
Cyber Security News for October 8 2026 - Daily DefSec Brief
Show notes
1. Japan's data thefts came through internal APIs — CVE-2026-72898 — Do: Find the internal APIs your apps expose — https://www.jpcert.or.jp/at/2026/at260030.html
2. Phishing now hides orders for your inbox AI — Do: Confirm every payment change with a phone call — https://blog.barracuda.com/2026/10/07/email-attacks-target-both-humans-ai-assistants
3. SonicWall SMA1000 gets another pre-login flaw — CVE-2026-102255 — Fixed: 12.4.3-03670 or 12.5.0-03082 — Do: Hotfix the SonicWall SMA1000 again — https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
4. Veeam's Backup Viewer role can run code on v12 — CVE-2025-64393, CVE-2026-93026 — Fixed: 12.3.2.4934 — Do: Patch Veeam 12 and audit Backup Viewer accounts — https://www.veeam.com/kb4934
5. Nexus switches get root-level RCE fixes — CVE-2026-76471, CVE-2026-76465, CVE-2026-76485 (+ 2 more) — Do: Upgrade switches running NX-API, MPLS OAM or NGOAM — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
6. Splunk clusters run commands with no login — CVE-2026-76268, CVE-2026-76281 — Fixed: 10.4.3, 10.2.7, 10.0.10 or 9.4.15 — Do: Upgrade Splunk Enterprise on every release line — https://advisory.splunk.com/advisories/SVD-2026-1001
7. Meraki firmware fixes flaws rated up to 9.6 — CVE-2026-76464, CVE-2026-76463 — Fixed: MX 26.1.7 or 26.2.3; MR 33.1.3; MS 26.1.2 or 18.1.9 — Do: Schedule the Meraki firmware upgrades — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH
8. Attackers messaged ASOS customers through its app — Do: Lock down your customer-messaging platform logins — https://www.rapid7.com/blog/post/it-asos-incident-attackers-using-channels-customers-trust
9. A botnet gets its C2 address from a poem — CVE-2026-42271 — Fixed: LiteLLM 1.83.7 — Do: Get your AI servers off the open internet — https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware