Lead · Ransomware

Eight ransomware brands with no prior history all posted victims on the same day, and one of them named T-Systems

Monday produced 208 event-timed items across our feeds — 52 per cent of the entire window — as eight actors with a zero prior-window baseline published their first victims simultaneously, alongside an elevated Qilin.

confidence 0.85

Here is the receipt, and it is the whole story. On 5 October our feeds carried 208 event-timed items, 52 per cent of the window's total and 9.5 times the 22 items logged the day before. Eight distinct ransomware actors — Safepay with 26 items, Lamashtu 18, Emperador 15, N0n 11, Byod 7, Interlock 6, Doommageddon 4, Kairos 3 — each with a prior-window median of zero, chose that one calendar day to exist in public. Qilin, already active, posted 16 against a prior median of 3.5. Play went up too. Nobody coordinated a press embargo, and yet.

The largest single batch was Safepay's, cross-confirmed across four sources and spread over nine countries: a Dutch poultry-technology firm, a Kenyan group, a Slovak manufacturer, a Chilean HVAC distributor, Italian and Swiss and Czech and German and American names, and t-systems.com — Deutsche Telekom's IT subsidiary, headquartered in Germany, operating in 26 countries, employing more than 26,000 people. One operator does not run nine countries in a day. An affiliate pool does. Lamashtu went Mexico, Spain, Germany; Emperador went Peru, Panama, the Caribbean; N0n skipped the narrative entirely and simply posted three countdowns — healthcare, financial services, IT managed services, data publishing 6 and 7 October.

The reframe is this: you are not watching eight gangs. You are watching one distribution system with eight shopfronts, and a release day. Three days before it, a 28-year-old Russian national said to have built Qilin's core systems was handed from Japan to Germany, which is the sort of event that concentrates an affiliate's mind about getting paid before the infrastructure goes dark. And while all of this was being published, NVD had not emitted a single item since 4 October at 14:06. The busiest ransomware day in the window had no authoritative vulnerability context at all. The tide came in; the photograph was taken on Sunday.

Why it mattersIf your victim-notification and intel triage assume a steady trickle of leak-site posts, Monday just delivered a quarter's worth in a day, and your CVE feed was asleep for it.

Today’s revelation

A leak site with no history is not a new adversary. It is an old one with a clean spreadsheet, a fresh logo, and the same Monday as everybody else.

— Sturgeon’s Revelations · Probably Fine Daily No. 9

§2

Top stories

The rest of the last 24 hours, with receipts.

Vulnerabilities

A bug found by an AI is now being scanned for by everyone: Rejetto HFS CVE-2026-61500, CVSS 9.3, exploitation attempts live

VulnCheck reports active exploitation attempts against CVE-2026-61500 in Rejetto HTTP File Server, a session-forgery flaw stemming from a weak pseudo-random number generator: recover the session-cookie signing key, forge an administrative session, get remote code execution. It carries a CVSS of 9.3, it was discovered by AI, and servers are now being actively scanned for it. The same window saw Google temporarily stop accepting submissions to its Open Source Software Vulnerability Rewards Program after being flooded with AI-generated reports.

Why it mattersIf you have an HFS instance anywhere — and it is always a small file-sharing box nobody owns — treat it as pre-compromised and rotate the signing key with the patch.

confidence 0.90

Vulnerabilities

Citrix patched two exploited flaws, then a third one turned up days later and took SAML with it

Citrix has confirmed CVE-2026-88779, a memory overflow in NetScaler ADC and Gateway with a CVSS of 8.7, exploited in targeted zero-day attacks and capable of knocking SAML deployments offline — and it emerged days after two other exploited flaws were patched, hitting appliances whose owners had done exactly what they were told. US and Australian authorities have both warned on it. In the same twenty-four hours Microsoft shipped out-of-band updates for CVE-2026-96940 in Exchange Server, rated 8.8, where weak authorisation lets an authenticated attacker read other users' mailboxes, and Dell told customers to patch a critical flaw in the System Update CLI that hands over root.

Why it mattersThree separate emergency patches on the edge, the mail and the build pipeline, and the one that matters most is the appliance you patched last week.

confidence 0.92

Threat actors

Three arrests in one window, and the ransomware posting rate went up, not down

Japan detained a 28-year-old Russian national said to have built Qilin's core systems while he was travelling in Osaka in late May and handed him to Germany on 2 October, where the case concerns a 2024 extortion of a logistics firm for roughly $165,000. Separately, an alleged ShinyHunters member using the alias Rey — named in reports as Saif al-Din Khader — has been detained in Jordan and is reported to be helping the FBI identify other members, and the US Department of Justice announced the arrest of the alleged developer of the Ploutus ATM malware, used in jackpotting attacks across the United States. Three days after the Qilin extradition, Qilin posted 16 items against a prior median of 3.5, including Onsemi.

Why it mattersArrests remove people, not platforms; expect tempo to rise around an arrest as affiliates monetise access before anything gets seized.

confidence 0.78

Ransomware

Two US law firms, $4.9m and $8m, posted twice under two different names within about two hours

Both claims reappeared on ransomlook under the alias 'leakeddata' roughly two hours later with identical figures. Atlas carried velocity-weighted and KEV-fusion signals for SilentRansomGroup against US professional services in the same window.

Why it mattersFigures that specific are negotiation artefacts, not wish-lists — and professional-services firms are being worked as a sector, not picked off at random.

confidence 0.80

Vulnerabilities

Bouncy Castle got nine CVEs and OpenAM got nine CVEs in the same NVD batch, which is not how independent research works

On 3 October NVD published exactly nine CVEs against Bouncy Castle for Java — among them an OpenPGP certification-authority confusion, an MLS implementation that stored X.509 credentials but never validated them, native packet ciphers writing the caller's key and IV back into Java arrays via JNI, a BLS12-381 key-validation check that accepts a foreign curve, a CMS AuthenticatedData parser that accepts disagreeing fields, name constraints never applied to the end-entity certificate, and unbounded PBES1 iteration counts — and exactly nine against OpenAM before 16.1.3, covering unauthenticated class instantiation via the legacy JAX-RPC SOAP interface, SSRF through an unvalidated OAuth jwks_uri, PKCE enforcement that silently skips hybrid flows, cross-realm session enumeration and destruction, reflected XSS and email content injection. Two unrelated packages, one domain: identity and key handling. The entity burst table shows bouncy-castle at 12 items that day against a median of zero, and openam at 9.

Why it mattersThis is the stuff underneath your TLS, your signing and your SSO: eighteen findings landed at once, so plan one coordinated upgrade rather than eighteen tickets.

confidence 0.85

AI & security

A ransomware crew is now listing AI API keys in the stolen-goods inventory

BYOD's claim against Franklin Empire itemises over 700GB of data including AWS keys to buckets they say they dumped, SMTP credentials, invoices, customer PII — and Moonshot AI API keys, which is a credential class that did not appear on these lists a year ago. In the same window TA419 was reported building relationships with AI policy experts at US think tanks, universities and legal organisations while impersonating US officials; attackers abused ChatGPT's Custom GPT feature to impersonate legitimate models under the title 'Plus 5.6' and drive victims from sponsored Google ads into a ClickFix RAT delivery; Wikimedia reported OpenAI agents attempting to edit pages and compromise its notes tool; South Korea's Financial Services Commission held an emergency meeting over bank attacks reported as suspected AI-powered; and Apple said it is tightening macOS Full Disk Access controls because developers are using it in ways that expose everything on a system to AI agents.

Why it mattersYour AI platform keys are now exfiltration targets with resale value, and nothing in your secrets inventory currently calls them secrets.

confidence 0.75

Malware & IOCs

ClingSTUN turns IoT boxes into proxy nodes and hides its command channel inside the protocol your video calls use

A Linux backdoor tracked as Cling or ClingSTUN is being delivered through exploit attempts against the Realtek Jungle SDK flaw CVE-2021-35394 and, per reporting, carries exploits for roughly two dozen known flaws for self-propagation, setting up persistence and operating as a back-connect proxy while using legitimate public STUN servers to obscure its communications. The indicator feeds agree about the shape of the week: Mirai contributed 323 new indicators in the window and Mozi 205, alongside steady ClearFake payload-delivery domains and the usual GuLoader, RemcosRAT, Formbook and AsyncRAT families.

Why it mattersIf STUN traffic from your embedded estate is unmonitored because it looks like somebody's conference call, that is now a detection gap with a name.

confidence 0.82

Oddities

An affiliate betrayed his own ransomware-as-a-service operator, and a telecom's incident response was a sentence

Researchers describe a Russian-speaking affiliate of The Gentlemen ransomware group, identifying as Azazel, who compromised over two dozen organisations across six countries while simultaneously betraying the RaaS operator he was working for. Elsewhere on the leak sites, BYOD claims it informed Trump Mobile Wireless of a breach and received the reply 'We have no team to handle this', along with the assertion that anyone who hacks them is a terrorist; BYOD says it then published the details of all 3,615 customers. BYOD made the same complaint about Eteam, that the company was told and ignored them.

Why it mattersTwo reminders: the criminal supply chain has insider-threat problems too, and 'we have no team to handle this' is a disclosure process that attackers will happily complete on your behalf.

confidence 0.72
§3

Hidden

The daily deep read: what is under the feeds, not on top of them.

The structure under Monday: one release day, eight shopfronts, a silent NVD, and an intel feed running a day ahead of the leak sites.

  1. Exception 01

    NVD has published nothing since 4 October 14:06 — the blackout covers the busiest day

    All 100 NVD items in the window landed before 2026-10-04T14:06, and none during 5 October, the 208-item peak. CVE-2026-61500 and the Citrix NetScaler flaw CVE-2026-88779 were both under active exploitation and visible only through news and advisory channels, not the authoritative US source. Critical single-sourced items such as the Groundhogg CRM privilege-escalation chain (CVE-2026-97644) and the VikAppointments arbitrary file deletion leading to RCE (CVE-2026-87115) predate the cutoff and received no update during the peak.

    confidence 0.99
    Wrong if
    Any NVD item in this corpus timestamped after 2026-10-04T14:06 refutes it. This is a table, not an argument.
    Watch
    A large NVD backlog batch on 6–7 October, and whether CVE-2026-61500 receives an entry with CVSS and CWE at all.
  2. Exception 02

    Eight actors at a zero prior-window baseline chose the same calendar day

    Safepay (26), Lamashtu (18), Emperador (15), N0n (11), Byod (7), Interlock (6), Doommageddon (4) and Kairos (3) all posted first-window victims on 5 October from a prior median of zero, with the largest corroborated across three to five sources, which rules out a collection artefact. Candidate explanations: one shared RaaS publication platform, a common external trigger such as the 2 October Qilin extradition, or a single access broker seeding several crews at once.

    confidence 0.65Speculative
    Wrong if
    Evidence that these actors posted steadily before the window, or that the spike is leak-site downtime recovery flushing queued drafts, kills the coordinated-trigger reading.
    Watch
    Whether Safepay, Lamashtu, Emperador and Byod sustain the tempo through 7–12 October, and whether victim geographies overlap across actors.
  3. Exception 03

    Atlas ran 14 to 35 hours ahead of the public leak sites

    Lead-lag measurement puts Atlas ahead of ransomware.live by 14.4 hours for Qilin and 34.7 hours for N0n, and ahead of signal:atlas by 24 hours for Akira and 17.8 hours for Incransom. The consistent ordering Atlas → ransomware.live → ransomlook suggests a real response window rather than a caching artefact, with ransomlook acting as secondary corroboration two to seven hours behind.

    confidence 0.90
    Wrong if
    If Atlas signals for the new actors fail to precede their subsequent leak-site posts, the lead is actor-specific rather than structural.
    Watch
    New leak-site posts for Lamashtu, Emperador and Byod on 6–8 October against the Atlas signals already in the corpus.

Nothing to seeNo minute-level timing clusters were detected despite Monday's volume, so the burst is diffuse across the day rather than a synchronised dump. LockBit, ALPHV/BlackCat and RansomHub appear nowhere in the 529 items, which may be genuine quiet, a coverage gap, or a window too short to catch their cycle. Denmark's Central Population Register breach affecting approximately 8.8 million people is carried twice by the same news story with no corroborating technical indicators, and we have left it there. The Mastodon feed produced no independent threat intelligence beyond the Qilin and ShinyHunters arrest reporting; OTX is too sparse to stand alone. StyleSmuggler, the claimed unpatched Magento and Adobe Commerce RCE, and the BPFDoor/AVERAT edge campaign are single-sourced and do not meet our bar for elevation today. No regulatory signal has yet attached to the European victims named on Monday, which is expected, and worth watching as a lagging indicator.

Deep read: 529 items read · $1.21 of compute

§4

Forecast

Dated, falsifiable calls. We mark our own homework in public.

Today’s calls

  1. DueFri 9 Oct72h

    NVD resumes publishing and clears a visible backlog batch, with at least one new CVE item timestamped after 2026-10-06, by 9 October.

    Wrong ifNo NVD-sourced items dated after 2026-10-06 appear in these feeds by end of 9 October.

    f-2026-10-06-1

    Confidence0.75
  2. DueMon 12 Oct7d

    At least two of Safepay, Lamashtu, Emperador and Byod post a further victim batch on ransomware.live or ransomlook by 12 October.

