A Daily Field Report on Things That Are Probably Fine
No. 6·Saturday 3 October 2026·Published 06:00 UK·Fine Meter 3/5: Not fine, but survivable
Lead · Vulnerabilities
CISA confirms exploitation of a FortiMail zero-day, and adds a two-bug Zammad chain for the weekend
A mail security gateway that writes files for anyone who asks, a helpdesk that hands over root in two moves, and a national vulnerability feed that chose this week to go quiet.
confidence0.95
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalogue on Thursday following reports of active exploitation. It is a critical path traversal combined with improper NULL byte neutralisation in FortiMail versions 7.2 through 8.0, and it lets an unauthenticated attacker write arbitrary files to the underlying system, which is a polite way of describing a mail security appliance that will accept a file from a stranger and keep it. SecurityWeek and AlienVault's OTX both carried it inside the same morning, which tells you it was not a quiet disclosure.
Alongside it, CISA listed a Zammad pair that is really one attack written down twice: CVE-2026-102489, a session fixation flaw leading to remote code execution as the zammad user, chained with CVE-2026-102490, an improper privilege management flaw that takes the local zammad user to root. The catalogue entries say explicitly that each can be chained with the other. Helpdesk software is where your organisation keeps the sentence "here is my password, sorry to bother you", several thousand times, searchable.
Meanwhile the NVD items in this window stop dead after 2026-10-01T23:47, with the whole hundred-item batch landing on 30 September. Your scanner is not necessarily broken. It is just quieter than the thing it is meant to be watching.
Why it mattersInternet-facing mail gateways and ticketing systems are both on the KEV list today with working exploitation paths; those are weekend changes, not Monday changes.
A vulnerability feed that goes quiet has not made the week safer; it has simply stopped photographing the tide.
— Sturgeon’s Revelations · Probably Fine Daily No. 6
Every morning06:00 UK
Get it in your inbox. Every morning. Probably.
One email a day. The whole paper. Unsubscribe in one click.
§2
Top stories
The rest of the last 24 hours, with receipts.
Vulnerabilities
Dell ships two maximum-severity CSM fixes, GitLab patches a 9.9 in the bit that talks to the AI
Dell has patched two maximum-severity flaws in Container Storage Modules, the components that connect Dell enterprise storage arrays to Kubernetes environments, including CVE-2026-63688 at CVSS 10.0, a missing authentication for a critical function that enables unauthenticated admin access and root on Kubernetes nodes. Separately GitLab warned customers to patch CVE-2026-90970, CVSS 9.9, a flaw in the self-hosted AI Gateway that lets a logged-in user with Duo Agent Platform access run commands on the gateway via crafted flow configs; fixes are in 19.2.4, 19.3.2 and 19.4.1, and only self-hosted gateways are affected. Neither carries confirmed exploitation today. Both are the sort of thing that acquires it quietly.
Why it mattersStorage control planes and AI gateways both sit inside the trust boundary and neither is usually on the emergency patch list; today they are.
Warlock keeps mining SharePoint, and three other China-nexus campaigns surface the same day
Symantec's Threat Hunter Team reports the China-nexus group Longlegs is still deploying Warlock ransomware via Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain, with victims including a water utility, a telecom provider, a regional government body and a university, and activity in Portuguese and Spanish-speaking countries; the group has been exploiting SharePoint since July 2025. On the same day, three further China-attributed operations surfaced: TA419 credential-phishing AI experts at US think tanks and universities by impersonating economists and AI policymakers in July 2026, the Antino backdoor using Outlook and OneDrive for command and control against government and policy organisations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar, and a Chinese-speaking crew dubbed Gambling Goblin running sustained SEO poisoning of Brazilian government and education sites since mid-2025.
Why it mattersIf you have SharePoint on the internet and have not confirmed ToolShell remediation, assume the question is when you were visited, not whether.
Five crews published on the same day, and one of them appears to be two crews with one spreadsheet
'Booba Project' on ransomware.live and 'booba team' on ransomlook posted identical victims with identical volumes — 344 GB, 5.5 GB, 103 GB and 1 GB — so any count treating them as two groups is counting one group twice. Elsewhere Inc Ransom claimed a Colorado electric association, Vicksburg, Mississippi shut systems down after a ransomware incident with the FBI investigating, and ShinyHunters told two named companies their data would be published by end of day Friday.
Why it mattersLeak-site counts are claims, not confirmations, and today at least one actor is inflating the active-group number purely through platform naming.
MISP, the platform we all share intelligence through, has a three-flaw path to site admin
Three MISP CVEs disclosed together describe a complete climb on any shared instance: CVE-2026-103235, a mass assignment flaw in event delegation where the application authorises the user against the event in the URL and then saves the whole submitted record including caller-supplied primary key and event_id; CVE-2026-103237, an ORM save-path validation failure reachable through attribute add and edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add and user admin edit; and CVE-2026-103239, where tag collection create and edit accept the full HTTP payload and pass it to a bulk-association save. No CISA KEV entry, no press release, no vendor webinar.
Why it mattersIf you run a shared MISP instance, a standard account on it is now a plausible route to other members' data and to the integrity of the IOCs you feed your detections.
Patched NetScaler, still odd: Citrix customers compare notes while Google reports 0-day webshells
Dark Reading frames the Kiteworks and Citrix incidents as a study in zero-day response, one vendor telling customers to power down its data-protection platform during a nine-hour window and the other staying quiet about reported attacks until it had a patch. On Mastodon, an intelligence outfit asked anyone still having Citrix NetScaler trouble after applying every patch and remediation to share intel confidentially, with a PGP key published, and another practitioner replied that we need to look out for each other because the companies can't or won't. Meanwhile elhacker.net reports Google warning of Citrix 0-day exploitation used to deploy web shells. Patched is not the same as clean.
Why it mattersIf you patched NetScaler and stopped there, the open question is what was dropped on the appliance before the patch landed; hunt, do not assume.
AI agents pointed SQL injection at government sites, and OpenAI parted ways with three safety researchers
SecurityWeek reports attacks using AI agents to aim SQL injection at the US Department of Education and Library and Archives Canada, with researchers linking some of the agents to OpenAI. Separately, OpenAI parted ways with three members of its safety team for violating policies on accessing and handling sensitive company information, and reporting elsewhere describes OpenAI disrupting a reasoning-extraction campaign tied to contributors of another AI lab. Dark Reading argues in the same window that calling this "rogue AI" anthropomorphises the models and shifts responsibility away from vendors, and that defenders should treat agents as untrusted, nondeterministic software. Also in the week's smaller print: an adblocker found spying on AI chats, and AI used to find 24 Android app flaws.
Why it mattersTreat agent traffic as attacker-controlled automation with a user-agent you have not fingerprinted yet, and log it like you log everything else.
Treasury sanctions eight Tren de Aragua members over ATM jackpotting, and an alleged Iranian state hacker is extradited
The US Treasury Department sanctioned eight members of the Venezuelan gang Tren de Aragua for their role in stealing millions of dollars through ATM jackpotting attacks across the United States. In a rarer move, Amir Barati, an alleged member of the Mabna Institute, was extradited to the US and indicted for targeting universities, private organisations and government entities in the US and abroad. On the domestic surveillance side, a bipartisan backlash to automated licence plate readers produced two bills, one from Senator Josh Hawley and a broader one from Senators Bernie Sanders and Jeff Merkley with Representative Alexandria Ocasio-Cortez.
Why it mattersSanctions and extraditions change the risk calculus for the people doing the work, which is about the only lever that touches the business model.
Microsoft's own X account spent Thursday promoting a Clippy-themed coin, and Chrome published an advisory with nothing in it
Unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, and used it in what appeared to be a pump-and-dump scheme amplifying a Clippy-themed cryptocurrency token. In a separate act of communication, Google Chrome published an empty blog post as a security advisory on Thursday afternoon, filling it in over the following day; one practitioner noted the listed "Critical CVE-2026-103628: Out of bounds write in WebGL" is in fact rated CVSSv3.1 9.6 because it allows remote code execution outside the sandbox.
Why it mattersVendor channels are part of your attack surface and part of your patch intelligence; both failed in public on the same afternoon.
The daily deep read: what is under the feeds, not on top of them.
The feeds agree on the exploitation; it is the plumbing underneath that is behaving oddly.
Exception 01
The CVE feed went quiet at the worst possible hour
All 100 NVD items in this window landed on 30 September and the feed stops after 2026-10-01T23:47, so the three highest-severity disclosures of the Oct 2–3 period — FortiMail CVE-2026-104286, Dell CSM CVE-2026-63688 and GitLab CVE-2026-90970 — reached defenders through news, OTX and RSS rather than through the feed that triggers most automated patch workflows.
confidence0.80
Wrong if
NVD entries dated 2–3 October appearing in a later scrape, confirming the gap is a collection artefact rather than a publication gap.
Watch
Whether NVD backfills FortiMail, Dell CSM and GitLab, and whether the 30 September batch is revised.
OTX led cyber-news on adversary and campaign intelligence by 1.9 hours for Warlock and 6.8 hours for TA419, while cyber-news led OTX by 1.7 hours on the FortiMail KEV disclosure — suggesting actor reporting and confirmed-exploitation reporting travel on different pipes with different latencies.
confidence0.60Speculative
Wrong if
A single counter-example in the next window: cyber-news leading OTX on a China-nexus actor story, or OTX leading on a KEV addition.
Watch
Direction of lead-lag across the next ten actor reports and ten KEV additions.
Thirty September was a mass-disclosure day across five unrelated ecosystems
Apache MINA SSHD, Moodle, Pgpool-II, Digiwin EasyFlow .NET and Apache PLC4X all posted multi-CVE batches on the same day across Java SSH, PHP LMS, PostgreSQL middleware, .NET ERP and industrial OT, and the structurally nastiest items in each batch — the MINA SSHD LDAP authentication bypasses, the PLC4X OPC UA certificate validation failure, the Pgpool-II certificate bypass and watchdog leader promotion — are exactly the ones most likely to be lost in batch noise.
confidence0.65Speculative
Wrong if
Reporter metadata showing independent submitters with unrelated timelines, or pre-30-September publication dates in the production feed.
Watch
Whether the same reporters produce further cross-project batches during October.
A WordPress plugin flaw filed as authenticated, described as not
CVE-2026-89294 in Simply Schedule Appointments is classified as requiring subscriber-level access for local file inclusion via the ssa_locale parameter, in all versions up to and including 1.6.12.27; teams triaging on the authentication field alone may rank it lower than the description warrants.
confidence0.70
Wrong if
Plugin source review showing the vulnerable path genuinely requires an authenticated session context.
Watch
Whether the CNA revises the authentication requirement, or unauthenticated exploitation is reported.
Nothing to seeLockBit, ALPHV/BlackCat and Cl0p do not appear anywhere in this window, and no DPRK-attributed activity surfaced either; over four days that is a sampling gap, not a trend, and anybody selling it to you as a trend is selling you something. ThreatFox's hundred items are a single bulk drop of AsyncRAT SHA256 hashes with one identical ingest timestamp and no C2, no network IOCs and no attribution metadata — volume, not intelligence.
Deep read: 351 items read · $0.93 of compute
§4
Forecast
Dated, falsifiable calls. We mark our own homework in public.
Today’s calls
DueCallConfidence
DueTue 13 Oct10 days
Tracking platforms will still list 'Booba Project' and 'booba team' as separate actors with overlapping victims, with no reconciliation note published.
Wrong ifEither platform renaming or merging the entity, or publishing a note that the two names are one actor.
At least one further MCP or AI-agent framework authorisation or credential-theft CVE is published by 13 October 2026.
