Weekly intelligence brief

Cybersecurity Weekly Intelligence Brief — week ending 2026-10-05

13 incidents disclosed · 318 stories reviewed · 21 critical · 5 newly exploited vulnerabilities

Summary

13 incidents were disclosed in the last seven days. The largest is Medela, with 423,947 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, no cybersecurity rule has a deadline coming up; the newest is from Commodity Futures Trading Commission.

Every item below links to its record. Times are UTC.

Top 5 incidents

  1. 1
    Medela: a data breach

    423,947 recordsHave I Been Pwned · 30 Sept

  2. 2
    Sheppard, Mullin, Richter & Hampton LLP: a data breach

    California Attorney General · 2 Oct

  3. 3
    Fragomen, Del Rey, Bernsen & Loewy, LLP: a data breach

    California Attorney General · 2 Oct

  4. 4
    Aldrich Services LLP: a data breach

    California Attorney General · 1 Oct

  5. 5
    Lincoln Property Company Commercial LLC: a data breach

    California Attorney General · 1 Oct

Top 5 exploited vulnerabilities

  1. 1
    Zammad GmbH Zammad

    CVE-2026-102490· added 2 Oct

    9.8Critical
  2. 2
    Zammad GmbH Zammad

    CVE-2026-102489· added 2 Oct

    9.8Critical
  3. 3
    Fortinet FortiMail

    CVE-2026-104286· added 1 Oct

    9.8Critical
  4. 4
    Cisco Catalyst SD-WAN Manager

    CVE-2026-76504· added 30 Sept

    9.8Critical
  5. 5
    Apple Multiple Products

    CVE-2026-86950· added 29 Sept

    8.8High

Compliance

Privacy Act Regulations

Commodity Futures Trading Commission · US

Published21 September 2026

Technical details

For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.

The analysis below is for subscribers. Add your email to read it now — the rest of this briefing stays open to everyone.

We send the briefing and nothing else. Unsubscribe in one click.

Fastnexa security experts

Which of these actually affect your company?

Send us what you run and a Fastnexa security expert will tell you which items in this briefing matter for you, and what to fix first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →