Jessica Entwistle
October 2 2026
Today's stories highlight three persistent challenges facing UK organisations: actively exploited vulnerabilities in widely deployed enterprise infrastructure, the growing market for insider access sold to criminals, and the continued threat from ransomware groups regardless of their operators' age or location. Together, they reinforce that mature security depends on disciplined patch management, clear visibility of who has access to what, and understanding that threats come from many directions.
The Hacker News reports that the US Cybersecurity and Infrastructure Security Agency has added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw, tracked as CVE-2026-104286 with a CVSS score of 9.8, allows unauthenticated attackers to write arbitrary files to the underlying system. Fortinet has released patches and organisations using FortiMail are advised to apply updates immediately. The vulnerability affects email security appliances widely deployed across enterprise environments to filter spam, malware and phishing attempts.
This matters because FortiMail sits at a critical point in many organisations' security architecture, handling inbound email before it reaches users. A vulnerability that allows unauthenticated arbitrary file writes gives attackers a direct route to compromise the appliance, potentially allowing them to intercept email, modify filtering rules, deploy malware or use the compromised system as a foothold into the wider network. For UK businesses relying on FortiMail for email security, the combination of a critical severity rating and confirmed exploitation means this is not a theoretical risk but an active threat requiring immediate attention.
For organisations using Fortinet FortiMail, this is a prompt to verify that patches have been applied across all instances, including any that may be managed by third parties or sit outside the usual patch cycle. It is also worth reviewing whether email security appliances are included in vulnerability scanning, patch management processes and incident response playbooks with the same priority as other internet-facing systems.
Source: The Hacker News
Infosecurity Magazine reports that a critical vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited in the wild. The flaw allows an unauthenticated remote attacker to access systems with administrator privileges. Cisco has confirmed the vulnerability and released patches. SD-WAN platforms are used by many organisations to manage and optimise connectivity across distributed sites, branch offices and cloud environments, making them high-value targets for attackers seeking persistent access to corporate networks.
The operational risk here is significant because SD-WAN management platforms control routing, security policies and connectivity for entire networks. An attacker gaining administrator access to an SD-WAN controller can reconfigure traffic flows, intercept data, disable security controls or pivot into connected sites and cloud environments. For UK businesses using Cisco SD-WAN infrastructure, particularly those with distributed operations, retail estates, manufacturing sites or remote offices, this vulnerability represents a direct threat to network integrity and the confidentiality of data in transit. The fact that exploitation is already happening means attackers are actively scanning for and targeting vulnerable systems.
For many organisations, SD-WAN platforms are managed by network teams or third-party providers rather than security teams, which can mean they are not always included in the same vulnerability management processes as servers or endpoints. This is a prompt to confirm that Cisco SD-WAN Manager instances have been patched, and to review whether network infrastructure is covered by the same patch management discipline and monitoring as other critical systems.
Source: Infosecurity Magazine
Help Net Security reports on research from Intel 471 showing that cybercriminals are actively recruiting employees at specific organisations to provide insider access and services. The report highlights that legitimate employee access allows criminals to circumvent security controls that would be difficult to overcome from outside. Routine actions such as information lookups, account resets, transaction approvals and shipment changes are being sold as services to criminal customers. Criminals are targeting employees at financial institutions, logistics companies, telecommunications providers and technology firms, offering payment in exchange for access or specific actions performed using legitimate credentials.
This matters because insider threats are often harder to detect than external attacks. When an employee with legitimate access performs an action using their own credentials, it may appear entirely normal to monitoring systems. For UK businesses, this represents a shift in how organisations need to think about risk. It is no longer enough to focus solely on keeping attackers out; organisations also need to understand who has access to what, whether that access is appropriate, and whether unusual patterns of behaviour are being detected and reviewed. The recruitment of insiders is not a new phenomenon, but the scale and organisation of the market for insider services has grown, driven by the difficulty criminals face in bypassing modern security controls from the outside.
For UK businesses, this is a reminder to review whether access controls, segregation of duties and monitoring are designed to detect misuse by legitimate users, not just external attackers. It is worth considering whether high-risk actions such as account changes, transaction approvals or data exports are subject to dual authorisation, logging and review, and whether HR, security and legal teams have a shared understanding of how insider risk is identified and managed.
Source: Help Net Security
The Hacker News and Dark Reading report that Spanish police have arrested a 16-year-old suspected of running the KillSec ransomware group, which is accused of stealing data from organisations and threatening to publish it unless victims paid. The teenager was one of three people arrested on 30 September, when police also seized the group's leak site and servers. Investigators believe KillSec has claimed approximately 500 victims worldwide over the past two years. The operation involved collaboration between law enforcement agencies from multiple countries.
The significance of this story is not the age of the suspect, but the operational reality it illustrates. Ransomware groups do not require nation-state resources, sophisticated infrastructure or years of experience to cause significant harm. A teenager operating from home was allegedly able to compromise hundreds of organisations, steal sensitive data and extort victims using readily available tools and techniques. For UK businesses, this reinforces that ransomware is not an exotic threat requiring advanced defences; it is a persistent, industrialised criminal activity that exploits common weaknesses in patching, access control, backup integrity and incident response readiness. The disruption of KillSec is welcome, but it does not change the underlying risk landscape.
For many organisations, the assumption that ransomware is a sophisticated nation-state problem can lead to underinvestment in the basics. This is a prompt to review whether backup and recovery processes are tested, whether privileged access is monitored and controlled, whether patching is timely, and whether incident response plans include clear decision-making processes for ransomware scenarios. The threat does not require advanced adversaries; it requires gaps in foundational security discipline.
Source: The Hacker News
The stories today reflect challenges that are neither new nor exotic, but they do require consistent attention. Zero-day vulnerabilities will continue to emerge, insiders will continue to be targeted by criminals, and ransomware will remain a persistent threat regardless of who is operating it. What separates organisations that manage these risks well from those that do not is not the sophistication of their tools, but the discipline of their processes. Mature security comes from knowing what you have, who has access to it, how quickly you can respond when something goes wrong, and ensuring that responsibility for these areas is clearly owned and actively managed. The organisations that handle incidents well are the ones that built the habits, the visibility and the decision-making structures before the incident happened.