> InfoSec News Nuggets – 10/02/2026
[AUTHOR: Mary]
[DATE: 02/10/2026 14:19]
[LANGUAGE: EN]
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CISA has added a critical Fortinet FortiMail vulnerability, CVE-2026-104286 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog after Fortinet confirmed in-the-wild attacks. The path traversal and NULL byte handling flaw lets an unauthenticated attacker write arbitrary files to the underlying system using crafted HTTP or HTTPS requests, and it affects FortiMail 7.2 through 8.0. With fixes still pending for some branches, Fortinet is urging customers to disable the IBE feature and cut off internet access to the management interface, and it has published attacker IP addresses and file-based indicators of compromise. Federal civilian agencies have until October 4 to apply patches or workarounds.
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer-run non-profit that ethically reports security flaws, has revealed it was breached in what it describes as an agentic AI-powered attack. The intruders chained two zero-days in the Zammad helpdesk platform, CVE-2026-102489 and CVE-2026-102490, to hijack sessions, execute code remotely and escalate to root within seconds before moving to other services and exfiltrating data, including volunteer email addresses and possibly contact details. Logs showed the attacker’s scripts contained notes in which the agent justified its own actions, and DIVD credits network segmentation with limiting the damage while urging all Zammad users to upgrade to version 7 or take the platform offline.
In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an Iranian national accused of being a member of the Mabna Institute, has been extradited from Montenegro to the United States after his arrest there on an FBI warrant in June. A superseding indictment unsealed in August charges 17 Mabna members with hacking on behalf of Iran’s Islamic Revolutionary Guard Corps and private clients, targeting 144 U.S. universities, 178 foreign universities, dozens of companies and several government agencies, stealing more than 31 terabytes of academic data and intellectual property and causing losses estimated at over $3.4 billion. Extraditions of Iranian state-linked hackers are extremely rare because such actors usually stay inside Iran, and Barati reportedly moved to Turkey in 2021, became a citizen and changed his name.
Police disrupt KillSec ransomware, arrest suspected teenage leader
Spanish police have arrested a 16-year-old Romanian national in Alicante suspected of leading the KillSec ransomware-as-a-service group, part of a Hamburg-led international operation that also seized the gang’s leak site and five servers. Raids hit eight homes across Greece, Romania, the U.K. and Spain, with two additional arrests, and Europol, Bitdefender and Group-IB supported the investigation. Since emerging in 2024, KillSec is believed to have launched around 1,000 attacks, at least half successful, largely by exploiting vulnerabilities and insecure cloud storage, and it was known for offering one of the cheapest RaaS platforms available, lowering the bar for low-skilled criminals.
Autonomous AI agents tried to hack US, Canadian government websites
Research lab Transluce found that autonomous AI agents performing routine data-retrieval tasks resorted to rudimentary hacking attempts against government websites, including a SQL injection probe during more than 200,000 requests to a U.S. Department of Education site and 13 attack payloads sent to Library and Archives Canada while hunting for historical divorce records. Neither attempt appears to have reached non-public data, and Canadian officials said there is no sign of compromise. The investigation also documented agents hammering state and federal sites with huge request volumes, using disposable email addresses, trying to bypass anti-bot defenses and reusing exposed API keys. Transluce said the tactics are consistent with activity previously attributed to OpenAI but stopped short of confident attribution, and OpenAI said it is reviewing the findings.
The post InfoSec News Nuggets – 10/02/2026 appeared first on AboutDFIR - The Definitive Compendium Project.