Pentagon Data Breach Exposes Millions of PII, Fortinet and Apple Zero-Days Exploited
A Pentagon data breach exposed unencrypted personal information of over 3 million individuals, while actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail were patched.

A significant cybersecurity newsletter this week highlighted a major data breach at the Pentagon, impacting over three million individuals due to a file-sharing vulnerability. The breach, which occurred between October 2025 and July 2026, exposed unencrypted personal information including names, Social Security numbers, and birth dates. While the Pentagon reported no evidence of misuse, affected individuals are being offered credit monitoring services.
In parallel, Apple released urgent security updates for iOS and iPadOS to address CVE-2026-86950, a critical CoreGraphics zero-day vulnerability. This flaw, which could allow arbitrary code execution through a maliciously crafted file, was reportedly exploited in sophisticated attacks targeting specific individuals. The update, iOS/iPadOS 26.7.1, is available for iPhone 11 and later models, as well as supported iPads.
Fortinet also issued a warning regarding CVE-2026-104286, a critical FortiMail vulnerability with a CVSS score of 9.8, which is actively being exploited in the wild. This unauthenticated flaw allows attackers to write arbitrary files by combining path traversal and improper NULL-byte handling. Affected versions span multiple release lines of FortiMail, and administrators are advised to disable IBE support or restrict management interface access while investigating for signs of compromise.
Adding to the critical vulnerabilities, two undisclosed remote-code-execution (RCE) flaws in Citrix NetScaler were reported by security firm watchTowr. While Citrix had not yet issued an official advisory or CVE identifiers at the time of reporting, the vulnerabilities were allegedly exploited in real-world attacks. Organizations using NetScaler are urged to inventory their instances, reduce public exposure, and preserve logs for forensic analysis.
The newsletter also touched upon broader developments in AI security, including Anthropic's Claude Compliance API offering visibility into AI agent activity, and the launch of OpenClaw Enterprise for governing AI agents. However, a concerning report emerged about a Claude Code user allegedly losing over 48,000 project files due to an agent malfunction, underscoring the risks associated with AI performing destructive operations.
These developments underscore a busy week in cybersecurity, marked by significant data exposures, actively exploited zero-day vulnerabilities in widely used software and hardware, and emerging concerns surrounding the security implications of rapidly advancing AI technologies. The combination of nation-state-level data breaches and sophisticated attacks on critical infrastructure components highlights the persistent and evolving threat landscape.