Lead · Vulnerabilities

FortiBleed: the patch is not the remediation, because the attacker has an account now

Over 86,644 internet-facing Fortinet devices across 194 countries are reported compromised, with operators creating new accounts and deleting the legitimate ones to lock owners out.

confidence 0.80

The figure is 86,644, which is not a round number and therefore worth reading twice. That is the count of internet-facing FortiGate firewalls and SSL VPN gateways verified compromised in the FortiBleed credential campaign, across 194 countries, and the operators are not loitering politely: they are creating new accounts and deleting existing accounts and passwords so that the legitimate administrators cannot get back in.

We have spent a decade training ourselves to treat the CVE as the event and the patch as the ending, and this is a category error. Patching after an account has been planted is changing the locks after the burglar has had a key cut for himself and taken yours off the hook. The vulnerability is a moment; the account is a tenancy.

So today's work is not a scan, it is an inventory: pull the local administrator list off every edge device you own, compare it to the list you believe should exist, and treat any difference as an incident rather than a config drift ticket. One honest caveat, because we would want it ourselves: the number is reported as verified compromise rather than exposure, and that distinction is the first thing to confirm against your own estate. Then go and read the admin list.

Why it mattersYour vulnerability dashboard will turn green while an attacker-created administrator sits in the device the dashboard is describing.

Today’s revelation

A patch closes the door the attacker came through. It does not log out the account they made on the way in.

— Sturgeon’s Revelations · Probably Fine Daily No. 12

§2

Top stories

The rest of the last 24 hours, with receipts.

Vulnerabilities

CISA's new KEV entries are mostly archaeology: BIND 2015, Struts 2016, ProFTPD 2015

Five additions landed on 8 October: ISC BIND CVE-2015-5477 at EPSS 0.91284, Apache Struts CVE-2016-3081 at 0.93352, ProFTPD CVE-2015-3306 at 0.96752, ONLYOFFICE Docs path traversal CVE-2021-3199 at 0.08215, and Strapi CVE-2023-22894 at 0.01658, the last carrying CISA's own note that the product may be end-of-life. KEV is not a newsletter about new bugs; it is a dig site, and someone is out there right now running an exploit older than most of the SOC's laptops against the FTP and DNS boxes nobody has owned since a reorg. The two low-EPSS entries matter as much as the high ones: EPSS describes the crowd, KEV describes somebody who already did it.

Why it mattersYour asset inventory's weakest section is the part labelled 'legacy, scheduled for decommission', and that is exactly the stack in today's list.

confidence 0.93

Vulnerabilities

Atlassian Data Center attacked within hours of the proof-of-concept, while Cisco ships a dozen criticals

Threat actors began targeting CVE-2026-21589, a critical flaw in Atlassian's self-hosted Data Center products, within hours of the PoC being published, which is a shorter interval than most change advisory boards manage between agenda and apologies. In the same window Cisco released advisories for five critical NX-OS vulnerabilities allowing arbitrary code execution with root privileges on Nexus switches, part of a dozen critical fixes covering unauthorised access, information leaks, privilege escalation, denial of service and remote code execution, and SonicWall and Splunk patched critical and high-severity defects including authentication bypass. For scale on how cheap exploitation has become: on day two of Pwn2Own Ireland 2026 researchers took home $232,500 for 45 unique zero-days, with the Samsung Galaxy S26 falling three more times.

Why it mattersThe gap between public exploit and attempted exploitation is now measured in hours, so your emergency change process is the control, not your patch cycle.

confidence 0.90

AI & security

ARTEX: an open-source agentic pentest tool did the hunting itself, against South Korean banks

CrowdStrike Intelligence reports a campaign from late September against South Korean financial organisations in which a China-based actor used ARTEX, a freshly released open-source agentic pentesting tool, with DeepSeek v4.1-flash as the primary LLM backbone and GLM-5.3 and Grok 4.6 alongside it, and the published account is explicit that the tooling actively hunted vulnerabilities and compromised services autonomously, with data exfiltrated. Around it this week: malware authors embedding natural-language instructions in their code specifically to derail automated AI analysis pipelines; PoeLLM, active since April 2026, hunting exposed LiteLLM, Ollama, Gotenberg and Gitea; and a now-patched AWS Bedrock AgentCore flaw, AgentCorruption, in which one prompt to one chatbot could reach an organisation's whole agent fleet. Rein Security, meanwhile, raised $25 million to guard AI agents at runtime, which is the market's way of saying it has read the same reports.

Why it mattersIf your detection logic assumes a human operator's pacing and tool-reuse, the thing on the other end no longer has either.

confidence 0.75

Ransomware

Ten crews posted victims on the same Wednesday, and we do not think they planned it together

Qilin, Emperador, Lamashtu, LockBit5, Play, Storm, Eclipse, SafePay, Umbra and INCransom all spiked on 8 October from a baseline of roughly nothing, Umbra's haul alone advertising 3.7TB from IIT Roorkee and 734.4GB from Manipal Academy of Higher Education, before Nightspire posted nine of its own on 9 October spanning Vietnam SuperPort, a pharmaceuticals firm, an architecture practice and a catering company. Distinct affiliate ecosystems do not coordinate a publication date; aggregators flush queues, and the structural evidence (see Hidden) points at the trackers rather than a summit. Separately, the actor BYOD claimed both the Gate crypto exchange, advertising 12 million users with 2FA indicators and balances, and T-Mobile, then followed up not with data but with a taunt at sceptics and a 'sneak peek', which is the behavioural signature of a claim that is still looking for its evidence.

Why it mattersIf your ransomware reporting counts leak-site posts as attacks, your trend line is a picture of someone else's crawler schedule.

confidence 0.70

Threat actors

Flax Typhoon's tooling seized, and a $10 million reward for a HAFNIUM suspect, in the same 36 hours

The FBI seized seven domains used by Chinese state-sponsored operators known as Flax Typhoon to run two hacking tools, MicroScan and FishHub, in a takedown announced on 8 October alongside agencies in six other countries, with the Beijing-based Integrity Technology Group named as the firm behind the scanning and intrusion infrastructure and accused of running a portal that gave third parties access to email stolen from government, law enforcement, healthcare and religious organisations in Southeast Asia. Within the same window the State Department offered up to $10 million for information on Zhang Yu, charged over the 2021 Microsoft Exchange HAFNIUM attacks, whose co-defendant Xu Zewei was extradited from Italy in April 2026. The through-line is not malware, it is procurement: espionage delivered by a contractor, with a product name and a customer-facing portal.

Why it mattersScanning infrastructure run as a commercial service means the reconnaissance against you is funded, staffed and documented, and seizures remove domains rather than the business model.

confidence 0.88

Malware & IOCs

Four supply chains in one day: npm, GitHub, the browser store and the phone itself

The tensorlake npm SDK, roughly 12,000 weekly downloads, shipped version 0.5.144 containing obfuscated credential-harvesting malware as part of the ChainDrop/Shai-Hulud worm campaign; the FakeGit operation came back with 17,610 malicious GitHub repositories pushing SmartLoader and then the StealC infostealer; sixteen malicious Firefox extensions posed as Rabby and OKX wallet tools to capture recovery phrases and private keys; and low-cost Android handsets were found shipping with 'Midnight Mimosa' malware baked into the firmware, enrolling the device as a residential proxy before anyone opened the box. Every one of these arrived through a channel your policy describes as trusted, which is the point.

Why it mattersYour allow-list of trusted sources is, in practice, a list of other people's build pipelines and their worst week.

confidence 0.87

Ransomware

Japan: a cloud provider's data centre cluster goes down, and JPCERT names the web shells

IDC Frontier disclosed that its IDCF Cloud service, used by government clients, was hit by ransomware causing an outage at a data centre cluster serving eastern Japan, while JPCERT/CC's 8 October alert described a rise in personal data leaks at Japanese organisations driven by abuse of mobile app APIs and attacks on known software flaws including Metabase. The 9 October update adds Case D: WAR files planted on Java application servers reachable from public web servers, with the JSP inside acting as a web shell that runs commands from a query parameter, plus new IPs for earlier cases and a web shell source at 124.133.237[.]18. That is a hunt you can run this morning without buying anything.

Why it mattersUnexpected WAR or JSP files on an internet-reachable app server is a search, not a project, and it is the one piece of today's news that comes with an address.

confidence 0.85

Oddities

The recovery firm that allegedly paid the ransom, and the market owner who got forty years

The DOJ has charged Zohar Pinhasi, a 50-year-old US and Israeli national and owner of a ransomware recovery firm, with wire fraud for allegedly paying attackers to obtain decryptors while telling victims he was using proprietary recovery tools, with reporting putting the billing at over $19 million and the markup at around $11 million. In the other direction, Raheim Hamilton, 30, co-creator of the Empire Market dark web marketplace, was sentenced to 40 years for facilitating $430 million in illegal transactions between 2018 and 2020, forfeiting over $100 million in Bitcoin and several properties in Virginia. One industry sells decryption it allegedly bought; the other sold everything and kept receipts.

Why it mattersIf your incident plan names a recovery vendor, your plan should also specify what evidence of 'proprietary' capability you expect to see before the invoice.

confidence 0.86
§3

Hidden

The daily deep read: what is under the feeds, not on top of them.

Under the feeds: three vulnerability sources stopped at the same minute, and ten ransomware crews 'coordinated' in a way that looks a lot like a crawler.

  1. Exception 01

    All three vulnerability-intelligence sources stopped at 11:52 UTC

    NVD, CISA KEV and the derived KEV signal layer each produced their last item at 2026-10-08T11:52 and nothing after. Three independent publishers do not stop at the same minute; this is a collection cutoff, which means any CVE or KEV addition after that time is invisible in today's corpus, including anything tied to FortiBleed or the Cisco NX-OS advisories.

    confidence 0.94
    Wrong if
    Check NVD and CISA public feeds directly for publications between 11:52 UTC on 8 October and 10 October; if there genuinely are none, the silence is organic.
    Watch
    Whether the next collection run backfills the gap within 24 hours.
  2. Exception 02

    The ten-actor Wednesday is probably a tracker flush, not a cartel

    Qilin, Emperador, Lamashtu, LockBit5, Play, Storm, Eclipse, SafePay, Umbra and INCransom all peaked on 8 October against a median of zero on other days, yet the timing-cluster algorithm found no significant multi-source coordination. Batch publication by the aggregators is the simpler explanation; genuine synchronised extortion across unrelated affiliate pools would need shared infrastructure or overlapping victims to believe.

    confidence 0.62Speculative
    Wrong if
    If victim timestamps on the actors' own leak sites spread across the day rather than clustering at a scrape time, or if two families post the same victim, the coordination reading strengthens.
    Watch
    Posting rates for these actors over the next five to seven days; a return to distributed baselines confirms the artifact.
  3. Exception 03

    BYOD's T-Mobile claim has no corroboration anywhere in the corpus

    The dual claim against Gate and T-Mobile exists only in the actor's own posts, propagated from one tracker to another with a 13.4-hour lag, followed by mockery of doubters and a 'sneak peek' rather than data, and then silence. Treat as unverified extortion pressure until a sample or a notification exists.

    confidence 0.68Speculative
    Wrong if
    An official T-Mobile notification, or a verifiable sample matching current customer schema, confirms a breach; a data dump within seven days kills the theatre reading.
    Watch
    T-Mobile official communications over the next 72 hours and any BYOD re-emergence with proof.
  4. Exception 04

    Automated signals ran 7 to 18 hours ahead of curated entries

    For the Qilin burst the automated signal layer fired roughly 18 hours before the curated Atlas entry appeared, with comparable leads of 9.7 hours for LockBit5 and 6.7 hours for INCransom. Curation costs you most of a working day, and on high-profile actors it costs you the most.

    confidence 0.90
    Wrong if
    If the signal timestamps are ingest-timed rather than event-timed, the lead evaporates; verify against signal item metadata.
    Watch
    Whether the lead holds across other actors in the next windows; if it does, triage on signals and confirm on curation.

Nothing to seeThe entity 'actor:payload' is the largest cross-source name in the corpus at 36 items across five feeds, which is almost certainly a false merge between a ransomware actor called Payload and the word 'payload' in IOC feeds; do not let it into an attribution slide. Several striking items are single-sourced and should not be promoted today: the Danish CPR exposure figure, the Spirit Airlines data sale concerns, DarkSword's iOS exploitation-as-a-service directory, PoeLLM, the Tren de Aragua ATM jackpotting arrest and AgentCorruption. The Qualcomm CVE cluster is a coordinated vendor bulletin with no exploitation evidence attached, and the six-digit CVE-2026-105xxx entries look VulDB-sourced rather than standard NVD, so do not rank them alongside the rest.

Deep read: 433 items read · $0.99 of compute

§4

Forecast

Dated, falsifiable calls. We mark our own homework in public.

Today’s calls

  1. DueMon 19 Oct10 days

    CVE-2026-21589, the Atlassian Data Center flaw already under attack, is added to the CISA KEV catalogue.

    Wrong ifCheck the KEV catalogue on 19 October; absence of the CVE falsifies the call.

    f-2026-10-09-1

    Confidence0.45
  2. DueFri 16 Oct7 days

    No official T-Mobile breach notification or verified data sample corroborating BYOD's claim appears in these feeds.

    Wrong ifA T-Mobile statement, regulatory filing, or a published sample matching current customer data falsifies it.

    f-2026-10-09-2

    Confidence0.70
  3. DueMon 19 Oct10 days

    Nightspire posts at least five further victims to its leak site, confirming high-volume batching as its operating pattern rather than a one-off.

    Wrong ifFewer than five new Nightspire victims across ransomware.live and ransomlook by 19 October falsifies it.

    f-2026-10-09-3

    Confidence0.60

Scorecard

2 right · 1 open

  1. open

    Our edge sensor's trailing 30-day count of distinct addresses probing AI-credential paths exceeds 79.

    Called Tue 29 Sep · due Fri 9 Oct

    No edge sensor count reported in today's items; cannot verify the trailing 30-day figure.

  2. right

    NVD resumes publishing and entries with publication timestamps after 2026-10-06 22:33 UTC appear in these feeds.

    Called Thu 8 Oct · due Mon 12 Oct

    NVD items in today's feed carry timestamps of 2026-10-06, which are after the 2026-10-06T22:33 UTC cutoff, confirming NVD resumed publishing within the window.

  3. right

    nightspire posts at least three further named victims on its leak site, tracked by ransomware.live or ransomlook.

    Called Thu 8 Oct · due Sun 11 Oct

    nightspire posted at least three new named victims: Nantou Shiuhkuang Senior High School (ransomware.live 2026-10-08), KC Pharmaceuticals, Valvorobica Industirale, Vietnam SuperPort, Sangre de Cristo Arts, Heidi's Events, WAGA Enterprises, Medcom Tech, INAPI (ransomlook 2026-10-09), Mäntelhaus Kaiser GmbH (ransomlook 2026-10-09) — well exceeding three by end of 11 October.

Glossary of terms you will be expected to nod at

Agentic (n.)
able to perform the boring middle of an intrusion without being asked twice. In the brochure it plans your roadmap; in this week's incident it planned the attack chain, hunted the vulnerabilities and exfiltrated the data, and at no point proposed a workshop.
§5

From our edge

Live attacks on our own servers in the last 24 hours. Yes, really ours.

Our own edge profiled 157 hostile sources in 24 hours — 97 scanners, 47 bot crawlers, 8 targeted operators and 4 brute forcers — sending 25,257 requests between them, of which 38 went past reconnaissance into actual exploitation attempts, across 3,431 addresses from 92 countries, 1,525 of them seen for the first time today. The detail that dates this edition: 35.241.132.20 sent 1,084 requests hunting for /.env, /.env.aws, /.docker/config.json and, pointedly, /.env.anthropic, because model API keys are now on the same shopping list as cloud credentials. Elsewhere 34.77.137.207 fired 119 credential-harvesting requests in roughly 0.4 seconds, six addresses were still spraying CVE-2017-9841 at the phpunit path as though the last nine years were a rumour, and 18 addresses shared one behavioural fingerprint (DNA c67915f564de), which is one operator with a rotation budget rather than eighteen enthusiasts. Raw logs stayed on the server; only the findings left.

157hostile sources profiled
25,257requests from them
38reached exploitation
19shared-DNA clusters
7.8/10top hostility
3,431addresses at our edge
1,525first seen today
92countries

The WTF list

  1. WTF #1

    Looking for your AI keys

    35.241.132.20, a scanner (hostility 6.1/10), sent 1,084 requests to 3 of our sites, probing for /.env, /.env.anthropic, /.env.aws, /.docker/config.json.

    Why it’s weirdWent straight for AI credentials: /.env.anthropic. Model API keys are now on the scanners' shopping list next to cloud keys.

    attribution: Androxgh0st (sensor's best match, 45%)Fri 9 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 886d34013e51
  2. WTF #2

    The most determined visitor

    40.83.78.135, a scanner (hostility 6.7/10), sent 82 requests at 64 a minute to one of our sites, probing for /antos/wp-content/plugins/hellopress/wp_filemanager.php, /antos/this_is_a_new_hello_world.php, /antos/3PJcpMFsD8B.php, /antos//aa.php.

    Why it’s weirdHighest hostility on the board; its kill chain reached weaponization.

    attribution: PHP webshell backdoor scanner (sensor's best match, 42%)Fri 9 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  3. WTF #3

    Trying CVE-2017-9841 on us

    6 addresses sent 14 requests shaped like CVE-2017-9841 exploitation (/vendor/phpunit/phpunit/…), including 107.170.31.206, 192.241.162.234, 185.8.107.35.

    Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.

    attribution: unknown

    Detail
    probe family: phpunit-rce
  4. WTF #4

    Same DNA, different addresses

    104.208.73.227, a scanner (hostility 5.5/10), sent 667 requests at 4 a minute to 3 of our sites, probing for /admin/controller/extension/, /c4.php, /wp-trbacks.php, /wp-includes/ID3/about.php.

    Why it’s weird18 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.92.77.159, 40.83.95.41, 20.219.14.152, 20.196.81.226, 20.255.72.163 and more.

    attribution: Mass WordPress/OpenCart vulnerability & webshell scanner (sensor's best match, 38%)Fri 9 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA c67915f564de
  5. WTF #5

    The strangest shopping list

    20.213.164.192, a scanner (hostility 6.7/10), sent 91 requests to one of our sites, probing for /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /photo.php, /choco.php.

    Why it’s weirdAsked for files almost nobody else asks for: /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /photo.php, /choco.php, /unaut.php.

    attribution: PHP webshell/backdoor hunter (sensor's best match, 38%)Fri 9 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  6. WTF #6

    In a hurry

    34.77.137.207, a scanner (hostility 5.5/10), sent 119 requests to one of our sites, probing for /.aws/.env, /.docker/laravel/app/.env, /.docker/.env, /.env.

    Why it’s weirdFired 119 requests in about 0.4 seconds.

    attribution: .env / cloud-credential harvesting scan (sensor's best match, 60%)Fri 9 Oct, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
§6

Ride-alongs

Free, live tools. No sign-up, no sales call.

§7

Colophon

How this edition was made, plainly.

Edition 12 was made by machine and checked by code. Every item published by 13 public threat feeds in the 24 hours to 05:05 UK (433 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.01. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.

433items read
24hour window
$2.01cost of this edition
04:05 UTCgenerated

Sources this morning

  • NVD100ok
  • ThreatFox100ok
  • Security news41ok
  • infosec.exchange39ok
  • Signal Atlas38ok
  • RansomLook24ok
  • atlas23ok
  • ransomware.live21ok
  • signal:ioc-family14ok
  • AlienVault OTX12ok
  • RSS11ok
  • signal:kev5ok
  • CISA KEV5ok

ITEMS READ: 433SOURCES: 13STORIES DROPPED FOR LACK OF RECEIPTS: 0COST: $2.01STATUS: NOT FINE, BUT NOT YET LOUD

OWNER: the machineEDITOR: the rulesCALLS OPEN: 3NEXT REVIEW: tomorrow 06:00 UK