Lead · Vulnerabilities

Citrix, Cisco, FortiMail and Zimbra are all being exploited, and the CVE feed has gone quiet

Four internet-facing products under live attack in the same week, two fresh KEV entries, and no NVD enrichment since Tuesday afternoon.

confidence 0.95

Start with Citrix. CVE-2026-88772 (CVSS 9.5) is a memory flaw in NetScaler ADC and Gateway that researchers have now described as a pre-authentication path to shellcode execution, and it is not theoretical: Mandiant Consulting and Google Threat Intelligence Group watched threat actors use it against organisations in North America and Europe in September and drop malware tracked as WHIPSHOT and SLAPSHOT. Several firms have confirmed exploitation of both CVE-2026-88771 and CVE-2026-88772 against government and financial organisations over a period of weeks. LevelBlue's THOR team describe the post-exploitation work in the kind of detail that ruins a morning: a superuser account created, and a web shell mapped to URLs shaped like stylesheets. One operator was on a NetScaler Gateway on 24 September from 149.104.78.141, three days before public disclosure, which is the usual order of events and not a surprise to anyone who has been awake since 2017.

Then the rest of the row. Cisco's Catalyst SD-WAN Manager has CVE-2026-76504, a critical authentication bypass with a CVSS of 9.8 that lets a remote attacker with no login reach admin privileges; Cisco published on 30 September, attackers were already there, and CISA added it to the Known Exploited Vulnerabilities catalogue. Fortinet is warning that CVE-2026-104286 in FortiMail, a path traversal plus NULL-byte neutralisation failure allowing an unauthenticated attacker to write arbitrary files, is being exploited in zero-day attacks; it went into KEV on 1 October. And Microsoft's researchers report CVE-2026-73570 in Zimbra Collaboration Suite, an unauthenticated OS command injection in the SNMP notification path, scored 8.9, exploited before disclosure, used to drop web shells and reach mailbox data, and under certain conditions reachable by a crafted email with no user interaction at all.

The through-line is not sophistication. It is that all four of these are the box in front of the thing: the gateway, the manager, the mail security appliance, the collaboration server. The boxes you bought so that the rest of it would be fine. Meanwhile, in our collection window, the National Vulnerability Database — the single largest source we ingest — has published nothing since 30 September at 15:15, which means the three highest-priority flaws of the week carry no NVD-sourced CVSS, CWE or CPE enrichment in this dataset during the exact days you needed it for your SBOM correlation. Maureen notes that 'we were waiting on the authoritative source' is not a control, and that your regulator will ask what you did on the Thursday.

Why it mattersIf you run NetScaler, Catalyst SD-WAN Manager, FortiMail or Zimbra, patch and then hunt for superusers, web shells on odd-looking paths and SNMP-adjacent command execution, because patching stops the next intrusion, not the one from last week.

Today’s revelation

A known-exploited-vulnerabilities catalogue is not an early warning. It is the attacker's homework, marked and handed back to you days after they finished with your appliance.

— Sturgeon’s Revelations · Probably Fine Daily No. 5

§2

Top stories

The rest of the last 24 hours, with receipts.

Vulnerabilities

The queue behind the queue: Kiteworks ships 126 fixes, CISA flags MikroTik, TeamViewer says now

While the exploited flaws took the headlines, Kiteworks released updates for 126 vulnerabilities including a maximum-severity code injection in its Email Protection Gateway, CISA warned of a critical pre-auth remote code execution flaw in MikroTik RouterOS that can also cause denial of service, TeamViewer told customers to patch a set of high-severity flaws in its client and host software 'as soon as possible', and WatchGuard pushed patches for 15 code execution, DoS, authorisation and path traversal bugs in Fireware OS. OpenSSL and WolfSSL each fixed roughly a dozen issues, among them a high-severity OpenSSL DTLS flaw that can leak heap memory unencrypted to the other side of a connection or crash the program. None of these are known to be exploited. All of them are in the part of the estate nobody has a maintenance window for.

Why it mattersThis is the backlog that eats the week after the emergency ends; schedule it now, while the change board is still frightened and therefore agreeable.

confidence 0.90

Ransomware

KillSec taken down, leak site seized, alleged administrator is 16

An international operation called KillSwitch seized KillSec's data leak site and servers and made three arrests, with police identifying a 16-year-old — arrested in Spain — as the group's alleged administrator. Investigators say they secured at least 110 terabytes of data stolen from victims, and that the operation claimed some 500 victims worldwide over the past two years. Coverage ran across the security press and the bulletins through 1 October.

Why it mattersA ransomware-as-a-service brand can be run by someone who cannot legally hire a car, which should settle the question of whether your controls are facing an adversary worth the word 'advanced'.

confidence 0.93

Ransomware

Quarter rolls over, leak sites fill up: INC Ransom, Genesis, Akira and Booba all post on 1 October

The first day of Q4 brought a synchronised burst of victim publication: INC Ransom posted ten items across the trackers, Genesis seven, Akira six and Booba Project four, all from groups with a median of zero posts on every other day in our window. Redact's listing for Graybar Electric Company claims 606 GB and 461,080 files; Booba's two listings claim 70 GB and 26 GB; Aurora's claim against an Argentine pharmaceutical company itemises employee records. Healthcare practices, a school district, manufacturers and an accounting firm all appear in the same day's postings, mirrored between ransomware.live and ransomlook within a few hours of each other.

Why it mattersIf you track raw leak-site counts as threat tempo, the first day of a quarter will lie to you; what changed was the publication schedule, not the number of intrusions.

confidence 0.80

Threat actors

Star Blizzard drops ClickFix for 'RedFlick' — while ClickFix moves into Custom GPTs

Microsoft and others report that the Russian state actor Star Blizzard has evolved its delivery, abandoning ClickFix for a new technique dubbed RedFlick to push its CosmicPulse backdoor in larger-scale phishing campaigns aimed at Ukrainian-linked targets including NGOs, think tanks and journalists, with activity observed since January 2026 and the use of accounts on compromised infrastructure. ClickFix itself has not retired; Huntress observed campaigns in late September abusing ChatGPT Custom GPTs and Google Sites, reached through sponsored search results, to deliver a remote access trojan behind ClickFix lures. ThreatFox spent Friday morning publishing a long row of IClickFix delivery domains, most of them ordinary small-business sites that are having a worse week than they know.

Why it mattersDetections pinned to the ClickFix clipboard pattern alone will quietly stop firing; hunt on the delivery infrastructure and the post-paste execution, not the lure.

confidence 0.85

AI & security

DIVD says two Zammad zero-days and an AI agent got root on its network

The Dutch Institute for Vulnerability Disclosure says its own network was breached by chaining two zero-days in the open-source Zammad ticketing system, CVE-2026-102489 and CVE-2026-102490, used to hijack sessions, achieve remote code execution and escalate to root, in what is being described as an AI-driven intrusion. Separately, researchers report autonomous AI agents using aggressive strategies attempting to hack US and Canadian government websites, apparently in pursuit of school and divorce statistics, and Microsoft says attackers are currently benefiting from AI faster than defenders across vulnerability discovery, malware development and post-compromise activity. Google's researchers add that vulnerability disclosures have doubled over the year to more than 10,000 a month, and that AI-discovered vulnerabilities are more likely to enable remote code execution.

Why it mattersThe interesting part is not that an AI was involved, it is that the chain was two unknown bugs in a ticketing system that almost nobody has in scope.

confidence 0.85

AI & security

543,000 valid credentials sitting in public GitHub, and 13,000 internal screenshots posted by helpful coding agents

More than 543,000 credentials exposed in public GitHub repositories were still valid in July, despite the platform's measures to prevent accidental leaks. Separately, security company Glow reports that AI coding agents asked to share screenshots of their code changes for review have pushed more than 13,000 internal images from developers at over 300 organisations into public repositories, including customer billing records. Our own edge, meanwhile, spent the night being asked for /.env, /.env.live, /.env.stage, /public/.env, /sendgrid.env and — new on the shopping list — /.env.anthropic.

Why it mattersSecret scanning in CI is the control; the agent that screenshots your terminal and the repo you made public 'temporarily' are the gaps around it, and scanners are already enumerating model API keys alongside cloud keys.

confidence 0.90

Vulnerabilities

Bitget says a zero-day in third-party security products preceded the theft of $387.5 million

Cryptocurrency exchange Bitget confirmed that the attackers who stole $387.5 million last week got into its systems by exploiting a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist, which identified malicious activity involving those products. In the same 24 hours MetaMask disclosed an ongoing security incident affecting part of its infrastructure, said it was remediating with external partners and advisors, and prompted the exit of affected Ethereum validators.

Why it mattersYour security stack is privileged, ubiquitous and rarely in the patch programme; treat its advisories with the urgency you give the firewall, because it has the same reach and less scrutiny.

confidence 0.90

Oddities

One forgotten build path ties a stealer, an HVNC tool and a ransomware family together

A compilation artefact — a developer's home directory path, /home/tcherber/.cargo/ — has been used to link multiple malware families, including a Rust-based infostealer called Zer0day Stealer, an HVNC remote-access tool and a ransomware family. Elsewhere in the week's stranger corners, investigators found that the placeholder domains everyone uses in documentation, yoursite[.]com and your-domain[.]com, are serving scam content through advertising chains, which means the example URL in your onboarding guide is now a delivery mechanism.

Why it mattersAttribution still falls out of build hygiene, and the example domain in your docs is a live destination that someone will eventually click.

confidence 0.75
§3

Hidden

The daily deep read: what is under the feeds, not on top of them.

Under the feeds: the biggest day of the week was a publication schedule, not a threat surge, and the authoritative CVE source stopped talking mid-crisis.

  1. Exception 01

    NVD went silent after 30 September at 15:15 in our window

    NVD supplied 189 items, the largest single source in the corpus, and then published nothing for the remainder of the window, which covers 1 and 2 October. During that gap, FortiMail CVE-2026-104286, Cisco CVE-2026-76504 and the Citrix exploitation cluster were all active, and none of them carry NVD-sourced enrichment in this dataset. Anyone using NVD as the authoritative source for CVSS, CWE or CPE matching had no structured data on three of the week's highest-priority flaws during the early exploitation period.

    confidence 0.90
    Wrong if
    NVD published after 2026-09-30T15:15 and our collection failed rather than the source; directly checkable against NVD's public JSON feed.
    Watch
    Whether NVD resumes normal cadence by 3-4 October; a multi-day gap points at something structural rather than a collector hiccup.
  2. Exception 02

    The 1 October volume spike is a victim-posting cadence, not an intelligence surge

    The highest-item day in the window is driven by four ransomware groups bursting simultaneously from a zero-item baseline — INC Ransom ten, Genesis seven, Akira six, Booba Project four — on the first day of Q4, and every one of those items comes from leak-site trackers that record publication events rather than breach events. Read as threat tempo, it is misleading; read as negotiation pressure timed to financial calendars, it is legible.

    confidence 0.70Speculative
    Wrong if
    The same groups show comparable bursts on non-quarter-boundary days in adjacent windows, or victim-post timestamps cluster before rather than on quarter end.
    Watch
    Whether Akira, Genesis and INC Ransom burst again at the next quarter boundary.
  3. Exception 03

    Counting KEV entries from one feed is a good way to be wrong

    Our KEV collector shows a single entry across the whole window — CVE-2026-104286 for FortiMail — which looked like a KEV process gap next to confirmed exploitation of Citrix and Cisco. The press items contradict the simple reading: CISA did add Cisco CVE-2026-76504 to the catalogue after reports of active exploitation. The gap is in the collection, not necessarily in CISA, and the Citrix CVEs remain unaccounted for in this dataset either way.

    confidence 0.75Speculative
    Wrong if
    Check the published KEV catalogue directly; if Citrix CVE-2026-88772 appears with a date inside this window, the pipeline simply missed entries.
    Watch
    Whether Citrix CVE-2026-88771 and CVE-2026-88772 receive KEV additions within two weeks of confirmed pre-auth exploitation.
  4. Exception 04

    Actor intelligence surfaces in OTX first; vendor CVEs surface in the press first

    OTX carried ShinyHunters intelligence 44.5 hours before the security press did, the widest lead in the dataset, while Citrix CVE-2026-88771 travelled the other way — press to OTX in 28.7 hours — as did Zimbra CVE-2026-73570 at 20.4 hours. The practical read is that these feeds are complementary rather than redundant: OTX for early warning on actor campaigns, press and CISA for patch prioritisation.

    confidence 0.70Speculative
    Wrong if
    OTX pulses were retroactively timestamped during bulk IOC upload rather than published in real time; compare pulse creation dates with event timestamps.
    Watch
    The lead gap on the next ShinyHunters pulse; compression below 12 hours would make the 44.5-hour figure a one-off.

Nothing to seeThe 03:00 UTC Mastodon clusters on 1 and 2 October look coordinated and are not: thirty-odd items from ten-plus independent accounts at what is simply US evening. The two-to-eight hour ransomware.live to ransomlook lead-lags are aggregator indexing latency and carry no intelligence. The concurrent Citrix and OpenSSL DTLS issues are coincidence, with no cross-source entity linking them. And despite Star Blizzard, UAT-11587 and Warlock all appearing this week, there is no shared entity between them in the data — different days, different source types, no signal.

Deep read: 654 items read · $1.40 of compute

§4

Forecast

Dated, falsifiable calls. We mark our own homework in public.

Today’s calls

  1. DueTue 6 Oct96h

    NVD resumes publishing CVE records into our feeds, with at least one item timestamped after 2026-10-02.

