News
ASOS Data Breach: Names and Contact Details Accessed
A big UK retailer had its own app used against its customers this week, and the follow-up phishing is the part small firms should plan for. There are also two more exploited flaws in kit that sits on the edge of a company network, one of them a fresh NetScaler bug that last week’s patch does not fix, and the data protection regulator has opened a call for evidence on AI agents.
ASOS: customer names and contact details accessed
Some ASOS customers received an unauthorised push notification from the ASOS app on Tuesday 6 October. ASOS says it is investigating, that customers’ names and contact details have been accessed, and that it does not believe payment card details or account passwords were affected. The NCSC published advice the same day and told ASOS customers to assume they are affected even if they did not get the notification. On 7 October the ICO’s chief executive, Paul Arnold, urged anyone who received a message “from apparent hackers” not to click links in unexpected texts or emails about their account, and to change passwords only by logging in through the official app or website.
For a business the lesson is about what comes after. Stolen names and contact details are raw material for convincing phishing, often weeks later, and staff who shop with ASOS on a work email address are in the pool. Remind people not to trust messages that claim to come from a retailer, even through its own app. Our guides to phishing attacks and the 2025 attacks on UK retailers cover the patterns. The advice is on the NCSC website and the ICO website.
A third NetScaler flaw is being exploited, and last week’s fix is not enough
Last week we covered two exploited flaws in Citrix NetScaler ADC and Gateway. On Sunday 4 October CISA added a third, CVE-2026-88779, to its Known Exploited Vulnerabilities catalogue and gave US federal agencies until 7 October to deal with it. It is a memory overflow in how NetScaler handles SAML sign-in requests. An attacker who needs no login can crash the service, and if they keep doing it, users can lose VPN and single sign-on access for as long as the attack lasts. Citrix said it has seen targeted attacks on unmitigated NetScalers and has not found an impact on the integrity of customer data.
It only affects on-premises appliances set up for SAML, as a service provider or identity provider, with Gateway or AAA. The fixed versions are 14.1-73.41 and 13.1-64.28, which are later than the 14.1-73.37 and 13.1-64.23 that fixed last week’s pair, so a box patched last week still needs updating. Citrix has also published an indicator of compromise script, and watchTowr warned that its latest version can report a false positive, so read the results before acting on them. If an outsourced IT firm runs your remote access, ask which build it is on now. Under Cyber Essentials, critical fixes are due within 14 days; our patch deadline calculator works out the date. The write-up is at Help Net Security and the entry is in CISA’s catalogue.
FortiMail email gateways: an exploited file-write bug
Fortinet published an advisory on 1 October for CVE-2026-104286 in FortiMail, its email security appliance. A path traversal bug lets an attacker with no login write files to the system using crafted web requests, and Fortinet says it has been exploited in the wild. CISA added it to its exploited list the same day. The fixes are 8.0.2, 7.6.7 and 7.4.9; anyone on the 7.2 branch has to move to 7.4 or later. Fortinet updated FortiMail Cloud itself on 5 October, so cloud customers need do nothing.
If you cannot update straight away, Fortinet’s workaround is to switch off the IBE encryption feature or keep the webmail interface off the internet. Email gateways sit in front of everything your staff receive, which is why a compromised one is so useful to an attacker running business email compromise. The advisory, with indicators of compromise, is on FortiGuard.
The ICO wants evidence on AI agents by 20 November
On 8 October the ICO said ten AI model developers, including Amazon, Google, Meta, Microsoft and OpenAI, have made or committed to data protection changes after two years of supervision. It also opened a six-week call for evidence on the data protection risks of agentic AI, the tools that carry out tasks, use other software and browse websites with limited human oversight, and confirmed it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agent testing.
The call is open to organisations that deploy these tools, not only those that build them, and covers security, transparency, accountability and lawful use of data. Its findings will feed a statutory code of practice on AI and automated decision-making. If your firm is letting an AI agent handle customer data, the regulator’s message is that autonomy “is not an excuse for poor compliance”; our guide to UK GDPR and the Data Protection Act 2018 sets out the duties that already apply. Responses close on 20 November 2026; details are on the ICO website.