Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Oct 6, 2026·4m

Cyber Security News for October 6 2026 - Daily DefSec Brief

Show notes

1. ClickFix stages its payload in the browser cache — Do: Disable Windows Script Host where it isn't needed — https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html

2. Atlassian Data Center leaks files without a login — CVE-2026-21589 — Fixed: see Atlassian's table (Confluence 9.2.26 / 10.2.19, Jira 9.12.40 / 10.3.26 / 11.3.12, Bitbucket 9.4.26 / 10.2.8 / 10.5.1, Crowd 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4, Bamboo 10.2.24 / 12.1.12, Crucible and Fisheye 4.9.15) — Do: Patch Atlassian Data Center or take it offline — https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html

3. HPE iLO 7 flaw gives remote iLO admin — CVE-2026-79820 — Fixed: 1.25.01 — Do: Update iLO 7 firmware — https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf05163en_us&docLocale=en_US

4. ClingSTUN turns old edge devices into proxies — CVE-2023-46805, CVE-2024-21887, CVE-2022-36553 (+ 1 more) — Do: Replace edge devices that no longer get updates — https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure

5. Dell System Update flaw gives root — CVE-2026-86360, CVE-2026-86361, CVE-2026-86362 (+ 2 more) — Fixed: 2.3.0.0 — Do: Update Dell System Update on PowerEdge servers — https://www.dell.com/support/kbdoc/en-us/000515843/dsa-2026-324-security-update-for-dell-system-update-dsu-vulnerabilities

6. Mail-gateway backdoors hide inside SMTP — Do: Hunt your mail gateways for deleted-binary processes — https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/

7. A retired SSO service stayed up and leaked — Do: Switch off the services you've replaced — https://www.theregister.com/security/2026/10/05/legacy-sign-on-service-comes-back-to-bite-school-software-provider-bromcom/5301156

8. One lookup account pulled 8.8M Danish records — Do: Alert on unusual volume from partner accounts — https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html