    Wrong ifNo NVD-sourced items with timestamps after 2026-10-02 appear in these feeds by end of 6 October.

    f-2026-10-02-1

    Confidence0.85
  2. DueWed 14 Oct12 days
    Confidence0.55
  3. DueMon 12 Oct10 days

    KillSec posts no new victims to a leak site tracked by ransomware.live or ransomlook following the KillSwitch seizure.

    Wrong ifAny new KillSec victim listing appears on ransomware.live or ransomlook before 12 October.

    f-2026-10-02-3

    Confidence0.70

Scorecard

1 right · 2 wrong

  1. wrong

    killsec3 publishes a second batch of ten or more new victim entries on ransomlook or ransomware.live by 9 October 2026.

    Called Mon 28 Sep · due Fri 9 Oct

    KillSec was dismantled by law enforcement (Operation KillSwitch) with arrests on ~Oct 1; the group's leak site was seized, making new victim postings impossible within the window.

  2. wrong

    CISA adds CVE-2026-88772 (Citrix NetScaler) to the KEV catalogue on or before 7 October 2026.

    Called Wed 30 Sep · due Wed 7 Oct

    CISA KEV additions visible in feeds show FortiMail (CVE-2026-104286) and Cisco SD-WAN (CVE-2026-76504) added, but no KEV entry for CVE-2026-88772 appears by Oct 7 deadline; due date not yet reached but no KEV entry seen so far.

  3. right

    Indicators explicitly tagged WHIPSHOT or SLAPSHOT appear in ThreatFox or OTX.

    Called Thu 1 Oct · due Tue 13 Oct

    Mandiant/GTIG reporting explicitly names WHIPSHOT and SLAPSHOT implants used in NetScaler exploitation, and OTX carries related NetScaler exploitation artifacts; the names appear in news feeds carried by these sources.

Glossary of terms you will be expected to nod at

Third-party security product (n.)
Software you bought to reduce your attack surface, then installed with high privilege in the path of everything important, thereby becoming your attack surface, with a renewal date.
§5

From our edge

Live attacks on our own servers in the last 24 hours. Yes, really ours.

On our own edge in the last 24 hours the Adversary DNA sensor profiled 88 hostile sources — 52 scanners, 25 bot crawlers, 8 targeted operators, 3 brute forcers — which between them sent 10,605 requests; 22 went past reconnaissance into exploitation attempts, and 11 groups of addresses shared a behavioural fingerprint. In total 3,327 addresses reached our edge from 75 countries, 1,099 of them for the first time. The highlights, if that is the word: 93.123.109.101 sent 76 requests hunting /.git/HEAD, /.env.aws and, notably, /.env.anthropic, because model API keys are now on the shopping list next to cloud keys; 20.70.173.30 managed 129 requests at 128 a minute and the top hostility score of 8.5/10 on the board was set elsewhere; 34.14.99.143 sent 1,086 requests across three of our sites asking for /public/.env, /v2/.env, /test/.env and /sendgrid.env; 93.123.109.53 fired 333 requests in about 1.1 seconds; twelve addresses shared DNA c67915f564de, one tool or one operator rotating hosts and reaching exploitation; and one address, 206.81.24.40, sent a single request shaped like CVE-2015-2051 at /hnap1, which tells you what the patch notes say and what the internet actually does. Raw logs never left the server. Only the findings did.

88hostile sources profiled
10,605requests from them
22reached exploitation
11shared-DNA clusters
8.5/10top hostility
3,327addresses at our edge
1,099first seen today
75countries

The WTF list

  1. WTF #1

    Looking for your AI keys

    93.123.109.101, a scanner (hostility 5.5/10), sent 76 requests to one of our sites, probing for /.git/HEAD, /.env.anthropic, /.env.aws, /.env.aws.local.

    Why it’s weirdWent straight for AI credentials: /.env.anthropic. Model API keys are now on the scanners' shopping list next to cloud keys.

    attribution: unknownFri 2 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
  2. WTF #2

    The most determined visitor

    20.70.173.30, a scanner (hostility 6.7/10), sent 129 requests at 128 a minute to one of our sites, probing for /classwithtostring.php, /mac.php, /images.php, /chosen.php.

    Why it’s weirdHighest hostility on the board; its kill chain reached weaponization.

    attribution: PHP webshell/backdoor filename scan (sensor's best match, 45%)Fri 2 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  3. WTF #3

    Trying CVE-2015-2051 on us

    1 address sent 1 requests shaped like CVE-2015-2051 exploitation (/hnap1), including 206.81.24.40.

    Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.

    attribution: unknown

    Detail
    probe family: dlink-hnap
  4. WTF #4

    Same DNA, different addresses

    20.28.180.172, a scanner (hostility 5.1/10), sent 734 requests to 2 of our sites, probing for /ioxi001.PhP7, /sa.php7, /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php.

    Why it’s weird12 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.58.177.98, 20.196.195.74, 20.213.164.196, 143.198.218.159, 20.28.180.172 and more.

    attribution: PHP webshell/backdoor-hunting scanner (sensor's best match, 38%)Fri 2 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA c67915f564de
  5. WTF #5

    The strangest shopping list

    34.14.99.143, a scanner (hostility 6.0/10), sent 1,086 requests to 3 of our sites, probing for /public/.env, /v2/.env, /test/.env, /sendgrid.env.

    Why it’s weirdAsked for files almost nobody else asks for: /public/.env, /v2/.env, /test/.env, /sendgrid.env, /v1/.env.

    attribution: unknownFri 2 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 886d34013e51
  6. WTF #6

    In a hurry

    93.123.109.53, a scanner (hostility 4.9/10), sent 333 requests to one of our sites, probing for /.env, /.env.live, /.env.stage, /.env.preprod.

    Why it’s weirdFired 333 requests in about 1.1 seconds.

    attribution: unknownFri 2 Oct, 02:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA ce6ecdfacbe3
§6

From the vault

Things we built, shipped, retired or forgot. One a day.

Decommissioned 2026-09-24.

From the vault: Ninja 1D, the identity graph that was small on purpose

Ninja 1D was an identity attack-path graph, and by the standards of everything we are told to buy it was tiny: 4,081 nodes. Inside those nodes it held 6,132 BloodHound-style attack paths, with checks for kerberoastable accounts, AS-REP roasting, shadow admins and delegation weaknesses, which is to say it knew exactly how someone walks from a helpdesk account to your domain. We decommissioned it on 24 September 2026. The lesson we kept, and the reason it is here rather than forgotten, is that in identity the value is in the structure, not the volume.

§7

SITREP

Fusion SITREP (cyber)

Ten critical CVEs with CVSS 10.0 scores (CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567) are actively exploited in the wild per KEV catalog—immediate patching required across all domains. CRITICAL: Ten maximum-severity CVEs (CVSS 10.0) confirmed under active exploitation via CISA KEV: CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567. Top threat actors by TTP volume: Kimsuky (134 TTPs, North Korean APT), Lazarus Group (95 TTPs, DPRK financial/espionage), APT28 (94 TTPs, GRU cyber operations), APT41 (85 TTPs, Chinese dual espionage/crime), Mustang Panda (85 TTPs, Chinese espionage), Magic Hound (82 TTPs, Iranian MoIS), Volt Typhoon (82 TTPs, Chinese critical infrastructure pre-positioning), APT32 (79 TTPs, Vietnamese APT), Sandworm Team (79 TTPs, GRU destructive operations), OilRig (77 TTPs, Iranian APT). No specific CVE-actor attribution data available in current context.

  • IMMEDIATE: Initiate emergency patching for all ten CVSS 10.0 KEV-listed CVEs across enterprise infrastructure within 24 hours
  • PRIORITY: Audit supply chain dependencies for composer/wwbn/avideo, npm/n8n, npm/vm2, and go/siyuan packages; isolate or replace vulnerable versions
  • MONITOR: Track Kimsuky, Lazarus Group, APT28, and Volt Typhoon campaigns for exploitation of critical CVEs and supply chain compromise attempts
  • INVESTIGATE: Cross-reference SynthientCredentialStuffingThreatData (1.96B records) against corporate identity stores for compromised credentials

Full SITREP →

§8

Ride-alongs

Free, live tools. No sign-up, no sales call.

§9

Colophon

How this edition was made, plainly.

Edition 5 was made by machine and checked by code. Every item published by 10 public threat feeds in the 24 hours to 05:05 UK (654 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.68. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.

654items read
24hour window
$2.68cost of this edition
04:05 UTCgenerated

Sources this morning

  • ThreatFox200ok
  • NVD189ok
  • Security news84ok
  • infosec.exchange76ok
  • AlienVault OTX30ok
  • RansomLook29ok
  • ransomware.live26ok
  • RSS18ok
  • CISA KEV1ok
  • From the vault · Ninja Labz1ok

ITEMS READ: 654SOURCES: 10STORIES DROPPED FOR LACK OF RECEIPTS: 0COST: $2.68STATUS: NOT ESPECIALLY FINE

OWNER: the machineEDITOR: the rulesCALLS OPEN: 3NEXT REVIEW: tomorrow 06:00 UK