Security news from the BlueTeamSec community for Friday the 2nd of October 2026. Starting with something from CISA.
CISA have added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog — it's an unauthenticated path traversal in Fortinet FortiMail that leads to remote code execution. This one's actively exploited against public-facing email security gateways, and given we've just had the NetScaler zero-days last week, there's something of a pattern forming with enterprise security appliances. Patch to the latest minor release for your version, and lock down management interfaces to trusted addresses if you haven't already.
Belnet, Belgium's national research and education network, have published an update on a security incident from the 24th of September — someone exploited a zero-day in external supplier technology. They've contained it, patched the vulnerability, and deployed enhanced detection. Worth noting given the NetScaler timeline we've been following — there's a non-zero chance this is related, though they haven't confirmed the vendor.
FoxIO have released JA4Scan, which is essentially the successor to JARM for active server fingerprinting. It sends seventeen crafted Client Hello probes to TLS and QUIC servers and builds a fingerprint of the implementation. Useful for attributing C2 infrastructure or spotting threat actor servers based on their TLS stack. One for threat hunters and incident responders who need to track infrastructure at scale.
devZero Security have put out redStackPRO — it's a web-based canvas tool for designing red team infrastructure and cyber ranges, then exporting the whole lot as Terraform and Ansible. The interesting bit from a defensive perspective is that tool-generated infrastructure tends to produce consistent signatures, so knowing what legitimate red team tooling looks like can help you distinguish authorised testing from the real thing.
And finally, David Chisnall has written up the design philosophy behind CHERIoT's compartments and libraries — it's about when to use hardware-backed isolation versus treating components as trusted utilities in embedded systems. Adds useful context if you're working with capability-based architectures or evaluating isolation models for constrained devices.
That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated.