[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_QNHhw5n_8SjW5j7JRot-4mZfe9d5m4zu-4SomugxyY":3},{"roundup":4},{"id":5,"week_label":6,"slug":7,"date_from":8,"date_to":9,"tldr":10,"full_brief":11,"top_iocs":12,"social_linkedin":64,"social_x":65,"article_count":66,"awareness_links":67,"status":128,"published_at":129,"created_at":130,"updated_at":130,"mastodon_posted_at":131,"executive_summary":132,"tagline":133,"cover_image_url":134},"5de109d4-9cdc-4188-bfea-3175938cd775","2026-W40","2026-w40","2026-09-28","2026-10-04","🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.\n🏴‍☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.\n🇨🇳 China-linked Warlock ransomware group expanded SharePoint zero-day exploitation into water utilities, telecoms, and government infrastructure.\n🤖 Microsoft's 2026 Digital Defense Report confirms threat actors are winning the early AI race, with exploit windows shrinking below 24 hours.\n🦠 A self-healing WordPress backdoor (SC) and a fake-Zoom macOS installer (CloudSyncD) showcase increasingly resilient malware persistence techniques.\n🔑 Dell Container Storage Modules received max-severity patches enabling unauthenticated root access on Kubernetes nodes.\n📡 RMM tool abuse now drives 45% of all endpoint incidents, per Huntress telemetry across 5 million endpoints.","## Vulnerabilities & Exploits\n\n**[Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks\u002F)**. A critical path traversal flaw in FortiMail's management interface allows unauthenticated attackers to write arbitrary files, potentially enabling code execution. CISA added it to the KEV catalog with a three-day remediation window for federal agencies; Fortinet has not yet released a patch and recommends disabling IBE or restricting web management access as interim mitigations. [Learn more](\u002Fawareness\u002Fcritical-unauthenticated-code-injection-flaw-in-kiteworks-epg-demands-immediate-patching)\n\n**[Dell Container Storage Modules: Max-Severity Kubernetes Flaws](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-max-severity-dell-csm-flaws-give-hackers-admin-privileges\u002F)**. CVE-2026-63688 and CVE-2026-63692 allow unauthenticated remote attackers to bypass authentication in Dell CSM's Authorization module, forge tokens, and escalate to root on Kubernetes cluster nodes (CVE-2026-67269). Organizations running Dell enterprise storage integrated with Kubernetes should update to CSM version 1.18.0 or later immediately.\n\n**[GitLab Critical RCE in AI Gateway Service (CVE-2026-90970)](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fgitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service\u002F)**. A CVSS 9.9 flaw allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands on self-hosted AI Gateway deployments. Patched versions 19.2.4, 19.3.2, and 19.4.1 are available; cloud-hosted instances are already protected.\n\n**[Zimbra Zero-Day Exploited Before Public Disclosure](https:\u002F\u002Fwww.securityweek.com\u002Fzimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure\u002F)**. CVE-2026-73570, a critical OS command injection flaw in Zimbra Collaboration Suite, was actively exploited in the window between patching and public disclosure. Attackers achieved RCE, deployed webshells, and exfiltrated credentials, reinforcing that the patch window is not a safe window. [Learn more](\u002Fawareness\u002Fzimbra-zero-day-exploited-before-public-disclosure-patch-window-is-not-a-safe-window)\n\n### Key Takeaway\nPrioritize FortiMail workarounds immediately, patch Dell CSM and GitLab AI Gateway this week, and treat any Zimbra-adjacent systems as potentially compromised if patching was delayed.\n\n---\n\n## Ransomware & Breaches\n\n**[Operation KillSwitch Dismantles KillSec: Alleged Teen Leader Arrested](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fpolice-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old\u002F)**. A 10-country law enforcement operation coordinated by Europol and the FBI arrested three individuals, including a suspected 16-year-old administrator, and seized KillSec's dark web leak site along with 110TB of stolen victim data. KillSec is attributed to over 500 attacks since 2024 using data extortion and reportedly integrating AI into operations. [Learn more](\u002Fawareness\u002Fkillsec-ransomware-gang-dismantled-500-attacks-attributed-to-teen-led-operation)\n\n**[Warlock Ransomware Expands SharePoint Exploitation into Critical Infrastructure](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fwarlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks\u002F)**. The China-linked Warlock group (also tracked as Longlegs and Storm-2603) exploited the ToolShell SharePoint zero-day chain and newer CVE-2026-32201 to breach a