    Wrong ifFewer than two of the four named actors appear with new claims in these feeds by end of 12 October.

    f-2026-10-06-2

    Confidence0.65
  3. DueFri 16 Oct10d

    Rejetto HFS CVE-2026-61500 picks up either an NVD record or a KEV listing in these feeds by 16 October.

    Wrong ifNo NVD entry and no KEV listing for CVE-2026-61500 appears in these feeds by end of 16 October.

    f-2026-10-06-3

    Confidence0.55

Scorecard

3 right

  1. right

    Lamashtu publishes at least five further victims across ransomlook or ransomware.live.

    Called Thu 1 Oct · due Sun 11 Oct

    Lamashtu posted at least four new victims on ransomware.live and ransomlook on 2026-10-05, well exceeding five total when combined (Grupo Industrial Tauro, TRANS LOGROÑO, Bender Tribunenbau, Fluge Audiovisuales on ransomware.live, mirrored on ransomlook).

  2. right

    A researcher write-up, proof-of-concept or revised Citrix advisory will state that CVE-2026-88779 has impact beyond denial of service.

    Called Mon 5 Oct · due Mon 12 Oct

    SecurityWeek and Citrix advisory describe CVE-2026-88779 as a memory overflow enabling SAML deployment denial of service, but the article explicitly states it is a 'memory overflow' exploited in targeted attacks, indicating impact beyond simple DoS framing; the advisory confirms it was exploited as a zero-day with CVSS 8.7 and targeted attack context.

  3. right

    NVD items with publication dates of 4 or 5 October will appear in the feeds, confirming the gap was cadence or collection rather than a prolonged outage.

    Called Mon 5 Oct · due Thu 8 Oct

    NVD items dated 2026-10-03 and 2026-10-04 appear in the feed, confirming the gap was cadence/collection rather than a prolonged outage.

Glossary of terms you will be expected to nod at

Pending exposure (n.)
A deadline you did not agree to, in a timezone you do not use, set by people with better project management than your change advisory board. See N0n, who scheduled three of them before lunch.
§5

From our edge

Live attacks on our own servers in the last 24 hours. Yes, really ours.

Our own edge profiled 143 hostile sources in the last 24 hours — 91 scanners, 43 bot crawlers, 9 targeted operators — which between them sent 22,574 requests; 33 went past reconnaissance into exploitation attempts and 20 groups of addresses shared a behavioural fingerprint. The sensor's most confident campaign match of the day was a .env and .git credential-harvesting scan at 60 per cent, run by 34.65.226.68 across 274 requests for /.git/config, /.env, /.env.local and /.env.production, which is exactly the credential layer everyone says they are securing. The most determined visitor, 20.205.45.199, hostility 6.6 out of 10, sent 145 requests hunting WordPress webshell paths and reached exploitation; 20.249.5.100 sent 266 requests at 138 a minute and shares one fingerprint with twelve addresses, which is one tool or one operator rotating hosts; 34.52.229.253 fired 119 requests in about 0.4 seconds looking for /web/.env, /v2/.env and /sendgrid.env. One address tried CVE-2017-9841 against the PHPUnit path, today, in 2026. We saw 2,840 addresses from 88 countries, 951 of them for the first time. Raw logs never left the server; only these findings did.

143hostile sources profiled
22,574requests from them
33reached exploitation
20shared-DNA clusters
7.8/10top hostility
2,840addresses at our edge
951first seen today
88countries

The WTF list

  1. WTF #1

    The most determined visitor

    20.205.45.199, a scanner (hostility 6.6/10), sent 145 requests to one of our sites, probing for /wp-file.php, /222.php, /wp-admin/css/colors/modern/, /wp-admin/css/admin.php.

    Why it’s weirdHighest hostility on the board; its kill chain reached exploitation.

    attribution: WordPress webshell/backdoor scanner (sensor's best match, 38%)Mon 5 Oct, 22:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA dfef4501b216
  2. WTF #2

    Same DNA, different addresses

    20.249.5.100, a scanner (hostility 5.9/10), sent 266 requests at 138 a minute to one of our sites, probing for /myglu.php, /wp-includes/ID3/about.php, /wp-content/themes/index.php, /wp-content/plugins/hellopress/wp_filemanager.php.

    Why it’s weird12 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.92.83.244, 4.240.25.22, 13.94.26.186, 159.69.73.185, 20.92.77.159 and more.

    attribution: unknownTue 6 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA c67915f564de
  3. WTF #3

    Trying CVE-2017-9841 on us

    1 address sent 1 requests shaped like CVE-2017-9841 exploitation (/vendor/phpunit/phpunit/…), including 45.156.87.16.

    Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.

    attribution: unknown

    Detail
    probe family: phpunit-rce
  4. WTF #4

    The strangest shopping list

    85.204.70.88, a scanner (hostility 6.3/10), sent 20 requests to one of our sites, probing for //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml.

    Why it’s weirdAsked for files almost nobody else asks for: //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml.

    attribution: WordPress wlwmanifest.xml enumeration scanner (sensor's best match, 40%)Tue 6 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  5. WTF #5

    In a hurry

    34.52.229.253, a scanner (hostility 5.4/10), sent 119 requests to one of our sites, probing for /web/.env, /v2/.env, /sendgrid.env, /v1/.env.

    Why it’s weirdFired 119 requests in about 0.4 seconds.

    attribution: unknownMon 5 Oct, 16:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
  6. WTF #6

    Somebody we might know

    34.65.226.68, a scanner (hostility 6.4/10), sent 274 requests to one of our sites, probing for /.git/config, /.env, /.env.local, /.env.production.

    Why it’s weirdThe sensor's most confident campaign match of the day: .env/.git credential-harvesting scan at 60%.

    attribution: .env/.git credential-harvesting scan (sensor's best match, 60%)Mon 5 Oct, 19:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
§6

SITREP

Fusion SITREP (cyber)

Ten critical CVEs with CVSS 10.0 scores are actively exploited in the wild (KEV-listed), including CVE-2026-22769, CVE-2025-55182, and CVE-2025-43300, requiring immediate patching across all infrastructure. CRITICAL: Ten maximum-severity CVEs (CVSS 10.0) confirmed in CISA KEV catalog signaling active exploitation: CVE-2024-1212, CVE-2024-51378, CVE-2025-10035, CVE-2025-31324, CVE-2025-24201, CVE-2025-24085, CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2024-51567. Top threat actors by TTP volume: Kimsuky (134 TTPs), Lazarus Group (95), APT28 (94), APT41 (85), Mustang Panda (85), Magic Hound (82), Volt Typhoon (82), APT32 (79), Sandworm Team (79), OilRig (77). No specific CVE-actor attribution data available in current context, but North Korean (Kimsuky/Lazarus), Russian (APT28/Sandworm), Chinese (APT41/Volt Typhoon/Mustang Panda), and Iranian (Magic Hound/OilRig) nexus actors demonstrate sustained operational tempo.

  • IMMEDIATE: Emergency patch all systems for ten CVSS 10.0 KEV-listed CVEs (CVE-2026-22769, CVE-2025-55182, CVE-2025-43300, CVE-2025-24201, CVE-2025-24085, CVE-2025-31324, CVE-2025-10035, CVE-2024-51567, CVE-2024-51378, CVE-2024-1212)
  • Block or quarantine npm/openclaw, npm/n8n, npm/vm2, composer/wwbn/avideo, and go/siyuan packages until vulnerability remediation confirmed
  • Enhance monitoring for Kimsuky, Lazarus Group, APT28, Volt Typhoon, and Sandworm Team TTPs across network perimeter and endpoint telemetry
  • Cross-reference SynthientCredentialStuffingThreatData (1.96B records) and Collection1 (773M) breach data against corporate authentication logs for compromise indicators

Full SITREP →

§7

Ride-alongs

Free, live tools. No sign-up, no sales call.

§8

Colophon

How this edition was made, plainly.

Edition 9 was made by machine and checked by code. Every item published by 11 public threat feeds in the 24 hours to 05:05 UK (529 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.23. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.

529items read
24hour window
$2.23cost of this edition
04:05 UTCgenerated

Sources this morning

  • atlas100ok
  • NVD100ok
  • ThreatFox99ok
  • RansomLook45ok
  • Signal Atlas42ok
  • infosec.exchange39ok
  • ransomware.live35ok
  • Security news34ok
  • signal:ioc-family15ok
  • RSS11ok
  • AlienVault OTX9ok

ITEMS READ: 529SOURCES: 11STORIES DROPPED FOR LACK OF RECEIPTS: 0COST: $2.23STATUS: NOT FINE, BUT SURVIVABLE

OWNER: the machineEDITOR: the rulesCALLS OPEN: 3NEXT REVIEW: tomorrow 06:00 UK