6 verified findings from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.
Criticality
Kind
Topic
Region
TL;DR · the day in one read
01Three unrelated AI platforms, three intrusions, one pattern: gateways and orchestrators concentrate the credentials and execution privilege attackers want. Microsoft Threat Intelligence confirms three separate real-world intrusions against exposed AI infrastructure: a LiteLLM gateway compromised via CVE-2026-42271 chained with CVE-2026-48710, a RAGFlow deployment reached through an unattributed code-execution path, and a Kestra workflow environment exploited via CVE-2026-49869. Credential harvesting and durable persistence recurred across all three despite different initial-access paths; compute monetisation followed in the LiteLLM and Kestra intrusions but not RAGFlow's, whose objective was narrower credential interception. Together they establish AI gateways, retrieval platforms and orchestration services as a distinct, high-value attack surface. →
02The fake-CAPTCHA lure now targets a console that can run multi-line scripts, not the one-line Run box. Microsoft Threat Intelligence documents TerminalFix, a ClickFix variant that tricks users into pasting a malicious command into Windows Terminal or PowerShell via a fake Cloudflare CAPTCHA overlay, then runs a multi-stage chain of DLL sideloading, PNG-steganography payload delivery, domain reconnaissance and a custom Python reverse-tunnel implant that gives the attacker persistent SOCKS-style proxy access into the victim's internal network. →
03A BI tool's own admin API handed over the production database password it was supposed to protect. The actor ZeroBytes, already tracked for the DGFiP tax-authority and Ministry of National Education intrusions, claims a third French public-sector platform compromise: Zéro Logement Vacant, a housing-vacancy tool run by the Ministry of Ecological Transition on beta.gouv.fr. Per the actor's own account, a valid Metabase administrator session exposed a production PostgreSQL password stored in cleartext in a database-connection description field, yielding ~148.9M raw rows including national property-owner and DGFiP/DataFoncier records; no government confirmation of scope exists, but the platform was taken offline. →
04WatchGuard tells Firebox admins to update now: two unauthenticated code-execution paths sit in the IKE/VPN daemon itself. WatchGuard's 27 August 2026 "Immediate Action Required" advisory fixes eleven CVEs in Fireware OS, led by CVE-2026-19313 (pre-auth heap overflow) and CVE-2026-19315 (pre-auth type confusion), both unauthenticated remote code execution in the iked IKE/VPN daemon, plus CVE-2026-13086, a pre-auth stack overflow in the deprecated Mobile Security epm service with no stack canary and a non-PIE binary. A third iked flaw and a Dimension management-platform session-hijack bug surfaced in a follow-up NCSC-CH advisory on the same bulletin. WatchGuard reports no observed exploitation for any of the five; fixed in Fireware OS 2026.3.1 / 2026.2.2 / 12.12.2 / 12.5.20 and Dimension 2.3.1. →
The actor known as ZeroBytes (already tracked in this store for the DGFiP tax-authority credential intrusion and the claimed Ministry of National Education leak) claims a third French public-sector platform compromise in three months: Zéro Logement Vacant, a housing-vacancy tool built by La Fabrique numérique (Ministry of Ecological Transition) with the Agence nationale de l'habitat and hosted on beta.gouv.fr for municipal and collectivité housing officers (ZATAZ.COM, 2026-08-30). Per the actor's own account, initial access was a valid Metabase (open-source BI tool) administrator session, which exposed the platform's full configuration: connected databases, accounts, permissions, saved queries and stored secrets, plus the ability to run native SQL against every connected database from within the tool.
The pivot that mattered came from a configuration weakness inside Metabase itself: the actor states Metabase's at-rest secret encryption was disabled, and a production PostgreSQL password had been stored in cleartext in a database connection's description field, retrievable through a call to Metabase's own admin API (ZATAZ.COM, 2026-08-30). That password gave a direct, Metabase-independent read connection to the production instance hosted at Clever Cloud, so deleting the compromised Metabase accounts afterward did not cut off access; the credential reportedly stayed valid until rotated. Thirteen dashboards were said to be reachable with no authentication at all, some exposing email/bcrypt-hash pairs, and a JWT signing key was allegedly recoverable from platform settings.
The claimed haul totals 148,929,194 raw rows, roughly 82M from a national property-owner table and 67M from a 2024 DGFiP/DataFoncier national file (per ZATAZ: names, dates of birth, addresses and tax identifiers, ZATAZ.COM, 2026-08-30; per Clubic's own read of the same claim: property identifiers of the owners rather than tax identifiers, Clubic, 2026-08-30), plus roughly 3,500 municipal-agent accounts and 10,729 unique emails and 6,847 unique phone numbers; deduplicated, the actor claims 48–71M distinct individuals depending on the matching method (ZATAZ.COM, 2026-08-30). No government confirmation of scope was located, but Clubic reports the platform remains offline since the intrusion was discovered (Clubic, 2026-08-30), a de facto acknowledgment an incident occurred, even absent a formal government statement.
According to his account, initial access was obtained via a valid Metabase administrator session.
the production PostgreSQL password was allegedly kept in cleartext in the description field of a database connection
ZATAZ.COM
ZeroBytes strikes a third public service in three months
Over the last weekend of August 2026 a criminal actor published fresh data-leak claims against seven more French Services départementaux d'incendie et de secours (Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges and Moselle) extending a campaign ZATAZ first documented in late July 2026 against five other SDIS (Aisne, Alpes-de-Haute-Provence, Landes, Marne, Alpes-Maritimes), where postings were attributed to three separate criminal-forum handles: ChimeraZ, Cybernox and AplaGroup (ZATAZ.COM, 2026-08-30). Of the August wave, Objectif Gard names only ChimeraZ, tying the same handle to five of the seven units (Gard, Bouches-du-Rhône, Moselle, Bas-Rhin and Vosges); no source names an actor for the Somme or Essonne claims, or ties Cybernox or AplaGroup to this wave. This is not merely a criminal claim: contacted directly on 30 August, the president of SDIS du Gard's governing board confirmed the cyberattack and theft of personal data on personnel, including copies of identity documents and bank details, with the full scope and intrusion method still under investigation (Objectif Gard, 2026-08-30).
No common intrusion vector has been established across the incidents in this campaign. The one case with a stated mechanism is from the July wave: SDIS de l'Aisne, where a claimed administrator-level access credential was posted in cleartext by the actor; ZATAZ notes its current validity cannot be established from the post alone, since access can be disabled or changed after disclosure, but the posting itself is a more critical indicator than a plain directory extraction (ZATAZ.COM, 2026-07-26). The July wave's cumulative claims, spanning the Landes, Marne (2,167 people), Alpes-Maritimes (2,325 people), Alpes-de-Haute-Provence and Aisne SDIS, plus separate claims against SDIS d'Indre-et-Loire (2,637 public-service agents plus 54 individuals linked to private structures) and the Pompiers.fr / Fédération nationale des sapeurs-pompiers de France membership platform (ZATAZ.COM, 2026-07-26), totalled at least 166,376 exposed individuals, with a potential total exceeding 932,376 depending on the volumes claimed; ZATAZ is explicit that this estimate is a straight sum of announced record counts and does not mean each line was technically verified or maps to a distinct person (ZATAZ.COM, 2026-08-30). Each publication in the campaign otherwise appears to be a distinct claim rather than evidence of one coordinated technical compromise.
SDIS du Gard was indeed the victim of a cyberattack and data theft. Contacted this Sunday 30 August by Objectif Gard, Alexandre Pissas, chairman of SDIS 30's board, confirms the computer attack and the theft of personal data concerning personnel.
Among the stolen information are said to be particularly sensitive data, notably copies of identity documents and bank details.
Microsoft Threat Intelligence documents TerminalFix, a ClickFix variant targeting organizations across multiple industries (Microsoft Threat Intelligence, 2026-08-28). A compromised website displays a fake Cloudflare Turnstile verification overlay that silently copies a malicious PowerShell command to the clipboard and instructs the user to paste it into Windows Terminal or PowerShell rather than Windows' Run dialog, which traditional ClickFix lures use; a console that runs complex, multi-line scripts far more reliably (Microsoft Threat Intelligence, 2026-08-28). Once pasted, the command downloads a ZIP archive containing a legitimate signed binary (LockScreenContentServer.exe) alongside a malicious dui70.dll masquerading as the Windows DirectUI Engine; the signed binary's static import dependency loads the planted DLL from its own working directory instead of System32, a DLL side-loading technique that starts execution inside a trusted, signed process (Microsoft Threat Intelligence, 2026-08-28).
The sideloaded DLL runs an elaborate second stage: PowerShell downloads three PNG images from attacker domains, extracts binary data hidden in their pixel channels (the first eight bytes of each embedded payload encode its length) and reassembles an executable and a DLL split across two of the images, deleting the source images afterward to reduce forensic artifacts (Microsoft Threat Intelligence, 2026-08-28). Persistence lands through both an HKCU\...\Run registry key and a scheduled task re-executing every 60 minutes, both under a masquerading name chosen to blend with the abused Lock Screen component, with the payload directory hidden via system and hidden file attributes. The malware then conducts extensive Active Directory reconnaissance, domain trust enumeration, domain admin group membership, user and computer discovery, and targeted pings of named infrastructure roles (domain controllers, databases, backup, gateways, mail), with the system-information-collection step run in English, Spanish and German locale variants, consistent with an operator or automated pre-assessment scoring whether the compromised host sits near high-value, domain-joined infrastructure (Microsoft Threat Intelligence, 2026-08-28).
The most significant capability is the final stage: an unmodified, signed embeddable Python 3.14.5 runtime pulled directly from python.org, launched with no visible window via pythonw.exe, running a custom client.py tunneling implant that dials out over TLS on port 443, upgrades to a WebSocket, and relays arbitrary TCP connections to any internal host and port the operator specifies, SOCKS5-style addressing over a custom 7-byte multiplexed protocol, indistinguishable on the wire from an ordinary encrypted web session (Microsoft Threat Intelligence, 2026-08-28). Combined with the reconnaissance data already gathered, this turns the compromised host into a full network pivot point. Microsoft states it did not observe the downstream hands-on-keyboard actions this access typically enables (privilege escalation, security-control tampering, data exfiltration, ransomware deployment) in the analyzed chain, but assesses the access itself makes those the expected next step (Microsoft Threat Intelligence, 2026-08-28).
While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully.
The client.py script is a compact but full-featured reverse tunnel. It dials outbound to the C2 over TLS/443, upgrades the session to a WebSocket, and uses that channel to relay arbitrary TCP connections on behalf of the operator. On the wire, the traffic is indistinguishable from an ordinary encrypted web session to a single destination
Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure.
A distributed denial-of-service attack against Vivicta, the IT partner operating infrastructure for Norway's Digitalisation Agency (Digdir), disrupted ten government digital services from the early hours of Monday 24 August through roughly 19:30 on Wednesday 26 August 2026, about 64 hours, with intensity varying and short recovery windows in between (Digdir status page, 2026-08-28). The disrupted services include ID-porten, the shared identity gateway more than 4.5 million people use to log into government services via BankID and MinID, plus eFormidling, eSignering, Maskinporten and several other cross-agency data-exchange and access-management systems. Because ID-porten authenticates far beyond Digdir's own services, the disruption also affected parts of Norway's health infrastructure, several health services rely on ID-porten for authentication, and authorities warned of possible problems accessing online pharmacies and the electronic prescription system (The Record, 2026-08-25).
Digdir press officer Are Kvistad told Norwegian broadcaster NRK the attack was two to three times larger than the previous one, and it is the third DDoS incident to hit Digdir's infrastructure since June 2026 (The Record, 2026-08-25). Digdir states no sensitive data stored in the affected systems was accessed, and as of the incident's close, normal operation was expected to resume within days; some disruption from foreign traffic persisted afterward. No attribution has been made public, and it remains unclear whether the three 2026 incidents are connected or represent a broader campaign.
The attack started during the night of Monday at 03:38 and stopped around 19:30 Wednesday evening. Except for short periods, ID-porten and the shared solutions have been available the whole time.
What is special about this latest attack, which has now been ongoing for a day, is that it is two to three times larger than what we experienced last time
WatchGuard's 27 August 2026 "Immediate Action Required" advisory ships fixes for eleven CVEs in Fireware OS, reserved under coordinated disclosure and detailed on WatchGuard's PSIRT pages. Two are pre-authentication remote code execution in the iked process, the daemon that handles IKE/IPsec VPN negotiation, each rated CVSS 4.0 9.3 Critical by WatchGuard: CVE-2026-19313 is a heap buffer overflow triggered by specially crafted network traffic reaching iked, and CVE-2026-19315 is a type confusion reached by sending an IKE_AUTH message containing two EAP payloads, causing an out-of-bounds read followed by a free() call on an attacker-influenced pointer, a crash-and-respawn denial of service at minimum, with WatchGuard itself stating the memory-corruption pattern carries potential for code execution beyond that (WatchGuard PSIRT, 2026-08-27). Both flaws need no authentication and no configuration beyond a running iked process, which handles VPN and Mobile IKEv2 negotiation and is commonly reachable from the internet on a Firebox configured as a VPN gateway.
The third flaw, CVE-2026-13086 (also CVSS 4.0 9.3 Critical), sits in the epm service used by Fireware's deprecated Mobile Security feature: a network-adjacent, unauthenticated attacker can send a crafted JSON-RPC request that overflows a stack buffer and overwrites the saved return address, reaching arbitrary code execution as root (WatchGuard PSIRT, 2026-08-27). WatchGuard's own advisory notes the binary ships with no stack canary and is not position-independent, which its own text states makes return-oriented-programming exploitation straightforward; even a failed attempt can crash and respawn the process. Reachability for this one is narrower than the iked pair; it requires network adjacency to a trusted interface where the deprecated Mobile Security feature is still enabled, rather than a bare internet-facing IKE listener.
All three, along with the remaining eight CVEs WatchGuard's own bulletin lists, are fixed in Fireware OS 2026.3.1, 2026.2.2, 12.12.2 and 12.5.20 (WatchGuard PSIRT, 2026-08-27). The 2026.3 branch is a separate affected band from the 2025.0-2026.2.2 one and takes its own fix: on CVE-2026-19315 and CVE-2026-13086 the band >= 2026.3, < 2026.3.1 sits on the Default product row, and on CVE-2026-19313 and CVE-2026-19318 it sits on the T15/T35 row (WatchGuard PSIRT, 2026-08-27). WatchGuard states it has not seen any indication that these vulnerabilities have been exploited. Germany's BSI CERT-Bund relayed the same advisory as WID-SEC-2026-3068 the same day, listing a twelfth CVE for the same iked heap-overflow class not present in WatchGuard's own blog roundup, CVE-2026-81851, "Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service" (BSI CERT-Bund, 2026-08-27).
A remote, unauthenticated attacker can send a specially crafted IKE_AUTH message containing two EAP payloads to crash the IKE daemon (iked), causing a denial-of-service condition through process termination and respawn. Because the flaw results in an out-of-bounds read followed by a free() call on an attacker-influenced pointer value, it may also present potential for further memory corruption and remote code execution beyond denial of service.
WatchGuard PSIRT (CVE-2026-19315)
A network-adjacent attacker with access to a trusted interface can send a specially crafted JSON-RPC request to the epm service to overflow a stack buffer, overwrite the saved return address, and execute arbitrary code with root privileges without authentication. The lack of a stack canary and use of a non-PIE binary make exploitation via return-oriented programming straightforward
WatchGuard PSIRT (CVE-2026-13086)
An unauthenticated remote attacker who completes IKE_SA_INIT can send a specially crafted IKE_AUTH message containing an EAP-MSCHAPv2 payload with an undersized embedded length field, triggering a stack buffer overflow in the iked process. This causes a crash and denial-of-service condition (with automatic respawn), and given the attacker-influenced nature of the stack overwrite, may carry potential for remote code execution. Exploitation requires that IKE payload diagnostic logging, a supported operational troubleshooting setting, be enabled on the affected device.
WatchGuard PSIRT (CVE-2026-19318)
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
NCSC Switzerland's advisory on the same 27 August bulletin, created 2026-09-01, adds two CVEs this entry had not covered. CVE-2026-19318 (CVSS 9.3) is a third pre-authentication stack overflow in iked's IKE_AUTH handling: an attacker who completes IKE_SA_INIT can send an IKE_AUTH message carrying an EAP-MSCHAPv2 payload with an undersized embedded length field, triggering the overflow, which WatchGuard's own advisory describes as causing "a crash and denial-of-service condition (with automatic respawn)," with "potential for remote code execution" given the attacker-influenced stack overwrite (WatchGuard PSIRT, 2026-08-27), the same hedged severity language WatchGuard uses for the two iked flaws already covered above. Unlike those two, exploitation here is conditional: it requires that IKE payload diagnostic logging, an operational troubleshooting setting not enabled by default, be turned on (WatchGuard PSIRT, 2026-08-27); a Firebox with diagnostic logging off is not exposed to this specific flaw.
CVE-2026-78174 (CVSS 9.3) is a different bug class on a different product: WatchGuard Dimension, the centralized reporting and management platform. Dimension's web UI diagnostic log records session identifiers for logged-in users unredacted; a low-privileged Dimension Administrator who retrieves that log can extract a Super Administrator's session token while the Super Administrator is logged in, then impersonate them fully, reaching Access Management, creating, deleting or altering any user or group, changing system-wide configuration, locking out legitimate administrators, and holding persistent full administrative control (WatchGuard PSIRT, 2026-08-27). Both flaws share the same fix cadence as the original three: Fireware OS 2026.3.1 / 2026.2.2 / 12.12.2 / 12.5.20 for CVE-2026-19318, Dimension 2.3.1 for CVE-2026-78174. WatchGuard reports no observed exploitation for either.
Defender takeaway (updated): the exposure decision for CVE-2026-19318 turns on whether IKE payload diagnostic logging is enabled; check that setting before assuming this flaw applies to a given appliance. For Dimension, treat diagnostic-log export or viewing as a privileged, logged action and audit which accounts have exercised it; patch to 2.3.1 regardless, since a compromised low-privileged Dimension Administrator account is now a path to full Super Administrator control.
The version ranges recorded for four of the five CVEs were incomplete. WatchGuard's PSIRT page for each lists a second affected band alongside the 2025.0-2026.2.2 and 12.0-12.12.2 ones, >= 2026.3, < 2026.3.1, and names Fireware OS 2026.3.1 in its Solution section alongside 2026.2.2, 12.12.2 and 12.5.20. The band's placement differs by CVE: on CVE-2026-19315 and CVE-2026-13086 it sits on the Default product row (WatchGuard PSIRT, 2026-08-27), and on CVE-2026-19313 and CVE-2026-19318 on the T15/T35 row (WatchGuard PSIRT, 2026-08-27).
What this changes for a defender: an appliance running any 2026.3.0 build is in scope for all four flaws, including the two unauthenticated iked code-execution paths, and upgrading it to 2026.2.2 does not remediate them; 2026.3.1 is its fix. CVE-2026-78174 on Dimension is unaffected by this correction, its >= 2.0, < 2.3.1 range matching WatchGuard's page exactly.
The Ministry of National Education's precautionary access shutdown at affected académies is still disrupting the 2026 school-year start more than a month after the intrusion: as of 2026-08-30, Toulouse and Nantes remain significantly impacted, with professional mailboxes and family access to digital workspaces cut and academies falling back to paper and phone procedures. Teacher unions warn some classes may begin September without an assigned teacher because substitute-assignment orders are sent by email.
The delta here is operational, not technical. The Ministry of National Education's precautionary decision to cut network and mailbox access for affected académies, taken after the intrusion this entry already tracks, is still causing real disruption to the 2026 school-year start more than a month later. As of 2026-08-30, most académies report normal access restored, but Toulouse and Nantes remain significantly impacted: at Toulouse, professional mailboxes and applications stay cut "until further notice," family access to the digital workspace is also suspended, the rector describes it as an unprecedented start of term, and "full restoration could take around two weeks", all translated from French (ZATAZ.COM, 2026-08-30), with the digital workspace targeted for relaunch on 7 September. Because substitute-teacher assignment orders are sent by email, the mailbox shutdown has left some substitute and contract teachers without their assigned school days before term starts; teacher unions warn some classes may open in September with no assigned teacher: "we risk finding ourselves on 1 September with classes lacking teachers in quite a few schools" (translated from French) (Thomas Cabioch, SNES-FSU Mayenne, via ICI/France Bleu, 2026-08-26). Toulouse has fallen back to paper timetables and phone or messaging-app communication with families (ZATAZ.COM, 2026-08-30). The ministry states payroll will still be paid on the usual schedule, and the Toulouse rector separately states all students will be accommodated in schools on the planned dates, allowing for possible last-minute adjustments, both translated from French (ZATAZ.COM, 2026-08-30).
Huntress published forensic detail from five individuals across three 2026 investigations against the same cluster (which it names Famous Chollima, an alias this entry already carries) with reusable methodology: detecting PiKVM and Guermok USB hardware via Windows Security Event ID 6416 and the USB registry enumeration path, a laptop-farm network-transition timeline, and identity-document metadata forensics (camera model, device time offset, near-identical issue dates, and a reverse-image/mugshot match) across separate cases.
Huntress published forensic detail from five individuals identified as likely DPRK workers across three separate 2026 investigations against the same cluster, which it names Famous Chollima; an alias this entry already carries for PurpleDelta (Huntress, 2026-08-26). In one of those investigations (a financial-services employer), Huntress found a PiKVM (an open-source Raspberry Pi-based KVM-over-IP device giving remote control of a host at the hardware level before the operating system even boots) together with a Guermok USB capture card that registers as a webcam and lets streamed video substitute for the operator's own camera in video calls, both connected to the same host. Huntress gives a concrete detection path for both device classes generally, based on the pattern across the incidents it has investigated this year: "Defenders can alert on Windows Security Event ID 6416 when device_description contains PiKVM or Guermok, and hunt the Windows registry path HKLM\SYSTEM\CurrentControlSet\Enum\USB, especially FriendlyName values such as PiKVM Composite Device and Guermok USB3 Video" (Huntress, 2026-08-26). In that same case, forensic timeline reconstruction from router connection and Windows event logs showed the laptop moving from an MSP's guest network to a residential wireless network to a fixed ethernet connection, consistent with the device becoming a rack asset in a laptop farm, with the serial console adapter and then the PiKVM connected just hours after the laptop first appeared on the residential wireless network, and the switch to a fixed ethernet connection, its last network change, following roughly 15 minutes after the PiKVM.
Huntress also adds identity-document forensics as a distinct evidence class, drawn from two further, separate cases. In the February 2026 healthcare-sector investigation (three individuals), two of the fabricated identity submissions shared the same photography angle, the same issuing police station and passport office, validity periods that matched exactly, the same recorded camera model (an iPhone 15 Pro Max), and photo-metadata timestamps within minutes of each other and a consistent device time offset, indicating one production pipeline behind both. In the same financial-services case as the PiKVM/Guermok finding, an employee's photo used on a messaging tool proved to be a stolen and face-altered image traced by reverse image search to an unrelated GitHub profile. In a third, separate case surfaced by a subsequent proactive hunt for the same hardware pattern, submitted identity documents shared a name, date of birth and driver's-license location with an unrelated individual whose mugshot had previously been published by law enforcement after an arrest, the underlying identification numbers validated as genuine, but the photograph had been swapped. That third case also used Toffeeshare (peer-to-peer file transfer), Codeshare (posting recurring Zoom meeting links with embedded passwords) and VDO Ninja (browser-based screen-capture streaming), a cluster of consumer web tools Huntress flags as a corroborating, if individually weak, behavioural signal alongside the hardware and document indicators.
The extortion group FulcrumSec claimed responsibility on 2026-08-30, telling BleepingComputer it stole roughly 86GB (considerably more than MAG's own disclosure suggested) and naming an access vector for the first time: airport-specific Iterable (marketing-platform) API credentials exposed in client-side JavaScript. MAG has not addressed the specific claims and continues to point to its existing customer statement.
The extortion group FulcrumSec claimed responsibility on 2026-08-30, telling BleepingComputer it stole approximately 86GB of data, considerably more than MAG's original disclosure suggested (BleepingComputer, 2026-08-30). The group says it obtained access using airport-specific Iterable (marketing-platform) API credentials exposed in client-side JavaScript (code that runs in the customer's own browser, so anyone inspecting network calls or page source could read the credentials) and claims the haul includes nearly 200,000 records tied to upcoming travel through the rest of 2026, alongside a roughly 21.5GB Manchester customer export combining identifiers, historical booking activity and marketing classifications. BleepingComputer validated one sample record against a real traveller's known purchase history, matching Fast Track bookings, arrival times, terminal and amounts paid, though it could not independently verify the claimed scope. MAG has not addressed the specific claims (the exposed credentials, the 86GB figure, the future-travel data) and continues to point to its existing customer-notification statement: "MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support" (BleepingComputer, 2026-08-30). No payment-card or banking data is reported exposed.
The exposure class this adds is distinct from the original disclosure: a third-party marketing or analytics SaaS API key embedded directly in browser-delivered JavaScript is effectively a public credential the moment the page is inspectable, independent of any server-side hardening. Organisations embedding third-party API keys client-side should verify with the vendor whether the key's scope can be restricted to write-only/track-only actions rather than full read access to customer records, and review outbound API call patterns from public web front-ends for tokens visible in bundled JS or the browser's network tab.
AI gateways, retrieval platforms and workflow orchestrators have become a new layer of enterprise infrastructure sitting between users, applications, data and models, and that position concentrates credentials, data access and execution privilege in one runtime. Microsoft Threat Intelligence confirms three separate real-world intrusions exploiting exactly that concentration: a LiteLLM gateway, a RAGFlow retrieval-augmented-generation deployment, and a Kestra workflow orchestration environment. The initial-access paths differed by product, and credential theft and durable persistence recur across all three, but resource monetisation was specific to two of them: Microsoft states the LiteLLM and Kestra objectives each included compute monetisation, while the RAGFlow intrusion's objective was narrower, intercepting newly configured LLM provider credentials and model metadata, with no miner deployment observed (Microsoft Threat Intelligence, 2026-08-26). The June 2026 disclosure of the LiteLLM chain itself is already tracked in this store; what is new here is confirmation that the chain reached real production environments, alongside two further distinct AI-workload intrusions with no vulnerability overlap.
Case 1: LiteLLM gateway, credential harvesting to database exfiltration to cryptomining
Microsoft assesses with high confidence that initial access exploited the exposed LiteLLM gateway surface via CVE-2026-42271 (CVSS 8.7, affecting LiteLLM >= 1.74.2 and < 1.83.7, fixed in 1.83.7, BerriAI GHSA-v4p8-mg3p-g94g), a command-execution flaw in LiteLLM's MCP stdio test endpoints, chained with CVE-2026-48710 (CVSS 6.5, affecting Starlette <= 1.0.0, fixed in 1.0.1, Starlette GHSA-86qp-5c8j-p5mr), a host-header validation bypass that can strip the authentication requirement in vulnerable configurations, the combination yields unauthenticated remote code execution in the gateway process itself. From that foothold, the observed chain ran six stages. First, the payload read /proc/1/environ (the environment block of the gateway's PID-1 process in its container) filtering for provider API keys, the LiteLLM master key, database connection strings and other credential-shaped values, and exfiltrated them using whichever of Python's urllib, curl or wget was available. Second, a masqueraded ELF binary was retrieved and launched with Linux-service-style arguments; a parallel shell-based delivery path provided redundancy. Third, the payload fingerprinted the host, checked for passwordless sudo, and swept for competing miners or remote-access tooling. Fourth, it loaded the Linux MSR kernel module with write access (RandomX/XMRig CPU-tuning behaviour) and rewrote crontab entries to remove rival miners before installing its own. Fifth, using the harvested DATABASE_URL, it connected directly to the LiteLLM-backed Azure Database for PostgreSQL instance and dumped the LiteLLM_ProxyModelTable and LiteLLM_VerificationToken tables (model configuration, upstream provider keys and proxy-issued virtual keys) base64-encoding and exfiltrating the output in chunks to an out-of-band endpoint. Sixth, it established durable access via an SSH key written to a service account, immutable-flag protection on its payload directories, and periodic callbacks confirming continued execution.
Case 2: RAGFlow, a persistent hook inside the application itself
Microsoft assesses with high confidence that the RAGFlow intrusion also began with exploitation of the exposed application surface, but states explicitly it has only low confidence in which specific vulnerability enabled the resulting code execution; telemetry could not isolate the precise execution sink from inside the RAGFlow Flask service process. Several publicly documented RAGFlow vulnerabilities provide plausible technical context without being confirmed as the cause. What followed exploitation was distinctive: the payload located the RAGFlow install from inside the container, identified the tenant LLM configuration code path, and modified the application's own startup/import sequence so a hidden hook would load every time the service started, persistence implemented as a backdoored application component rather than a separate process, surviving container restarts as long as the modified filesystem state remains. The hook then wrapped the tenant LLM configuration flow itself, capturing provider type, model name, API key material and endpoint metadata every time a user configured a new LLM connection from that point forward, and exfiltrated it over outbound HTTP with errors suppressed so the application kept functioning normally. Unlike the LiteLLM case, Microsoft observed no miner deployment or interactive shell here; the objective was narrowly future-credential interception.
Case 3: Kestra, workflow execution as the shell-access primitive
Microsoft assesses with high confidence that the Kestra intrusion exploited CVE-2026-49869 (CVSS 10.0 Critical, affecting Kestra prior to 1.0.45 and 1.3.21, fixed in those releases, Kestra GHSA-5vc5-wxxq-3fjx via the CVE Program), a pre-authentication bypass that lets an unauthenticated, network-reachable attacker skip the login mechanism entirely, define a malicious workflow using Kestra's Process runner, and trigger shell-script execution on a worker node. Two closely timed workflow-origin shell sessions followed: the first performed shell initialisation, the second executed the main follow-on actions. Because the worker had access to the mounted Docker socket, the attacker queried container metadata and enumerated the Config.Env arrays of every other container reachable through that socket, a single compromised orchestration worker exposing the environment-embedded cloud keys, database passwords and API tokens of unrelated containers on the same host. A cryptominer (XMRig, RandomX-tuned) was then deployed, and a later workflow-origin event retrieved and executed a remote script via a curl-pipe-shell pattern with no file ever written to disk, storing its output through Kestra's own key-value interface rather than a standalone file.
The pattern that matters more than any single product
Initial access differed (command execution from a gateway process, SSRF-then-RCE against a web application, and workflow-engine authentication bypass) but credential collection and durable access converged in all three; resource monetisation converged in two of the three (LiteLLM's cryptomining, Kestra's XMRig deployment on the compromised worker), while the RAGFlow intrusion pursued only future-credential interception with no miner or interactive shell observed (Microsoft Threat Intelligence, 2026-08-26). Microsoft's own framing is the operational takeaway: these platforms should be monitored according to their control-plane role, not as isolated applications, because a gateway, retrieval or orchestration service can concentrate credentials, database access, workflow execution and container privileges in one runtime. Correlating an unexpected shell or interpreter spawned from an AI-workload process with subsequent secret access, application-file modification, Docker-socket use, outbound callbacks and resource-hijacking activity exposes this class of attack earlier than any single product-specific indicator (Microsoft Threat Intelligence, 2026-08-26).
Microsoft assesses with high confidence that initial access likely occurred through exploitation of the exposed LiteLLM gateway surface. Relevant public vulnerability paths include CVE-2026-42271, an authenticated command-execution issue in LiteLLM MCP stdio test endpoints, and the route described in public research that chains this flaw with CVE-2026-48710, a Starlette host-header validation bypass, to achieve unauthenticated remote code execution in vulnerable exposed deployments.
Telemetry showed the payload reading /proc/1/environ, filtering for keywords such as master, API key, token, password, and UI-related fields, then sending collected values to attacker-controlled infrastructure.
Microsoft assesses with high confidence that initial access likely occurred through exploitation of CVE-2026-49869, a critical authentication-bypass vulnerability in Kestra. Exploitation could allow an unauthenticated remote attacker with network access to bypass the login mechanism, define a malicious workflow using the Process runner, and trigger worker-side shell-script execution.
Audit every internet-reachable LiteLLM, RAGFlow or Kestra deployment for direct exposure of admin/management interfaces; patch LiteLLM against CVE-2026-42271/CVE-2026-48710 and Kestra against CVE-2026-49869 immediately, and rotate every credential (model-provider keys, LiteLLM master key, database connection strings) that gateway process could have held, since a patch alone does not invalidate an already-exposed secret.
Patch every WatchGuard Firebox to Fireware OS >= 2026.2.2 / 12.12.2 / 12.5.20 (T15/T35: >= 12.5.20) now, and separately to >= 2026.3.1 on any appliance already running a 2026.3.x build: WatchGuard places a 2026.3 affected band on each of the four iked and epm flaws (on the Default product row for two of them and the T15/T35 row for the other two), and the 2026.2.2 fix does not cover it. Where immediate patching is not possible, restrict IKE/VPN exposure to trusted interfaces, disable the deprecated Mobile Security feature to remove the epm attack surface, and disable IKE payload diagnostic logging if enabled to close CVE-2026-19318.
Patch every WatchGuard Dimension instance to >= 2.3.1 now, and audit which accounts have exported or viewed the web UI diagnostic log; a low-privileged Dimension Administrator account that has done so should be treated as a possible path to Super Administrator compromise.
2026-08-31T0411Z-intel· Sonnet 5 · window 24 h · 6 entries published
Verification & coverage notes
Runaway-duration explanation. This fire's corrected duration_seconds (13655s, ~3.8h) trips the 3h watchdog threshold. The cause is the Phase 5.7 verification loop running its full 8-iteration cap: each of iterations 1-8 returned NEEDS_FIXES (never CLEAN), with genuine, well-evidenced truth-gate and editorial findings on every pass; none of the eight iterations was a wasted or repeated cycle. Phase 0-5.5 (research, composition, the mechanical gate) completed in under an hour; the remaining ~2.8h was entirely the verification loop's sequential remediate-and-re-spawn cycle. Per Phase 5.7's decision rule 6 (cap fail-open), the run published on the 8th iteration's residual findings, 8 of 9 truth+editorial findings remediated before publish, one (a low-moderate-confidence CVE-status hedge on the AI-infrastructure deep dive) declined with a documented rebuttal; verification_residual_count: 8 reflects that no further independent cold pass confirmed the applied fixes, not that they are believed wrong.
Window: gap_hours=15 (previous run: 2026-08-30T1312Z-audit, started 2026-08-30T13:12:06Z), window_hours=24 (24h floor applies), standard-class gap, no catch-up disclosure required.
Coverage backlog worked down (state/coverage_backlog.md). Five open rows from the 2026-08-30 audit were re-gated on today's facts, deep-read from their primaries, and published this run: WatchGuard Fireware OS (new vulnerability entry), Microsoft's TerminalFix campaign (new threat entry), Microsoft's "AI infrastructure becomes the target" report (new threat entry, this run's deep dive; CVE-2026-42271/CVE-2026-48710 already covered by the 2026-06-09 entry are declared in references[]; CVE-2026-49869 is new), Huntress's Famous Chollima/DPRK forensic report (landed as an update record on 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection; Famous Chollima is an alias this entry already carried, so the reusable PiKVM/Guermok detection methodology extended the existing entry rather than opening a new one), and the Norway/Digdir ID-porten DDoS (new incident entry, direct sector nexus as a public-sector shared-identity-gateway incident, carrying a transferable architectural lesson for Switzerland's own Agov/CH-Login consolidation). Two rows stay open: Boston Scientific (re-checked, still no source names an attacker mechanism) and the inside-it.ch Insel Gruppe lead (escalated, see below).
S3 classifier trip. S3's first attempt terminated immediately with a content-safety classifier trip ("Sonnet 5's safeguards flagged this message"). Retried per this pipeline's documented recovery procedure for classifier-blocked research workers: the reframed instructions dropped inline campaign/cluster names (pointing at the coverage-backlog file instead of enumerating them) and asked for incremental findings-YAML checkpointing. The retry completed cleanly within its 45-min cap. The failed first attempt is not counted in sub_agents.S3 telemetry above, which reflects the successful retry only.
inside-it-ch: now a persistent, not transient, block. Three independent research workers (S2, S3, S4) each attempted inside-it-ch this run, essential-tier, and S2 additionally chased the specific rotation-priority backlog lead (an article on Insel Gruppe/Bern hospital group delaying a ServiceNow migration "wegen eines Sicherheitsvorfalls"). Every transport failed identically across all three: direct GET 403, trafilatura extraction returns no readable body, the jina reader relays an upstream block/challenge, and the RSS path separately returns Cloudflare error 526 (an invalid SSL certificate on inside-it.ch's own origin, not an egress-side block). tools/source_health.py's store-wide sweep confirms HTTP 526 and flags needs-demote. Per the hard rule that a transport block never demotes, the source's tier/status are unchanged; consecutive_fetch_failures was incremented and the finding documented in its notes for the audit. This is now the 3rd consecutive fire fully unreachable, if a 4th also fails, the source needs either a new working transport or an explicit fetch_method: blocked classification.
Borderline-drop: CVE-2026-77956 (ash_ai / Elixir Ash Framework AI extension), unauthenticated CVSS 10.0 RCE with a public working PoC, published today. S1 flagged this as borderline and it was dropped after triage: the ecosystem (Elixir/Ash/Phoenix) is niche with no confirmed Swiss public-sector or supplier deployment, and the underlying pattern (untrusted input reaching an LLM-agent framework's code-evaluation layer) is already well covered in-store by higher-relevance entries (Hugging Face, the Taiwan agentic-AI intrusion, GTIG AVDH, isolated-vm, and this run's own AI-infrastructure deep dive). Doubt about relevance to this constituency resolves toward drop per PD-11's calibration rule.
Essential-coverage: missed=cisa-advisories (persistent 403, reader-credit-exhausted per the source's own notes; the CISA KEV JSON feed substitutes for the exploited-vulnerability surface), cisa-directives (same 403 condition; no corroborating evidence of a new directive from any other source), inside-it-ch (whole-host transport block, 3rd consecutive fire, see above).
Watchlist: not applicable, this deployment configures no product or supplier watchlist (documented no-op; S1 and S4 both reported checked=0/hits=0 as instructed).
Coverage gaps: ssd-disclosure (Cloudflare robot-challenge screen on every transport, no substitute source); helpnetsecurity (homepage is a JS-driven newsletter stub with no article listing, recipe gap, not a transport failure, worth a dated source-notes update); ncc-research (listing HTML did not expose parseable per-post links in the time available, light-effort miss, not pursued given no expected regional signal); google-tag (resolves to Google's general security blog, not a TAG-specific dated listing, known recipe gap).
Item-granularity note. The Zéro Logement Vacant breach and the France SDIS data-leak campaign are both new entries despite sharing the actor:zerobytes / French-public-sector-breach theme with existing entries, distinct victim, distinct platform/mechanism and distinct victim class in each case, per the item-granularity rule; none shares a CVE with covered ground.