-
-
Your Email Gateway Is the Way In: FortiMail Zero-Day CVE-2026-104286 Is Under Attack, There’s No Patch, and CISA’s Deadline Is Tomorrow
Attackers are writing files onto Fortinet FortiMail email security gateways without logging in. Fixed builds for the main branches are still pending, CISA wants it handled by October 4, and the obvious upgrade path for 7.2 customers still lands on a vulnerable release. DataWater Threat Intelligence Desk | Published October 3, 2026 | 8-minute read…
-
Attackers Now Move From Breach to Data Theft in Minutes. Most Enterprise Defenses Are Still Measured in Days.
Executive Threat Briefing · Week ending October 3, 2026 Two NetScaler zero-days exploited for weeks before disclosure. A fifth Cisco SD-WAN zero-day this year. Ransomware that blinds 40 machines in two hours. And Microsoft’s new data says AI has handed attackers the speed advantage. Here is what changed this week, and what to do on…
-
Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. DataWater Threat Intelligence Desk | Published September 30, 2026 | 9-minute read Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC…
-
-
-
The System That Decides Who Gets on Your Network Is Under Active Attack — Cisco ISE Zero-Day Hits CVSS 10.0, and CISA’s Deadline Is Tomorrow
🚨 CRITICAL VULNERABILITY ALERT — Network Access Control / Identity Infrastructure: Cisco has patched a CVSS 10.0 authentication bypass in Identity Services Engine (ISE) that attackers are already exploiting. CISA gave federal agencies three days to fix it. That deadline is tomorrow, Sept 19. Executive Cyber Threat Intelligence Briefing — September 18, 2026 | DataWater…
-
Two Perfect-10 Vulnerabilities Are Being Exploited Right Now — Is Your Patch Window Fast Enough?
Executive Cyber Threat Intelligence Briefing — September 14, 2026 | DataWater Security Intelligence Desk Executive Summary Two vulnerabilities hit the maximum possible CVSS score this week — and both are already being exploited. A path traversal flaw in GitLab was weaponized within days of the patch shipping. An authentication bypass in Cisco’s Secure Firewall Management…
