In partnership with

AI research, explained in one morning email

Most of what shapes AI next year is sitting in a research paper today. Keeping up with them is a full-time job, and the abstracts don't help.

TLDR AI is the newsletter that does the translating. Each morning you get the handful of papers worth knowing about, curated by Anthropic and ex-Google engineers, with a plain-English summary of what they found and why it matters.

You come away smarter about AI research in the time it takes to finish your coffee.

Free, and delivered to 1.1M+ inboxes every morning.

Good morning. If your customers' perimeter is a NetScaler, a FortiMail, or both, today is a patching day. Edge appliances took three exploited-in-the-wild hits in about a week, and the rest of the news is a reminder that old servers and new AI plumbing both bite.

Citrix NetScaler gets a third exploited zero-day in under a week

Citrix patched CVE-2026-88779, a SAML memory overflow rated 8.7 (CVSS v4.0), after observing targeted attacks on unmitigated NetScaler ADC and Gateway appliances. On its own it looks like a crash-and-DoS bug, but researchers report attackers chaining it with one of the earlier RCE zero-days. CISA has added it to the KEV catalog.

Why it matters: If you manage NetScaler for clients, this is the third emergency change window in one week. Check which boxes are configured as a SAML service provider, patch, and review logs for the earlier exploitation too. Expect clients to ask why the VPN keeps showing up in the news.

FortiMail zero-day: unauthenticated file writes, CVSS 9.8

CVE-2026-104286 is a path traversal flaw that lets an unauthenticated attacker write arbitrary files to a FortiMail appliance with crafted HTTP or HTTPS requests. CISA added it to KEV on October 1 with a three-day federal deadline. Affected branches reported: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9. Fortinet's interim advice is to disable identity-based encryption or restrict the management interface, and it has published indicators of compromise.

Why it matters: Mail gateways are the appliance nobody revisits. Inventory them, apply the mitigation now, and hunt with Fortinet's IOCs before you assume you are clean.

Oracle Health's 2025 breach now tied to nearly 20 million people

Information released by the Texas attorney general on October 5 puts the Oracle Health (former Cerner) breach at nearly 20 million people, including roughly 3 million Texans, according to Bloomberg and others. Attackers reached legacy Cerner servers that had not been migrated to Oracle's cloud, using stolen customer credentials to copy data to a remote server. Earlier state filings counted far fewer people, so expect more revisions.

Why it matters: Two lessons for healthcare clients: legacy environments left behind after a migration are a liability, and stolen customer credentials still beat good perimeters. Ask clients which vendor-hosted systems they assume someone else is watching.

GitLab patches a 9.9 in its self-hosted AI Gateway

GitLab disclosed a critical flaw on October 2 in the AI Gateway component. An authenticated user with Duo Agent Platform access can craft a flow configuration that escapes the prompt template sandbox and runs arbitrary commands on the gateway. It is a template injection bug (CWE-1336) rated CVSS 9.9. CISA's assessment on the CVE record lists exploitation as "none" so far.

Why it matters: Self-hosted AI features are new attack surface that sits next to source code and secrets. If a client runs GitLab Duo on their own infrastructure, confirm the gateway is on a fixed version from GitLab's advisory.

Agent security gets its first real tooling

Bitdefender released a free public beta of AI Guardian for macOS, which checks what autonomous agents do before their actions take effect, aimed at prompt injection, tampered MCP tools and unauthorized credential access. A security roundup also notes Nvidia's Open Agent Safety Platform, built with 100+ partners to quarantine rogue agents, and a month heavy on coding-agent sandbox escapes.

Why it matters: Your clients' developers are already running coding agents. Agent governance is turning into a billable service line, and the free tools give you something to pilot before pricing it.

That is the edge-appliance fire drill for today. Patch the gateways, check the mail box nobody remembers, and go ask a healthcare client where their old servers went. See you tomorrow.

The ChannelBytes team

Keep Reading