2026-10-02
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- ransomware
Spain Arrests Teen Suspected of Running KillSec Ransomware
Spanish police arrested a 16-year-old suspected of operating the KillSec ransomware group and seized its servers and leak site. U.S. prosecutors simultaneously charged a Dutch national with assisting the group in extorting victims, including a Puerto Rico company.
Why it matters: Ransomware operators and their support networks face law enforcement action; organizations should review incident response plans and check whether they were targeted by KillSec.
- ai security
Omada Purchases EmpowerID to Govern AI Agents at Runtime
Omada acquired EmpowerID, an Ohio-based vendor, to enhance its platform with artificial intelligence (AI) agent identity governance and runtime authorization. The acquisition enables enterprises to discover AI agents, restrict their tools and permissions, govern actions in real time, and maintain auditable execution records.
Why it matters: Organizations deploying AI agents need runtime controls to limit agent capabilities and track their actions; this addresses governance gaps as AI adoption accelerates in production environments.
- vulnerabilitiesCVE-2026-104286
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet disclosed CVE-2026-104286, a critical FortiMail vulnerability with a CVSS score of 9.8 that attackers are actively exploiting in zero-day attacks. The flaw allows remote code execution on vulnerable devices.
Why it matters: Organizations running FortiMail must patch immediately; this vulnerability is listed on the Known Exploited Vulnerabilities (KEV) catalog and is under active exploitation.