The three stories logged on this beat recently share one thread: attackers are not breaking in so much as walking in through known, patchable flaws in internet-facing software. Warlock's campaigns, a GitLab AI Gateway flaw, and an actively exploited FortiMail bug all point to the same operational reality, that the vulnerable window between disclosure and patching is now the primary attack surface. For US technology companies, that shifts the burden from threat hunting to patch discipline, and it raises hard questions about how much of their critical infrastructure still depends on systems they cannot quickly fix.
Known Flaws, Not Novel Exploits
The Warlock activity, as BleepingComputer reported, involved a China-linked ransomware group hitting a water utility, a telecom operator, a regional government body, and a university. The initial access vector in every case was exploitation of SharePoint vulnerabilities. That is not a zero-day chain. That is a widely deployed Microsoft product with known flaws being used to cross into organizations that hold sensitive operational and personal data. The variety of victims matters: a water utility and a telecom operator are not typical ransomware targets chosen for a quick payout. They are targets chosen because they run internet-exposed SharePoint and because disruption there has consequences beyond the affected organization. US utilities, carriers, and public agencies run the same class of software. The lesson is not that SharePoint is uniquely broken. It is that the same enterprise collaboration layer that US firms rely on for daily operations is also the first door attackers try.
The Vendor Warning Becomes the Starting Gun
GitLab's warning about a critical AI Gateway vulnerability, also via BleepingComputer, illustrates the second half of the pattern. The company told customers to patch immediately because the flaw could let attackers run arbitrary commands on vulnerable instances. The phrase describes the highest-severity category of remote code execution. Once a vendor publishes that warning, the clock starts. Defenders get a narrow head start; attackers get a map. There is no evidence in the reporting that this particular flaw was exploited in the wild, but the reason vendors issue urgent advisories is precisely that the gap between disclosure and exploitation has collapsed for internet-facing services. For US technology companies running AI gateways and similar newer infrastructure, the practical question is whether their patch pipelines can move as fast as the advisory cycle. Many cannot, because the people who own those systems are the same people shipping features.
Active Exploitation Is the New Normal
Fortinet's warning about a critical FortiMail flaw, tracked as CVE-2026-104286, goes one step further. According to BleepingComputer, the vulnerability is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. That is the clearest signal in this set: the flaw was being used before defenders had a fix. FortiMail sits at the email gateway, which means a compromised appliance can expose mail flow, credentials, and downstream systems. US enterprises and service providers run large fleets of security appliances like this precisely because they are trusted to sit at the perimeter. When one is exploited in zero-day fashion, the trust model inverts. The device meant to filter threats becomes the entry point. The pattern across all three stories is that the exploited components are not exotic. They are the security and collaboration products that US organizations bought to reduce risk.





