THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • FortiMail fixes remain pending despite reported exploitation; CISA set October 4, 2026, as the remediation deadline for US federal civilian agencies.
  • Proofpoint describes phishing against US AI policy experts designed to steal cloud-session cookies after credentials and MFA checks pass.
  • In Microsoft's investigated intrusions, public-facing application exploitation rose from 15% to 24%, while phishing rose from 7% to 23%; these figures describe its response caseload, not all attacks.
01

Fortinet warns of exploited FortiMail zero-day affecting multiple releases

Fortinet says attackers are exploiting CVE-2026-104286, an unauthenticated path-traversal and NULL-byte flaw that can allow arbitrary file writes through crafted HTTP or HTTPS requests. The vulnerability affects specified FortiMail 7.2, 7.4, 7.6 and 8.0 releases; fixes are pending. Until then, Fortinet recommends disabling identity-based encryption or restricting access to the management interface, and says it has shared indicators to help customers check for compromise.

Why it matters FortiMail administrators face an immediate mitigation decision rather than a routine patch rollout: fixed releases are unavailable, and users on 7.2 are directed to move to a newer branch.

What to watch next Watch for the promised fixed releases. Separately, the reported October 4 federal remediation deadline falls before any patch availability date established by this source.

HelpNet Security ↗
02

Rapid7 details BPFDoor and AVERAT activity targeting network-edge systems

Rapid7 reports Linux malware activity targeting telecom environments, including a newly observed BPFDoor variant, BPF Rekoobe samples seen against South Korean targets, and six AVERAT builds deployed against Taiwanese appliances. The researchers describe malware disguising itself with names and processes suited to target systems, and say SMTP traffic is used to help conceal activity. The report also details a BPFDoor controller that can tunnel triggers through HTTPS POST requests.

What changed Earlier BPFDoor triggers used recognizable raw packet markers. The reported HTTPS-wrapped approach exploits edge-proxy handling and may reduce the effectiveness of signatures aimed at those older network anomalies.

Why it matters For telecom and network-edge defenders, checking only executable files could miss running implants: the reported deployment chain deletes staged binaries while leaving their processes active.

Rapid7 ↗
03

CISA adds two actively exploited Zammad flaws to KEV catalog

CISA added Zammad session-fixation vulnerability CVE-2026-102489 and improper-privilege-management vulnerability CVE-2026-102490 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The agency says federal civilian agencies must prioritize remediation under BOD 26-04 and encourages other organizations to use risk-based vulnerability management.

Why it matters Federal civilian agencies using Zammad need to assess exposure and post-exploitation control when prioritizing remediation. The cited directive also establishes expectations for checking whether compromise preceded patching.

US Certs Alerts ↗
04

TA419 impersonates policy figures in phishing campaigns against US AI experts

Proofpoint says China-aligned group TA419 ran credential-phishing campaigns in July 2026 impersonating a former White House technology official and an economist to target US AI policy experts. After an initial invitation to join a fictitious committee or contribute to a report, the attackers sent shortened links to fake OneDrive pages using a browser-in-the-browser login tool designed to capture credentials and session cookies. Proofpoint assessed the activity as likely supporting Chinese intelligence objectives related to US AI policy and regulation.

Why it matters For targeted AI policy experts, completing MFA would not necessarily prevent account access: the kit is designed to relay authentication and capture the resulting session. The source does not establish that any account was successfully compromised.

HelpNet Security ↗
05

Microsoft report warns attackers are using AI to accelerate cyber operations

Microsoft’s 2026 Digital Defense Report says AI is helping attackers find vulnerabilities, develop malware, personalize phishing and conduct intrusions faster, while remediation lags. The report says phishing accounted for 23% of investigated intrusions from July 2025 to June 2026, and exploitation of public-facing applications rose to 24%. Microsoft also describes AI-assisted activity by state-linked groups, but says target selection and complex operational decisions remain manually driven in most observed campaigns.

What changed Within Microsoft's incident-response caseload, phishing increased from 7% to 23% and public-facing application exploitation from 15% to 24% in the July 2025–June 2026 period compared with a year earlier. These are changes in investigated entry routes, not measurements of AI's causal contribution.

Why it matters Defenders responsible for exposed applications face a compressed response window: Microsoft reports median weaponization below 24 hours while remediation trails discovery. That supports urgency, but does not establish that AI caused every faster exploit.

HelpNet Security ↗
Cybersecurity — October 3, 2026 | Briefing24