Fortra disclosed eight vulnerabilities in its BoKS privileged-access manager, three of them critical and one rated CVSS 9.9. Because the predictable passwords can be verified offline, applying the fix does not retire service-account credentials an attacker may already hold.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Fortra patched CVE-2026-79901, a CVSS 9.9 BoKS keytab flaw that lets any authenticated Active Directory user rebuild Unix service-account passwords offline. Patching replaces the generator, but passwords it already minted stay predictable until rotated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Fortra researchers say the extortion crew likely read Dynamics 365 data straight out of portals where a table was exposed to the Anonymous Users web role.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.
Perspective Coverage
7 publishers
- Builder
- Builder 12%
- Operator
- Operator 79%
- Investor
- Investor 9%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence74
A record count that Microsoft's own AI bug-hunting produced arrives with two flaws already under attack, and the affected-product lists an operator would use to scope them are the part of the record two vendors read differently.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
Microsoft's September release addressed 972 CVEs, the largest count it has ever shipped. Within hours a researcher published a working proof-of-concept against CVE-2026-69414, the second fix for a Defender flaw first patched in July.
Reality
- Evidence48
- Adoption45
- Hype gap+22
- Incentives55
- Confidence52
A hunting signature Microsoft built to catch prompt injection in email started firing on ordinary phishing instead, where invisible tag characters were splitting lure words like "funding" so filters never parsed them.
Perspective Coverage
4 publishers
- Builder
- Builder 31%
- Operator
- Operator 60%
- Investor
- Investor 9%
Reality
- Evidence64
- Adoption72
- Hype gap+16
- Incentives74
- Confidence66