A Daily Field Report on Things That Are Probably Fine
No. 7·Sunday 4 October 2026·Published 06:00 UK·Fine Meter 3/5: Not especially fine
Lead · Vulnerabilities
FortiMail joins the KEV catalogue while Citrix NetScaler takes a second hit in a week
A FortiMail zero-day is confirmed exploited and catalogued by CISA; Citrix NetScaler is being exploited as a 0-day to drop web shells, with a separate unauthenticated crash bug and no workaround.
confidence0.88
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalogue on Thursday after reports of active exploitation. It is a path traversal combined with improper NULL byte neutralisation in FortiMail 7.2 through 8.0, and it allows unauthenticated attackers to write arbitrary files to the underlying system. Writing a file where no file should be is the quiet, unglamorous first move of almost every intrusion anybody ever described afterwards as sophisticated.
Citrix, meanwhile, is having the sort of week that gets a one-word post on Mastodon and a link. Google has warned of 0-day exploitation of Citrix being used to deploy web shells, and separately CVE-2026-88779 lets an unauthenticated stranger crash NetScaler ADC and Gateway appliances configured for SAML single sign-on. There is no workaround. The fix is 14.1-73.41, and it is Sunday, which in this trade counts as Friday.
If you want the shape of the problem in one line, it is this: both products exist to stand between the internet and everything else, both are now a path into everything else, and the vendor disclosure cadence is such that defenders were comparing notes on infosec.exchange and a researcher was publicly offering a PGP key for confidential telemetry from affected organisations before anybody had a complete picture.
Why it mattersMail gateway and remote-access appliance, both exploited, both unauthenticated: patch, then hunt for web shells and new files, because patching does not evict anyone already inside.
The appliance you bought to inspect all of the traffic is, on the day it fails, the fastest available route to all of the traffic.
— Sturgeon’s Revelations · Probably Fine Daily No. 7
Every morning06:00 UK
Get it in your inbox. Every morning. Probably.
One email a day. The whole paper. Unsubscribe in one click.
§2
Top stories
The rest of the last 24 hours, with receipts.
Vulnerabilities
Two Zammad flaws added to KEV, and they chain; Dell ships a maximum-severity fix for CSM
CISA added CVE-2026-102489, a Zammad session fixation that can lead to remote code execution as the zammad user, and CVE-2026-102490, improper privilege management letting that same local user escalate to root. The catalogue entries say plainly that the two can be chained, which is the polite way of writing 'foothold plus root'. Separately, Dell has asked administrators to patch two maximum-severity Container Storage Modules flaws as soon as possible, including CVE-2026-63688 at CVSS 10.0, a missing authentication for a critical function in the software that connects Dell enterprise storage arrays to Kubernetes environments. Our fusion SITREP this morning counts ten CVSS 10.0 CVEs in the KEV catalogue listed as actively exploited.
Why it mattersChained KEV entries are not two tickets, they are one path; and anything that connects storage to Kubernetes without authentication is a cluster-wide event waiting for a scanner.
Warlock is still eating SharePoint, and tunnelling out through VS Code
Symantec and Carbon Black report the suspected China-linked group Warlock continuing to weaponise Microsoft SharePoint vulnerabilities, likely old and new, against organisations in Portuguese- and Spanish-speaking countries. The named victim set is a water utility, a telecommunications provider, a regional government body and a university, with initial access via the ToolShell exploit chain. The chain runs web shell, arbitrary code execution inside the SharePoint application pool, deeper tunnelling via VS Code, disabling of security tooling, then ransomware. OTX carried the indicators and the news cycle picked it up roughly two hours later, which is the fastest propagation anywhere in this week's data.
Why it mattersIf you run SharePoint Server on-premises, assume ToolShell is still in scope: patch, then hunt unauthorised web shells, app-pool child processes and VS Code tunnel traffic.
Six leak sites had their best day of the week on the same day
On 2 October, Krybit, Booba Project, Qilin, Akira, Wallstreet and Rhysida all hit their highest daily posting counts in this window, against medians of nought to two on other days. The following day theGentlemen posted its own run, including a Barcelona hospital, a Swindon primary school, a Western Australian volunteer emergency service unit and Aware at 400 GB.
Why it mattersLeak-site volume is a lagging indicator of intrusions that happened weeks ago, so treat a burst day as a prompt to check your own third parties, not as this morning's weather.
A ShinyHunters member is reportedly detained in Jordan and helping the FBI, while the leak site keeps counting down
A suspected ShinyHunters member known online as Rey has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. At the same time, the group's leak site carries posts against O'Reilly Automotive and DexCom, both with the same text: data published by end of day Friday if you do not reach out. Ransomlook carried the listings some twenty-three hours before the news outlets carried the detention, which is roughly how long it takes a newsroom to verify an arrest.
Why it mattersAn extortion brand that is simultaneously running deadlines and losing members to law enforcement is unpredictable, so do not treat a missed publication date as a negotiation win.
GitLab patches a 9.9 in its AI Gateway, and someone pointed agents at government websites
GitLab has fixed CVE-2026-90970, a critical flaw rated 9.9 in which a logged-in user with Duo Agent Platform access can execute commands on a self-hosted AI Gateway via crafted flow configs; fixed versions are 19.2.4, 19.3.2 and 19.4.1, and self-hosted deployments should patch and audit for abuse. Separately, researchers report AI agents aiming SQL injection at the US Department of Education and Library and Archives Canada, linking some of those agents to OpenAI, while a Chinese-speaking operator has been observed using an AI orchestration framework called SecFlow for intrusions across Taiwan, Indonesia, China, Vietnam and Afghanistan. Google, undeterred, is preparing to let Gemini access any file on a macOS device, open applications and browse the web without asking permission each time.
Why it mattersAgent frameworks are now both a target and a tool: treat the gateway as a privileged system, log every tool call, and keep a human approving change.
Four China-nexus campaigns and an MI5 alert surfaced in the same twenty-four hours
A China-nexus actor is deploying the Antino backdoor against government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar, using Outlook and OneDrive for command and control. China-aligned TA419 spent July 2026 impersonating prominent economists and AI policymakers to phish AI experts at US think tanks and universities. A Chinese-speaking crew tracked as Gambling Goblin has been turning Brazilian government and education sites into an SEO weapon since mid-2025. And MI5 issued a Security Service Espionage Alert on 30 September 2026 saying more than 100 UK-linked academics helped China's MSS, which funded the research.
Why it mattersDifferent methods, same sponsor direction: mailbox-based C2 and credential phishing of researchers both land inside identity and email telemetry, not on the perimeter.
A Danish university's identity system and an American school supplier both leaked the staff
The Technical University of Denmark says up to 200,000 people may be affected after attackers used compromised credentials to log into DTUBasen, its identity and access management system, and downloaded a large volume of data covering more than twenty years, including CPR numbers, names, addresses, work details and next-of-kin contacts. In the United States, Frontline Education is notifying school districts of a breach in which attackers exploited a vulnerability in third-party software to reach its systems and steal employee information including Social Security numbers. Two different failure modes, one outcome: the staff directory walks out of the building.
Why it mattersYour IAM platform is the crown jewel, not the control: monitor logins to it the way you monitor logins through it, and know which supplier holds your HR records.
Microsoft's own X account spent Thursday promoting a Clippy-themed coin
Unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, and used it in what appeared to be a crypto pump-and-dump, amplifying a Clippy-themed cryptocurrency account. No exploit chain, no implant, no vendor report with a cover illustration: just somebody else holding the credentials to a very large megaphone. The company that publishes a Digital Defense Report had its social media presence taken over by a cartoon paperclip with a token.
Why it mattersCorporate social accounts sit outside most identity programmes and have no EDR, no conditional access and a shared password; treat them as production.
The daily deep read: what is under the feeds, not on top of them.
Under the feeds: a synchronised ransomware Friday, a twenty-hour head start on victim data, and two leak sites that stopped at the same minute.
Exception 01
Six actors, one peak day
Krybit (8 items against a median of 1 on other days), Booba Project (8 against 0), Qilin (6 against 2), Akira (6 against 1), Wallstreet (6) and Rhysida (6) all hit their highest daily counts on 2026-10-02, with Microsoft SharePoint also bursting the same day on confirmed Warlock exploitation, and no patch Tuesday or common advisory in the data to explain it.
confidence0.65Speculative
Wrong if
If victim-side evidence shows intrusion dates spread over weeks, or a leak-site aggregator published a bulk back-import on that date, this is reporting artefact rather than tempo.
Watch
Whether the same actors keep posting into 2026-10-05 and 2026-10-06, and whether an initial-access-broker announcement turns up dated 1–2 October.
Ransomlook listed theGentlemen's victims about twenty hours before ransomware.live attributed them
For zoominfo.com, rotamac.ca, Hospital de la Santa Creu i Sant Pau, Westrop Primary School and Mandurah SES, ransomlook carried the victim entries roughly twenty hours ahead of ransomware.live's actor-attributed posts, even though for the actor entity itself ransomware.live leads by 11.6 hours.
confidence0.70
Wrong if
If ransomlook's early entries attributed those victims to a different group, the gap is re-attribution rather than scraping depth.
Watch
Whether the same inversion holds for other groups; if it does, ransomlook is the faster surface for early victim notification and ransomware.live the better one for attribution.
Krybit and Booba Project both went quiet at 13:44 on 2 October while their peers carried on
Both actors stopped producing items after exactly 2026-10-02T13:44, while Akira, Qilin, Wallstreet, Rhysida and theGentlemen all produced items later, several of them bursting on 2026-10-03 — so a pure collection cutoff does not explain it.
confidence0.55Speculative
Wrong if
Direct leak-site monitoring showing posts from either group after that timestamp, or evidence the collector stopped polling those two sources specifically.
Watch
Leak-site availability for both groups, and any law enforcement announcement naming them.
CVE-2026-103111 in PCRE2 before 10.49 allows an out-of-bounds write with arbitrary data where an attacker controls the regular expression under certain JIT API usage, and it appears exactly once in the window, from NVD, with no cross-source pickup at all.
confidence0.50Speculative
Wrong if
If no commonly deployed software accepts attacker-controlled regex through PCRE2's JIT API, real-world exposure is effectively nil.
Watch
PCRE2 10.49 landing in distribution repositories, and any proof-of-concept that reaches it through a web application input.
Nothing to seeThe 200 ThreatFox entries are bulk submissions — AsyncRAT hashes by the hundred, Mirai, Potassium C2 on one port — useful for infrastructure mapping and nothing else. The SWIFT banking middleware RCE claim is single-sourced with no corroboration anywhere in 629 items; treat as unverified. The Paragon Solutions IPO item is one person's post. Wallstreet's 17 TB World Cup 2034 figure is the attacker's own claim and cannot be checked from here. No new malware family emerged: AsyncRAT, Mirai, Potassium and ScreenConnect abuse are all known commodities.
Deep read: 629 items read · $1.25 of compute
§4
Forecast
Dated, falsifiable calls. We mark our own homework in public.
Today’s calls
DueCallConfidence
DueSun 11 Oct7d
A Citrix NetScaler vulnerability will be added to the CISA KEV catalogue on or before 11 October 2026.
Wrong ifNo Citrix or NetScaler entry appears in cisa-kev feed items dated up to and including 2026-10-11.
Krybit or Booba Project will post at least one new victim to ransomware.live or ransomlook by 14 October 2026, showing the 2 October silence was a lull rather than a takedown.
Wrong ifNeither actor appears in ransomware.live or ransomlook items dated 2026-10-05 to 2026-10-14.
Tracking platforms will still list 'Booba Project' and 'booba team' as separate actors with overlapping victims, with no reconciliation note published.
Called Sat 3 Oct · due Tue 13 Oct
Today's feed shows both 'Booba Project' on ransomware.live and 'booba team' on ransomlook posting the identical four victims with no reconciliation note, confirming they remain listed as separate actors.
At least one further Citrix NetScaler post-patch compromise report, with webshell indicators, appears in these feeds.
Called Sat 3 Oct · due Tue 13 Oct
Mastodon posts and a cyber-news article confirm ongoing Citrix NetScaler exploitation with webshell indicators reported by Google and discussed in the feeds.
The component that connects your source code to a language model and, in self-hosted GitLab before 19.2.4, 19.3.2 or 19.4.1, connects the language model to your command line.
§5
From our edge
Live attacks on our own servers in the last 24 hours. Yes, really ours.
Our own edge, which is not special and that is precisely the point: in the last twenty-four hours the Adversary DNA sensor profiled 118 hostile sources — 72 scanners, 29 bot crawlers, 17 targeted operators — sending 12,449 requests between them, of which 34 went past reconnaissance into actual exploitation attempts, across 3,215 addresses from 75 countries, 1,400 of them seen for the first time today. Thirteen groups of addresses shared a behavioural fingerprint; one of them, DNA c67915f564de, covers 18 IPs, with 20.198.74.230 alone firing 358 requests at 134 a minute, hunting for wp_filemanager.php and a shortlist of planted PHP files, which is a scan for other people's web shells rather than for us. Another, 91.148.245.81, asked for /.git/HEAD, /backup.sql, /.ssh/id_rsa and /.ssh/id_ed25519 — 31 requests in about 0.8 seconds, which is not a person, it is a loop. And three addresses sent 16 requests shaped like CVE-2024-4577 exploitation, a named, patched, thoroughly documented bug, still being sprayed at the internet, because somewhere out there Dave from procurement has a box that nobody has looked at since the migration, and the attackers know it even if the asset register does not. Raw logs never left the server. Only the findings did.
118hostile sources profiled
12,449requests from them
34reached exploitation
13shared-DNA clusters
8.9/10top hostility
3,215addresses at our edge
1,400first seen today
75countries
The WTF list
WTF #1
The most determined visitor
45.148.10.15, a scanner (hostility 6.4/10), sent 27 requests to one of our sites, probing for /wp-login.php, /blog/wp-login.php, /wordpress/wp-login.php, /wp/wp-login.php.
Why it’s weirdHighest hostility on the board; its kill chain reached credential-access.
attribution: WordPress wp-login credential brute-force campaign (sensor's best match, 38%)Sun 4 Oct, 04:00 UTC
Detail
kill chain: reconnaissance → weaponization → credential-access · DNA 776dadf486a3
WTF #2
Same DNA, different addresses
20.198.74.230, a scanner (hostility 6.0/10), sent 358 requests at 134 a minute to one of our sites, probing for /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /wp-admin/css/colors/ocean/gZqjPe.php, /wp-admin/css/colors/midnight/ZDOUJz.php.
Why it’s weird18 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.214.145.90, 20.205.114.149, 20.92.83.244, 4.196.166.155, 20.58.177.98 and more.
attribution: WordPress webshell/backdoor locator scan (sensor's best match, 42%)Sun 4 Oct, 04:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA c67915f564de
WTF #3
Trying CVE-2024-4577 on us
3 addresses sent 16 requests shaped like CVE-2024-4577 exploitation (/index.php), including 165.101.250.169, 77.91.122.15, 172.104.241.92.
Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.
attribution: unknown
Detail
probe family: webshell
WTF #4
The strangest shopping list
20.210.186.186, a targeted operator (hostility 6.3/10), sent 264 requests to 3 of our sites, probing for /wp-content/plugins/hellopress/wp_filemanager.php, /myglu.php, /bnmtp.php, /wp-includes/ID3/about.php.
