AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
Netlify - Elevated error rates for AI Gateway
Oct 6, 20:12 UTC Resolved - Between 19:05 and 19:18 UTC, some requests to the AI Gateway returned errors. We've since increased the capacity of the affected service, and error rates returned to normal levels at 19:18 UTC. We apologize for the disruption.
GitHub - Several services are degraded
Oct 6, 19:57 UTC Investigating - We are investigating reports of degraded performance for Pull Requests and Webhooks
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
Four incidents, four completely different initial access paths: 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence. Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye. April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens s...
Sentry - Sentry dashboard down
Oct 6, 18:57 UTC Investigating - We are investigating an issue impacting our dashboard in both US and EU regions
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
submitted by /u/dx7r__ [link] [comments]
Vercel - Vercel Auth login failures for pages with Deployment Protection enabled
Oct 6, 16:26 UTC Resolved - This incident has been resolved. Oct 6, 16:17 UTC Monitoring - A fix has been implemented and we are monitoring the results. Oct 6, 16:14 UTC Identified - The issue has been identified and a fix is being implemented. Oct 6, 16:10 UTC Investigating - We are investigating an issue causing Vercel Auth login failures for pages with Deployment Protection enabled. We will provide an update as more information becomes available.
CircleCI - Delays in pipelines, workflows, UI data, and notifications
Oct 6, 16:00 UTC Investigating - What's impactedCustomers using CircleCI pipelines and workflows, including UI data display, outbound notifications, and outbound webhooks.What can you expectDelays in pipelines being created and in workflows and jobs starting. Job, workflow, and pipeline data may take up to 15 minutes to appear in the UI. Outbound notifications and webhooks are delayed by up to 1 minute.Next updateWe will provide another update within 30 minutes or as we have more information t...
Zoom - Zoom Chat Update: October 06, 2026 (No Operational Impact)
Oct 6, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 22, 20:08 PDT Scheduled - We will be providing an update to Zoom Chat Backend Service. There will be no operational impact. All services will be available during this scheduled update.
Snowflake - INC20000263
Oct 6, 15:57 UTC Resolved - Current status: We've coordinated with our third-party provider who implemented a fix for this issue, and we've monitored the environment to confirm that service was restored. If you experience additional issues or have questions, please open a support case via Snowflake Community or the Support page in Snowsight.Customer experience: Customers hosted in the specified regions may have seen pages that loaded indefinitely. Customers in other regions who connected from ...
Supabase - Upgrade Issues
Oct 6, 15:23 UTC Investigating - We have observed failures in attempted upgrades to 17.11.0.003. We are investigating.
Elastic Cloud - Delayed Serverless Metrics in Azure UAE North region
Oct 6, 14:04 UTC Investigating - Customers with Serverless projects in the Azure UAE North region may see delays in metrics displayed in Cloud UI. The team is investigating the issue and we will post an update in 2 hours or sooner if necessary
Loggly - Degraded Data Collection
Oct 6, 05:17 PDT Update - We are continuing to investigate this issue. Oct 6, 05:16 PDT Investigating - We are currently investigating an issue affecting log ingestion for a subset of customers. Customers using certain ingestion endpoints may experience delayed processing or failed ingestion of new log data. Services not utilizing the affected ingestion path remain operational. We will provide an update within the hour.
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP
Vercel - Elevated Sandbox error rates in Paris (cdg1)
Oct 6, 09:36 UTC Resolved - This incident has been resolved. Oct 6, 09:31 UTC Monitoring - A fix has been implemented and we are monitoring the results. Oct 6, 09:27 UTC Update - We are seeing signs of recovery in Sandbox in Paris, France (cdg1). We will share updates as they become available. Oct 6, 09:12 UTC Identified - We've identified an issue where some customers may experience elevated error rates with Sandbox in Paris, France (cdg1). We are currently investigating this issue. ...
Supabase - Increased errors on management api leading to project operation failures
Oct 6, 08:13 UTC Monitoring - We have identified a rollout causing error increase on management api dependant services, which is causing project operation failures and FGA Authentication errors across multiple functions. We have implementing a fix and observing recovery. Our teams are continuing to monitor for full resolution. Oct 6, 07:55 UTC Update - We are continuing to investigate this issue. Oct 6, 07:53 UTC Investigating - We are investigating an increase in errors on project updat...
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
GitHub - Disruption with some GitHub services
Oct 5, 23:47 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Zoom - Service Degradation Affecting ZoomMate
Oct 5, 14:57 PDT Investigating - We are currently investigating a service degradation with ZoomMate services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
GitHub - Incident with Actions
Oct 5, 19:50 UTC Update - We’re still investigating delays in assigning GitHub-hosted runners, affecting workflow start times across multiple runner configurations. Our teams are working to mitigate the impact; we’ll share another update as we learn more. Oct 5, 19:15 UTC Update - We’re investigating an issue causing delays when assigning GitHub-hosted runners to Actions jobs. Some workflows may take longer to start across runner configurations. Our teams are working to mitigate the issue, ...
Amplitude - Guides and Surveys Service Disruption
Oct 5, 11:56 PDT Resolved - Between 11:40 AM and 11:48 AM PT on October 5, 2026, Amplitude experienced a full outage of the Guides and Surveys service. During this time, users may have been unable to create, publish, or edit Guides and Surveys, or may have seen Guides and Surveys fail to load for end users.The issue has been resolved and Guides and Surveys is fully operational. We are continuing to confirm there was no data loss. No customer action is needed at this time.
Zoom - Zoom Phone Maintenance - NRT3 Data Center: October 5, 2026
Oct 5, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 15, 16:32 PDT Scheduled - Zoom will perform service maintenance at our NRT3 Data Center starting at 9:00 AM Pacific on October 5, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the KIX3 sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get di...
Netlify - Error accessing Netlify-hosted sites
Oct 5, 12:44 UTC Investigating - We are investigating reports of errors affecting access to sites on our High-Performance Edge Network. Our engineering team is actively investigating the issue.We will provide additional updates as more information becomes available.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 5, 10:38 UTC Monitoring - We have implemented a fix for the issue affecting Cloud SIEM Processing. Log security records may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. Users may also experience delayed insights and signal generation on the affected security records. We are currently monitoring the results. Oct 5, 10:25 UTC Identifi...
DigitalOcean - VPC Networking Availability
Oct 5, 10:38 UTC Identified - Our Engineering team identified a disruption affecting VPC Networking operations that began at approximately 08:48 UTC. During this time, customers may have experienced delays or failures when creating or deleting VPC peerings, VPC Native DOKS clusters, or Private Network Connections (PNCs), as well as when adding cluster members. Creating routes and subnets may also have been affected.Operations are now returning to normal, and our Engineering team is monitoring ...
Zoom - Network Maintenance in SJC Datacenter: October 4, 2026
THIS IS A SCHEDULED EVENT Oct 4, 22:00 PDT - Oct 5, 02:00 PDT Aug 31, 09:06 PDT Scheduled - Zoom will perform service maintenance at SJC Datacenter. During the maintenance window, Users may experience an impact for a brief amount of time for services mentioned.
Zoom - Service Degradation Affecting Zoom Rooms Management and Workspaces Management in SA01.
Oct 4, 17:41 PDT Resolved - This incident has been resolved and the affected services have been restored. Oct 4, 17:00 PDT Monitoring - The issue affecting Zoom Rooms Management and Workspaces Management has been successfully resolved. Our team will continue to monitor the situation closely and keep you informed of any further developments. Oct 4, 16:50 PDT Identified - We have identified the service degradation with Zoom Rooms Management and Workspaces Management. Our team is actively w...
MAL-2026-17472: Anthropic Vulnerability
Malicious code in anthropic-sdk (PyPI)
AWS - Service is operating normally: [RESOLVED] Elevated packet loss
Between 8:48 AM and 11:28 AM PDT, we experienced elevated packet loss within a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region. This issue resulted in elevated API latencies and error rates for multiple workflows and AWS Services. We were automatically alerted to the issue at 8:54 AM, and immediately began work to identify the root cause while taking multiple parallel paths to mitigate the issue. By 10:00 AM, our mitigation efforts had led to some improvements. By 10:38 AM, we ident...
AWS - Service impact: Elevated packet loss
We are seeing early signs of recovery. We will provide you with another update by 12:00 PM PDT.
AWS - Service impact: Elevated packet loss
We have identified the root cause and are currently focusing our mitigation efforts to drive full recovery. While we don't have an exact estimate for how long our current efforts will take, we do expect to see incremental improvements as our efforts proceed. We will provide you with another update by 11:45 AM PDT, or sooner if new information becomes available.
AWS - Service impact: Elevated packet loss
Our efforts to mitigate the elevated packet loss with a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region is still underway. We are seeing some signs of improvement as a result of multiple parallel efforts. We continue to work to confirm root cause and fully mitigate the issue. While we currently do not have an estimate for how long our actions will take, we will keep you informed of our progress and provide you with another update by 11:00 AM PDT or sooner as new information becomes ...
AWS - Service impact: Elevated packet loss
We are experiencing elevated packet loss with a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region. This issue is also resulting in elevated API latencies and error rates for other workflows and AWS Services. Engineers were automatically engaged and are working to identify the root cause and to mitigate the issue. We will provide you with another update by 10:15 AM PDT or sooner as new information becomes available.
AWS - Service impact: Elevated packet loss
We are investigating elevated packet loss in the EU-SOUTH-2 Region.
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
submitted by /u/NISMO1968 [link] [comments]
ActiveCampaign - Planned Platform Maintenance
Oct 4, 05:00 CDT Completed - The scheduled maintenance has been completed. Oct 4, 04:00 CDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 29, 11:09 CDT Scheduled - On October 4th, between 4:00 AM and 5:00 AM (Central Time), engineers will be performing maintenance to improve ActiveCampaign infrastructure.During this time, customers may be unable to log in or utilize the platform. Delays in processing of automations, campaign sendin...
Zoom - Service Degradation Affected Inbound and Outbound Calls of Zoom Phone and Contact Center in North America Region
Oct 4, 01:20 PDT Resolved - This incident has been resolved and the affected services have been restored. Oct 4, 01:05 PDT Monitoring - On 10/04/2026, Between 06:36 UTC to 07:30 UTC, A subset of users may have experienced issues with inbound and outbound calls of Zoom Phone and Contact Center in North America region.This incident has been resolved and the affected services have been restored.
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
HashiCorp - HCP Vault Azure: Cluster Updates and Creation
Status: InvestigatingWe are aware of an issue affecting cluster updates and cluster creation on HCP Vault Dedicated Azure clusters. Our team is actively investigating. We will provide updates as more information becomes available.
Zoom - Service degradation affecting Developer Documentation Website
Oct 3, 09:49 PDT Investigating - We are currently investigating a service degradation affecting users ability to access documentation from Developer Documentation Website.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
DigitalOcean - A Network Disruption in BLR1 Region Impacted Multiple Products (Resolved)
Oct 3, 14:51 UTC Resolved - From 11:59 UTC to 13:02 UTC on October 3, 2026, a networking disruption in our BLR1 region affected multiple products, including Monitoring, App Platform, Managed Databases, Functions, Load Balancers, Spaces, and the Cloud Control Panel. During this period, some users experienced degraded connectivity, increased latency, or intermittent errors when accessing resources in the region.Multiple network paths operated by our upstream connectivity providers were unavailab...
LaunchDarkly - Delays in Guarded Rollouts, Progressive Rollouts, Release Pipelines, and Experimentation
Oct 3, 02:06 PDT Resolved - This incident has been resolved. Oct 3, 01:51 PDT Monitoring - The backlog of delayed changes has been fully processed as of 1:45 AM PT on October 3. All changes that were delayed during the incident have been applied. No data was lost. We are continuing to monitor. Oct 3, 00:29 PDT Identified - Some automatic changes in LaunchDarkly are being applied later than expected. This affects stage transitions for guarded and progressive rollouts, release pipeline pha...
Zoom - Zoom Phone Maintenance - US East (IAD9 / IAD10) Data Center: October 2, 2026
THIS IS A SCHEDULED EVENT Oct 2, 17:00 PDT - Oct 4, 21:30 PDT Sep 10, 11:40 PDT Scheduled - Zoom will perform service maintenance at our US East (IAD9 / IAD10)) Data Center starting at 5:00 PM Pacific on October 2nd, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the other side sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get disconnected, the system will att...
Segment - Audience & Journey data delivery delay in EU region
Oct 2, 16:12 PDT Identified - We have identified an issue affecting a small portion of Audience & Journey delivery resulting in data delay.
HubSpot - HubSpot is experiencing issues
Oct 2, 17:58 EDT Update - We estimate that we will restore service in the next hour.We are mitigating impact from a server impairment which we believe is caused by a bad production configuration change. We are reverting the change.We will be back with an update within 30 minutes.The information on this page reflects our understanding of the incident and impact at the time of the update. Oct 2, 17:44 EDT Update - We estimate that we will restore service in the next several hours.We are mitig...
Heap - Salesforce integration: data-in not syncing
Oct 2, 14:57 PDT Update - We are continuing to work on a fix for this issue. Oct 2, 14:49 PDT Identified - Salesforce data isn't syncing into Heap, and new connections or reconnections are failing. We've identified the root cause and are working on a fix. Please don't try to reconnect until we post an update.Thank you for your patience!
Amplitude - Amplitude- Platform Loading Issues
Oct 2, 11:43 PDT Resolved - The issue has been resolved, and the platform is operating normally again.Our Engineering team will continue to monitor the platform closely to ensure everything remains stable.Thank you for your patience and understanding while we worked to resolve this issue. Oct 2, 11:36 PDT Update - We are continuing to investigate this issue. Oct 2, 11:35 PDT Investigating - Beginning at approximately 11:15 AM PT, we are currently investigating an issue affecting the Ampl...
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
Oct 2, 17:45 UTC Completed - The scheduled maintenance has been completed. Oct 2, 17:06 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Oct 2, 17:05 UTC Scheduled - Maintenance is ongoing and we are working through it
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
THIS IS A SCHEDULED EVENT Oct 2, 15:00 - 17:00 UTC Sep 28, 20:53 UTC Scheduled - We'll be performing scheduled maintenance on our support tooling on Friday October 2nd starting 8am PDT to 10am PDT (2 hours). During this window, customers may briefly lose access to viewing ticket history in the support portal. No tickets or data will be lost — you can still reach us and follow up via email or chat as normal, and portal visibility will return once the maintenance concludes. If you have a browser ...
LaunchDarkly - Elevated error rates in the LaunchDarkly application
Oct 2, 07:10 PDT Identified - We're investigating elevated error rates affecting the LaunchDarkly web application and API. Some requests may fail or time out intermittently, including custom role management. We'll share an update as we learn more.
Akamai - Edge Delivery Issues
Oct 2, 13:53 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001WrkrnCABWe will provide an update as we progress. Oct 2, 13:24 UTC Investigating - We are investigating an emerging issue with Edge Delivery related to Edge DNS report with record change on master DNS server not reflected to Akamai Edge DNS. We are actively investigating the issue and will provide...
Datadog - Delayed RUM sessions
Oct 2, 08:46 EDT Investigating - We are investigating increased latency processing RUM sessions.As a result of this issue, some users may see gaps or delays in RUM graphs as well as empty or partial query results on RUM Sessions, RUM Analytics, and RUM Application pages since Oct 2, 2026, 11:42 AM UTCTo prevent false monitor alerts due to delayed data, monitors affected by the delay will not notify and will automatically resume once current data is available. All other monitors will operate no...
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
Twilio - SMS Delivery Delays from a Subset of Twilio Long Codes to Telenet BidCo NV Belgium
Oct 2, 03:46 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers in Belgium. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 2, 03:35 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers ...
SendGrid - SMS Delivery Delays from a Subset of Twilio Long Codes to Telenet BidCo NV Belgium
Oct 2, 03:46 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers in Belgium. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 2, 03:35 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers ...
SendGrid - United States SMS Carrier Maintenance - AT&T
Oct 2, 01:00 PDT Completed - The scheduled maintenance has been completed. Oct 1, 21:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 30, 04:41 PDT Scheduled - The AT&T network in the United States is conducting an emergency maintenance from 01 October 2026 at 21:00 PDT until 02 October 2026 at 01:00 PDT. During the maintenance window, there could be intermittent delays delivering SMS to and from AT&T United States handsets whe...
Twilio - United States SMS Carrier Maintenance - AT&T
Oct 2, 01:00 PDT Completed - The scheduled maintenance has been completed. Oct 1, 21:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 30, 04:41 PDT Scheduled - The AT&T network in the United States is conducting an emergency maintenance from 01 October 2026 at 21:00 PDT until 02 October 2026 at 01:00 PDT. During the maintenance window, there could be intermittent delays delivering SMS to and from AT&T United States handsets whe...
Twilio - Silent Network Authentication (SNA) Failure Increase on AT&T in United States
Oct 1, 23:56 PDT Investigating - Twilio customers may be experiencing verification failures during API transactions for Silent Network Authentication (SNA) on AT&T in the United States. Our team is actively investigating the issue. API transactions may temporarily fail over to secondary methods like SMS OTP. We will provide another update in 1 hour or as soon as more information becomes available.
SendGrid - Silent Network Authentication (SNA) Failure Increase on AT&T in United States
Oct 1, 23:56 PDT Investigating - Twilio customers may be experiencing verification failures during API transactions for Silent Network Authentication (SNA) on AT&T in the United States. Our team is actively investigating the issue. API transactions may temporarily fail over to secondary methods like SMS OTP. We will provide another update in 1 hour or as soon as more information becomes available.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 2, 06:23 UTC Investigating - We are currently investigating reports of problems with Cloud SIEM Processing. Logs may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. We will provide more information soon.
SendGrid - SMS Delivery Delays from a Subset of Twilio Phone Numbers to Vodafone Netherlands
Oct 1, 22:59 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers in the Netherlands. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 2 hours or as soon as more information becomes available. Oct 1, 21:58 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers i...
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Twilio - SMS Delivery Delays from a Subset of Twilio Phone Numbers to Vodafone Netherlands
Oct 1, 21:58 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers in the Netherlands. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 1, 21:42 PDT Investigating - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscri...
MongoDB Atlas - MongoDB Charts: Infinite login loop when creating new Charts projects
Oct 2, 00:01 UTC Identified - Since approximately 23:30 UTC on 2026-10-01, users creating new Charts projects by clicking on the "Visualization" tab will repeatedly be prompted to login and will not be able to view the Charts interface. While these Charts projects will be created, we cannot guarantee the timing at this moment.Existing Charts projects are not affected.
Xero - Degraded Performance: US Payroll (Powered by Gusto)
Oct 1, 21:37 UTC Identified - We're aware that some US customers may experience slowness when using US Payroll in Xero due to an issue on Gusto's side. Gusto is currently investigating and working on a fix. We'll provide an update as soon as we can.
TV Box Sentinel v2.0: Open-source network monitoring and heuristic threat detection for compromised Android TV / IoT devices
Hey everyone, I wanted to share an open-source project I’ve been developing: TV Box Sentinel (v2.0). The Problem: A widespread issue with uncertified Android TV boxes (often powered by Allwinner, Rockchip, etc.) is factory-installed malware residing directly in the /system partition, as well as botnet loaders (such as Badbox, Peachpit, Triada, and Guerrilla). Since on-device antiviruses are untrus...
Zoom - Service Degradation Affected Incoming and Outgoing Calls of Zoom Contact Center, Virtual Agents, Mail, Calendar, Meetings, Cloud Meeting Recordings, Webinars and Events
Oct 1, 10:53 PDT Resolved - This incident has been resolved. Oct 1, 09:49 PDT Update - On 10/01/2026, Between 15:33 UTC to 15:37 UTC, a subset of users may have experienced service degradation affected incoming and outgoing calls of Zoom Contact Center, Virtual Agents, Mail, Calendar, Meetings, Cloud Meeting Recordings, Webinars and Events.This incident has been resolved and the affected services have been restored. Oct 1, 09:08 PDT Monitoring - On 10/01/2026, Between 15:33 UTC to 15:37 ...
MongoDB Atlas - Trigger processing may be delayed in AWS ap-southeast-2
Oct 1, 15:41 UTC Investigating - As of approximately 15:00 UTC, some users of MongoDB Atlas Triggers in AWS ap-southeast-2 may experience delayed unordered trigger processing. We are investigating and working to restore normal processing.
GitHub - Actions Job Delays
Oct 1, 14:54 UTC Update - We have identified the cause of increased Actions run start delays on Ubuntu runners and are actively deploying a fix. Customers may continue to experience intermittent delays while the mitigation rolls out and service metrics return to normal. Oct 1, 14:47 UTC Investigating - We are investigating reports of degraded performance for Actions
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 1, 14:04 UTC Resolved - We are no longer seeing issues with Cloud SIEM Processing and normal operation has been restored at this time. Oct 1, 13:55 UTC Identified - We have identified the source of the issue affecting Cloud SIEM Processing. Logs may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. We are working on a fix for the problem...
GitHub - Elevated request latency
Oct 1, 13:57 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Oct 1, 13:51 UTC Monitoring - The degradation has been mitigated. We are monitoring to ensure stability. Oct 1, 13:39 UTC Update - We are investigating recurrent periods of elevated latency affecting web requests. We’ll share updates as more information becomes available. Oct 1, ...
Slack - Incident: Free Plan Customers Are Experiencing Message Failures
We identified that a third-party app is stuck in a loop that has triggered billions of messages. This is causing free plan users to exceed messaging limits. We apologize for the inconvenience and will provide another update as soon as we have more details to share.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securit...
Zoom - Service Degradation Affecting user’s integration of Zoom app in 3P Calendar Services
Oct 1, 04:52 PDT Investigating - We are currently investigating a service degradation affecting users ability to add Zoom app in 3P Calendar Services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any
Box - [Medium] Issue with File Requests
Oct 1, 03:00 PDT Resolved - From approximately 2:50 AM to 3:30 AM PDT on Oct 01, 2026, we observed an issue impacting File Requests. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.
CircleCI - Delays starting Gen 2 Docker Jobs
Oct 1, 09:47 UTC Identified - We have identified the root cause and we are actively working on a fix. Thank you for your patience. Oct 1, 09:06 UTC Investigating - Customers may experience delays in starting Docker Gen 2 Jobs. We are working to increase the throughput of the system to accomodate this.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 1, 09:42 UTC Resolved - We are no longer seeing issues with Cloud SIEM Processing and normal operation has been restored at this time. Oct 1, 09:03 UTC Monitoring - We have implemented a fix for the issue affecting Cloud SIEM Processing. Log security records may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. Users may also experience d...
Wix - RESOLVED: Some Users Are Experiencing Issues With Multiple Services
Oct 1, 05:42 UTC Resolved - This incident has been resolved. Oct 1, 05:23 UTC Monitoring - Monitoring telemetry shows normal performance across all services. We are continuing to observe system metrics closely. Oct 1, 05:17 UTC Update - We are continuing to investigate this issue. Oct 1, 05:17 UTC Investigating - We are currently investigating this issue.
Confluence - Job processing and scheduling is degraded affecting multiple Atlassian products
Oct 1, 03:47 UTC Identified - Our teams have identified the root cause of this incident and is now actively working on mitigating the issue. We will provide further updates within an hour or sooner if we have any significant progress to share. Oct 1, 02:55 UTC Investigating - Job processing and job scheduling is degraded, which is affecting scheduled and asynchronous work across several products, including Jira, Confluence and Bitbucket Cloud.Affected users may see delayed or missing job ex...
Segment - Braze Web Event Delivery is experience event delivery issue
Sep 30, 20:30 PDT Investigating - The issue is reported by one customer. We are investigation this issue.
GitHub - [Retroactive] Actions workflow run failures after deployment gate approvals
Oct 1, 02:00 UTC Resolved - On October 1, around 02:00 UTC, an isolated infrastructure failure caused GitHub Actions to lose execution state for a small number of existing workflow runs. Affected runs may remain stuck, fail deployment approvals, or return errors when cancelled. Service connectivity has recovered, but the lost state cannot be restored by retrying an approval.If you're affected, you can trigger a new run or contact GitHub Support with links to your stuck runs so we can unblock t...
[CISA KEV] CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
Product: FortiMail by Fortinet Description: Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Azure - Active - Multiple services experiencing connectivity issues in multiple regions
Starting at 20:30 UTC on 30 September 2026, customers using ExpressRoute and VPN Gateway may have experienced degraded or interrupted network connectivity. Customers may also experience failures or delays with some network management operations.Current status: ExpressRoute gateways are showing significant recovery as of 22:35 UTC, and we continue to monitor service health to validate that recovery is sustained. We have paused infrastructure servicing activity associated with the onset of this ev...
Azure - Active - ExpressRoute Gateway - Multiple services experiencing connectivity issues in multiple regions
Starting at 20:30 UTC on 30 September 2026, customers using ExpressRoute and/or Azure VPN Gateway may experience degraded or interrupted connectivity. We are also seeing impact to components responsible for managing network gateways, which may affect some management operations. Our investigation has identified a correlation between the onset of impact and infrastructure ‘operating system’ servicing activity. During this activity, some network gateway instances became unhealthy or temporarily una...
Cybersecurity statistics of the week (September 21st - September 27th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between September 21st - September 27th. You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ Inside the SOC 2026 Creating a Mod...
Box - [Medium] Issue with User Engagement Reports
Sep 30, 11:53 PDT Update - Data recovery is progressing. User Engagement Reports and collaboration-related insights may continue to contain missing or outdated data while processing catches up. We are continuing to monitor recovery. Sep 30, 11:08 PDT Monitoring - We are monitoring an issue affecting User Engagement Reports and collaboration-related insights in the Admin Console. Some data may be missing or out of date. We have taken steps to restore data processing and are validating recovery...
MongoDB Atlas - Delays in Atlas cluster management operations
Sep 30, 18:51 UTC Investigating - We are investigating an issue with Atlas metrics ingestion that may delay cluster management operations, including cluster creation and modification.
Datadog - Delayed Events
Sep 30, 14:51 EDT Resolved - The issue is now resolved. Sep 30, 14:29 EDT Monitoring - We have deployed a mitigation and we are monitoring the results. Sep 30, 14:05 EDT Identified - We have identified the issue and are working on a mitigation strategy. Sep 30, 14:02 EDT Investigating - We are investigating increased latency processing Events generated by RUM, Trace Analytics, Service Checks, CI Visibility, Cloud Network Monitoring, and Error Tracking.As a result of this issue, some users...
Akamai - Akamai Control Center and Configuration Deployment Issues
Sep 30, 15:03 UTC Resolved - We became aware of an issue with Configuration Deployment and Akamai Control Center related to errors when activating delivery configurations in Property Manager and an inability to access Identity Manager in Akamai Control Center to manage users. The issue lasted between 14:13 UTC and 14:34 UTC on September 30, 2026. We can confirm that the issue is now resolved, and the service has resumed normal operation. Customers and partners can view additional details about ...
Asana - Partial API outage
Sep 30, 14:31 UTC Investigating - We are currently investigating this issue.
I taught my laptop to fake cyberattacks — and it's scarily good at it.
Meet log-generator: an open-source tool that spits out realistic SIEM logs so you can test your security stack without waiting for an actual breach to ruin your Friday. Just shipped a bunch of new toys: Attack Chains — replay full multi-stage attacks (recon → exploit → exfil), every step mapped to MITRE ATT&CK. Basically a "choose your own villain" adventure for your detection rules. Benchmark mo...
Optimizely - Optimizely Graph - All region's production clusters experienced failed stored queries
Sep 30, 13:57 UTC Monitoring - We have identified the root cause and applied a mitigation. The service has returned to normal operation and we are actively monitoring to confirm stability.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
I Want Better Reporting on AI Genie Behavior
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening. I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsib...
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way