Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Oct 8, 2026·4m

Cyber Security News for October 8 2026 - Daily DefSec Brief

Show notes

1. Japan's data thefts came through internal APIs — CVE-2026-72898 — Do: Find the internal APIs your apps expose — https://www.jpcert.or.jp/at/2026/at260030.html

2. Phishing now hides orders for your inbox AI — Do: Confirm every payment change with a phone call — https://blog.barracuda.com/2026/10/07/email-attacks-target-both-humans-ai-assistants

3. SonicWall SMA1000 gets another pre-login flaw — CVE-2026-102255 — Fixed: 12.4.3-03670 or 12.5.0-03082 — Do: Hotfix the SonicWall SMA1000 again — https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017

4. Veeam's Backup Viewer role can run code on v12 — CVE-2025-64393, CVE-2026-93026 — Fixed: 12.3.2.4934 — Do: Patch Veeam 12 and audit Backup Viewer accounts — https://www.veeam.com/kb4934

5. Nexus switches get root-level RCE fixes — CVE-2026-76471, CVE-2026-76465, CVE-2026-76485 (+ 2 more) — Do: Upgrade switches running NX-API, MPLS OAM or NGOAM — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j

6. Splunk clusters run commands with no login — CVE-2026-76268, CVE-2026-76281 — Fixed: 10.4.3, 10.2.7, 10.0.10 or 9.4.15 — Do: Upgrade Splunk Enterprise on every release line — https://advisory.splunk.com/advisories/SVD-2026-1001

7. Meraki firmware fixes flaws rated up to 9.6 — CVE-2026-76464, CVE-2026-76463 — Fixed: MX 26.1.7 or 26.2.3; MR 33.1.3; MS 26.1.2 or 18.1.9 — Do: Schedule the Meraki firmware upgrades — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH

8. Attackers messaged ASOS customers through its app — Do: Lock down your customer-messaging platform logins — https://www.rapid7.com/blog/post/it-asos-incident-attackers-using-channels-customers-trust

9. A botnet gets its C2 address from a poem — CVE-2026-42271 — Fixed: LiteLLM 1.83.7 — Do: Get your AI servers off the open internet — https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware