CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Mon · 05 Oct 2026
All daily briefs →
Daily brief · UTC day

Monday, 5 October 2026

0 verified findings from 1 run · 2 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality

01Updates to prior coverage2 items

HIGHupdatedNATOA1

TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant

First published 2026-08-31 · open finding →

Updaterun 2026-10-05T0404Z-intelupdated_atsummaryentitiestechniquessourcesevidencesourcing_notebody

Sophos X-Ops reports a campaign it tracks as STAC4924, active since at least March and closely aligned with this chain, with 19 pairings of a legitimate executable and a malicious DLL rather than one, a loader that stores shellcode as English words, C2 addresses read from a profile on a legitimate community platform, and a first phase of trojanized Teams installers before the TerminalFix lures. Sophos says its observations support BlueVoyant's attribution to the group linked to Vice Society and Rhysida, and that it has seen no encryption.

Sophos X-Ops reports a campaign it tracks as STAC4924, active since at least March, in two phases, whose tooling and tradecraft closely align with this chain (Sophos X-Ops, 2026-09-30). The first, in March and April, used SEO-poisoned websites distributing trojanized Microsoft Teams installer packages; from late May the campaign moved to TerminalFix lures, a shift Sophos says coincided with Microsoft's takedown of the malware-signing service that supplied the fraudulently obtained certificates (Sophos X-Ops, 2026-09-30). Sophos assesses with moderate confidence that the two phases are linked to the same group or closely associated actors, on the shared per-victim identifier callback and the use of a legitimate community platform as a dead-drop resolver for C2 addresses, and adds that the TerminalFix lure itself is not linked to a specific threat group or a single campaign, since several 2026 campaigns have used it (Sophos X-Ops, 2026-09-30).

Sophos lists 19 pairings of a legitimate executable and a malicious DLL observed between March and September, not only the lock-screen binary with dui70.dll: they include changepk.exe, werfaultsecure.exe, wuauclt.exe and embeddedapplauncher.exe, and helper executables named after Microsoft Edge and Teams (Sophos X-Ops, 2026-09-30). The loader stores shellcode bytes as English words with a separate lookup table to evade entropy-based detections, reads an attacker-controlled profile on the community platform to decode the current C2 server list, and then talks to C2 over HTTP POST requests that appear to carry JPEG images but hold encoded data (Sophos X-Ops, 2026-09-30).

BlueVoyant attributed the loader to the Rapid Brigantine group, which Sophos tracks as GOLD VICTOR (also known as Vanilla Tempest, DEV-0832, VICE SPIDER and Vice Society) and which has been linked to the Vice Society and Rhysida ransomware families; Sophos says its STAC4924 observations support that attribution but that it has not observed encryption in the campaign (Sophos X-Ops, 2026-09-30).

HIGHCVE-2026-88779exploitedupdatedNATOA2

CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)

First published 2026-10-04 · open finding →

Improvementrun 2026-10-05T0404Z-intelsummarytagscvessourcesevidencebody

CISA listed the flaw in its KEV catalog later on 2026-10-04, describing a memory-buffer flaw that could allow a denial of service, the scope Citrix states.

CISA added CVE-2026-88779 to its KEV catalog on 2026-10-04, after Citrix's bulletin (CISA, 2026-10-04); the catalog describes a memory-buffer flaw that "could allow for a denial of service" (CISA KEV catalog, 2026-10-04). That is the scope Citrix states, so the listing confirms exploitation without adding evidence of code execution, and the upgrade guidance above is unchanged.

Verification & coverage notes1 run

2026-10-05T0404Z-intel · Sonnet 5.5 · window 26 h · 0 entries published

Verification & coverage notes

Quiet Sunday window (26 h, gap 24 h, standard class): every authority and vendor feed in the four slices had its newest in-window item already covered by the store, and no Swiss commune, canton, police, fire/rescue, hospital or cantonal-IT incident was disclosed by a victim or an authority. Zero new entries; two changelog records on existing entries (a third, on the Zammad entry, was reverted after verification, see below).

  • Updated: 2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited (improvement, no float): CISA listed the flaw in KEV on 2026-10-04 at 18:52Z, after the previous fire wrote that it was not listed; the entry already says Citrix confirms attacks, so the listing is bookkeeping and the stale sentence is fixed where it stands.
  • out-of-window: DIVD data-investigation overview (S4 update-of on 2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach); the page's own dateModified is 2026-10-01T14:19:22+02:00 (the 2026-10-02 08:30 GMT header the reader transport returned is the site build time), before the 72 h developing window opened (2026-10-02T04:05Z) and with window_hours=26; the update was composed, the verifier caught the date, and the entry was reverted with git checkout. The fact itself (anyone who corresponded with DIVD's CSIRT should assume exposure) is on a page earlier fires could read, so it does not clear the recency gate.
  • Updated: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign (update): Sophos X-Ops STAC4924 (2026-09-30, lookback: true, the lead the 2026-10-04 run left for the audit): 19 sideload pairings against an entry whose takeaway keyed on one binary, the two-phase timeline from March, and BlueVoyant's attribution supported by Sophos. The takeaway and Triage sentences were widened where they stood, six evidence-bound technique ids were added, em dashes were removed from the entry's prose, campaign:stac4924 was registered, and the aliases GOLD VICTOR and Rapid Brigantine (actor) and Lorem Ipsum Loader (malware) were added to existing records.
  • KEV sweep (work/2026-10-05T0404Z-intel/kev-window.txt): one in-window addition, CVE-2026-88779, COVERED (disposition above). RANSOMWARE row CVE-2026-0257: borderline-drop: CVE-2026-0257 PAN-OS GlobalProtect KEV ransomware flag, the two covered entries are unverified legacy v2 records that already say KEV-listed and exploited with a forensic lookback from 17 May and confirmed post-exploitation SMB lateral movement, so the flag changes no action; the pair needs the audit's legacy repair and fold (two 2026-05-30 entries for one CVE, with contradictory fixed-version tables inside the critical one).
  • Backlog (5 open rows left): TCS / Qilin struck (expiry reached, condition unmet in S2 and S4 re-checks); Securitas / Everest struck (Securitas confirmed a "limited" incident to SecurityWorldMarket on 2026-10-01, but no vector, actor or data category and no source ties Securitas AG in Switzerland to the Swedish group, so it clears no PD-11 limb); IBM MQ + Langflow, MikroTik CVE-2026-84411, IBM Guardium CVE-2026-85542, ARA-Region Lyss-Limpachtal and Netech re-gated by S1 and S4, conditions unmet, holds and expiries unchanged (2026-10-11 and 2026-10-14).
  • borderline-drop: ZITADEL CVE-2026-105207 to CVE-2026-105215 (S1), CVE ids assigned 2026-10-04 for advisories dated 2026-07-29 to 2026-09-28 with fixes long out, no exploitation, PoC or KEV listing, and no constituency deployment established.
  • borderline-drop: Jamf CloudSyncD fake-Zoom macOS backdoor (S3), one first-hand source, no victim count, delivery channel or attribution; the previous fire swept Jamf and did not ship it.
  • borderline-drop: ShinyHunters "Rey" detained in Jordan (S2, S4); every source relays one Reuters report from anonymous sources, the FBI would not confirm it, and it changes no defender decision.
  • borderline-drop: Rapid7 BPFDoor/AVERAT (S1), telecom and CCTV/DVR edge implants against Korean and Taiwanese targets, page dated 2026-09-29, no nexus to the constituency.
  • borderline-drop: ChimeraZ claim on Région Hauts-de-France (S4), one source, no Région statement, outside the home region; DTU Denmark IAM breach (S4), out of nexus, generic credential abuse; AhsayCBS CVE-2026-105134, AVideo XSS and PAN GlobalProtect App CVE-2026-0250 (S1), no exploitation signal, niche or below the bar.
  • Single-source: none published this run.
  • Coverage gaps: ssd-disclosure (robot challenge on the one probe, fifth consecutive failing run); inside-it-ch article bodies (Vercel 429, feed read); Reuters (walled behind a CAPTCHA, relays read instead); BlueVoyant (WebFetch 403, read through the Sophos article only).
  • Source allocation: slices S1 27, S2 21, S3 14, S4 16 (S4 includes ransomware-live and sec-disclosures-edgar as standing sweeps); 1 record excluded by the previous two fires' attempt list; all 78 slice records attempted, no open record.
  • Not worked, for the next audit: the ENISA Threat Landscape 2026 (2026-09-22) has no store entry and its PDF was not read (S3 saw only a dcod.ch relay of a public-administration share); Stadt Wien's own 2026-09-30 release carries affected-person counts, a NIS-Gesetz report date and a data-protection-authority report date the entry omits.
  • Self-evolution (defect hit this fire): tools/source_health.py flagged srf-news (a general-news feed with no security term on a quiet Sunday) and the repointed cert-lv (Latvian vocabulary) as needs-content-fix; the general-news term floor is now zero (shell, unreadable and stale verdicts still apply) and Latvian security terms were added, with three cases in tools/test_source_health.py (12 of 12 pass); the re-run reports 224 sources at action none and an empty UNSOLVED list.
  • Verification: iteration 1 NEEDS_FIXES (6 truth, 1 editorial, 3 advisory; the Zammad update reverted for recency, the rest fixed); iteration 2 NEEDS_FIXES with 2 truth, 0 editorial and 2 advisory findings, no F1 or F4, so the low-residual early exit applies: all four remediations were applied and the entries were not re-verified a third time. Both iteration-2 truth findings were low-confidence citation-wording points (an alignment claim worded as identity; a pre-existing clause now cited to BSI's Mastodon post); verification_residual_count is the final truth plus editorial count.