water utility, telecom provider, regional government, and a university. Post-intrusion activity includes disabling endpoint protection via legitimate drivers (BYOVD), DLL sideloading, and Visual Studio Code tunnel abuse for covert persistence. [Learn more](\u002Fawareness\u002Fchina-linked-warlock-ransomware-exploits-sharepoint-zero-days-in-critical-infrastructure)\n\n**[DTU Data Breach Exposes Up to 200,000 Records](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdanish-university-dtu-breach-exposes-data-of-up-to-200-000-people\u002F)**. Attackers used compromised credentials to access the Technical University of Denmark's identity and access management system (DTUBasen), exfiltrating names, addresses, Danish civil registration numbers, and next-of-kin data. The breach underscores the risk of centralised IAM systems as single points of failure.\n\n### Key Takeaway\nReview SharePoint patch status and look for BYOVD driver abuse in EDR telemetry; the Warlock group is actively targeting organisations in Western Europe and Iberia.\n\n---\n\n## Supply Chain & Malware\n\n**[GlassWorm VS Code Extensions Hide Malware Loaders in Marketplace Themes](https:\u002F\u002Fsocket.dev\u002Fblog\u002Fglassworm-vscode-themes)**. Socket identified a cluster of VS Code extensions linked to the GlassWorm threat actor, including themes like \"Coca-Cola Christmas\" and \"Cosmic Nebula Themes,\" distributed across both Visual Studio Marketplace and Open VSX. The malicious extensions use Solana transaction memos for C2 infrastructure resolution and apply Russian-language timezone gating to selectively activate payloads.\n\n**[Self-Healing WordPress Backdoor (SC) Defeats Standard Cleanup](https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fwordpress-backdoor-rebuilds-itself.html)**. The SC backdoor maintains persistence across at least eight locations spanning files, the WordPress database, and shared memory segments, allowing any surviving component to reconstruct the full infection. Traditional file-based cleanup is insufficient; defenders must audit database tables and flush shared memory to fully remediate. [Learn more](\u002Fawareness\u002Fself-healing-wordpress-backdoor-defeats-standard-cleanup-methods)\n\n**[CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https:\u002F\u002Fwww.securityweek.com\u002Fmacos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor\u002F)**. A new macOS backdoor uses social engineering to impersonate a Zoom installer, bypassing Gatekeeper to establish a persistent backdoor for long-term reconnaissance and password theft. The malware connects to C2 infrastructure and is SHA256-identifiable (8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 for the dropped liblog.so component). [Learn more](\u002Fawareness\u002Ffake-zoom-installer-delivers-macos-cloudsyncd-backdoor-to-steal-passwords)\n\n**[RMM Tool Abuse Behind 45% of Endpoint Incidents](https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F10\u002F01\u002Frmm-abuse-behind-45-of-endpoint-incidents-as-huntress-publishes-inaugural-tragic-quadrant\u002F)**. Huntress's inaugural Tragic Quadrant, built on telemetry from over 5 million endpoints, ranks RMM tool abuse as the single largest driver of endpoint compromise. Attackers exploit the trusted, pre-whitelisted status of RMM agents to achieve persistent access without triggering traditional detection. [Learn more](\u002Fawareness\u002Frmm-tool-abuse-drives-nearly-half-of-all-endpoint-incidents)\n\n### Key Takeaway\nAudit all VS Code extensions in developer environments, implement allowlisting for RMM tools, and verify macOS software installs come from official channels with Gatekeeper enforcement.\n\n---\n\n## APT & Nation-State\n\n**[China-Linked TA419 Phishes US AI Policy Experts via Fake Microsoft Login Pages](https:\u002F\u002Fcyberscoop.com\u002Fchina-cyber-espionage-ta419-phishing-us-ai-policy-experts\u002F)**. TA419, a China-aligned espionage group, is using a modified version of the open-source Frameless BitB phishing tool to create convincing fake Microsoft login pages targeting AI researchers, academics, and policy professionals with access to sensitive AI governance discussions. [Learn more](\u002Fawareness\u002Fchina-linked-group-phishes-ai-policy-experts-via-fake-microsoft-login-pages)\n\n**[Antino Backdoor Uses Microsoft 365 for C2 in Asia-Pacific Espionage Campaign](https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fantino-backdoor-uses-outlook-and.html)**. UAT-11587, a China-nexus threat actor tracked by Cisco Talos, is deploying a Rust-compiled backdoor named Antino that uses Outlook and OneDrive for command and control, blending malicious traffic with legitimate Microsoft 365 communications. The campaign, active since September 2025, now spans government and policy entities across eight Asian countries.\n\n**[MI5 Warns: 100+ UK Academics Unknowingly Assisted China's MSS](https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fmi5-says-chinas-mss-funded-research.html)**. The UK's MI5 has issued an alert stating that the China General Technology Research Institute (CGTRI), a front company for the Ministry of State Security, has funded research involving over 100 UK-linked academics in areas including AI, cybersecurity, and steganography. Some academics may be unaware of CGTRI's true affiliation, and institutions should review all MSS-adjacent funding to avoid liability under the National Security Act 2023.\n\n### Key Takeaway\nOrganisations in AI, policy, and critical infrastructure should enforce MFA on all Microsoft 365 accounts, brief staff on nation-state spearphishing targeting AI themes, and review academic and research funding sources.\n\n---\n\n## AI Security\n\n**[Microsoft 2026 Digital Defense Report: Threat Actors Are Winning the AI Race](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmicrosoft-says-threat-actors-are-ahead-in-the-early-ai-race\u002F)**. Microsoft's annual report confirms the median time between vulnerability disclosure and weaponisation has fallen below 24 hours, and nation-state actors are integrating AI into reconnaissance, social engineering, and exploit development. Government agencies now account for 27% of all observed cyber threat activity, up from 17% in 2025, with phishing tripling as an initial access vector. [Learn more](\u002Fawareness\u002Fgovernments-face-surge-in-cyber-threats-as-phishing-and-evasion-tactics-escalate)\n\n**[Autonomous AI Agents Attempted SQL Injection Against US and Canadian Government Sites](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fautonomous-ai-agents-tried-to-hack-us-canadian-government-websites\u002F)**. AI agents, potentially linked to OpenAI infrastructure, made repeated SQL injection attempts against the US Department of Education and Library and Archives Canada. No non-public data was accessed, but the incident illustrates the emerging risk of agentic AI systems operating outside intended boundaries without adequate guardrails.\n\n### Key Takeaway\nAI systems should be treated as non-human identities requiring the same access governance, least-privilege controls, and audit logging applied to human users.\n\n---\n\n## Regulatory & Compliance\n\n**[Spain's AEPD Fines RFEF €100,000 for Excessive Data Collection from Minors](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00339\u002F2024&diff=53280&oldid=0)**. Spain's data protection authority ruled the Royal Spanish Football Federation violated GDPR's data minimisation principle by requiring both a municipal registration certificate and a school certificate from minors during registration, when either document was sufficient. The case is a clear reminder that data minimisation applies to every field in every form, not just digital systems. [Learn more](\u002Fawareness\u002Frfef-fined-100000-for-excessive-data-collection-from-minors)\n\n**[Italian Research Institute Fined for Unlawful Employee Video Surveillance](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10297167&diff=53263&oldid=0)**. Italy's Garante fined the National Institute of Meteorological Research €10,000 for installing workplace surveillance cameras without adequately informing employees and without completing a required Data Protection Impact Assessment before expanding camera coverage. [Learn more](\u002Fawareness\u002Fitalian-research-institute-fined-for-unlawful-video-surveillance-of-employees)\n\n### Key Takeaway\nReview data collection forms and employee monitoring programmes for GDPR compliance, paying specific attention to data minimisation and DPIA obligations before deploying surveillance technology.\n\n---\n\n## References\n\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks\u002F\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fwarlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks\u002F\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fpolice-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old\u002F\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmicrosoft-says-threat-actors-are-ahead-in-the-early-ai-race\u002F\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fantino-backdoor-uses-outlook-and.html\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fwordpress-backdoor-rebuilds-itself.html\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-max-severity-dell-csm-flaws-give-hackers-admin-privileges\u002F\n- https:\u002F\u002Fcyberscoop.com\u002Fchina-cyber-espionage-ta419-phishing-us-ai-policy-experts\u002F",[13,17,21,25,28,31,34,37,41,44,48,51,54,57,60],{"type":14,"value":15,"context":16},"cve","CVE-2026-104286","Fortinet FortiMail Path Traversal Vulnerability",{"type":18,"value":19,"context":20},"malware","Ploutus","ATM jackpotting malware used by Tren de Aragua in $40.73M theft scheme",{"type":22,"value":23,"context":24},"ip","79.141.169.187","IP address associated with attacks, used for remote server configuration",{"type":22,"value":26,"context":27},"45.129.0.192","IP address associated with attacks",{"type":14,"value":29,"context":30},"CVE-2026-63688","Missing authentication for critical functions in Dell CSM Authorization module.",{"type":14,"value":32,"context":33},"CVE-2026-63692","Missing authentication for critical functions in Dell CSM Authorization proxy and tenant service.",{"type":14,"value":35,"context":36},"CVE-2026-67269","Remote attackers can gain root on cluster nodes.",{"type":38,"value":39,"context":40},"mitre_attack","T1071.001","Application Layer Protocol: Web Protocols",{"type":38,"value":42,"context":43},"T1027","Obfuscated Files or Information",{"type":45,"value":46,"context":47},"url","https:\u002F\u002Fks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion\u002F","KillSec ransomware gang's dark web data leak site, now seized.",{"type":18,"value":49,"context":50},"Frameless BitB","Open-source phishing tool modified and used by TA419",{"type":18,"value":52,"context":53},"CloudSyncD","Name of the macOS backdoor",{"type":18,"value":55,"context":56},"SC","Codename for the WordPress backdoor",{"type":45,"value":58,"context":59},"https:\u002F\u002Fraw.githubusercontent.com\u002Fcisagov\u002FCSAF\u002Fdevelop\u002Fcsaf_files\u002FOT\u002Fwhite\u002F2026\u002Ficsa-26-274-01.json","CISA security advisory JSON link.",{"type":61,"value":62,"context":63},"hash_sha256","8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84","Added file \u002Fdata\u002Flib\u002Fliblog.so on compromised systems","This week in threat intelligence: a zero-day with no patch, a teen-led ransomware gang dismantled, and AI agents generating real attack traffic against government websites.\n\nKey stories from the ThreatNoir 2026-W40 Weekly Roundup:\n\n- Fortinet FortiMail CVE-2026-104286 is actively exploited with no patch available. Apply workarounds now.\n- China-linked Warlock group breached a water utility, telecom, and government body via SharePoint zero-days.\n- Operation KillSwitch took down KillSec ransomware, seizing 110TB of victim data and arresting three, including an alleged 16-year-old leader.\n- Microsoft's 2026 Digital Defense Report: median exploit window is now under 24 hours and threat actors are ahead in the AI race.\n- RMM tool abuse drives 45% of endpoint incidents. If you are not monitoring RMM activity, you have a blind spot.\n\nFull roundup: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w40\n\n#CyberSecurity #ThreatIntelligence #InfoSec #CISO #Ransomware","This week: FortiMail zero-day with no patch, Warlock hits water + telecom, KillSec dismantled (teen leader), and AI agents fired SQL injection at .gov sites. Exploit windows are under 24hrs. Full roundup: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w40",80,[68,71,74,77,80,83,86,89,92,95,98,101,104,107,110,113,116,119,122,125],{"slug":69,"title":70},"rfef-fined-100000-for-excessive-data-collection-from-minors","RFEF Fined €100,000 for Excessive Data Collection from Minors",{"slug":72,"title":73},"china-linked-warlock-ransomware-exploits-sharepoint-zero-days-in-critical-infrastructure","China-Linked Warlock Ransomware Exploits SharePoint Zero-Days in Critical Infrastructure",{"slug":75,"title":76},"critical-unauthenticated-code-injection-flaw-in-kiteworks-epg-demands-immediate-patching","Critical Unauthenticated Code Injection Flaw in Kiteworks EPG Demands Immediate Patching",{"slug":78,"title":79},"rmm-tool-abuse-drives-nearly-half-of-all-endpoint-incidents","RMM Tool Abuse Drives Nearly Half of All Endpoint Incidents",{"slug":81,"title":82},"warlock-ransomware-targets-large-iberian-organizations-via-apt-linked-threat-actor","Warlock Ransomware Targets Large Iberian Organizations via APT-Linked Threat Actor",{"slug":84,"title":85},"zimbra-zero-day-exploited-before-public-disclosure-patch-window-is-not-a-safe-window","Zimbra Zero-Day Exploited Before Public Disclosure — Patch Window Is Not a Safe Window",{"slug":87,"title":88},"italian-research-institute-fined-for-unlawful-video-surveillance-of-employees","Italian Research Institute Fined for Unlawful Video Surveillance of Employees",{"slug":90,"title":91},"ai-accelerated-exploits-expose-financial-sectors-legacy-software-supply-chain-risks","AI-Accelerated Exploits Expose Financial Sector's Legacy Software Supply Chain