| DEAFNEWS |
DEAFLETTER // SECURITY BRIEF |
|
|
VERIFIED SIGNALS // EDITORIAL SNAPSHOT
DeafLetter — week 41Fortinet: Critical FortiMail Zero-Day, Patches Missing for Three of Four Branches | 01 // LEAD STORY LEAD // 01 Fortinet: Critical FortiMail Zero-Day, Patches Missing for Three of Four BranchesCVE-2026-104286 hits FortiMail with a CVSS 9.8 score and active exploitation. CISA mandates action by October 4, but Fortinet has patches only for the 7.2 branch. Here is what you need to know. OPEN REPORT → |
| 02 // THREE SIGNALS SIGNAL // 02 Autonomous AI Agent Hits DIVD: Operational Errors Leave Forensic TrailThe Dutch Institute for Vulnerability Disclosure suffered a breach carried out by an automated AI agent that operated autonomously during post-exploitation. The incident, announced September 29, 2026, marks one of the first documented cases of an agentic AI system used in a real-world attack against a cybersecurity organization. READ THE ANALYSIS → | SIGNAL // 03 Android 17 Moves the Anti-Spyware Battlefield to Google's ServersAndroid 17 adds six features to Advanced Protection, headlined by Intrusion Logging — a forensic logging system that stores encrypted logs on Google's servers even if an attacker wipes the device. The shift changes the risk calculus for state-sponsored spyware operators who have long relied on local trace deletion as standard tradecraft. READ THE ANALYSIS → | SIGNAL // 04 AI Agent Breaches DIVD in Seconds Using Zammad Zero-Days: The ReportOn September 21, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) was compromised by an autonomous AI agent that chained two zero-day vulnerabilities in the Zammad ticketing system — CVE-2026-102489 (unauthenticated RCE) and CVE-2026-102490 (local privilege escalation to root) — achieving full system takeover in seconds. The attack marks the first detailed documentation of a fully autonomous AI-driven cyber operation that makes its own tactical decisions, leaves explanatory comments in its attack code, and operates at speeds far beyond human reaction times. Stolen data includes volunteer email addresses, raising targeted social-engineering risks. Network segmentation contained lateral movement. Zammad versions 6.3.0–6.5.4 are vulnerable to CVE-2026-102489; CVE-2026-102490 affects all versions including the latest alpha. DIVD urges immediate upgrade to version 7 or taking instances offline. READ THE ANALYSIS → |
| 03 // CVES AND PATCHES CVE_PATCH // 05 RMM Tools Abused in 45% of Endpoint Incidents: The Trust Paradox in ITHuntress reports that 45% of endpoint incidents in Q1 2026 leveraged legitimate RMM tools. Abuse surged 277% year-over-year in 2025, forcing a fundamental rethink: the line between authorized remote administration and predatory access has become invisible to traditional defenses. READ THE ANALYSIS → | CVE_PATCH // 06 Doxx.net Raises $38M from a16z to Isolate AI Agents from the InternetOn October 1, 2026, doxx.net announced a $38 million Series A led by Andreessen Horowitz, with Joel De La Garza joining the board. The company simultaneously launched the open beta of Agentic Defined Networking (ADN), a parallel, sovereign network infrastructure designed to prevent autonomous AI agents from taking harmful actions using user credentials. READ THE ANALYSIS → | CVE_PATCH // 07 CISA Adds Zammad Zero-Days to KEV: Federal Deadline Set for Oct. 5CISA added two zero-day vulnerabilities in Zammad to its Known Exploited Vulnerabilities catalog, both rated CVSS 9.4. Federal Civilian Executive Branch agencies must patch by Oct. 5, 2026, per Binding Operational Directive 26-04. The flaws form an exploit chain discovered during the Dutch Institute for Vulnerability Disclosure's (DIVD) incident response after its own ticketing system was compromised. READ THE ANALYSIS → | CVE_PATCH // 08 CVE-2026-71885: Identity Spoofing in Bouncy Castle MLS with CVSS 9.2A flaw in the binding between an X.509 certificate and its signing key enables full impersonation in encrypted groups. Version 1.86 with the fix was released on September 15, 2026. READ THE ANALYSIS → | CVE_PATCH // 09 Google Suspends Open-Source Bug Bounty After AI-Generated Spam FloodOn October 1, 2026, Google halted product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP), citing a surge in automated, AI-generated reports that were overwhelmingly invalid. Supply-chain reports remain open, while product submissions await an architectural overhaul promised for Q1 2027. READ THE ANALYSIS → |
| 04 // THE GUIDE GUIDE // 10 Foundations of Ethical Security Testing with Python: A Beginner's Laboratory GuideYou have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise.
**What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors.
**What you will not do:** run unmodified exploits against infrastructure you do not own. READ THE ANALYSIS → |
| | MANAGE PREFERENCES → | You receive this email because you subscribed to DeafLetter. Unsubscribe Samuel — DeafNews · Privacy | |