CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Sat · 03 Oct 2026
All daily briefs →
Daily brief · UTC day

Saturday, 3 October 2026

1 verified finding from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Symantec: Warlock's operator steals SharePoint machine keys, forges signed payloads and ships ransomware via SYSVOL. Symantec reports that Longlegs (also known as Storm-2603), the China-nexus developer of Warlock ransomware, attacked at least four organizations in two months, a water utility, a telecommunications provider, a regional government body and a university in Portuguese- and Spanish-speaking countries, and still gets in through on-premises SharePoint Server. In the intrusion Symantec walks through, a web shell harvested the farm's ASP.NET machine keys to forge signed payloads, a security-tool killer ran on at least 40 hosts in about two hours, and Warlock reached at least 33 hosts through SYSVOL replication. →

01Active threats, incidents & disclosures1 item

HIGHNATOB2

Longlegs (Storm-2603), the developer of Warlock ransomware, still enters through on-premises SharePoint: a water utility, a telecom, a regional government body and a university hit in two months

Symantec reports that Longlegs, also known as Storm-2603, develops the Warlock ransomware and attacked at least four organizations in two months: a water utility, a telecommunications provider, a regional government body and a university, in Portuguese- and Spanish-speaking countries (Symantec, 2026-10-01). Symantec says the group typically enters through on-premises SharePoint Server, and that the 2025 ToolShell flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771) likely remain in its arsenal alongside newer SharePoint flaws (Symantec, 2026-10-01); BleepingComputer relays the report (BleepingComputer, 2026-10-02).

In the intrusion Symantec walks through, the likely entry was SharePoint exploitation, and on 2026-07-22 PowerShell wrote a web shell into the SharePoint LAYOUTS template directory (Symantec, 2026-10-01). The group drops one into the directories of several SharePoint versions at once; it harvests the farm's ASP.NET machine keys, which the attackers use to forge a validly signed payload that runs code in the SharePoint application pool (Symantec, 2026-10-01). From 2026-07-28 PowerShell commands loading the System.Workflow.ComponentModel assembly, the deserialization gadget behind the forged payload, ran at intervals (Symantec, 2026-10-01). The attackers also used DLL sideloading, fetched installers with msiexec from legitimate cloud file-sharing services, enumerated domain accounts and trusts, added a setup-lookalike domain account to local Administrators on three more hosts, installed Visual Studio Code Insiders as a tunnel service, and ran NetExec for enumeration, credential spraying and remote execution (Symantec, 2026-10-01).

On 2026-07-31 a security-tool killer, pushed with one-line commands that copied a tool set from an internal share, ran on at least 40 hosts in about two hours; its driver is unknown, but in other recent attacks the group used the signed K7RKScan driver (CVE-2025-1055) (Symantec, 2026-10-01). Warlock then ran on at least 33 hosts from the domain's SYSVOL scripts share, with the DFS Replication service (dfsrs.exe) as the parent on three hosts, so SYSVOL replication delivered the payload (Symantec, 2026-10-01).

Exposure: on-premises SharePoint Server farms reachable from the internet or from an attacker's foothold that were unpatched against the ToolShell and later flaws; Symantec gives no version table (Symantec, 2026-10-01). Because the web shell takes the machine keys, patching alone does not replace them; Microsoft's ToolShell guidance says it is critical to rotate the machine keys and restart IIS on all SharePoint servers (Microsoft, 2025-07-22).

Triage: Visual Studio Code tunnels are ordinary on developer workstations; the observed pattern is a service installed from a system folder on a host in a domain already showing SharePoint exploitation or an unexpected administrator account (Symantec, 2026-10-01).

In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university.

The webshell's function is to harvest the SharePoint farm's ASP.NET machine keys, which the attackers then use to forge a validly signed payload that achieves remote code execution inside the SharePoint application pool.

In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines.

Symantec Threat Hunter Team / Carbon Black 2026-10-01

Builds on: Swiss federal SharePoint servers breached mid-patching, ~200 accounts taken, servers now being… · A second Swiss public-sector SharePoint victim in 48 hours, and the intrusion sat unnoticed for…

threat03 Oct 04:41Zsingle-sourceOpen finding →

02Updates to prior coverage3 items

CRITICALCVE-2026-76504exploitedupdatedNATOA1

CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)

First published 2026-10-02 · open finding →

Updaterun 2026-10-03T0404Z-intelsummaryimmediate_actionactionsbodysourcesevidence

Cisco revised the advisory on 2026-10-02 (version 1.1) to add a Live Protect shield for this CVE, which it describes as temporary, partial protection that may block legitimate logins using URI encoding. The first fixed releases are unchanged and the upgrade remains Cisco's only remediation.

Cisco revised its advisory to version 1.1 on 2026-10-02 ("Added information about Live Protect shield availability") and now states it has released a Live Protect shield for CVE-2026-76504 "to provide temporary security coverage" while upgrades are planned (Cisco PSIRT, 2026-09-30). Cisco says the shield offers only temporary partial protection and that, once applied, a legitimate user with URI encoding might not be able to log in to the Manager (Cisco PSIRT, 2026-09-30). Cisco's Live Protect page lists the feature from Catalyst SD-WAN Control Components release 20.18.3, describes a monitoring mode that shows exploit attempts without enforcing and an enforce mode that applies the mitigation, and says Cisco creates shields for the release current when a shield is published and for the two immediately preceding releases in each supported release train that includes Live Protect, so older releases may have no shield (Cisco, 2026-07-01). The fixed releases, the exploitation statement and the KEV listing are unchanged, and Cisco keeps its position that the only remediation is the upgrade.

CRITICALCVE-2026-104286exploitedupdatedNATOA2

CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)

First published 2026-10-02 · open finding →

Updaterun 2026-10-03T0404Z-intelsummaryimmediate_actionactionsbodycvessourcesevidenceverificationsourcing_notereferences

Belnet, the Belgian government and research network, says a zero-day in its supplier Fortinet's technology let attackers copy its inbound mail from 2026-07-22 and links this advisory, which puts exploitation about ten weeks before the disclosure. NCSC Switzerland lists the artifacts attackers left. Fortinet's advisory words its workaround as the webmail interface or a web application firewall rule on POST requests to /ibe, where press and NCSC Switzerland say management interface.

Belnet, the Belgian government and research network (Risky Bulletin, 2026-09-30), updated its incident notice on 2026-10-02 to say its incident was caused by a zero-day in technology from its supplier Fortinet and to link this advisory for the vulnerability and its CVE, without naming FortiMail (Belnet, 2026-10-02). Belnet says attackers copied all incoming mail to its domains between 2026-07-22 and the morning of 2026-09-25 and that the vulnerability was remediated on 2026-09-25 at 08:10, without saying how (Belnet, 2026-10-02). Read with the advisory, the notice puts exploitation of this flaw about ten weeks before Fortinet's 2026-10-01 disclosure, against a European government network whose loss was bulk inbound mail.

NCSC Switzerland's advisory of 2026-10-02 says observed attacks deploy malicious binaries and modified system files (NCSC Switzerland, 2026-10-02). The Fortinet advisory as read on 2026-10-03 words its second workaround as disabling access to the FortiMail webmail interface from the internet and adds an option to block POST requests to /ibe that contain '../' at a web application firewall (Fortinet PSIRT, 2026-10-01); BleepingComputer and NCSC Switzerland word the second workaround as the management interface, and the page's timeline lists only the initial publication.

NOTABLEupdatedNATOA2

Belnet, the Belgian government and research network, confirms a supplier zero-day let attackers copy all incoming mail to Belnet-owned domains and the transfer links its FileSender and FedSender services sent directly for 65 days

First published 2026-10-02 · open finding →

Updaterun 2026-10-03T0404Z-intelheadlinesummaryprioritysourcesevidencesourcing_notereferencesbody

Belnet's notice, updated 2026-10-02, now names the supplier as Fortinet and links Fortinet's advisory FG-IR-26-175, says the Centre for Cybersecurity Belgium is assisting, and says transfers created in the affected period were disabled on 2026-09-29, so senders who still need to share the files must create new transfers.

Belnet's incident notice, updated on 2026-10-02 at 11:00, now names the external supplier as Fortinet and links Fortinet's advisory FG-IR-26-175 (Belnet, 2026-10-02). Belnet also says it engaged the Centre for Cybersecurity Belgium for incident response and forensics, and that on 2026-09-29 it removed download links that were still active and disabled transfers created during the affected period, which generated notifications to senders and recipients (Belnet, 2026-10-02). Senders who still need to share the files must create new transfers, because Belnet cannot recreate them, and Belnet still names no actor (Belnet, 2026-10-02).

