The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
FortiMail Zero-Day File Write Hits KEV Ahead of Saturday
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Friday, October 2, 2026. CISA put a critical Fortinet FortiMail path-traversal and null-byte bug on Known Exploited Vulnerabilities Thursday after confirming active exploitation. C V E twenty twenty-six dash one hundred four thousand two hundred eighty-six is a nine point eight. An unauthenticated attacker who can reach the management plane over H T T P or H T T P S writes arbitrary files on the underlying system. Fortinet says it has been hit in the wild. Federal civilian agencies have until October fourth. Affected trains include eight point zero through eight point zero point one, seven point six through seven point six point six, seven point four through seven point four point eight, and seven point two through seven point two point nine. Until the fixed builds land, disable I B E encryption support and pull the FortiMail management interface off the open internet. Hunt the I O Cs Fortinet published: rogue I Ps, a fresh liblog dot s o under slash data slash lib, webconsole and mailservice binaries, and a rewritten ld dot s o dot preload. Your secure mail appliance just became someone else's drop box. WIRED reports Objective-See found a patched flaw in OpenAI's ChatGPT macOS app that could let local malware take over the client. The payoff is every chat log, stored file, and connected browser session the app can see. Patrick Wardle calls agents the building manager with keys to every room. Corrupt that manager and unprivileged code suddenly looks trusted. ChatGPT's components check digital signatures across parent and grandparent processes before they talk to each other. Attackers bypassed that by spawning the trusted script interpreter three times, then feeding it an untrusted command list. Wardle says the proof of concept was about a dozen lines. OpenAI fixed it in the September twenty-fifth change log and says it needs to move faster on security. Your months of proprietary code and private plans in that chat history are a juicier target than most browser extensions. Update the Mac app if you have not already. Spanish police in Alicante arrested a sixteen-year-old on September thirtieth whom Hamburg investigators call KillSec's suspected main administrator. Two others in their twenties were detained the same day in the U K and Romania. Police seized the leak site, at least one hundred ten terabytes of victim data, five servers, and five domains. The joint operation pulled in Europol, Eurojust, the F B I's San Juan office, Bitdefender, and Group-I B. KillSec is blamed for roughly one thousand suspected attacks and about five hundred confirmed hits, with Spanish police counting more than two hundred eighty victims. The group stole data through software flaws and weak cloud access, then extorted victims on a dark web leak site. Investigators say it also used A I to build infrastructure and pick targets. Hamburg police describe the three arrests as provisional and say the hunt for other members continues. Ransomware-as-a-service with a teenage ops lead is not the future anyone wanted, but it is the one that just got a hotel office in Alicante searched. OpenAI has parted ways with three safety-team researchers after an internal investigation found they mishandled sensitive company information, the Wall Street Journal reported. Named are Jasmine Wang, Tomek Korbak, and Mikita Balesni. All three had raised concerns about the pace of A I development. OpenAI says they shared confidential material with a third-party A I-safety group
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472