Enterprise Cybersecurity IntelligenceFriday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

FortiMail zero-day is being exploited while fixed builds remain…Cisco SD-WAN Manager auth bypass gives attackers administrator accessMetaMask exits staking validators after infrastructure compromiseCalifornia subpoenas OpenAI over AI model security incidents
Friday decision brief · 06:00 America/New_York · Executive decision brief

FortiMail zero-day is being exploited while fixed builds remain unavailable

Fortinet and CISA confirm exploitation of an unauthenticated FortiMail arbitrary-file-write flaw. Fixed builds were still unavailable at disclosure, making isolation, feature-level mitigation and forensic triage today’s highest-priority decision.

Executive consequence

CVE-2026-104286 allows unauthenticated arbitrary file writes through crafted HTTP or HTTPS requests to affected FortiMail appliances. Fortinet published appliance indicators and temporary mitigations, while CISA added the flaw to KEV and set a short federal deadline.

Decision today

Inventory affected FortiMail branches, IBE status and management exposure.

Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Daily executive briefing

Security.io Daily Headlines

Five equally weighted stories: what happened and the leadership decision each creates.

Read this edition’s headlines

Today’s decision ledger

What changed · Why it matters · What to do
03
Third-Party Risk

MetaMask exits staking validators after infrastructure compromise

Why it matters

MetaMask disclosed an infrastructure security incident and began precautionary exits of affected validators in its non-custodial staking operations. Lido expects the exit and re-entry process to create foregone rewards and possible downtime penalties.

Do today

Map treasury, staking and customer dependencies on MetaMask Staking.

Read the briefing →

Signal desk

Evidence that changes prioritisation
Lead risk profile

FortiMail decision profile

Scores are Security.io editorial assessments from 0–100. Exposure reflects reachable affected estate, Urgency reflects exploitation and fix availability, and Business Consequence reflects mail-gateway privilege and compromise cost. Source: Security.io editorial score using Fortinet PSIRT and CISA KEV evidence.

Back page

Daily comic · Circuit Chuckles
A brief pause after the intelligence

Configuration Drift

A wheeled server rack literally drifts across the room, and Rusty contains it with rope even though the settings continue to change.

Friday, 2 October 2026Open comic page →
In a retro server room, a wheeled rack rolls across the floor until Rusty lassos it to a wall anchor while Glitch points out that the settings still drifted.