Attackers abusing trusted customer channels, critical infrastructure flaws, and Microsoft products reaching end of support.
ASOS has confirmed unauthorised activity involving third-party platforms used to communicate with customers, after an extortion message was sent through the retailer’s own app.
In this edition, our SOC team focus on what the incident reveals about the identities and integrations trusted to reach customers, and the authority they carry across connected systems.
Also: Microsoft’s busiest retirement date of the year, Citrix NetScaler zero-days exploited for root access, a FortiMail zero-day, and a critical flaw in Dell’s update tooling.
How attackers turned the ASOS app into an attack channel
On 6 October, thousands of ASOS customers received an “ASOS HACKED” push notification through the retailer’s app. Xuanye Group claimed to have compromised ASOS’s Snowflake instance and threatened to leak data unless the company engaged.
ASOS confirmed unauthorised activity involving third-party customer communication platforms and said names and contact details may have been accessed. It does not believe payment-card information or passwords were affected. Snowflake found no compromise of its platform, leaving the precise route unresolved.
The important detail is that the attackers could send a message through ASOS’s customer notification channel. That suggests a service account, API key or integration held more authority than its function required.
Kocho’s Anna Webb commented: “The critical question is how much authority a compromised identity has and which systems it can reach. Privileged access can accumulate across employees, third parties, service accounts and applications. Organisations need to map those access paths, remove unnecessary standing privileges and prevent one compromised identity providing a route into multiple parts of the business.”
For organisations concerned about similar incidents impacting them, we’d recommend starting with three checks:
- Map every identity and integration that can write to customer communication channels
- Restrict each to the permissions its function requires
- Define who can authorise customer-facing messages
New Webinar
What do high-performing security teams do differently?
Security operations teams face growing pressure to detect threats earlier, respond faster and demonstrate value, often while managing limited resources.
This webinar explores the people, processes and technologies that help high-performing security operations teams build stronger detection and response capabilities.
Also in the news
Microsoft’s October retirements leave unsupported products exposed
On 13 October, support ends for Office 2021, Windows 11 Home and Pro version 24H2, and the final year of Extended Security Updates for Windows Server 2012 and 2012 R2. The products will continue to run but will no longer receive security updates.
Identify affected products still in use and put a funded migration or support decision in place before the deadline.
Citrix NetScaler exploitation makes patching only the first step
Attackers have exploited CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway since early September, gaining root access and planting web shells across several sectors. Both flaws carry a CVSS score of 9.5 and appear in CISA’s Known Exploited Vulnerabilities catalog.
Patch affected appliances, rotate credentials and investigate for compromise. An unexplained AAA or Gateway crash may be a warning sign, and applying the update does not confirm an appliance is clean.
FortiMail exploitation began before every affected branch had a fix
Fortinet has disclosed CVE-2026-104286, a critical path-traversal flaw in FortiMail that attackers are using to write arbitrary files to appliances. Fixed builds were not available for every affected branch when the vulnerability was disclosed.
Apply Fortinet’s guidance or restrict access to the management interface until a fixed build is available. Review appliance integrity rather than treating the update alone as evidence that the incident is closed.
Dell update-tool flaw gives attackers a route to root access
Dell has patched CVE-2026-86360, a critical path-traversal vulnerability in Dell System Update that allows an unauthenticated remote attacker to execute code with root privileges. It also fixed four other high-severity flaws in the tool and two maximum-severity Container Storage Modules vulnerabilities.
Upgrade Dell System Update to version 2.3.0.0 or later and confirm that PowerEdge servers have received the update.
This month’s priority actions
References and Resources
The Guardian: Asos warns customer data may be compromised after ‘unauthorised’ app access
NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Infosecurity Magazine: Citrix NetScaler Targeted Via New Zero Day
Microsoft Learn: Ending support in 2026 (Microsoft Lifecycle)
Softwr: The 13 October 2026 Cliff: Everything Microsoft Retires On One Day
CISA: CISA Adds One Known Exploited Vulnerability to Catalog (FortiMail CVE-2026-104286)
BleepingComputer: New Dell System Update flaw lets hackers gain root privileges
With thanks to the Kocho Security Operations Centre (SOC) team.
Stay safe. Stay informed.
Get cyber confident
Real partnership. Microsoft expertise. Complete transparency.
Request a call back today.
- AI-powered rapid protection, from day one
- Dedicated Microsoft experts, by your side
- Powerful, intuitive reporting tools
- Collaboration and transparency as standard
Got a question? Need more information?
Our expert team is here to help.