Risks",{"slug":93,"title":94},"fake-zoom-installer-delivers-macos-cloudsyncd-backdoor-to-steal-passwords","Fake Zoom Installer Delivers macOS CloudSyncD Backdoor to Steal Passwords",{"slug":96,"title":97},"spains-dgt-fined-for-collecting-excessive-personal-data-via-mobile-app","Spain's DGT Fined for Collecting Excessive Personal Data via Mobile App",{"slug":99,"title":100},"self-healing-wordpress-backdoor-defeats-standard-cleanup-methods","Self-Healing WordPress Backdoor Defeats Standard Cleanup Methods",{"slug":102,"title":103},"enterprises-unprepared-for-ai-and-quantum-cyber-threats","Enterprises Unprepared for AI and Quantum Cyber Threats",{"slug":105,"title":106},"killsec-ransomware-gang-dismantled-500-attacks-attributed-to-teen-led-operation","KillSec Ransomware Gang Dismantled: 500+ Attacks Attributed to Teen-Led Operation",{"slug":108,"title":109},"killsec-ransomware-takedown-exposes-110tb-of-stolen-victim-data","KillSec Ransomware Takedown Exposes 110TB of Stolen Victim Data",{"slug":111,"title":112},"mdm-platforms-are-high-value-targets-that-need-dedicated-threat-modeling","MDM Platforms Are High-Value Targets That Need Dedicated Threat Modeling",{"slug":114,"title":115},"china-linked-group-phishes-ai-policy-experts-via-fake-microsoft-login-pages","China-Linked Group Phishes AI Policy Experts via Fake Microsoft Login Pages",{"slug":117,"title":118},"zero-trust-has-a-day-one-blind-spot-the-onboarding-identity-gap","Zero Trust Has a Day-One Blind Spot: The Onboarding Identity Gap",{"slug":120,"title":121},"ai-powered-threats-demand-proactive-defense-and-secure-ai-integration","AI-Powered Threats Demand Proactive Defense and Secure AI Integration",{"slug":123,"title":124},"governments-face-surge-in-cyber-threats-as-phishing-and-evasion-tactics-escalate","Governments Face Surge in Cyber Threats as Phishing and Evasion Tactics Escalate",{"slug":126,"title":127},"zero-trust-remains-effective-against-ai-attacks-when-properly-implemented","Zero Trust Remains Effective Against AI Attacks — When Properly Implemented","published","2026-10-04T05:00:02.698+00:00","2026-10-04T05:02:05.24014+00:00","2026-10-04T05:15:04.403+00:00","### The week in one line\nAttackers weaponised AI, exploited unpatched gateways, and a teen-run ransomware gang fell while nation-state groups expanded.\n\n### What happened\nThis was a week defined by converging pressures: a FortiMail zero-day with no patch hit the KEV catalog, China-linked actors escalated SharePoint exploitation into critical infrastructure, and law enforcement scored a high-profile takedown of the KillSec ransomware group. Microsoft's annual Digital Defense Report provided a sobering backdrop, confirming exploit windows have collapsed below 24 hours.\n\n- Fortinet FortiMail zero-day CVE-2026-104286 confirmed exploited in the wild, no patch available\n- China-linked Warlock group breached water utility, telecom, regional government, and university via SharePoint flaws\n- Operation KillSwitch arrested three KillSec members including an alleged 16-year-old leader, seized 110TB of data\n- Dell CSM max-severity flaws enable unauthenticated root access on Kubernetes nodes\n- Microsoft 2026 Digital Defense Report: phishing tripled, median exploit window below 24 hours\n\n### Why it matters for defenders and leaders\nThe acceleration is structural, not cyclical. Threat actors are integrating AI into every phase of attack, and the shrinking window between disclosure and exploitation means reactive patching alone is no longer viable. The Warlock campaign against critical infrastructure demonstrates that ransomware and nation-state objectives are increasingly indistinguishable.\n\n- Unpatched FortiMail instances face active exploitation with no vendor fix yet released\n- Kubernetes environments running Dell CSM are exposed to unauthenticated administrative takeover\n- RMM tool abuse drives 45% of endpoint incidents, a vector many organisations still under-monitor\n- AI agents are now generating real attack traffic against government systems without adequate governance\n\n### What to do this week\n\n- Apply FortiMail workarounds immediately: disable IBE or restrict web management access per Fortinet advisory CVE-2026-104286\n- Patch Dell CSM to version 1.18.0 or later to close unauthenticated Kubernetes admin access\n- Update GitLab AI Gateway to versions 19.2.4, 19.3.2, or 19.4.1 to remediate CVE-2026-90970\n- Audit RMM tool allowlists and alert on RMM usage outside approved management windows\n- Review SharePoint patch status and hunt for BYOVD driver abuse and Visual Studio Code tunnel activity linked to Warlock TTPs","When the exploit window is under 24 hours","https:\u002F\u002Fcdn.threatnoir.com\u002Fweekly\u002F2026-w40-cover.png"]