Cybersecurity News: October 2026 | Kocho
Skip to content
Funnel overlay image

Cybersecurity Roundup October 2026

arrow icon arrow icon

From Kocho’s Security Operations Centre (SOC)

Published: 07 October 2026

Attackers abusing trusted customer channels, critical infrastructure flaws, and Microsoft products reaching end of support.

ASOS has confirmed unauthorised activity involving third-party platforms used to communicate with customers, after an extortion message was sent through the retailer’s own app.

In this edition, our SOC team focus on what the incident reveals about the identities and integrations trusted to reach customers, and the authority they carry across connected systems.

Also: Microsoft’s busiest retirement date of the year, Citrix NetScaler zero-days exploited for root access, a FortiMail zero-day, and a critical flaw in Dell’s update tooling.

How attackers turned the ASOS app into an attack channel

On 6 October, thousands of ASOS customers received an “ASOS HACKED” push notification through the retailer’s app. Xuanye Group claimed to have compromised ASOS’s Snowflake instance and threatened to leak data unless the company engaged.

ASOS confirmed unauthorised activity involving third-party customer communication platforms and said names and contact details may have been accessed. It does not believe payment-card information or passwords were affected. Snowflake found no compromise of its platform, leaving the precise route unresolved.

The important detail is that the attackers could send a message through ASOS’s customer notification channel. That suggests a service account, API key or integration held more authority than its function required.

Kocho’s Anna Webb commented: “The critical question is how much authority a compromised identity has and which systems it can reach. Privileged access can accumulate across employees, third parties, service accounts and applications. Organisations need to map those access paths, remove unnecessary standing privileges and prevent one compromised identity providing a route into multiple parts of the business.”

For organisations concerned about similar incidents impacting them, we’d recommend starting with three checks:

  • Map every identity and integration that can write to customer communication channels
  • Restrict each to the permissions its function requires
  • Define who can authorise customer-facing messages
tag icon

New Webinar

What do high-performing security teams do differently?

Security operations teams face growing pressure to detect threats earlier, respond faster and demonstrate value, often while managing limited resources.

This webinar explores the people, processes and technologies that help high-performing security operations teams build stronger detection and response capabilities.

Also in the news

Microsoft’s October retirements leave unsupported products exposed

On 13 October, support ends for Office 2021, Windows 11 Home and Pro version 24H2, and the final year of Extended Security Updates for Windows Server 2012 and 2012 R2. The products will continue to run but will no longer receive security updates.

Identify affected products still in use and put a funded migration or support decision in place before the deadline.

Citrix NetScaler exploitation makes patching only the first step

Attackers have exploited CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway since early September, gaining root access and planting web shells across several sectors. Both flaws carry a CVSS score of 9.5 and appear in CISA’s Known Exploited Vulnerabilities catalog.

Patch affected appliances, rotate credentials and investigate for compromise. An unexplained AAA or Gateway crash may be a warning sign, and applying the update does not confirm an appliance is clean.

FortiMail exploitation began before every affected branch had a fix

Fortinet has disclosed CVE-2026-104286, a critical path-traversal flaw in FortiMail that attackers are using to write arbitrary files to appliances. Fixed builds were not available for every affected branch when the vulnerability was disclosed.

Apply Fortinet’s guidance or restrict access to the management interface until a fixed build is available. Review appliance integrity rather than treating the update alone as evidence that the incident is closed.

Dell update-tool flaw gives attackers a route to root access

Dell has patched CVE-2026-86360, a critical path-traversal vulnerability in Dell System Update that allows an unauthenticated remote attacker to execute code with root privileges. It also fixed four other high-severity flaws in the tool and two maximum-severity Container Storage Modules vulnerabilities.

Upgrade Dell System Update to version 2.3.0.0 or later and confirm that PowerEdge servers have received the update.

This month’s priority actions

Map which identities and service accounts can write to customer-facing notification channels, confirm they hold only the access required, and define who can authorise customer messages.

Ebony and green magnifying glass tick icon on transparent background

Identify any Office 2021, Windows 11 24H2 Home or Pro, and Windows Server 2012 or 2012 R2 still in use, then commit to migration or an Extended Security Updates decision before 13 October.

Ebony and green tickets on transparent background

Patch Citrix NetScaler, apply Fortinet’s FortiMail mitigations and fixed builds, and update Dell System Update to version 2.3.0.0 or later. Rotate NetScaler credentials and investigate affected appliances for compromise rather than relying on patch status alone.

tag icon

Get cyber confident

Real partnership. Microsoft expertise. Complete transparency.

Request a call back today.

  • AI-powered rapid protection, from day one
  • Dedicated Microsoft experts, by your side
  • Powerful, intuitive reporting tools
  • Collaboration and transparency as standard

Butterfly overlay image

Got a question? Need more information?

Our expert team is here to help.