Security news.
Critical software flaws take center stage today, led by active exploitation targeting Fortinet FortiMail and active ransomware campaigns striking Microsoft SharePoint environments. Meanwhile, administrators face urgent patching requirements for critical flaws in Dell Container Storage Modules and self-hosted GitLab AI Gateways, alongside notable law enforcement crackdowns on the ShinyHunters extortion ring.
Exploited Fortinet FortiMail Zero-Day Demands Immediate Action
A critical path traversal flaw (CVE-2026-104286) in Fortinet FortiMail is being actively exploited in the wild to write arbitrary files and compromise systems, prompting emergency patching warnings and a rapid addition to CISA's KEV catalog.
Warlock Exploits SharePoint Flaws in Ransomware Campaigns
China-linked threat actor Warlock is actively weaponizing Microsoft SharePoint vulnerabilities to disable endpoint defenses and deploy ransomware across government, telecom, and critical infrastructure sectors.
Critical Dell CSM Vulnerabilities Grant Kubernetes Node Takeover
Dell released updates fixing two maximum-severity flaws (including CVSS 10.0 CVE-2026-63688) in Dell Container Storage Modules that permit unauthenticated remote attackers to gain root access on underlying Kubernetes hosts.
GitLab Fixes Critical AI Gateway Remote Code Execution Flaw
Self-hosted GitLab deployments face risk from a critical 9.9-severity vulnerability that allows authenticated users with Duo Agent Platform access to execute arbitrary commands directly on the AI Gateway server.
CISA Adds Two Actively Exploited Zammad Bugs to KEV Catalog
Federal agencies have been ordered to remediate session fixation (CVE-2026-102489) and improper privilege management (CVE-2026-102490) vulnerabilities in Zammad after confirmed weaponization in malicious campaigns.
ShinyHunters Extortion Member Detained in Jordan
Authorities have apprehended suspected ShinyHunters hacker "Rey" (Saif al-Din Khader) in Jordan, who is reportedly cooperating with the FBI to identify other members of the notorious data breach and extortion group.
Chinese APT TA419 Targets AI Policy Experts via AitM Phishing
Espionage actors aligned with China are launching Adversary-in-the-Middle credential-phishing operations by impersonating prominent AI policymakers and Anthropic staff to target researchers at U.S. think tanks and academic institutions.
Fortra Patches Critical Flaws in BoKS Server Software
Fortra addressed multiple high-impact vulnerabilities in its BoKS privileged access management platform that could enable unauthenticated attackers to bypass authentication, trigger shell execution, or corrupt memory.