
Cyber Security News for October 7 2026 - Daily DefSec Brief
Show notes
1. FortiBleed is active and locking admins out — Do: Reset Fortinet admin and VPN passwords — https://www.ic3.gov/CSA/2026/261006.pdf
2. Ninja Forms flaw is being used to add admins — CVE-2026-94504, CVE-2026-93836 — Fixed: Ninja Forms 3.15.4 or later, WPC Product Bundles 8.6.7 or later — Do: Update the plugins and check for hidden admins — https://www.wordfence.com/threat-intel/vulnerabilities/id/c599a562-5218-4b37-bcf7-0e82008a4e68?source=cve
3. Hijacked country registries mint real certificates — Do: Watch certificate logs for your domains — https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
4. Chrome 155 fixes 247 flaws, four critical — CVE-2026-106382, CVE-2026-106197, CVE-2026-106358 (+ 1 more) — Fixed: 155.0.8059.39 — Do: Push the Chrome update and force a relaunch — http://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html
5. FBI blames a contractor's missed patch — Do: Verify your contractors' patching yourself — https://www.securityweek.com/fbi-blames-contractors-missed-patch-for-shinyhunters-breach/
6. OpenSSH 10.6 fixes bugs, releases will speed up — Fixed: 10.6 — Do: Upgrade OpenSSH and plan for more releases — https://www.openssh.org/txt/release-10.6
7. Outlook will block .msix attachments by default — Do: Check who needs MSIX attachments first — https://www.theregister.com/software/2026/10/06/microsoft-extends-the-outlook-naughty-step-with-two-more-file-types/5301350
8. Npm package was malicious for over a year — Do: Search your lockfiles for function-flag — https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign