FortiMail Zero-Day, Dell CSM Flaws, and Microsoft's Hijacked X Account
Fortinet confirms a FortiMail zero-day under active exploitation, Dell patches six critical Container Storage Module flaws, and chained Zammad bugs reach root. Plus, Microsoft's X account promotes a fake Clippy token and a WordPress backdoor rebuilds itself after cleanup.
Dell CSM Flaws Hand Attackers Storage Admin Control
Dell has released fixes for six critical vulnerabilities in its Container Storage Modules (CSM), the components that connect Kubernetes clusters to Dell enterprise storage.
What You Need to Know
Two of the six flaws are rated maximum severity and let an unauthenticated remote attacker take administrative control of enterprise storage infrastructure. The other four lead to root on cluster nodes, forged admin tokens, and cluster-wide read access to Kubernetes Secrets. If you run Dell CSM with Kubernetes, find your affected deployments and upgrade to version 1.18.0 or later.
What's Vulnerable
Dell CSM extends Kubernetes Container Storage Interface functionality for Dell PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT storage platforms. The two worst flaws are in its Authorization module. CVE-2026-63688 is a missing authentication flaw. An unauthenticated attacker can use it to retrieve backend administrator credentials for every registered storage array, bypass authorization controls, and take full administrative control of the storage infrastructure. CVE-2026-63692 affects the authorization proxy and tenant service and lets an unauthenticated attacker bypass authentication and gain administrative access to the authorization service.
The other four are also rated critical. CVE-2026-67269 may let unauthenticated remote attackers get root access on Kubernetes cluster nodes. CVE-2026-54472 could give administrative access to the CSM Authorization proxy. CVE-2026-61421 may let attackers forge authentication tokens and gain administrative privileges, and CVE-2026-67273 can bypass Kubernetes access controls to give cluster-wide read access to Kubernetes Secrets.
Why This Matters
An attacker who can reach one CSM component has several routes from there: into the Kubernetes control plane, onto the cluster nodes, into the secrets store, and up to the storage administration layer. In a multi-tenant Kubernetes environment, CVE-2026-63692 alone could allow unauthorized access to and manipulation of storage resources across tenants. These Dell platforms often hold the persistent data behind container workloads, so a compromise here reaches the data itself and not just the cluster.
What To Do
Inventory every CSM Authorization deployment, determine whether the authorization proxy or tenant service is exposed to untrusted networks, and confirm that version 1.18.0 or later is deployed. After updating, rotate storage backend administrator credentials, Kubernetes service-account tokens, and any other secrets that vulnerable instances may have exposed. Then review CSM, Kubernetes API, and storage-array logs for unauthorized administrative activity.Patching closes the door, but credential rotation is what locks out anyone who may have already walked through it.
Microsoft's X Account Hijacked to Pump a Fake Clippy Token
Attackers took over Microsoft's official X account and used it to promote an unauthorized cryptocurrency token named after Clippy, the company's former virtual assistant.
What You Need to Know
For a brief window, @Microsoft pointed its more than 13 million followers at a $Clippy token in an apparent pump-and-dump scheme. Microsoft has confirmed the compromise, removed the posts, and secured the account. It is still investigating how the attackers got in. The incident shows how quickly one trusted corporate account can be turned into a fraud distribution channel.
What Happened
Attackers hijacked @Microsoft and used it to follow and repost content from @clippymsftcto, a now-suspended account impersonating Clippy, which gave the fake profile instant credibility. A second account, @ClippyMSFT, kept promoting the token and claimed it had a liquidity pool paired with $MSFT. Microsoft said it has not authorized, sponsored, endorsed, or permitted any cryptocurrency token connected to Clippy, Microsoft, or its stock symbol, and that it plans to pursue legal action to remove the token and related materials.
Microsoft has been here before. In June 2024, attackers compromised the Microsoft India X account to impersonate meme-stock trader Keith Gill, also known as Roaring Kitty, and sent users to a fake GameStop cryptocurrency presale site built to steal assets from connected wallets. Compromised verified X accounts are regularly used to promote fraudulent crypto projects, wallet drainers, and market-moving misinformation. One well-known case was the January 2024 takeover of the U.S. Securities and Exchange Commission's X account through SIM swapping, when attackers posted a false Bitcoin ETF approval announcement that briefly moved Bitcoin's price.
Why This Matters
Even a short-lived post from a major brand carries that brand's legitimacy, and attackers are counting on it. Borrowed trust drives speculative trading and gets victims to token-sale or wallet-connection pages before anyone stops to question it. For organizations, this cuts both ways: your own high-visibility accounts are attractive targets, and your users and employees can be fooled by someone else's compromised account.
What to Do
Treat unexpected cryptocurrency promotions, token launches, or investment claims from verified corporate accounts as potentially compromised until you confirm them through official corporate channels. For your own organization, protect high-visibility social media accounts with phishing-resistant MFA, limit who holds administrative access, monitor recovery settings, and keep incident procedures that support fast account recovery and public correction.
Social media accounts are part of your attack surface. Lock them down like any other privileged account.
FortiMail Zero-Day Is Being Exploited Now
Fortinet has disclosed an actively exploited critical vulnerability in FortiMail, its email security appliance, and published indicators from observed compromises.
What You Need to Know
A CVSS 9.8 flaw in the FortiMail management interface lets unauthenticated remote attackers write arbitrary files to the appliance, and attackers are already using it. Successful exploitation can lead to command execution, persistence, and access to the mail data the device handles. CISA has added the flaw to its Known Exploited Vulnerabilities catalog. Fixes are not yet available for every affected branch.
What's Vulnerable
CVE-2026-104286 comes from path traversal and improper handling of NULL characters. Crafted HTTP or HTTPS requests to the management interface trigger it. Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
Fortinet's indicators from observed compromises include:
- Newly created files: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload
- Modified files: /bin/smit, /data/etc/httpd.conf, /data/migadmin.tar.gz
- IP addresses: 79.141.169.187, 45.129.0.192
One observed log entry shows the creation of an archive account configured to transfer archived data to 79.141.169.187.
Why This Matters
Fortinet has confirmed active exploitation but hasn't attributed it or said how large the campaign is or how long it has run, so it's unclear how long exposed appliances may have been targeted. An archive account sending data to an attacker-controlled IP points to possible data staging or exfiltration, which is a serious problem on a device that sits in the middle of your mail flow. CISA has given federal agencies until October 4 to complete forensic triage and mitigation.
What to Do
Upgrade FortiMail 7.2 deployments to the 7.4 branch or later. Fixes for the other affected branches are expected in FortiMail 7.4.9, 7.6.7, and 8.0.2. Until they ship, disable identity-based encryption (IBE) using the vendor-provided configuration command. If you don't need internet-exposed management, remove public access to the FortiMail administrative interface and limit management to trusted private networks.
Treat any exposed FortiMail appliance as potentially compromised. Hunt for the published file and log indicators, review changes to administrator and archive-account configuration, and rotate credentials or secrets stored on systems the appliance may have been able to reach. When a mail gateway is the target, assume the attacker wanted the mail and investigate with that in mind.
The WordPress Backdoor That Rebuilds Itself
Researchers have uncovered a WordPress backdoor dubbed SC that spreads its payload across site files, the database, and server memory so it can restore itself after cleanup.
What You Need to Know
SC has at least eight interconnected components, and any surviving copy can rebuild the others after you remove a file, plugin, or database entry. That makes an SC infection a persistent, system-level problem that can't be fixed by deleting one malicious file. Removing the pieces you find won't get rid of it, so remediation means a full compromise investigation.
How It Works
The backdoor gets execution through several WordPress loading mechanisms: a .user.ini file configured with auto_prepend_file, malicious db.php and advanced-cache.php drop-ins, a compromised theme functions.php file, and duplicate fake plugins named hyper-engine-kit. The payload is encoded and compressed to slow down analysis, and it uses a substitution cipher to obscure function names. On servers that support System V shared memory, SC also stores PHP code in RAM under a fixed numeric key, so it survives file deletion and database cleanup. Scheduled WordPress cron activity can then restore removed components without the attacker needing new access.
Once active, SC hides from the WordPress administration interface and update checks, creates hidden administrator accounts, fingerprints the compromised site, and retrieves additional payloads through a command-and-control channel that runs over the Ethereum blockchain. Operators can execute arbitrary PHP, inject their own JavaScript into pages, deploy payment skimmers or other browser-based malware, and turn off selected plugins.
Why This Matters
Most WordPress cleanup playbooks assume the infection lives in files you can find and delete, and SC is designed around that assumption being wrong. The shared-memory copy is especially hard to remove on shared hosting, where the segment may be retained or owned by another account and stay out of the site owner's reach. Add blockchain-based command and control and the ability to drop payment skimmers, and a site that looks clean can keep serving malicious code to visitors.
What to Do
Take the affected site offline or restrict public access, and preserve forensic evidence before you change anything. Rebuild the WordPress environment from verified clean sources instead of cleaning it in place. Rotate WordPress, hosting, database, SSH, API, and administrator credentials. Review server-level cron jobs, PHP configuration, shared-memory segments, database options, plugin directories, themes, and administrator accounts.
To reduce the chance of reinfection, update WordPress core, themes, and plugins, and remove anything you aren't using. Likely initial access paths include known vulnerabilities, weak credentials, compromised plugins, and insecure upload functionality.
Zammad Flaws Chain to Root on Helpdesk Servers
Two critical vulnerabilities in Zammad, the open-source helpdesk platform, can be chained to give attackers remote code execution and then root access on the underlying server.
What You Need to Know
An attacker can hijack a session to run commands as the Zammad service account, then escalate to root. The Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security found the flaws while investigating a September 21 intrusion on DIVD's own infrastructure, which DIVD says played out within seconds. If you run Zammad 6.3.0 through 6.5.4, restrict public access and upgrade now.
What's Vulnerable
CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4 and allows session hijacking that can lead to remote command execution as the Zammad service account. That account usually has access to application files, ticketing data, databases, logs, credentials, and the services the platform needs to run. The same vulnerable code reportedly exists in versions 7.0.0 through 7.1.3.
CVE-2026-102490 is a local privilege escalation flaw affecting Zammad 1.5.0 through 7.1.0-alpha. Once an attacker has code execution as the Zammad account, this flaw lets them escalate to root. From there they can keep persistent access, tamper with logs, steal credentials, reach other local data, and move into connected systems.
Why This Matters
Helpdesk platforms hold much of what attackers are after: customer tickets, credentials, internal conversations, attachments, and operational details. An internet-facing Zammad deployment puts all of it one exploit chain away from root. DIVD attributed the speed of the intrusion it observed to an agentic AI-powered workflow, which leaves defenders less time between exposure and compromise. Releases 7.0.0 through 7.1.3 are not believed to be exploitable because of runtime-environment differences, but the vulnerable code is still there, and the privilege escalation flaw spans nearly every release line.
What to Do
If you run Zammad 6.3.0 through 6.5.4, restrict public access to the application now, preserve web-server, application, authentication, and host-level logs, and upgrade to a supported version. Zammad 7.2.0 includes mitigations for the vulnerable session-handling code. Moving to version 7 also removes the legacy environmental conditions that make remote exploitation viable in 6.x deployments.
Rotate Zammad, database, API, SMTP, integration, and system credentials that may have been exposed. Review active sessions, administrator accounts, plugins, scheduled tasks, and command-execution logs, and look for signs of post-exploitation activity. When an intrusion takes seconds, close off exposure before the next attempt.
Our Threat Intelligence Team monitors emerging vulnerabilities and adversary activity, like what's covered in these articles, across federal and commercial environments. To learn how our Managed Security Services can help protect your organization, visit our Managed Security Services page.