Cybersecurity Weekly Intelligence Brief — week ending 2026-10-05
13 incidents disclosed · 318 stories reviewed · 21 critical · 5 newly exploited vulnerabilities
Summary
13 incidents were disclosed in the last seven days. The largest is Medela, with 423,947 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, no cybersecurity rule has a deadline coming up; the newest is from Commodity Futures Trading Commission.
Every item below links to its record. Times are UTC.
Top 5 incidents
- 1Medela: a data breach
423,947 recordsHave I Been Pwned · 30 Sept
- 2Sheppard, Mullin, Richter & Hampton LLP: a data breach
California Attorney General · 2 Oct
- 3Fragomen, Del Rey, Bernsen & Loewy, LLP: a data breach
California Attorney General · 2 Oct
- 4Aldrich Services LLP: a data breach
California Attorney General · 1 Oct
- 5Lincoln Property Company Commercial LLC: a data breach
California Attorney General · 1 Oct
Top 5 exploited vulnerabilities
- 1Zammad GmbH Zammad9.8Critical
CVE-2026-102490· added 2 Oct
- 2Zammad GmbH Zammad9.8Critical
CVE-2026-102489· added 2 Oct
- 3Fortinet FortiMail9.8Critical
CVE-2026-104286· added 1 Oct
- 4Cisco Catalyst SD-WAN Manager9.8Critical
CVE-2026-76504· added 30 Sept
- 5Apple Multiple Products8.8High
CVE-2026-86950· added 29 Sept
Compliance
Commodity Futures Trading Commission · US
Technical details
For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.
Fastnexa security experts
Which of these actually affect your company?
Send us what you run and a Fastnexa security expert will tell you which items in this briefing matter for you, and what to fix first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →