Severity: ElevatedAction: Be aware

FBI, Secret Service add to warnings of FortiBleed credential stealing campaign

Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.

Excerpt from the primary source: The Record by Recorded Future News

Who is affected

Small businesses · Enterprises · Security professionals

Affected technology: FortiGate / FortiOS

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

FBI, Secret Service add to warnings of FortiBleed credential stealing campaign The Record by Recorded Future News · therecord.media · Oct 7, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns

CISA added CVE-2026-104286 (Fortinet FortiMail) to its Known Exploited Vulnerabilities catalog on October 1, 2026, which means there is reliable evidence of exploitation in the wild. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or…

Why it matters

CISA lists this as exploited in the wild. Unpatched FortiGate / FortiOS and FortiMail systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

Apple’s Verified Photography System

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone. Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are concerned this puts some photographers, such as…

Severity: ElevatedAction: Be aware

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.

Severity: ElevatedAction: Be aware

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued.

FBI, Secret Service add to warnings of FortiBleed credential stealing campaign | CybersecurityNews.us