
Cybersecurity Threat Report — October 2026
August was 2026's worst ransomware month, more gangs now steal data without encrypting it, and attackers exploited Citrix, Check Point, SonicWall and ScreenConnect gear in September. This edition covers the threats, the patches that can't wait and an eight-step plan for businesses with 10–250 employees.
Bottom line
Threat level: Elevated. Ransomware hit a 2026 high in August, and attackers exploited edge devices that small offices run in September. Most of the fixes cost little.
If you do only three things
- Patch the edge this week. Citrix NetScaler, Check Point gateways and Spark firewalls, SonicWall SMA 1000, Fortinet FortiOS and ConnectWise ScreenConnect all have exploited flaws.
- Audit vendor access. List every app, plug-in and API key that can reach your data, and remove what you don't use.
- Verify payments by phone. Confirm any bank-detail change on a number you already have on file.
Ransomware and extortion
964 victims were claimed on leak sites in August, up 19% on July and the highest month of 2026 (Breachsense, Sep 2026). Qilin led with 157 claims, followed by The Gentlemen with 127. More crews now steal data instead of encrypting it: Coveware found only 15% of victims paid when data was stolen but not encrypted (Q2 2026), and Coalition reports data-theft ransomware claims cost more than twice as much.
AI threats and wire fraud
KnowBe4 reports 86% of phishing is now AI-driven, with reverse-proxy Microsoft 365 login theft up 139% in six months. CrowdStrike says phone-based intrusions doubled. Business email compromise cost $3.04B in 2025 (FBI IC3), and 61% of these attacks now pose as a trusted vendor (Abnormal AI, 2026). IBM's 2026 study found shadow-AI incidents at 43% of breached firms, up from 20%.
Breaches to learn from
- Brevo: a leaked key let attackers plant fake "verify you're human" pop-ups on 100,000+ websites.
- BigCommerce: stolen app logins injected scripts into online stores.
- ShipMonk: a vendor said it had deleted customer data but hadn't; 67,000 more people were exposed.
- Fake IT help-desk calls tricked staff into giving up Microsoft 365 logins.
Patches that can't wait
| Product | Flaw | Added to CISA KEV |
|---|---|---|
| Citrix NetScaler ADC / Gateway | CVE-2026-88771 / 88772 | Sep 27 |
| Check Point Gateway & Spark | CVE-2026-85102 | Sep 22 |
| ConnectWise ScreenConnect | CVE-2026-84869 | Sep 11 |
| Fortinet FortiOS | CVE-2025-25249 | Sep 9 |
| Microsoft Windows | CVE-2026-81963 | Sep 8 |
| SonicWall SMA 1000 | CVE-2026-83548 | Sep 2 |
What changed
Paid Windows 10 security updates for business PCs reach the end of year one on Oct 13. CMMC Phase 2 is paused. The CIRCIA incident-reporting rule is still pending. Delaware's privacy law now applies from 10,000 consumers. Cyber insurance rates fell for a 12th straight quarter (Marsh, Q2 2026).
Your 8-step action plan
- Patch internet-facing gear this week.
- Use phishing-resistant MFA everywhere.
- Verify every payment change by phone.
- Review third-party apps and API keys.
- Approve one AI tool for staff.
- Alert on large data transfers.
- Keep offline, tested backups.
- Settle the Windows 10 plan.
The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF
Discuss the security controls behind the headlines.
Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.
