Daily Digest

Citrix, Cisco, Fortinet Zero-Days Exploited; Pentagon Breach Update

October 2, 2026
8 articles (3 new, 5 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Citrix NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772): Exploitation began in early September, predating public disclosure. Multiple threat actors are leveraging these vulnerabilities for mass exploitation, deploying webshells and novel tunneler malware. The impact is significant, affecting dozens of organizations across various sectors, with an estimated 20,000 NetScaler instances exposed online. Organizations are urged to patch and conduct post-compromise investigations.
  • Cisco Catalyst SD-WAN Manager Auth Bypass (CVE-2026-76504): Cisco has released patched software versions 26.2.1 and 26.1.2.1 to address this critical vulnerability. Cisco's own cloud-hosted deployments have also been patched, reinforcing the urgent need for organizations to apply these updates.
  • Fortinet FortiMail Zero-Day (CVE-2026-104286): This critical vulnerability, rated CVSS 9.8 and under active exploitation, allows unauthenticated attackers to achieve remote code execution by writing arbitrary files. CISA has added it to its KEV catalog, mandating urgent action. While patches are pending, workarounds include disabling the IBE feature or restricting web access to the management interface.

Data Breaches and Threat Actor Activity:

  • Pentagon DMDC Data Breach: The U.S. Department of Defense confirmed a breach exposing personal records of over 3 million individuals, including military and civilian personnel and their families. Attackers maintained undetected access for nine months, exploiting a file-sharing system vulnerability. The compromised data includes highly sensitive information, increasing the risk of identity theft and targeting by foreign intelligence services. Notifications began on September 18, 2026.
  • Europol Dismantles KillSec Ransomware: Five central servers were seized, providing insight into the operation. An 18-year-old developer and a 16-year-old administrator were identified as key figures. KillSec, active since 2024, targeted professional services, technology, healthcare, and government sectors, primarily gaining access through software vulnerabilities and insecure cloud storage. Monitoring for large data transfers, credential abuse, and disabled security tools is advised.
  • China-Aligned Group TA419 Targets U.S. AI Policy Experts: This group is conducting sophisticated phishing campaigns impersonating officials and AI company employees. The objective is to steal cloud account credentials, including MFA codes and session cookies, to gather intelligence on U.S. AI strategy.

Emerging Trends and Reports:

  • Google Report: AI Accelerates Vulnerability Discovery & Exploitation: AI-assisted vulnerability discovery yields more severe flaws, with 50% leading to Remote Code Execution (RCE). A critical example, CVE-2026-1731 in BeyondTrust, was exploited within four days of disclosure. The report also identifies AI systems themselves as a new attack surface, with over 1,500 AI-related CVEs disclosed in 2026 impacting orchestration frameworks.
  • Ransomware Data Exfiltration Surges 275%: Zscaler ThreatLabz reports a significant shift in ransomware tactics, with data exfiltration increasing dramatically to nearly 900 terabytes. This indicates a move towards data theft for extortion. Attackers are increasingly targeting privileged employees and using generative AI to accelerate operations, with the freight & logistics and utilities sectors seeing the largest growth in attacks.

Filter by Category

New Articles (3)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.