Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Oct 1, 2026·3m

Cyber Security News for October 1 2026 - Daily DefSec Brief

Show notes

1. Cisco SD-WAN Manager zero-day gives admin — CVE-2026-76504 — Fixed: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 — federal due 2026-10-03 — Do: Patch SD-WAN Manager, then check its logs — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

2. Zammad zero-days used in an AI-agent breach — CVE-2026-102489, CVE-2026-102490 — Do: Upgrade Zammad to version 7 and check logs — https://csirt.divd.nl/cases/DIVD-2026-00015/

3. MikroTik web interface flaw gives root — CVE-2026-84411 — Fixed: 7.24 — Do: Upgrade RouterOS and close WebFig to the internet — https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06

4. TeamViewer session permissions can be bypassed — CVE-2026-92370, CVE-2026-19743, CVE-2026-92368 (+ 2 more) — Fixed: 15.82, 15.64.8, 14.7.48855, 13.2.36230 (Windows) — Do: Update TeamViewer everywhere it is installed — https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/

5. WatchGuard fixes 15 Fireware OS flaws — CVE-2026-86131, CVE-2026-81433, CVE-2026-86101 (+ 2 more) — Fixed: 2026.3.2, 2026.2.3, 12.12.3, 12.5.21; AP 3.4.8 — Do: Upgrade Firebox and WatchGuard access points — https://psirt.watchguard.com/CVE-2026-86131

6. Star Blizzard's archive-and-disk-image phish — Do: Hunt for the three fake maintenance tasks — https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/

7. Google: exploit growth is fast n-days — Do: Order the patch queue by exploitation evidence — https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/

8. SSMS Copilot made a database owner sysadmin — CVE-2026-65669 — Fixed: 22.8.2 — Do: Update SQL Server Management Studio — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669