauthorized administrative control of vulnerable charging stations or disrupt charging services. The advisory lists missing authentication on WebSocket endpoints and other issues, and says all versions are affected. Monta is working to expand authenticated connections and deprecate unauthenticated access; it also recommends operators enable OCPP 1.6 Security Profile 2, according to the advisory.

Why it matters Charging operators face a service-availability risk, not merely an application-data issue: successful exploitation could interrupt charging or give attackers administrative control over vulnerable stations.

What to watch next Monta says it is progressively retiring unauthenticated access. Completion remains unresolved in the supplied advisory, which gives no deadline and encourages operators to enable OCPP 1.6 Security Profile 2.

US Certs Alerts ↗
05

Android 17 adds encrypted cloud logging and other Advanced Protection safeguards

Google has added six features to Advanced Protection in Android 17, including optional Intrusion Logging that records security, network and app activity in end-to-end encrypted logs stored on Google’s servers. Logs are retained for a rolling 12 months and can be downloaded and shared with trusted experts; Google says it cannot read them. Other changes include blocking new USB data connections while a supported phone is locked and restricting AccessibilityService access to verified accessibility tools.

What changed Failed Authentication Lock was already an Android theft-protection feature; it is now included within Advanced Protection on selected Android 17 devices.

Why it matters Users opting into forensic logging accept a privacy trade-off: decrypted records can reveal websites visited in Incognito mode, and disabling logging or closing an account does not erase retained logs early.

What to watch next Existing Advanced Protection users are to receive a notification when the new capabilities become available on their devices; the source supplies no universal availability date.

HelpNet Security ↗
Cybersecurity — October 2, 2026 | Briefing24