Threat Radar
-
PATCH NOW: Fortinet FortiMail CVE-2026-104286 (CVSS 9.8) is actively exploited and CISA KEV-listed — unauthenticated arbitrary file write, no credentials required.
-
Nation-state active campaign: China-linked Warlock has been exploiting SharePoint vulnerabilities against critical infrastructure since July 2025; the campaign is confirmed expanding.
-
AI-automated web attacks are operational: AI agents — some linked to OpenAI infrastructure — executed SQL injection attacks against US and Canadian government web applications, confirming offensive AI automation is no longer theoretical.
-
Vendor account compromise: Microsoft’s official X account (13M followers) was hijacked to run a cryptocurrency pump-and-dump scheme. Major vendors are not immune to social media account takeover.
-
T1190 dominates today’s threat picture: Three of four stories involve exploitation of public-facing applications — FortiMail, SharePoint, and government web apps — confirming perimeter exposure as the primary initial access vector.
Immediate Action Required
-
Fortinet FortiMail — CVE-2026-104286: Treat this as an emergency patch. The vulnerability is unauthenticated, remotely exploitable, and CISA KEV-listed. Validate patch status across all instances today. If immediate patching is not possible, assess whether internet-facing FortiMail instances can be isolated or access restricted at the network boundary.
-
SharePoint — Warlock Campaign: Critical infrastructure organizations must validate SharePoint patch levels immediately and review access logs for anomalous activity dating back to July 2025. Lateral movement risk is elevated given the campaign’s duration and nation-state backing.
High-Impact Developments
Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited — CISA KEV Listed
-
What happened: A critical path traversal vulnerability in Fortinet FortiMail allows unauthenticated remote attackers to write arbitrary files to the system. CISA added CVE-2026-104286 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation.
-
Why it matters: Unauthenticated arbitrary file write on an email security gateway is a reliable path to full system compromise, mail interception, and lateral movement into the broader environment. CISA KEV listing carries a mandatory remediation deadline for federal agencies; enterprise teams should apply equivalent urgency.
-
Who should care: CISOs, vulnerability management leads, IT operations, and email security teams at any organization running Fortinet FortiMail.
-
Recommended action: Apply Fortinet’s patch immediately. Confirm all FortiMail instances — including those managed by third parties or MSSPs — are inventoried and patched. Review FortiMail logs for unauthorized file writes or unexpected configuration changes.
-
Confidence: High — active exploitation confirmed, CISA KEV-listed, dual-source corroboration.
-
Search metadata: CVE-2026-104286, T1190, FortiMail, Fortinet, CISA-KEV, path-traversal, arbitrary-file-write
Intelligence Context
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action — https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/
- Context: SecurityWeek confirmed active exploitation of CVE-2026-104286 and characterized the path traversal flaw as enabling arbitrary file writes, calling for urgent patching action.
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
- Context: The Hacker News confirmed CISA’s addition of CVE-2026-104286 to the KEV catalog and provided the CVSS 9.8 score, reinforcing the severity and mandatory remediation posture for federal and enterprise environments.
China-Linked Warlock Group Expands SharePoint Exploitation Against Critical Infrastructure
-
What happened: China-linked threat actor Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, with the campaign now confirmed as expanding. Targets are critical infrastructure organizations.
-
Why it matters: A three-month-plus active campaign by a nation-state actor against critical infrastructure via SharePoint signals persistent, high-capability targeting. The expansion indicates the group has achieved sufficient success to broaden its scope. Long-term persistence and lateral movement are the likely objectives.
-
Who should care: CISOs and security architects at energy, utilities, manufacturing, transportation, and government organizations; SOC leaders who need to scope historical log review back to July 2025.
-
Recommended action: Validate SharePoint patch status against all Microsoft advisories. Scope a log review for T1190-consistent activity from July 2025 onward. Engage threat hunting resources if SharePoint is internet-facing. Confirm network segmentation between SharePoint and sensitive internal systems.
-
Confidence: High — active exploitation confirmed by SecurityWeek, named threat actor with nation-state attribution.
-
Search metadata: Warlock, T1190, SharePoint, Microsoft, critical-infrastructure, China
Intelligence Context
- Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks — https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/
- Context: SecurityWeek reported that Warlock has been exploiting SharePoint vulnerabilities since July 2025 and that the campaign is actively expanding, with critical infrastructure organizations as the confirmed target set.
AI Agents Deploy SQL Injection Against US and Canadian Government Web Applications
-
What happened: AI agents — some attributed to OpenAI infrastructure — conducted SQL injection attacks against the US Department of Education and Library and Archives Canada, demonstrating AI-enabled offensive automation applied against real public-sector targets.
-
Why it matters: This is a documented instance of AI being used to automate web application attacks at scale. The cost and complexity of executing SQL injection campaigns has dropped materially. Any organization with public-facing applications and unmitigated injection vulnerabilities faces a broadening threat surface.
-
Who should care: Security architects, application security teams, and SOC leaders at government agencies and any organization with public-facing web applications.
-
Recommended action: Review web application firewall coverage and confirm SQL injection protections are active across public-facing applications. Prioritize remediation of any applications with known injection findings. Assess whether AI-driven scanning activity is visible in current WAF or application logs.
-
Confidence: Medium — attack activity confirmed; attribution of agents to OpenAI infrastructure is researcher-assessed, not formally confirmed.
-
Search metadata: T1190, SQL-injection, AI-agents, OpenAI, Web Application Attack
Intelligence Context
- AI Agents Aimed SQL Injection at US and Canadian Government Sites — https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
- Context: SecurityWeek reported that AI agents conducted SQL injection attacks against the US Department of Education and Library and Archives Canada, with researchers linking some of the agents to OpenAI infrastructure.
Monitor Only
-
Microsoft’s official X account (13M followers) was hijacked to promote a Clippy-themed cryptocurrency pump-and-dump scheme — no direct enterprise security action required, but use this as a prompt to audit your organization’s social media account security posture and MFA coverage. Source: Crypto Scammers Hijack Microsoft’s Official X Account — https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/
-
Corroborating coverage confirms the Microsoft X account compromise was a cryptocurrency token pump-and-dump operation; the incident highlights downstream fraud and social-engineering risk for followers who may trust content from verified vendor accounts. Source: Microsoft’s X account hacked in crypto pump-and-dump scheme — https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
Analyst Observation
Today’s brief is dominated by T1190 — exploitation of public-facing applications — across three distinct stories simultaneously. That convergence is not coincidental; perimeter-exposed services remain the path of least resistance for both nation-state actors and automated tooling. The FortiMail zero-day is the most operationally urgent item: CVSS 9.8, unauthenticated, KEV-listed, and actively exploited means the window for unpatched exposure is effectively closed. The Warlock/SharePoint campaign deserves more attention than it typically receives — a three-month-plus active campaign by a China-linked actor against critical infrastructure, only now characterized as “expanding,” suggests detection and response in affected sectors has been slow. The AI-driven SQL injection story matters not because AI makes SQL injection novel, but because it confirms that offensive automation using AI agents is being applied against real targets today, and the cost to attackers is dropping.
Source Links
-
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action — https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/
-
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
-
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks — https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/
-
AI Agents Aimed SQL Injection at US and Canadian Government Sites — https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
-
Crypto Scammers Hijack Microsoft’s Official X Account — https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/
-
Microsoft’s X account hacked in crypto pump-and-dump scheme — https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
Generated by DevSecOpsDadAttack cyber threat intelligence.