Last Week in Tech for Monday 5 October 2026, covering the week from 27 September. Citrix NetScaler zero-days (27 Sep). CVE-2026-88771 (unauthenticated command execution, all deployments including default config) and CVE-2026-88772 (memory overflow, RCE when DTLS is on — the VPN default). Citrix: CVSS v4.0 9.5 for both. Fixed in 14.1-73.37, 13.1-64.23 and FIPS/NDcPP builds; 12.1 and 13.0 are end-of-life with no patch. CISA KEV 27 Sep, deadline 30 Sep. Mandiant: exploitation since at least 3 Sep, "dozens" of victims across government, finance, technology, education and professional services; suspected state-sponsored actors using the WHIPSHOT web shell and SLAPSHOT tunneller. Public PoC 28–29 Sep. ASD's ACSC alert 28 Sep, later updated: Australian organisations have confirmed exploitation; hunt back to 4 Sep. Patching does not remove existing web shells. Cisco Catalyst SD-WAN Manager (30 Sep). CVE-2026-76504, unauthenticated API authentication bypass to admin, CVSS v3.1 9.8 per Cisco, exploited in the wild, no workaround. Fixed in 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. CISA KEV 30 Sep. FortiMail zero-day (1 Oct). CVE-2026-104286, unauthenticated arbitrary file write via path traversal in the web interface's identity-based encryption (IBE) component, CVSS v3 9.8 per Fortinet, exploited in the wild. Affects 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9. Fixes 8.0.2, 7.6.7 and 7.4.9 were still "upcoming" at 3 Oct; 7.2 must migrate. Fortinet's workarounds: disable IBE, or block internet access to the FortiMail webmail interface. CISA KEV 1 Oct, deadline 4 Oct. Apple CoreGraphics zero-day (28 Sep). CVE-2026-86950, out-of-bounds write; fixed in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1. Apple: exploited in "an extremely sophisticated attack against specific targeted individuals" on iOS before 27. Reported by Meta Product Security. Crash PoC (PDF with crafted font) published 30 Sep (US). No vendor CVSS score. Microsoft Digital Defense Report 2026 (1 Oct). Median time from in-the-wild discovery to weaponisation "well below 24 hours"; AI used for personalised phishing, custom malware and faster data theft; government the most-targeted sector at 27%. AI price war. OpenAI DevDay (29 Sep): GPT-6.1 Sol at about one-fifth of flagship token prices (US$2/US$10 per million input/output); always-on "Dots" agents (off by default for enterprise); ChatGPT in Slack and Teams; Codex Security Cloud; Pro 500 at US$500/month. Google Gemini 4 Argon (30 Sep US): vetted cyber defenders first, broad release to follow; introductory US$2/US$10 per million tokens. Anthropic draft prospectus (Reuters, 28 Sep). Reported 2025 revenue ~US$4.6bn, net loss ~US$42bn (mostly non-cash), compute costs US$7.33bn, US$518bn infrastructure commitments; valuation target above US$2tn. Draft figures; Anthropic declined to comment. Disclosure: this podcast is produced with help from an Anthropic model. OFX Group (2 Oct). ASX-listed payments company investigating unauthorised access to data including some client and job-applicant data; no access to accounts or funds identified; ACSC, OAIC and overseas regulators notified; client numbers not yet known. Coming up: Wednesday, Stake and the DriveWealth breach. Friday, Fakturownia — 600,000 businesses' invoicing data. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Citrix CTX697096; CISA KEV; Mandiant; ASD's ACSC; BleepingComputer; Help Net Security; CyberScoop; Tenable; Cisco; Rapid7; Fortinet FG-IR-26-175; The Hacker News; Microsoft; OpenAI; Google; VentureBeat; Reuters; Fortune; OFX ASX announcement.