Security news.
Critical edge devices and enterprise infrastructure are under intense pressure today, led by active zero-day exploitation of Fortinet FortiMail and new warnings surrounding Dell container modules and GitLab AI services. Meanwhile, state-aligned and ransomware operators continue targeting critical utilities via widespread software flaws, prompting urgent patch advisories and CISA catalog additions. Development and operations teams must prioritize perimeter appliances and update internal self-hosted components immediately.
Fortinet FortiMail Zero-Day Under Active Attack
CISA added CVE-2026-104286 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog following reports of attackers exploiting the path traversal flaw to execute arbitrary file writes and unauthorized code without authentication.
Dell Patches Maximum-Severity Flaws in Container Storage Modules
Dell resolved critical vulnerabilities, including CVE-2026-63688 (CVSS 10.0), that allow unauthenticated attackers to bypass authentication and gain root administrative control over Kubernetes cluster nodes.
GitLab AI Gateway Flaw Enables Remote Command Execution
A critical 9.9-severity security hole in self-hosted GitLab AI Gateway deployments allows authenticated users with Duo Agent Platform access to execute arbitrary system commands on the underlying host.
Warlock Ransomware Breaches SharePoint in Critical Infrastructure Attacks
A China-linked threat group is leveraging known Microsoft SharePoint vulnerabilities to compromise telecom providers, water utilities, and regional government systems.
Antino Backdoor Employs Outlook and OneDrive for Espionage C2
A newly uncovered cyber espionage campaign attributed to China-nexus group UAT-11587 is targeting government agencies across Asia using novel Antino malware operated through legitimate Microsoft cloud services.
Frontline Education Breach Exposes School District Employee PII
Threat actors compromised employee records—including Social Security numbers—across multiple school systems after exploiting a vulnerability in a third-party software component.
Police Arrest 16-Year-Old Suspected Head of KillSec Ransomware
Spanish authorities arrested a teenager believed to be the mastermind behind KillSec while seizing leak sites and infrastructure connected to attacks on roughly 500 global victim organizations.