> InfoSec News Nuggets – 10/06/2026
[AUTHOR: Mary]
[DATE: 06/10/2026 10:46]
[LANGUAGE: EN]
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
Microsoft has shipped out-of-band security updates for CVE-2026-96940, a high-severity (CVSS 8.8) weak authorization flaw in Exchange Server that lets an authenticated attacker escalate privileges and access other users’ mailboxes within the same organization, reading their messages and attachments. The bug does not allow cross-tenant access, and Microsoft has already deployed a service-side fix for Exchange Online, so cloud customers need not act. On-premises admins running Exchange Server Subscription Edition RTM, 2016 CU23, or 2019 CU14 and CU15 should patch promptly; while there is no evidence of in-the-wild exploitation, Microsoft rates the flaw “Exploitation More Likely.”
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
NetScaler administrators spent the weekend scrambling after fully patched appliances began rebooting, and Citrix confirmed a new exploited zero-day, CVE-2026-88779, a memory overflow affecting NetScaler ADC and Gateway instances configured as a SAML SP or IdP. The flaw surfaced just days after two other exploited zero-days, CVE-2026-88771 and CVE-2026-88772, were patched. Admins reported authentication requests carrying shell commands in the username field designed to fetch a script that plants web shells and exfiltrates configuration backups. watchTowr reproduced the bug and believes it is a DoS-only flaw likely used to crash appliances to speed exploitation of CVE-2026-88771. CISA added it to the KEV catalog on October 4 with an October 7 deadline, making it the sixth exploited NetScaler flaw added this year.
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing “a significant rise in automated submissions, the vast majority of which are not valid.” Engineers and open-source maintainers had reportedly been overwhelmed by AI-generated reports that were invalid or contained hallucinated findings. The company says it will provide an update on the program in the first quarter of 2027 and is encouraging researchers to participate in its other bug bounty programs in the meantime, a stark sign of how low-quality AI output is straining vulnerability disclosure pipelines.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning that CVE-2026-104286, a critical (CVSS 9.8) path traversal and NULL-byte handling flaw in the FortiMail management interface, is being actively exploited to let unauthenticated attackers write arbitrary files via crafted HTTP or HTTPS requests. The bug affects FortiMail 7.2 through 8.0.1, and fixed releases for the 7.4, 7.6 and 8.0 branches are still pending, so admins are urged to disable IBE support or restrict management interface access in the meantime. Fortinet published IOCs including added shared libraries, a modified ld.so.preload, attacker IP addresses, and log entries showing a rogue archive account configured to ship data to a remote server. CISA added the flaw to its KEV catalog and ordered federal agencies to perform forensic triage and mitigate by October 4.
Pentagon breach exposes Social Security numbers and military records of millions
The Defense Department is notifying millions of people that attackers accessed personnel records held by the Defense Manpower Data Center after exploiting a vulnerability in an unspecified file-sharing system, with access lasting from October 2025 until July 2026. The breach affects 2.76 million living individuals, including current and former personnel and their dependents, plus 294,000 deceased individuals, and exposed unencrypted data such as Social Security numbers, names, dates of birth, service details and, in some cases, occupational specialty. The Pentagon says it has no indication of misuse but is offering 12 months of credit monitoring, and those affected are advised to freeze their credit, obtain an IRS Identity Protection PIN, and watch for targeted phishing referencing their unit or role.
The post InfoSec News Nuggets – 10/06/2026 appeared first on AboutDFIR - The Definitive Compendium Project.