03Action items1 item

Verification & coverage notes1 run

2026-10-03T0404Z-intel · Sonnet 5.5 · window 26 h · 1 entry published

Verification & coverage notes

Coverage window: standard fire. The previous intel fire started 2026-10-02T04:04Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The container clock was cross-checked against an external date header (skew 0 s) and origin/main was fresh at preflight.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found two CISA KEV additions in the window, Zammad CVE-2026-102489 and CVE-2026-102490 (added 2026-10-02), both COVERED by the existing Zammad entry; no row was NOT COVERED, MENTION-ONLY or COVERED-STALE (work/2026-10-03T0404Z-intel/kev-window.txt). S1 confirmed catalog version 2026.10.02 and found every EUVD-exploited record already covered.

New entry (1): Longlegs (Storm-2603) and the Warlock ransomware, still entering through on-premises SharePoint (threat, high; Symantec's report of 2026-10-01 with same-day-plus-one relays by BleepingComputer, The Record and SecurityWeek; single assessor, so verification is single-source and credibility 2). It was surfaced by two domains independently (S3 and S4); the primary is a day older than the window start, and it passed the recency rule because the freshest sources are the in-window relays and nothing in the store covered it. Priority is high because on-premises SharePoint is the entry technology of two Swiss breaches already in the store and the machine-key theft means patching alone does not close the exposure. No CVE record is carried: Symantec names the ToolShell CVEs only as likely still in the arsenal.

Updates (3): FortiMail CVE-2026-104286 (update: Belnet's notice, which links this advisory, puts exploitation from 2026-07-22; NCSC Switzerland's note on the artifacts; the entry now follows Fortinet's advisory as read on 2026-10-03, which words the second workaround as the webmail interface and adds a WAF rule on POST /ibe, while BleepingComputer and NCSC Switzerland say management interface; the previous fire's verifier read Fortinet's page with the management-interface wording and a file table, and the page's timeline lists only the initial publication, so Fortinet appears to have revised it without a timeline entry; the file list is now attributed to BleepingComputer and NCSC Switzerland and the CISA citation points to the per-event alert); Belnet incident (update: supplier named as Fortinet, FG-IR-26-175 linked, Centre for Cybersecurity Belgium engaged, transfers disabled on 2026-09-29; priority raised from routine to notable because a vector class is now known; the first evidence quote no longer matched the page and was replaced); Cisco Catalyst SD-WAN Manager CVE-2026-76504 (update: advisory revision 1.1 adds a Live Protect shield, temporary and partial, with a login side effect and a support rule limited to the current and two preceding releases of trains that include Live Protect).

Contradictions: NCSC-NL (NCSC-2026-0398) says Fortinet released security updates for FortiMail while Fortinet's table lists 8.0.2, 7.6.7 and 7.4.9 as upcoming; the FortiMail entry follows Fortinet and states the contradiction. BleepingComputer and NCSC Switzerland say management interface for the second workaround where Fortinet's current page says webmail interface; the entry follows the Fortinet page and says so.

Backlog (7 open rows, all held, none changed): S1 re-gated IBM MQ CVE-2026-10747 with the three Langflow CVEs, MikroTik CVE-2026-84411 and IBM Guardium CVE-2026-85542; S4 re-gated Qilin/Touring Club Suisse, Everest/Securitas, SafePay/ARA-Region Lyss-Limpachtal and Payload/Netech. Every stated hold condition is unmet (no KEV listing, exploitation report or public PoC; no victim statement or press confirmation; ZATAZ analysed the Everest file tree but states origin and access are unconfirmed). No row text was appended, per the no-carry-forward rule. Nearest expiry is Qilin/TCS on 2026-10-05.

borderline-drop / out-of-window:

  • borderline-drop: OrdaSoft OS CCK for Joomla CVE-2026-102427 (unauthenticated PHP upload, CVSS 4.0 10.0, fixed in 8.3.16 but the vendor updater still offers 8.3.14): not exploited, not in KEV, niche extension with no constituency deployment evidenced, single source (mySites.guru); below the PD-11(b) bar.
  • out-of-window: tac_plus pre-auth format string (elttam, primary 2026-09-23, beyond the source's 168 h lookback, CVE pending, internal management plane, no exploitation); Huntress municipal recreation-platform web shell (2026-09-30, US platform, no CVE).
  • borderline-drop: NeedyMantis (Microsoft, 2026-09-28), already dropped by the 2026-09-30 and 2026-10-02 fires; TA419 (Proofpoint, 2026-10-01: adversary-in-the-middle phishing of US/Japan policy and defense staff, technique not new, indirect relevance); Microsoft Digital Defense Report 2026 (vendor telemetry shares read from PDF chart text, no defender decision); DragonForce Lab52/Seqrite (2026-10-01: a second backdoor with an MQTT fallback resting on one lab's artifact-overlap attribution, on a legacy entry whose guidance already covers TURN egress and side-loading); Sysdig's Zammad hunts (same signals as the entry's Detection line).
  • borderline-drop: CERT-FR/CERT Santé health-software report CERTFR-2026-CTI-007 (no vendor, no CVE, French health sector); Swiss motion 24.4393 on .ch/.swiss domain-holder identification (a mandate to draft law, the text finally referred is not stated); BSI's Classic McEliece notice (cryptographic-baseline advice, not a SOC decision); SRG/SRF employee data (2020 contact data, no vector); ATEXO/Region Hauts-de-France, Svedala kommun and the US municipal incidents (incident floor: no vector, no actor, no behavior beyond impact; no Swiss nexus).
  • borderline-drop: OpenAI's count of over 100 notified organizations (scope statement, no decision for the constituency, five entries already carry the saga); VOISING/ApplyNow Metabase fallout (the Metabase link is Piyolog's inference, Japan); the ANSSI REACTIV lab/DINUM details (read by eye from an image-only PDF, no new decision); the ShinyHunters arrest statements (vanity figures, no defender action); the Censys exposure share for NetScaler (improvement-only).
  • borderline-drop: WatchGuard AP CVE-2026-101891 and CVE-2026-86102 (9.3, no exploitation, access-point management network), Zimbra 10.1.21 CVEs CVE-2026-66911 and CVE-2026-66912 (reserved, no exploitation; the fix is already carried by the CVE-2026-73570 entry), Dell CSM, GitLab AI Gateway, Apache httpd 2.4.69 (Apache rates all 20 as low or moderate), Joomla core 5.4.9/6.1.4, Chrome 154, Exchange CVE-2026-96940, Palo Alto CVE-2026-0250: patch-cycle items with no exploitation.

Single-source / reduced confidence: the Warlock entry rests on Symantec alone (relays add nothing); the Belnet-to-FortiMail link is Belnet's own pointer to the advisory, and Belnet does not name the product, which the entry states.

Sources: 26 changes in sources_changed: last-success dates for the six sources cited, recipe notes verified by the sub-agents (BleepingComputer and Fortinet direct feeds, the EUVD search API, YesWeHack, Censys, BSI's news listing, news.admin.ch, ransom-isac, Cloudflare Cloudforce One, elttam, ransomware.live endpoints), three new candidates (it-connect, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata) the two due promotions (ibm-support-security-bulletins, europol-newsroom) and the health recipes for the three records the health check flagged (news-admin-ch, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata: each now carries a tested health_cmd and content_scope: general-news). ssd-disclosure stays blocked on every transport.

Tool findings for the next audit (not fixed here): fetch_source.py pdf on an image-only PDF (CERTFR-2026-CTI-006) exits 0 and prints binary noise instead of reporting that the file has no text objects (S4's workaround: download the file and read rendered pages); fetch_source.py extract on theregister.com returns navigation boilerplate instead of the article body; the rapid7-research feed returned HTTP 404 (S3). The S1 sub-agent spent 7 unintended reader-pool fall-throughs (extract and feed auto-fallback), no deliberate reader use.

Coverage gaps: ssd-disclosure (blocked on every transport); inside-it-ch (article pages HTTP 429, RSS teasers only); ncsc-ch-incidents (undated listing, no in-window addition can be dated); anssi-fr (CERT-FR timestamps are flat 00:00 UTC); europol-newsroom (SPA shell, not in a slice); rapid7-research (feed HTTP 404, not in a slice).

Verification: three iterations, none CLEAN. Iteration 1 (truth 7, editorial 3) found the Fortinet file-table attribution, a wrong 'corrected' framing, a stale evidence quote and attribution slips; iteration 2 (truth 4, editorial 1) found a partly fixed rotation attribution and wording slips; iteration 3 (truth 2, editorial 0, no F1 or F4) found two low-confidence wording points and two advisories, so the early-exit rule applied: all four were fixed after the iteration and the run published without a fourth pass. verification_residual_count is 2, the final iteration's truth plus editorial count, although both findings are remediated on disk. The first-iteration finding on the Fortinet page is worth the audit's attention: Fortinet changed the advisory text (management interface to webmail interface, a file table dropped) without a timeline entry, so a vendor revision can be invisible to a check that trusts the page's own revision history.