Latest Threat Intelligence — Week of October 5, 2026
Our security analysts track vendor advisories, CISA alerts, and live attack campaigns, then translate each one into what it means for a business that has to keep working. At the top of the feed right now: a Cisco SD-WAN Manager flaw already exploited to take over the system that configures every branch router, with no workaround and a federal deadline that has passed; a FortiMail email-gateway flaw attacked before Fortinet had a fix ready; a 9.9-rated flaw in GitLab’s self-hosted AI gateway; and the Citrix NetScaler zero-days, now patched, where the real work is checking whether an attacker left a back door behind. Notice the pattern: two of these were exploited before a fix existed, and one stays dangerous after the patch. Patching is necessary and it is not sufficient — what decides the cost of an incident is how fast someone notices and what evidence you can hand the bank, the insurer and your customers afterward.