Threat Intelligence Brief - Friday, October 2, 2026

Operational threat reporting for defenders who need signal, not noise.

By DevSecOpsDad

Threat Radar

  • PATCH NOW: Fortinet FortiMail CVE-2026-104286 (CVSS 9.8) is actively exploited and CISA KEV-listed — unauthenticated arbitrary file write, no credentials required.

  • Nation-state active campaign: China-linked Warlock has been exploiting SharePoint vulnerabilities against critical infrastructure since July 2025; the campaign is confirmed expanding.

  • AI-automated web attacks are operational: AI agents — some linked to OpenAI infrastructure — executed SQL injection attacks against US and Canadian government web applications, confirming offensive AI automation is no longer theoretical.

  • Vendor account compromise: Microsoft’s official X account (13M followers) was hijacked to run a cryptocurrency pump-and-dump scheme. Major vendors are not immune to social media account takeover.

  • T1190 dominates today’s threat picture: Three of four stories involve exploitation of public-facing applications — FortiMail, SharePoint, and government web apps — confirming perimeter exposure as the primary initial access vector.



Immediate Action Required

  • Fortinet FortiMail — CVE-2026-104286: Treat this as an emergency patch. The vulnerability is unauthenticated, remotely exploitable, and CISA KEV-listed. Validate patch status across all instances today. If immediate patching is not possible, assess whether internet-facing FortiMail instances can be isolated or access restricted at the network boundary.

  • SharePoint — Warlock Campaign: Critical infrastructure organizations must validate SharePoint patch levels immediately and review access logs for anomalous activity dating back to July 2025. Lateral movement risk is elevated given the campaign’s duration and nation-state backing.



High-Impact Developments

Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited — CISA KEV Listed

  • What happened: A critical path traversal vulnerability in Fortinet FortiMail allows unauthenticated remote attackers to write arbitrary files to the system. CISA added CVE-2026-104286 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation.

  • Why it matters: Unauthenticated arbitrary file write on an email security gateway is a reliable path to full system compromise, mail interception, and lateral movement into the broader environment. CISA KEV listing carries a mandatory remediation deadline for federal agencies; enterprise teams should apply equivalent urgency.

  • Who should care: CISOs, vulnerability management leads, IT operations, and email security teams at any organization running Fortinet FortiMail.

  • Recommended action: Apply Fortinet’s patch immediately. Confirm all FortiMail instances — including those managed by third parties or MSSPs — are inventoried and patched. Review FortiMail logs for unauthorized file writes or unexpected configuration changes.

  • Confidence: High — active exploitation confirmed, CISA KEV-listed, dual-source corroboration.

  • Search metadata: CVE-2026-104286, T1190, FortiMail, Fortinet, CISA-KEV, path-traversal, arbitrary-file-write

Intelligence Context



China-Linked Warlock Group Expands SharePoint Exploitation Against Critical Infrastructure

  • What happened: China-linked threat actor Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, with the campaign now confirmed as expanding. Targets are critical infrastructure organizations.

  • Why it matters: A three-month-plus active campaign by a nation-state actor against critical infrastructure via SharePoint signals persistent, high-capability targeting. The expansion indicates the group has achieved sufficient success to broaden its scope. Long-term persistence and lateral movement are the likely objectives.

  • Who should care: CISOs and security architects at energy, utilities, manufacturing, transportation, and government organizations; SOC leaders who need to scope historical log review back to July 2025.

  • Recommended action: Validate SharePoint patch status against all Microsoft advisories. Scope a log review for T1190-consistent activity from July 2025 onward. Engage threat hunting resources if SharePoint is internet-facing. Confirm network segmentation between SharePoint and sensitive internal systems.

  • Confidence: High — active exploitation confirmed by SecurityWeek, named threat actor with nation-state attribution.

  • Search metadata: Warlock, T1190, SharePoint, Microsoft, critical-infrastructure, China

Intelligence Context



AI Agents Deploy SQL Injection Against US and Canadian Government Web Applications

  • What happened: AI agents — some attributed to OpenAI infrastructure — conducted SQL injection attacks against the US Department of Education and Library and Archives Canada, demonstrating AI-enabled offensive automation applied against real public-sector targets.

  • Why it matters: This is a documented instance of AI being used to automate web application attacks at scale. The cost and complexity of executing SQL injection campaigns has dropped materially. Any organization with public-facing applications and unmitigated injection vulnerabilities faces a broadening threat surface.

  • Who should care: Security architects, application security teams, and SOC leaders at government agencies and any organization with public-facing web applications.

  • Recommended action: Review web application firewall coverage and confirm SQL injection protections are active across public-facing applications. Prioritize remediation of any applications with known injection findings. Assess whether AI-driven scanning activity is visible in current WAF or application logs.

  • Confidence: Medium — attack activity confirmed; attribution of agents to OpenAI infrastructure is researcher-assessed, not formally confirmed.

  • Search metadata: T1190, SQL-injection, AI-agents, OpenAI, Web Application Attack

Intelligence Context



Monitor Only



Analyst Observation

Today’s brief is dominated by T1190 — exploitation of public-facing applications — across three distinct stories simultaneously. That convergence is not coincidental; perimeter-exposed services remain the path of least resistance for both nation-state actors and automated tooling. The FortiMail zero-day is the most operationally urgent item: CVSS 9.8, unauthenticated, KEV-listed, and actively exploited means the window for unpatched exposure is effectively closed. The Warlock/SharePoint campaign deserves more attention than it typically receives — a three-month-plus active campaign by a China-linked actor against critical infrastructure, only now characterized as “expanding,” suggests detection and response in affected sectors has been slow. The AI-driven SQL injection story matters not because AI makes SQL injection novel, but because it confirms that offensive automation using AI agents is being applied against real targets today, and the cost to attackers is dropping.





Generated by DevSecOpsDadAttack cyber threat intelligence.

Share: X (Twitter) LinkedIn