State of (in)security - Week 40, 2026
In week 40 of 2026 (Sept. 28 - Oct. 5), incidents rose to 26 while advisories dipped to 15. The incidents exposed about 7.7 million individuals, led by attacks on Tokyo Metro and Times Car that alone affected 6.66 million. Unauthorized access and ransomware were the top causes, and healthcare was the hardest-hit sector. Several actively exploited zero-days also emerged that week, in Apple, Cisco, Fortinet, GitLab and Roundcube products, alongside critical flaws from vendors such as WatchGuard, Microsoft Exchange and Dell.
**Update right away to the fixes for flaws already under attack: iPhone/iPad to iOS/iPadOS 26.7.1, Mac to macOS Tahoe 26.7.1 or Sequoia 15.8.1, Roundcube Webmail to 1.6.16 or 1.7.1, and self-hosted GitLab to its latest security release (AI Gateway 19.2.4, 19.3.2 or 19.4.1). Until Cisco Catalyst SD-WAN Manager, FortiMail and WatchGuard Firebox and access points are patched (WatchGuard access points to firmware 3.4.8), make sure their management interfaces can't be reached from the internet.**
#cybersecurity #infosec #knowledge #weeklyreport
https://beyondmachines.net/event_details/state-of-in-security-week-40-2026-l-u-k-5-5/gD2P6Ple2L