Security news.
Threat actors are actively leveraging zero-day flaws and critical vulnerabilities to compromise enterprise systems, highlighted by ongoing exploitation of Fortinet appliances and persistent SharePoint ransomware intrusions. Meanwhile, federal agencies and technology vendors have pushed critical updates to address CVSS 10.0 flaws in enterprise container platforms and AI gateways. Law enforcement operations also saw major breakthroughs this week with high-profile arrests dismantling notorious extortion and ransomware rings.
Fortinet FortiMail Zero-Day Under Active Attack
CISA added a critical path traversal vulnerability (CVE-2026-104286, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after attackers began exploiting the flaw to perform unauthenticated arbitrary file writes on FortiMail appliances.
Dell Container Storage Modules Plagued by CVSS 10.0 Flaws
Dell urged administrators to urgently patch critical flaws, including CVE-2026-63688, in its Container Storage Modules that permit unauthenticated root access to Kubernetes nodes and complete system takeover.
Warlock Threat Group Weaponizes SharePoint to Deploy Ransomware
The China-linked threat actor Warlock is exploiting both old and new Microsoft SharePoint vulnerabilities across government, education, and critical infrastructure sectors to disable security tools and deploy file-encrypting malware.
GitLab Issues Fix for Critical AI Gateway RCE Flaw
GitLab released security updates for a 9.9-severity vulnerability that allows users with Duo Agent Platform access to execute arbitrary commands on self-hosted AI Gateway instances.
CISA Adds Two Actively Exploited Zammad Flaws to KEV
Federal agencies have been ordered to patch CVE-2026-102489 (session fixation) and CVE-2026-102490 (improper privilege management) in Zammad helpdesk software following confirmed in-the-wild exploitation.
Key ShinyHunters Hacker Detained in Jordan
A suspected operative of the prolific ShinyHunters cybercrime syndicate known as "Rey" was arrested in Jordan and is actively cooperating with the FBI to identify fellow extortion group members.
Technical University of Denmark Breach Affects 200,000
Attackers penetrated the university's identity and access management system, exfiltrating large amounts of sensitive data belonging to up to 200,000 individuals.