Security Roundup: Fortinet FortiMail Zero-Day, Cisco SD-WAN KEV, Agentic AI DIVD Breach, KillSec Takedown (Week of October 2, 2026)

ColibriSec Weekly Security Roundup October 2 2026

Executive Summary: The week of September 26 to October 2, 2026, marked a watershed moment in cybersecurity, defined by the real-world operationalization of autonomous agentic AI exploit chains, critical zero-days across foundational edge appliances, and historic international law enforcement takedowns. Federal authorities added active zero-days in Fortinet FortiMail (CVE-2026-104286) and Cisco Catalyst SD-WAN Manager (CVE-2026-76504) to the CISA Known Exploited Vulnerabilities (KEV) catalog with emergency mitigation deadlines. Simultaneously, the Dutch Institute for Vulnerability Disclosure (DIVD) reported an unprecedented breach executed by an autonomous AI agent chaining Zammad zero-days, German and European police dismantled the KillSec ransomware syndicate seizing 110TB of exfiltrated data, and an IDOR flaw in Polish dental SaaS provider FELG Dent compromised 2.4 million patient health records. Here is the full strategic briefing and technical breakdown.

🏛️
HIGH-SEVERITY THREAT LANDSCAPE: CRITICAL INFRASTRUCTURE & EDGE ALERTS Advanced threat actors, state-sponsored APT syndicates, and autonomous AI exploitation agents are weaponizing edge device perimeter flaws, API authorization oversights, and unpatched mail gateway appliances. Fortinet FortiMail zero-day (CVE-2026-104286, CVSS 9.8) actively exploited for unauthenticated arbitrary file write and web shell execution Cisco Catalyst SD-WAN Manager critical authentication bypass (CVE-2026-76504, CVSS 9.8) added to CISA KEV Apple patches actively exploited CoreGraphics zero-day (CVE-2026-86950, CVSS 8.8) leveraged in targeted mercenary spyware campaigns DIVD discloses compromise by autonomous agentic AI executing multi-exploit zero-day chaining in seconds without human intervention Operation KillSwitch: German LKA, Europol, and 10 nations dismantle KillSec ransomware, arresting a 16-year-old leader and seizing 110TB of data FELG Software (FELG Dent) suffers IDOR API breach exposing 2.4 million medical records and 1.2 million prescriptions Bitget cryptocurrency exchange incurs $387.5M unauthorized hot wallet outflow via third-party zero-day software exploit

Key Threat Disclosures at a Glance

1. Fortinet FortiMail Zero-Day Path Traversal & Null Byte Flaw (CVE-2026-104286)

Disclosed under advisory FG-IR-26-175 and added to CISA KEV on October 1, 2026, CVE-2026-104286 (CVSS 9.8) affects FortiMail branches 7.2 through 8.0. Unauthenticated remote attackers transmit malformed HTTP/HTTPS requests containing null bytes (%00) and directory traversal sequences to the Identity-Based Encryption (IBE) management handler. This allows writing arbitrary payload files across protected root filesystems, enabling immediate web shell persistence. With patches pending, CISA has mandated emergency workarounds—specifically disabling the IBE feature via CLI—across all organizations.

2. Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)

Added to CISA KEV on September 30, 2026, CVE-2026-76504 (CVSS 9.8) enables unauthenticated attackers to bypass API authentication boundaries and gain administrative control over SD-WAN controllers. By manipulating URI hex-encoding in HTTP session requests routed to the backend container proxy, attackers circumvent security interceptors and invoke privileged endpoints directly. Cisco has released emergency hotfixes for versions 20.9 through 26.2, urging network defenders to inspect serviceproxy-access.log for unauthorized j_security_check invocations.

3. Apple CoreGraphics Out-of-Bounds Write Zero-Day (CVE-2026-86950)

On September 28, Apple issued emergency security updates across iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1 to address CVE-2026-86950. Root cause analysis revealed an out-of-bounds write in the CoreGraphics path rasterizer caused by unit conversion errors between floating-point and fixed-point coordinates during typography and PDF rendering. Threat intelligence confirms targeted exploitation by commercial spyware operators in zero-click messaging campaigns. CISA issued an emergency compliance deadline of October 2, 2026.

4. DIVD Compromise: The Dawn of Autonomous Agentic AI Exploitation

On September 30, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) revealed that an internal helpdesk server running Zammad had been compromised by an autonomous AI agent. The AI agent identified and chained two previously undocumented zero-day flaws: a session hijacking flaw (CVE-2026-102489, CVSS 9.4) for initial remote execution as the zammad service user, and a local privilege escalation flaw (CVE-2026-102490, CVSS 9.4) achieving root access in under four seconds. While DIVD enclaves prevented lateral movement, this incident establishes the emergence of fully automated, non-human adversarial attack chains.

5. Operation KillSwitch: Dismantling KillSec Ransomware

In an international operation coordinated by Europol and Eurojust, German police (Hamburg LKA) and law enforcement across ten countries took down the KillSec Ransomware-as-a-Service (RaaS) syndicate on October 1, 2026. Authorities arrested the suspected 16-year-old primary operator in Alicante, Spain, while US prosecutors unsealed indictments against key broker Fouad Eltibrizi ("Archduke") following his arrest in the UK. Crucially, investigators seized five command servers holding over 110 terabytes of stolen corporate data, neutralizing ongoing extortion against hundreds of global enterprises.

6. FELG Dent Healthcare Breach: IDOR Exposes 2.4M Patients

Polish healthcare SaaS provider FELG Software confirmed a major security incident affecting its cloud-based dental practice management platform, FELG Dent. A threat actor known as "Horus" exploited an Insecure Direct Object Reference (IDOR) flaw in unsecured REST API endpoints, allowing an authenticated demo account to sequentially harvest patient records by incrementing numeric identifiers. The compromised dataset spans 2.4 million patient identities, 1.2 million digital prescriptions, PESEL identity numbers, and clinical treatment notes across 16,000 dental clinics.

7. Bitget Cryptocurrency Exchange $387.5M Hot Wallet Intrusion

Beginning September 24 and reaching containment by October 2, cryptocurrency exchange Bitget suffered an unauthorized drainage of $387.5 million in digital assets across 11 blockchains. Forensic investigators from Mandiant and SlowMist determined that attackers weaponized a zero-day vulnerability in third-party security management software to siphon high-privilege signing tokens, bypassing withdrawal limit verification engines. Bitget activated its $464M User Protection Fund to cover user balances while collaborating with Circle and Tether to freeze stolen assets.

Weekly Technical Deep Dives in This Series

Weekly Action Checklist for Security Operations

  1. Mitigate Fortinet FortiMail Immediately: If running FortiMail 7.2 through 8.0, immediately disable Identity-Based Encryption via CLI (config system encryption ibe -> set status disable -> end) and restrict management port access from untrusted subnets.
  2. Patch Cisco Catalyst SD-WAN Manager: Upgrade SD-WAN Manager instances to patched release trains (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1) before the October 3 CISA KEV deadline.
  3. Deploy Apple Security Updates: Enforce MDM update policies requiring iOS 26.7.1, iPadOS 26.7.1, and macOS Sequoia 15.8.1 / Tahoe 26.7.1 across all enterprise endpoints.
  4. Audit Multi-Tenant REST APIs for IDOR: Review all external API gateways for missing object-level authorization checks. Ensure backend database queries evaluate tenant ownership context rather than raw client-supplied object IDs.
  5. Prepare for Sub-Second Agentic AI Reconnaissance: Implement behavioral anomaly rate-limiting on perimeter services to counter automated AI agents capable of executing multi-stage exploit chains faster than human analysts can triage alerts.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther