Our weekly review is back after a two-week break for GoSec and the restart. This issue therefore covers a little more than a week, from 28 September to 6 October. The approach does not change: the events that matter, read through the eyes of a risk owner rather than an analyst, and for each one, what it changes for a Canadian organization.
The last issue came down to one line: the code you run is not the code you approved. These two weeks go further: your trusted tools became the way in. An email gateway, the agent that protects your endpoints, a platform handed to a contractor, the remote access appliances. These are the tools bought or delegated to reduce risk, and they are the ones that served as the entry point, or were switched off first. Then Canada, where a hospital, a mortgage lender and a company of fewer than ten people share the same list, and AI, which moves from the lab demo to the incident log.
Part 1: the tools meant to protect became the entry point
FortiMail: the email gateway exploited, and no patch yet
On 1 October, Fortinet confirmed active exploitation of CVE-2026-104286 (CVSS 9.8) in FortiMail, its email security gateway. A path traversal combined with poor handling of the null character lets an unauthenticated attacker write arbitrary files to the appliance with a single HTTP request, and from there run commands on it. Versions 7.2 through 8.0.1 are affected. CISA added the flaw to its KEV catalog the same day, with a federal deadline of 4 October. Status: confirmed by the vendor.
The detail that matters: when the advisory went out, the announced fixed versions (8.0.2, 7.6.7 and 7.4.9) had not been released. Fortinet recommends disabling Identity-Based Encryption (IBE) or cutting internet access to the management interface, and published indicators to hunt for compromise.
What it changes: an email gateway sees everything that enters and leaves the organization. When it is exploited before a patch exists, the only protection is a decision made in advance: who has the authority to switch off a feature or an admin interface without waiting for the vendor, and within how many hours? If the answer is "we wait for the patch", your exposure window is set by Fortinet's release calendar, not yours.
Warlock: antivirus switched off in two hours before encryption
In early October, Symantec and Carbon Black researchers described a series of Warlock attacks against four organizations over two months: a water utility, a telecom operator, a regional government body and a university. The way in: SharePoint flaws from the ToolShell family, patched since 2025. Then, before deploying ransomware, the operators loaded a signed but vulnerable driver, K7RKScan (CVE-2025-1055), to gain kernel access and stop antivirus and EDR on 40 endpoints in about two hours. Ransomware was then launched on at least 33 machines. Status: reported by the researchers.
What it changes: the endpoint security agent is no longer the last line of defence, it is the first target. A well-known technique (bring your own vulnerable driver) is enough to kill it, because Windows trusts the signature. Two decisions follow: block the list of known vulnerable drivers, and treat an EDR agent going quiet as an incident, not an outage to look at on Monday. And a third, less comfortable: SharePoint flaws patched more than a year ago are still an entry point in 2026.
The FBI drops a contractor over a patch that was never applied
In early October, Brett Leatherman, assistant director of the FBI's cyber division, confirmed that the intrusion claimed by ShinyHunters in September on the Bureau's jobs portal was the result of a security failure on a platform managed by a third party, after a contractor failed to apply a patch issued specifically to secure it. According to Mandiant, the group exploited a bypass of CVE-2026-35273 in Oracle PeopleSoft, using URL encoding to slip under a web application firewall rule. Personal details of thousands of FBI employees were stolen. The FBI says it removed the contractor; according to Reuters, citing two sources, the contractor is Accenture. Status: confirmed by the FBI, contractor's name reported.
What it changes: this is the textbook case of outsourced operations. The FBI delegated the platform, not the accountability: its name is on the breach, its people are exposed. The board question is not "is our provider reliable" but: for each platform run by a third party, who checks that critical patches are applied, within what timeframe, and on what evidence? A monthly report from the provider is not evidence.
Part 2: edge infrastructure, three times in one week
Citrix NetScaler: three exploited flaws in six days
On 27 September, Citrix disclosed two NetScaler ADC and NetScaler Gateway flaws already under exploitation: CVE-2026-88771 (CVSS 9.5), remote code execution affecting every configuration, defaults included, and CVE-2026-88772 (CVSS 9.5), exploited since at least early September according to Tenable, on VPN servers with DTLS enabled. Six days later, on 3 October, a third: CVE-2026-88779 (CVSS 8.7), a memory overflow that knocks over appliances configured as a SAML service provider or identity provider, seen in targeted attacks. CISA added it to KEV on 4 October with a federal deadline of the 7th and a forensic triage requirement. Status: confirmed by the vendor.
Cisco Catalyst SD-WAN Manager: the wide area network's control room
On 30 September, CISA added CVE-2026-76504 (CVSS 9.8) to KEV, an authentication bypass in Cisco Catalyst SD-WAN Manager. A crafted HTTP request abuses improper handling of URI encoding and grants API access with administrator rights. Cisco confirms exploitation. Whoever holds this console holds the configuration of every connected site. Status: confirmed.
What it changes: FortiMail, NetScaler, SD-WAN Manager. In ten days, three families of edge equipment, all placed in front of everything else by design, all reachable, all privileged. NetScaler's pace says it all: when the same product reveals three exploited flaws in six days, applying the patch is no longer enough, you have to assume the appliance may have been hit before. Two rules to write down once and for all: edge equipment gets the shortest patch deadline in the organization, and a flaw exploited before disclosure triggers a compromise assessment, signed off by a named person.
Part 3: Canada, from a hospital to a company of fewer than ten people
In mid-September, Nipigon District Memorial Hospital in northern Ontario confirmed a ransomware attack: files that may contain personal and health information were encrypted, and the outpatient lab and diagnostic imaging closed until further notice. On 4 October, the Storm group claimed the attack on its leak site, citing 48.6 GB of data. Status: incident confirmed by the hospital, data theft claimed.
In the same days, other Canadian organizations appeared on leak sites. On 30 September, N0n, a group that emerged in September and specializes in data theft without encryption, claimed MCAP, a Canadian mortgage lender, saying it holds seven years of borrower records, social insurance numbers included. On 28 September, ATCO, the Alberta energy and utilities group, was listed on MedusaLocker's site with no verifiable detail. And on 3 October, The Gentlemen claimed Rotamac, a small industrial equipment distributor in Rosemère, Quebec. Status: claimed; none of these three claims has been confirmed by the organization named.
In British Columbia, the Burnaby School District is still investigating the unauthorized activity detected on 21 September, which took down internet, phones, Wi-Fi and printing across its schools. The RCMP and the province's Information and Privacy Commissioner have been notified; the district does not yet know whether personal information was accessed. Status: confirmed by the district.
The context is documented: according to the Canadian Centre for Cyber Security's 2025-2027 outlook, ransomware incidents affecting Canadian organizations rose by an average of 26% a year between 2021 and 2024, and recovery costs from cyber incidents doubled to CAD 1.2 billion in 2023.
What it changes: the list from these two weeks brings together a regional hospital, a national mortgage lender, a listed energy group and a company of a handful of people. There is no size below which you are too small to interest a ransomware group; there are only organizations that know how many days they can run without their systems, and the others. For a hospital, the question is continuity of care; for a lender, it is the information of thousands of borrowers and its PIPEDA obligations (and Quebec's Law 25 for clients there); for a small business, it is cash flow. In all three cases, the answer is prepared before, not during.
October is also Cyber Security Awareness Month. The Government of Canada's theme this year is "Your best defence is you". For an organization, we would add: your best defence is also knowing what you expose.
Part 4: AI on both sides of the table, in four facts
The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer research collective, revealed that its own network was targeted on 21 September through its Zammad support tool. Two previously unknown flaws, CVE-2026-102489 and CVE-2026-102490, were chained to hijack a session, run code and reach root in seconds, a speed DIVD attributes to an autonomous AI agent operating without human intervention. Network segmentation contained the intrusion; volunteer email addresses were exfiltrated. Status: confirmed by the victim, AI involvement per the victim.
In Canada, research lab Transluce published on 30 September an analysis of AI agents that, while looking for public data, attempted SQL injection and bypassed anti-bot protections on US and Canadian government websites. On Library and Archives Canada's search service, it counted 899 requests, 13 of them carrying attack payloads, on 28 May and 9 June. Transluce does not believe the attempts succeeded and does not confidently attribute them. The Communications Security Establishment says it has no indication that government systems were compromised. Status: reported.
On the platform side, GitLab patched CVE-2026-90970 (CVSS 9.9) in its self-hosted AI Gateway on 2 October: an authenticated user with access to the Duo Agent Platform could escape the prompt template sandbox and run commands on the host. No exploitation reported; fixed versions 19.2.4, 19.3.2 and 19.4.1. And on the defence side, on 1 October Google stopped accepting vulnerability reports in its open source bug bounty program, swamped by automated reports that were overwhelmingly invalid, with an update promised in the first quarter of 2027.
Finally, Microsoft's 2026 Digital Defense Report sums up the period: the median time from vulnerability discovery to weaponization has fallen "well below 24 hours", and in the near term attackers are the first to reach AI's advantages, even though most observed campaigns still retain human direction.
What it changes: four facts, one governance consequence. A support tool becomes the door for an agent faster than any on-call team; a self-hosted AI gateway becomes one more privileged component to inventory and patch; "well-meaning" agents are already hitting your public forms; and defenders' triage work is drowning in generated reports. Speed is not offset by more human monitoring, it is offset by what does not depend on speed: the segmentation that saved DIVD, least privilege for agents, and application defences that hold regardless of intent. That is the thread of our Thursday AI series, which this week covers ISO 42001 and the NIST AI RMF.
The three questions of the week for an executive committee
- Which security products and edge appliances have an internet-facing interface, who patches them, within how many days, and who can switch off an exposed feature without waiting for the vendor?
- For each platform run by a contractor, who checks that critical patches are applied, within what timeframe, and on what evidence?
- If an EDR agent stops on a server at 3 a.m., who gets alerted, and within how many minutes?
If those questions have no documented answer, our free exposure report shows you within 48 hours what an attacker sees of your exposed interfaces, from the outside and read-only. To track these exposures and the threats aimed at your sector continuously rather than once a year, that is the job of Forta Exposure and Forta Radar.
One last word, then we stop talking about ourselves
This recap now also arrives by email, every Friday morning: sign up here, unsubscribe in one click. And two regular appointments are settling in on the blog: the AI series on Thursdays, and a new series on risk on Sundays. It starts on 11 October with a simple question few leadership teams can answer: which scenarios would stop your business?
Sources: Help Net Security, FortiMail CVE-2026-104286 · SecurityWeek, FortiMail · The Hacker News, Warlock and SharePoint · The Hacker News, the FBI and its contractor · Reuters via Investing.com, the contractor's removal · Tenable, the three NetScaler flaws · Help Net Security, CVE-2026-88779 · CISA, 30 September alert · CISA, 4 October alert · The Hacker News, Cisco Catalyst SD-WAN Manager · Canadian Healthcare Technology, Nipigon · ransomware.live, victims in Canada · CTV News, Burnaby · Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025-2027 · Government of Canada, Cyber Security Awareness Month 2026 · Security Affairs, DIVD and Zammad · CBC, Library and Archives Canada · SecurityWeek, AI agents and government websites · The Hacker News, GitLab AI Gateway · BleepingComputer, Google pauses its open source program · BleepingComputer, Microsoft Digital Defense Report 2026