Lead · Vulnerabilities

Patched Tuesday, exploited Friday, and the backup platform never got a patch at all

A maximum-severity pre-auth flaw in SonicWall SMA1000 is under attack three days after the fix shipped, while attackers are already dropping webshells and miners through two AhsayCBS bugs that are still unpatched.

confidence 0.93

CVE-2026-102255 is a pre-authentication SSRF in the SMA1000 Work Place interface — an unintended alternate access path that makes the appliance issue requests on an attacker's behalf. SonicWall patched it on Tuesday. By Friday it was being exploited in attacks, which is three days, which is roughly the time it takes a change advisory board to agree on a date for the meeting about the date. It does not sit alone: CVE-2026-102256 is a post-auth OS command injection on the same appliance, and CVE-2026-102257 is a Zip Slip in the Appliance Management Console that ends in remote code execution. One gets you in the door, the others furnish the place.

The AhsayCBS situation is worse in the way that matters. Threat actors began exploiting CVE-2026-105133 and CVE-2026-105134 on 7 October to achieve unauthenticated remote code execution, deploying webshells and XMRig cryptominers dressed up as Microsoft Edge, and the flaws are still unpatched. The product in question is backup management. The thing you bought so that ransomware would be survivable is currently the thing mining somebody's Monero.

And tomorrow, Sunday, is CISA's deadline for the five flaws added to KEV after Flax Typhoon's abuse of them. We have arranged the week so that the exploitation is on a Wednesday, the news is on a Friday, and the deadline is on the one day nobody is in the building. The attack surface is not a fixed boundary; it is a tide, and this week the tide has read the on-call rota.

Why it mattersIf you run SMA1000 or AhsayCBS, exposure checks and hunting come before the patch window, because the window already opened for someone else.

Today’s revelation

A patch is not a control until it is installed. Until then it is a public disclosure with your name on the distribution list.

— Sturgeon’s Revelations · Probably Fine Daily No. 13

§2

Top stories

The rest of the last 24 hours, with receipts.

Threat actors

Five new KEV entries, one Sunday deadline, and seven domains taken off a Chinese contractor

CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalogue on Thursday after abuse by the China-linked actor Flax Typhoon, giving federal agencies until 11 October. In the same window the FBI seized seven web domains tied to Integrity Technology Group, a Chinese security firm alleged to supply hacking tools to Beijing-backed operators, with the MicroScan and FishHub tooling named as the instruments used to scan and compromise critical infrastructure in the US and abroad. Seven governments issued a joint warning about PRC-linked theft of sensitive data worldwide. Three sources carry it and they agree, which in this trade counts as a quiet miracle.

Why it mattersFive KEV entries with a deadline tomorrow is the one list your patch backlog is not allowed to be philosophical about.

confidence 0.90

Vulnerabilities

Citrix says patch now; Cisco's firewall manager is already being broken into

Citrix has told administrators to patch NetScaler ADC and NetScaler Gateway immediately against CVE-2026-107406, a memory overflow that can lead to remote code execution or denial of service under certain conditions, notably in SAML deployments. Separately, Cisco Talos is tracking active exploitation of two flaws in Secure Firewall Management Center, including CVE-2026-20079, a critical authentication bypass. Elsewhere, VulDB reports elevated activity against JetBrains Exposed, CVE-2026-108474, alongside the TeamCity fixes in the same advisory round. The pattern this week is unsubtle: the appliances that stand at the edge and the consoles that manage them.

Why it mattersRemote access gateways and the management plane are the same project now; patch them in that order and assume the gateway lied to you first.

confidence 0.88

Ransomware

TheGentlemen post a leak-site batch with ZoomInfo revenue figures attached, Deloitte and an Argentine gas transporter among the claims

Across Thursday evening the group dumped a long run of unverified victim claims onto its leak site, including Deloitte — the listing pastes the ZoomInfo company profile and a $74.5 billion revenue line — and Transportadora de Gas del Norte, described in the same listing as Argentina's largest natural gas transporter with 11,317 km of pipelines, plus schools, clinics, manufacturers and small family firms across the US, Canada, France, Taiwan, Israel and Denmark. Atlas signals escalated TheGentlemen across healthcare, manufacturing, education, technology and professional services, with velocity-weighted confidence as high as 0.82. None of it is confirmed by the affected organisations in this window; a leak-site post is an advertisement, not an incident report. Treat the names as claims and the sector pattern as the useful part.

Why it mattersIf you are a supplier to any of the named organisations, start the third-party conversation now rather than after someone else's press release.

confidence 0.76

Ransomware

A very good week for handcuffs changed the posting volume by approximately nothing

Germany arrested a Russian national suspected of being a leading member of Qilin following extradition from Japan, and Japan's National Police Agency confirmed it; on the same day Qilin's leak site carried claims against MCM Telecom, Hagiva Yh, Melchioni Spa, Tepcomp and Vadeto Group, and Atlas marked the actor escalating in technology and manufacturing. The FBI arrested another suspected ShinyHunters member over the breach of its jobs portal, and per KrebsOnSecurity also arrested the co-founder of a Canadian cybersecurity firm in connection with the same investigation. Oleg Korniev, 42, a dual Ukrainian-Russian citizen, pleaded guilty to running a network of 15,000 money mules, and Empire Market co-creator Raheim Hamilton received 40 years and agreed to forfeit more than $100 million in Bitcoin. Arrests remove people; the affiliate model was designed so that people are the replaceable part.

Why it mattersDo not let an arrest headline change a single control decision; the infrastructure the affiliate used is still there and so is the affiliate's colleague.

confidence 0.90

AI & security

The inference cluster is a listening socket that calls pickle.loads before anyone checks who you are

CVE-2026-105192 describes LMCache's multiprocess mode opening an unauthenticated ZeroMQ ROUTER so workers can share KV cache blocks; msgpack extension code 1 reaches pickle.loads while the server is still decoding the request arguments, before the handler runs. Alongside it this window: AgentCorruption, a now-patched AWS Bedrock AgentCore flaw in which one chatbot could be used to take over an organisation's entire agent fleet; CVE-2026-103435, a time-of-check-to-time-of-use gap in Claude Code where a path validated at permission time is re-resolved at write time, so a symlink swap sends the write elsewhere; and Obot's CVE-2026-105138 and CVE-2026-105139, leaking admin-set MCP secrets and reaching prompts and resources the profile never granted. A separate campaign used AI to orchestrate global exploitation of PaperCut NG/MF. Nobody is filing these as one story, because each lives in a different vendor's advisory.

Why it mattersYour AI platform team has shipped new unauthenticated network services into production this year; inventory them as appliances, not as experiments.

confidence 0.85

Malware & IOCs

Two maintainer accounts, 340-plus repositories, and a workflow that steals your secrets on push

Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts — including that of Takashi Kitao, author of an 18,400-star game engine — and pushed a malicious workflow into over 340 repositories, with the write-up headlined as tens of thousands of repositories affected. In the same window, seven fake npm packages posing as a NebulaAI SDK delivered a Windows remote-access trojan that needs no DLL, in an operation tracked as NEBULA from late September, and the Tensorlake npm SDK was reported compromised. The supply chain keeps being the one control you cannot buy, only verify.

Why it mattersPin actions by commit SHA, scope CI secrets per job, and treat any new workflow file in a dependency as a change to your production environment, because it is one.

confidence 0.80

Threat actors

Three country-code domains were hijacked and the certificate authorities believed every word

Attackers compromised the third-party registries behind the .gh, .sl and .as ccTLDs and altered authoritative DNS records, which was enough to pass automated domain validation and obtain valid HTTPS certificates — including, per reporting, certificates covering several Google domains. No malware, no zero-day, no hood: just control of the answer to the question 'who owns this name'. The trust model assumed DNS was the ground truth and DNS turned out to be a database somebody else administers.

Why it mattersEnable CAA records and certificate transparency monitoring for your domains; mis-issuance is only detectable if someone is reading the logs.

confidence 0.80

Oddities

A CVE description that threatens an entire continent, and a key you can derive from nothing

CVE-2026-107194 says Sungrow iSolarCloud allows authentication bypass and account takeover via "login_type":"5" in a login request, and the entry itself warns this could potentially lead to "local blackouts on the whole continent" in Europe; the attacker needs the account's email address, which a user can read off their parent organisation. Searchlight Cyber disclosed on 8 October that a bug in GoBalance lets anyone compute the secret key controlling a dark-web site's .onion address from public information alone, and then take the address over. Meanwhile Pwn2Own Ireland 2026 paid out $1,262,000 for 98 zero-days, $560,000 of it for breaking a fully patched Google Pixel 10. One of these cost a research team a week of effort; one of them is a JSON field set to the string five.

Why it mattersThe cheapest total compromise this week was a login parameter, as it usually is.

confidence 0.85
§3

Hidden

The daily deep read: what is under the feeds, not on top of them.

The feeds agreed loudly about Friday and went silent about everything that produced it

  1. Exception 01

    NVD stopped publishing just as the week got busy

    NVD is the largest single source in this window at 132 items and its last entry carries an event time of 2026-10-09T01:56, after which it contributes nothing to the two highest-activity days. Every CVE discussed on 9–10 October — Citrix CVE-2026-107406, the SonicWall chain, JetBrains CVE-2026-108474 — is therefore running on vendor-assigned severity with no authoritative scoring behind it. If your patch prioritisation is gated on a CVSS score pulled from NVD, it was gated on an empty feed for two days and nothing in any individual item told you so.

    confidence 0.90
    Wrong if
    NVD items with verified event timestamps after 2026-10-09T01:56 appearing in the dataset, or confirmation that this source is ingest-timed and the gap is a collection artefact.
    Watch
    Whether CVEs disclosed on 9–10 October receive NVD entries in the next 48 hours, and whether those scores differ materially from the vendor's own ratings.
  2. Exception 02

    The entity layer merged two unrelated arrests into one Qilin story

    The aggregate view attaches the name Oleg Korniev to the Qilin arrest burst. The underlying items do not support that: the Qilin reporting describes an unnamed Russian national extradited from Japan to Germany, while Korniev is a 42-year-old dual Ukrainian-Russian citizen who pleaded guilty to running a 15,000-strong money mule network under 'Your Mule Cashout' from 2007 to 2014. Two separate cases, same day, one entity node. This is what automated attribution looks like when it is confident and wrong.

    confidence 0.92
    Wrong if
    Any item in the window naming Korniev in connection with Qilin, or naming the extradited suspect at all.
    Watch
    Whether downstream trackers carry the merged version into next week's actor profiles.
  3. Exception 03

    The highest-volume 'threat actor' in the window is a string match

    actor:payload registers 150 items across NVD, ransomware.live and ThreatFox, with an apparent 34.3-hour lead from NVD to leak-site posts. NVD publishes CVE records, not actor profiles; the entity is conflating the word 'payload' in CVE text, a leak-site group called Payload, and payload-type IOC tags. actor:eclipse does the same trick, joining an Eclipse ThreadX NetX Duo CVE to an Eclipse leak-site claim with a 36.1-hour phantom lag. Left alone, both would top an automated triage queue.

    confidence 0.90
    Wrong if
    Manual review showing all 150 items reference a named Payload group, or NVD records explicitly attributing CVEs to it.
    Watch
    Whether 'Payload' posts further victims without NVD co-occurrence, which would let the real actor be separated from the artefact.
  4. Exception 04

    Seven ransomware actors all chose Thursday

    After a near-silent 8 October, seven distinct actors each hit their window maximum on 9 October with zero-median activity on every other day: Qilin, Akira, Black X, Everest, ArcusMedia, Panzer and Nightspire. Either multiple leak-site operations paused and then bulk-posted in unison, or 8 October is a collection gap and Thursday is catch-up scraping with Thursday timestamps. The second explanation is duller and more likely; the first, if it recurs weekly, would be a predictable surge day worth staffing.

    confidence 0.55Speculative
    Wrong if
    Victim post creation timestamps dated 7–8 October that were simply scraped on the 9th.
    Watch
    Whether the same quiet-day-then-surge shape repeats in the next two collection windows.

Nothing to seeBrain Cipher's claim of 80 GB from Hunt Companies, framed around military housing, is single-source and uncorroborated. The Midnight Mimosa pre-installed Android firmware campaign across 150-plus countries rests on one report with no secondary evidence for the geographic scale. The two-Chinese-actor Chrome zero-day chain is single-source. The ShinyHunters commentary naming an individual and a $70 million figure comes from social posts, not formal reporting, and should not be repeated as fact. Mozi indicators look like residual infrastructure from a long-dead operation, not a new campaign.

Deep read: 745 items read · $1.49 of compute

§4

Forecast

Dated, falsifiable calls. We mark our own homework in public.

Today’s calls

  1. DueTue 20 Oct10 days
    Confidence0.85
  2. DueSat 17 Oct7 days

    NVD resumes publishing and at least one CVE first seen on 9–10 October in these feeds (Citrix CVE-2026-107406 or JetBrains CVE-2026-108474) gets an NVD entry.

    Wrong ifNeither CVE has an NVD record by 17 October and the NVD feed remains silent.

    f-2026-10-10-2

    Confidence0.60
  3. DueTue 20 Oct10 days
    Confidence0.55

Scorecard

1 wrong

  1. wrong

    Our edge sensor's trailing 30-day count of distinct addresses probing AI-credential paths exceeds 79.

    Called Tue 29 Sep · due Fri 9 Oct

    Due date 9 October has passed; no item in today's feed reports the trailing 30-day edge sensor count exceeding 79 distinct addresses probing AI-credential paths.

Glossary of terms you will be expected to nod at

Max severity (n.)
The vendor's way of telling you that authentication was optional all along. Published on a Tuesday so that the exploitation can happen on a Friday, and the meeting about it can happen on a Monday.
§5

From our edge

Live attacks on our own servers in the last 24 hours. Yes, really ours.

Our own edge had a normal, which is to say grim, day: 171 hostile sources profiled — 105 scanners, 56 bot crawlers, 7 targeted operators and 3 brute forcers — throwing 74,424 requests at us, of which 42 went past reconnaissance into actual exploitation attempts, across 3,058 addresses from 91 countries with 1,398 of them seen for the first time today. Twenty-one groups shared a behavioural fingerprint; one of those, DNA c67915f564de, covers 18 addresses doing the same thing from different rooms. The shopping lists tell the story: 35.241.132.20 sent 1,084 requests hunting /.env, /.env.aws, /.docker/config.json and, pointedly, /.env.anthropic; 34.77.137.207 fired 119 requests in about 0.4 seconds looking for the same sort of thing; and two addresses tried a CVE-2024-4577 shaped request at /index.php, a named exploit from a previous year that the internet has evidently not finished with. Raw logs never left the server. Only the findings did.

171hostile sources profiled
74,424requests from them
42reached exploitation
21shared-DNA clusters
7.0/10top hostility
3,058addresses at our edge
1,398first seen today
91countries

The WTF list

  1. WTF #1

    Looking for your AI keys

    35.241.132.20, a scanner (hostility 6.1/10), sent 1,084 requests to 3 of our sites, probing for /.env, /.env.anthropic, /.env.aws, /.docker/config.json.

    Why it’s weirdWent straight for AI credentials: /.env.anthropic. Model API keys are now on the scanners' shopping list next to cloud keys.

    attribution: unknownFri 9 Oct, 14:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 886d34013e51
  2. WTF #2

    The most determined visitor

    40.83.78.135, a scanner (hostility 6.7/10), sent 82 requests at 64 a minute to one of our sites, probing for /antos/wp-content/plugins/hellopress/wp_filemanager.php, /antos/this_is_a_new_hello_world.php, /antos/3PJcpMFsD8B.php, /antos//aa.php.

    Why it’s weirdHighest hostility on the board; its kill chain reached weaponization.

    attribution: PHP webshell backdoor scanner (sensor's best match, 42%)Fri 9 Oct, 14:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  3. WTF #3

    Trying CVE-2024-4577 on us

    2 addresses sent 4 requests shaped like CVE-2024-4577 exploitation (/index.php), including 104.208.73.227, 93.152.221.156.

    Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.

    attribution: unknown

    Detail
    probe family: webshell
  4. WTF #4

    Same DNA, different addresses

    20.210.128.125, a scanner (hostility 5.9/10), sent 308 requests at 83 a minute to one of our sites, probing for /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /xc32tl6p1ockohrquxkroCfm.php, /wp-filemannger4h.php.

    Why it’s weird18 IPs share one behavioural fingerprint (DNA c67915f564de): one tool or one operator rotating addresses: 20.249.5.100, 20.92.77.159, 20.219.160.77, 158.23.176.177, 20.196.81.226 and more.

    attribution: unknownSat 10 Oct, 08:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA c67915f564de
  5. WTF #5

    The strangest shopping list

    20.219.185.206, a scanner (hostility 6.7/10), sent 134 requests to one of our sites, probing for /wp-includes/ID3/about.php, /wp-content/themes/index.php, /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php.

    Why it’s weirdAsked for files almost nobody else asks for: /wp-includes/ID3/about.php, /wp-content/themes/index.php, /wp-content/plugins/hellopress/wp_filemanager.php, /this_is_a_new_hello_world.php, /index/function.php.

    attribution: unknownSat 10 Oct, 08:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA dfef4501b216
  6. WTF #6

    In a hurry

    34.77.137.207, a scanner (hostility 5.5/10), sent 119 requests to one of our sites, probing for /.aws/.env, /.docker/laravel/app/.env, /.docker/.env, /.env.

    Why it’s weirdFired 119 requests in about 0.4 seconds.

    attribution: unknownFri 9 Oct, 14:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
§6

Ride-alongs

Free, live tools. No sign-up, no sales call.

§7

Colophon

How this edition was made, plainly.

Edition 13 was made by machine and checked by code. Every item published by 11 public threat feeds in the 24 hours to 09:22 UK (745 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.81. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.

745items read
24hour window
$2.81cost of this edition
08:22 UTCgenerated

Sources this morning

  • ThreatFox201ok
  • NVD132ok
  • Signal Atlas92ok
  • infosec.exchange81ok
  • ransomware.live73ok
  • atlas55ok
  • Security news46ok
  • RansomLook33ok
  • AlienVault OTX12ok
  • RSS10ok
  • signal:ioc-family10ok

ITEMS READ: 745SOURCES: 11STORIES DROPPED FOR LACK OF RECEIPTS: 0COST: $2.81STATUS: NOT ENTIRELY FINE

OWNER: the machineEDITOR: the rulesCALLS OPEN: 3NEXT REVIEW: tomorrow 06:00 UK