This day 02:05 06:05 10:06 14:06 18:08 22:08
⚠ exploit status: CVE-2026-104286 · KEV
Info  2026-10-02 10:06Z · last 4h · 15 findings · glm-5.2:cloud

Threat Brief — 2026-10-02 — KEV Catalog Grows Again

CISA has formally added the FortiMail zero-day (CVE-2026-104286KEV) to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and triggering federal remediation deadlines. Google announced a meaningful defensive hardening in Android 17 that restricts accessibility-service access to verified tools only. Separately, researchers surfaced that intimate deepfake extortion sites are operating on mainstream cloud infrastructure rather than hidden darknet hosting.

Top items

Themes

Mainstream platform abuse persists. Both the deepfake-hosting findings and the Microsoft X account compromise illustrate that attackers continue to operate on well-known infrastructure rather than retreating to hidden corners. The defensive challenge is not lack of visibility but lack of timely platform-level disruption.

Silent defaults create risk. The Windows 11 26H2 backup behaviour echoes a broader pattern of vendor updates that change security-relevant settings without explicit administrator consent, shifting the burden from opt-in to opt-out.

===

THREAT-TOPICS===

[{"slug":"fortimail-cve-2026-104286KEV-zero-day-exploitation","headline":"CISA adds FortiMail CVE-2026-104286KEV to KEV catalog","findingIds":[15118],"status":"developing","development":"CISA formally added the FortiMail unauthenticated file-write zero-day to its KEV catalog, confirming active exploitation and triggering federal remediation deadlines"},{"slug":"android-17-advanced-protection-accessibility-lock","headline":"Android 17 restricts accessibility services to verified tools under Advanced Protection","findingIds":[15128],"status":"new"},{"slug":"intimate-deepfake-sites-mainstream-infrastructure","headline":"Deepfake extortion sites operate on Cloudflare, Google, and Proton infrastructure","findingIds":[15122],"status":"new"},{"slug":"windows-11-26h2-2026-update","headline":"Windows 11 26H2 silently auto-enables backups on corporate PCs","findingIds":[15121],"status":"developing","development":"New detail: 26H2 changes backup defaults on work PCs to opt-out, creating potential unplanned data egress on managed devices"},{"slug":"china-ai-cybersecurity-national-infrastructure","headline":"China positions AI cybersecurity as national infrastructure for AI-on-AI conflict","findingIds":[15126],"status":"new"}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db