Why it’s weirdAsked for files almost nobody else asks for: /wp-content/plugins/hellopress/wp_filemanager.php, /myglu.php, /bnmtp.php, /wp-includes/ID3/about.php, /wp-content/themes/index.php.
attribution: unknownSat 3 Oct, 17:00 UTC
Detail
kill chain: reconnaissance → weaponization → exploitation · DNA 938595d2ae44
WTF #5
In a hurry
91.148.245.81, a scanner (hostility 4.9/10), sent 31 requests to one of our sites, probing for /.git/HEAD, /backup.sql, /.ssh/id_ed25519, /.ssh/id_rsa.
Why it’s weirdFired 31 requests in about 0.8 seconds.
attribution: unknownSat 3 Oct, 17:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA ce6ecdfacbe3
WTF #6
Somebody we might know
137.131.43.163, a scanner (hostility 6.3/10), sent 20 requests to one of our sites, probing for //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml.
Why it’s weirdThe sensor's most confident campaign match of the day: WordPress wlwmanifest.xml enumeration scan at 55%.
attribution: WordPress wlwmanifest.xml enumeration scan (sensor's best match, 55%)Sun 4 Oct, 04:00 UTC
Detail
kill chain: reconnaissance → weaponization · DNA dfef4501b216
§6
From the vault
Things we built, shipped, retired or forgot. One a day.
Decommissioned 2026-09-24. Idle since July.
Los Alamos Arena: the leaderboard where the bad agent was the house
Los Alamos Arena was an ELO leaderboard for AI agents, in which one deliberately nasty agent sat in the middle and tiers of attacker agents took turns at it, each one ranked like a chess player, which is a far more honest way of measuring machine capability than any vendor benchmark with a trophy on the slide. It did the thing good research does: it made a claim falsifiable and then let anyone try. It sat idle from about July, because the thing that kills a side project is never a flaw in the idea, and it was decommissioned on 24 September 2026. We liked it. It had a ranking and no marketing.
§7
SITREP
Fusion SITREP (cyber)
Ten critical CVEs with CVSS 10.0 scores are actively exploited in the wild (KEV=True), including CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, and seven others requiring immediate patching across all infrastructure. CRITICAL: Ten CVEs with CVSS 10.0 scores confirmed in CISA KEV catalog, indicating active exploitation: CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567. Top threat actors operational: Kimsuky (134 TTPs), Lazarus Group (95 TTPs), APT28 (94 TTPs), APT41/Mustang Panda (85 TTPs each), Magic Hound/Volt Typhoon (82 TTPs each), Sandworm Team (79 TTPs), OilRig (77 TTPs). No specific CVE-actor attribution data available but nation-state APT activity remains elevated.
IMMEDIATE: Emergency patching for all ten CVSS 10.0 KEV-listed CVEs across enterprise infrastructure within 24 hours
Block network traffic from Yemen, Syria, Mali, Afghanistan, Sudan (risk ≥0.99) at perimeter firewalls pending risk assessment
Threat hunt for Kimsuky, Lazarus Group, APT28, Sandworm Team, and Magic Hound TTPs across endpoint/network telemetry
Audit and remove npm/openclaw, siyuan/kernel, n8n, avideo, vm2 packages from production environments; assess alternatives
One email a day. The whole paper. Unsubscribe in one click.
§9
Colophon
How this edition was made, plainly.
Edition 7 was made by machine and checked by code. Every item published by 10 public threat feeds in the 24 hours to 05:05 UK (629 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.41. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.
629items read
24hour window
$2.41cost of this edition
04:05 UTCgenerated
Sources this morning
NVD200ok
ThreatFox200ok
infosec.exchange76ok
ransomware.live43ok
Security news41ok
RansomLook38ok
AlienVault OTX18ok
RSS10ok
CISA KEV2ok
From the vault · Ninja Labz1ok
ITEMS READ: 629|SOURCES: 10|STORIES DROPPED FOR LACK OF RECEIPTS: 0|COST: $2.41|STATUS: NOT ESPECIALLY FINE
OWNER: the machine|EDITOR: the rules|CALLS OPEN: 3|NEXT REVIEW: tomorrow 06:00 UK