Called Wed 30 Sep · due Tue 13 Oct
CVE-2026-102911 (pi-llm-wiki MCP tool OS command injection) and CVE-2026-90970 (GitLab AI Gateway sandbox escape allowing command execution) both appear and qualify as AI-agent/MCP-framework auth or credential-adjacent CVEs; due date not yet reached so full settlement awaits.
NVD resumes publishing CVE records into our feeds, with at least one item timestamped after 2026-10-02.
Called Fri 2 Oct · due Tue 6 Oct
Multiple NVD items timestamped 2026-09-30 appear in the feed, well after 2026-10-02 in terms of feed publication; NVD is actively publishing CVE records into these feeds.
The official list of things that were already happening to someone else while you were deciding whether they met your internal severity threshold. Published slightly before you are asked about them in a meeting.
§5
From our edge
Live attacks on our own servers in the last 24 hours. Yes, really ours.
Our own edge, meanwhile, had an ordinary day, which is the point. The local Adversary DNA sensor profiled 140 hostile sources — 87 scanners, 34 bot crawlers, 15 targeted operators, 4 brute forcers — sending 15,239 requests between them, of which 34 went past reconnaissance into exploitation attempts, across 3,222 addresses from 74 countries with 819 seen for the first time today. Sixteen groups shared a behavioural fingerprint; one of them, DNA c67915f564de, spans 17 addresses running the same PHP webshell hunt, which is one operator and a rotation list rather than seventeen adversaries. Two details are worth your time: 93.123.109.101 probed for /.env.anthropic alongside /.env.aws and /.git/HEAD, so model API keys are now on the shopping list next to cloud keys; and one source sprayed requests shaped like CVE-2018-20062, a named exploit from a year most of our compliance documents consider closed. Another fired 120 requests in about half a second, which is not stealth, it is just confidence. Raw logs never left the server; only the findings did.
140hostile sources profiled
15,239requests from them
34reached exploitation
16shared-DNA clusters
8.9/10top hostility
3,222addresses at our edge
819first seen today
74countries
The WTF list
WTF #1
Looking for your AI keys
93.123.109.101, a scanner (hostility 4.7/10), sent 157 requests to 2 of our sites, probing for /.git/HEAD, /.env.anthropic, /.env.aws, /.env.aws.local.
Why it’s weirdWent straight for AI credentials: /.env.anthropic. Model API keys are now on the scanners' shopping list next to cloud keys.
attribution: unknownFri 2 Oct, 14:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA 6c07885bf252
WTF #2
The most determined visitor
13.70.107.184, a scanner (hostility 6.8/10), sent 36 requests to one of our sites, probing for /admin.php, /1.php, /new.php, /num.php.
Why it’s weirdHighest hostility on the board; its kill chain reached exploitation.
attribution: PHP webshell/backdoor-hunting scanner (sensor's best match, 38%)Sat 3 Oct, 04:00 UTC
Detail
kill chain: reconnaissance → weaponization → exploitation · DNA dfef4501b216
WTF #3
Trying CVE-2018-20062 on us
1 address sent 3 requests shaped like CVE-2018-20062 exploitation (/index.php), including 2a0f:ca80:b00b:6b07::5.
Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.
attribution: unknown
Detail
probe family: webshell
WTF #4
Same DNA, different addresses
20.196.195.74, a scanner (hostility 6.0/10), sent 398 requests at 114 a minute to one of our sites, probing for /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /ccs.php, /set.php.
Why it’s weird17 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.214.109.68, 20.196.195.74, 20.219.14.152, 20.58.177.98, 20.213.164.196 and more.
attribution: PHP webshell backdoor locator scan (sensor's best match, 38%)Fri 2 Oct, 07:00 UTC
Detail
kill chain: reconnaissance → weaponization → exploitation · DNA c67915f564de
WTF #5
The strangest shopping list
20.70.173.30, a scanner (hostility 6.7/10), sent 129 requests at 128 a minute to one of our sites, probing for /classwithtostring.php, /mac.php, /images.php, /chosen.php.
Why it’s weirdAsked for files almost nobody else asks for: /classwithtostring.php, /mac.php, /images.php, /chosen.php, /wp.php.
attribution: PHP webshell/backdoor filename scan (sensor's best match, 45%)Fri 2 Oct, 14:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA dfef4501b216
WTF #6
In a hurry
35.241.202.92, a scanner (hostility 5.5/10), sent 120 requests to one of our sites, probing for /wp-config.php.bak, /web/.env, /v2/.env, /production/.env.
Why it’s weirdFired 120 requests in about 0.5 seconds.
attribution: unknownFri 2 Oct, 14:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
§6
From the vault
Things we built, shipped, retired or forgot. One a day.
Decommissioned 2026-09-24.
V0id Agents, retired 24 September, left the paperwork tidy
V0id Agents was decommissioned on 24 September 2026 and did the rarest thing a retired system can do, which is leave the place cleaner than it found it: eight incident-response playbooks covering ransomware, business email compromise, data exfiltration, insider, DDoS, supply chain, credential compromise and zero-day, plus a finished write-up of how its Warden agent contained ransomware. Most projects end with a Slack channel going quiet and a repository nobody dares delete. This one ended with a handover. The playbooks have a better home waiting in the NinJAFUNK SecOps agent, which is to say the work outlived the thing that did it.
§7
SITREP
Fusion SITREP (cyber)
Ten critical CVEs with CVSS 10.0 scores (CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567) are actively exploited in the wild per KEV catalog—immediate patching required across all domains. CRITICAL: Ten maximum-severity CVEs (CVSS 10.0) confirmed under active exploitation via CISA KEV: CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567. Top threat actors by TTP volume: Kimsuky (134 TTPs, North Korean APT), Lazarus Group (95 TTPs, DPRK financial/espionage), APT28 (94 TTPs, GRU cyber operations), APT41 (85 TTPs, Chinese dual espionage/crime), Mustang Panda (85 TTPs, Chinese espionage), Magic Hound (82 TTPs, Iranian MoIS), Volt Typhoon (82 TTPs, Chinese critical infrastructure pre-positioning), APT32 (79 TTPs, Vietnamese APT), Sandworm Team (79 TTPs, GRU destructive operations), OilRig (77 TTPs, Iranian APT). No specific CVE-actor attribution data available in current context.
IMMEDIATE: Initiate emergency patching for all ten CVSS 10.0 KEV-listed CVEs across enterprise infrastructure within 24 hours
PRIORITY: Audit supply chain dependencies for composer/wwbn/avideo, npm/n8n, npm/vm2, and go/siyuan packages; isolate or replace vulnerable versions
MONITOR: Track Kimsuky, Lazarus Group, APT28, and Volt Typhoon campaigns for exploitation of critical CVEs and supply chain compromise attempts
INVESTIGATE: Cross-reference SynthientCredentialStuffingThreatData (1.96B records) against corporate identity stores for compromised credentials
One email a day. The whole paper. Unsubscribe in one click.
§9
Colophon
How this edition was made, plainly.
Edition 6 was made by machine and checked by code. Every item published by 10 public threat feeds in the 24 hours to 05:05 UK (351 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $1.72. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.
351items read
24hour window
$1.72cost of this edition
04:05 UTCgenerated
Sources this morning
NVD100ok
ThreatFox100ok
infosec.exchange39ok
RansomLook34ok
Security news32ok
ransomware.live23ok
AlienVault OTX13ok
RSS7ok
CISA KEV2ok
From the vault · Ninja Labz1ok
ITEMS READ: 351|SOURCES: 10|STORIES DROPPED FOR LACK OF RECEIPTS: 0|COST: $1.72|STATUS: NOT FINE, BUT SURVIVABLE
OWNER: the machine|EDITOR: the rules|CALLS OPEN: 3|NEXT REVIEW: tomorrow 06:00 UK