Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Oct 2, 2026·3m

Cyber Security News for October 2 2026 - Daily DefSec Brief

Show notes

1. FortiMail zero-day exploited, no patch yet — CVE-2026-104286 — federal due 2026-10-04 — Do: Take FortiMail's admin interface off the internet — https://fortiguard.fortinet.com/psirt/FG-IR-26-175

2. Warlock still breaking in through SharePoint — CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 (+ 2 more) — Do: Patch SharePoint, then rotate its machine keys — https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure

3. Kiteworks fixes 126 flaws, one pre-auth root — CVE-2026-54154 — Fixed: 9.5.1 (EPG 9.4.1) — Do: Upgrade Kiteworks to the current release — https://cyber.gc.ca/en/alerts-advisories/kiteworks-security-advisory-av26-988

4. Dayforce Payroll flaws, vendor unreachable — CVE-2026-73640, CVE-2026-73641, CVE-2026-73642 — Do: Ask Dayforce in writing whether these are fixed — https://cert.pl/en/posts/2026/09/CVE-2026-73640/

5. Unsloth Studio ran code from a model repo — Fixed: 2026.6.9 — Do: Upgrade the unsloth package — https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution

6. Fake Zoom for Mac coaches users past Gatekeeper — Do: Install Zoom through MDM, not downloads — https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/