CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Fri · 09 Oct 2026
All daily briefs →
Daily brief · UTC day

Friday, 9 October 2026

5 verified findings from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

CriticalPatch every internet-facing NetScaler ADC/Gateway now and check for pre-patch compromiseCVE-2026-88771 +7 · exploited · improved 09 Oct 03:53Z
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01ReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature. ReliaQuest assesses with high confidence that LLM-driven agents carried out substantial parts of an intrusion it investigated, using only known techniques: an internet-facing Apache Tomcat application accepted Spring Batch job definitions without a login, jobs ran JavaScript through the Nashorn engine inside the application process, plaintext SQL Server sysadmin credentials from the application's configuration led to xp_cmdshell, and two public privilege-escalation tools reached SYSTEM. ReliaQuest names no victim, sector or region, nor the vendor of the exposed application, and could not determine how many agents ran, which model drove them or how much a person approved. →
  2. 02Talos: malware tells the analysing LLM to skip it; the text is plain and therefore detectable. Cisco Talos documents 84 samples from four malware families, collected from January 2025 to July 2026, that embed plain natural-language text meant to steer the LLM stage of automated triage: a verbatim "no need to analyze this file" comment reused by at least four actors, templated variants, instructions repeated across seven chat-template formats, and intimidation or fabricated-authority text. ESET separately found UAC-0099 using a decoy request in a script comment to trip an LLM scanner's refusal; Talos' own test of five local models put the best techniques at steering the outcome in the attacker's favour in about 35% of runs, and its advice is to treat text inside a sample as evidence, never as instruction. →
  3. 03Joint advisory: Flax Typhoon-consistent actors spray Exchange and Microsoft 365, steal mail and keep SoftEther access. The FBI, CISA, NSA, NCSC UK and partners from five more countries published AA26-281A on 2026-10-08 on China-linked actors enabled by Integrity Technology Group, whose tactics the advisory calls consistent with Flax Typhoon: open-source and MicroScan vulnerability scanning, XSS credential harvesting, password spraying against Exchange and Microsoft 365 interfaces, SoftEther VPN persistence, DCSync and bulk mail theft through Exchange Web Services. Five of the eight old flaws the advisory lists as successfully exploited (ProFTPD, ISC BIND, Apache Struts, ONLYOFFICE Docs, Strapi) were added to CISA's KEV catalog the same day; the FBI also seized the domains behind MicroScan and the FishHub phishing tool. →

01Active threats, incidents & disclosures3 items

NOTABLEupdatedNATOA2

PK Softech, software supplier of Swiss pension funds: malware and a data outflow at Publica, with the Bernese funds BPK and BLVK and Pensionskasse Post also reporting the supplier incident, and the Federal Prosecutor's Office investigating

The Confederation, in a release headlined "data outflow confirmed" (translated from German), says an external software supplier of the federal pension fund Publica detected a cyberattack at the end of September, informed its other customers, and that the Federal Prosecutor's Office has opened an investigation; no other federal office has a business relationship with the supplier (Swiss Federal Administration, 2026-10-08); the supplier, PK Softech AG of Reinach (BL), says unknown persons used malware to reach part of its IT infrastructure and that it must be assumed data left its systems, with type and scope still under investigation (PK Softech, 2026-10-08). Publica insures, among others, staff of the federal administration and the ETH domain, about 70,000 active members and 41,600 pensioners at the end of 2025, and its member letter lists name, date of birth, AHV number, address, contact details, salary and pension data and partner details as data that could have been stolen (watson.ch, 2026-10-08). Netzwoche reports it is still unclear whether data of the pension fund actually left (Netzwoche, 2026-10-08); no access vector or actor is public, and Publica declined to say whether a ransom was demanded (watson.ch, 2026-10-08); the supplier is a software supplier of a federal institution, and Publica data may be affected (Swiss Federal Administration, 2026-10-08). The Bernische Pensionskasse says its supplier is the same company (BPK, 2026-10-09), and the Bernische Lehrerversicherungskasse (BLVK, 2026-10-08) and Pensionskasse Post (Pensionskasse Post, 2026-10-09) report the supplier incident too.

At the end of September an external software supplier of the federal pension fund Publica detected a cyberattack. (translated from German)

Swiss Federal Administration (admin.ch) 2026-10-08

According to current knowledge it must be assumed that data left our systems. (translated from German)

PK Softech AG 2026-10-08

Whether and which data actually left in the incident is, however, still unclear. (translated from German)

watson.ch 2026-10-08

The supplier is the same company that also supplies the federal pension fund Publica. (translated from German)

At this time there are no indications that data of the BPK was stolen. (translated from German)

Bernische Pensionskasse (BPK) 2026-10-09

The manufacturer's customers include the Bernische Lehrerversicherungskasse, the Bernische Pensionskasse, the Migros-Pensionskasse, the Pensionskasse Post and the Syngenta Pensionskasse. (translated from German)

Inside IT (AWP) 2026-10-09

Pensionskasse Post obtains software for administering insured persons' data from PK Softech AG. (translated from German)

Pensionskasse Post 2026-10-09

Among others, the BPK insures the canton's staff and the staff of the three cantonal universities for occupational pension provision. (translated from German)

Netzwoche 2026-10-08
Updaterun 2026-10-10T0255Z-inteltitleheadlinesummaryprioritysourcesevidencesourcing_noteactionsbody

The supplier's customer base is now partly public and includes cantonal-level institutions. The Bernische Pensionskasse (BPK) states in a notice dated 2026-10-09 that an external software supplier of the BPK suffered a cyberattack at the end of September 2026 and that this is "the same company that also supplies the federal pension fund Publica" (translated from German); the supplier filed a criminal complaint, informed the relevant federal bodies and its affected customers, various federal bodies are clarifying with it which data is affected, and the Federal Prosecutor's Office has opened an investigation (BPK, 2026-10-09). The BPK says there are currently no indications that its data was stolen but that this cannot be entirely excluded, and that insured persons are being informed (BPK, 2026-10-09). Netzwoche reports that the Canton of Bern's own notice names the BPK and the Bernische Lehrerversicherungskasse (BLVK) as concretely affected, that the BPK insures canton staff and the personnel of the three cantonal universities (42,145 active insured and 18,321 pensioners on 31 December 2025) and that the BLVK insures 21,417 active Bernese teachers (Netzwoche, 2026-10-08). The BLVK's own notice does not name its supplier; it says the supplier took the affected environment off the network, brought in external specialists, informed the authorities and filed a criminal complaint, and that the supplier and the BLVK are still checking whether and to what extent BLVK data is affected (BLVK, 2026-10-08). Pensionskasse Post, the occupational pension fund of Swiss Post, names PK Softech and says whether and to what extent its insured persons' data is affected is under review; it states that its data at PK Softech is anonymised and holds no particularly sensitive personal data such as IV disability-insurance files, a claim that is the fund's own and not independently verified (Pensionskasse Post, 2026-10-09). Inside IT, working from the AWP agency, lists the BLVK, the BPK, Migros-Pensionskasse, Pensionskasse Post and Syngenta Pensionskasse as customers of the manufacturer "among others" and says each is checking with PK Softech for a possible data outflow (Inside IT, 2026-10-09). PK Softech says it has been fully available to its customers again since 2 October 2026 (PK Softech, 2026-10-08). The access vector, the actor, which data belongs to which fund and whether a ransom was demanded are still not public in any source read.

incident09 Oct 03:41Zmulti-sourceOpen finding →
NOTABLENATOB2

ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours

ReliaQuest says the attacker needed no zero-day and no new malware: an internet-facing Apache Tomcat application used Spring Batch, in which a task definition names the code to run, and accepted and ran task descriptions without a login (ReliaQuest, 2026-10-07). The decisive step was submitting tasks that invoked Nashorn, the JavaScript engine in the application's Java environment, so the code ran inside the application with its account privileges and created no child process until a shell was spawned later; results came back through deliberately triggered error messages, in fixed 1,800-byte chunks reassembled over hundreds of requests (ReliaQuest, 2026-10-07). The application's configuration files held plaintext credentials with SQL Server sysadmin rights; the attacker enabled xp_cmdshell, found SeImpersonatePrivilege, uploaded PrintSpoofer and GodPotato in base64 fragments through the same channel and reached SYSTEM when the first tool failed on file permissions and the second worked (ReliaQuest, 2026-10-07). With SYSTEM it saved the SAM, SYSTEM and SECURITY registry hives for offline extraction, created two local administrator accounts and deleted only one, and removed artifacts after the actions that produced them (ReliaQuest, 2026-10-07).

The agent-driven reading rests on a live, unauthenticated Cairn agent-orchestration dashboard (an open-source platform for coordinating AI agents; no source says whether it is the Cairn exploitation engine of Gambit Security's reporting, and it is not Talos' CAIRN toolkit) on the address that sent the opening requests, on command timing (roughly half the gaps five seconds or less), on job names that tracked read offsets and upload parts without a gap, on machine-readable pipe-delimited output, and on payloads whose next version repaired the fault the previous one returned; ReliaQuest says no single indicator establishes it and that it could not determine how many agents ran, which model drove them or how much a person approved (ReliaQuest, 2026-10-07). Submission and collection ran from different addresses, so blocking the submitting address alone would not have stopped retrieval, and the tool assembly is not a fingerprint for any group (ReliaQuest, 2026-10-07).

The attacker entered through an internet-facing application feature on an Apache Tomcat server that accepted and ran task descriptions without requiring a login.

No single one establishes that an LLM agent was involved; a human directing scripts could produce several of them.

ReliaQuest Threat Research 2026-10-07

Builds on: Three off-the-shelf AI agents ran almost the entire card-theft campaign, from discovery to…

threat09 Oct 03:45Zsingle-sourceOpen finding →
NOTABLECVE-2015-3306 +7exploitedNATOA2

AA26-281A: China-linked actors enabled by Integrity Technology Group scan with MicroScan, spray Exchange and Microsoft 365 passwords and steal mail, and five old flaws from the scanner's scripts enter CISA KEV

The FBI, CISA, NSA, NCSC UK and partners from Australia, Canada, Japan, New Zealand and Spain describe Integrity Technology Group as a China-based company with links to the Chinese government that builds and sells cyber tools, hosts infrastructure and compromises networks; the actors it enables use tactics consistent with Flax Typhoon, Ethereal Panda and Red Juliett, among others (FBI IC3, AA26-281A, 2026-10-08). The Justice Department says the FBI seized the domains of MicroScan and the FishHub phishing platform, both operated by Integrity Tech (U.S. Department of Justice, 2026-10-08). Victims include U.S. government services, other critical sectors and organisations in Southeast Asia, Africa and North America; the advisory names no Swiss victim (FBI IC3, AA26-281A, 2026-10-08).

The chain starts with open-source scanners and MicroScan, a Python-based web application of 1,300-plus scripts, used since at least 2017 (FBI IC3, AA26-281A, 2026-10-08). Initial access has mostly come since January 2021 from command-line exploit utilities, and additionally from a cross-site-scripting payload that overlays a login form and offers a ZIP holding an executable that starts a process named like the Windows DiagTrack service (FBI IC3, AA26-281A, 2026-10-08). The actors spray and guess passwords with the EBurst tool against Exchange and Microsoft 365 (ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, ActiveSync) (FBI IC3, AA26-281A, 2026-10-08). Persistence is a SoftEther VPN client, often named conhost.exe or dllhost.exe, which endpoint tools are less likely to flag (FBI IC3, AA26-281A, 2026-10-08). Collection uses a PHP bot and a Linux utility that read mail through Exchange Web Services and Microsoft 365 with application client, tenant and secret values, and a DCSync tool that replicates directory data from a domain controller; mail was stolen from government, law-enforcement and healthcare bodies in Southeast Asia (FBI IC3, AA26-281A, 2026-10-08).

Appendix B lists eight successfully exploited CVEs recovered from MicroScan's scripts: ProFTPD 1.3.5, ISC BIND 9.x, Apache Struts 2.3.19 to 2.3.28, ONLYOFFICE DocumentServer 5.1.5 through 5.6.2 and Strapi up to 4.5.5, plus GNU Bash through 4.3, Pulse Connect Secure and GitLab from 11.9 (FBI IC3, AA26-281A, 2026-10-08); CISA added the first five to its catalogue on 2026-10-08 (CISA KEV catalogue, 2026-10-08). Apache names Struts 2.3.20.3, 2.3.24.3 and 2.3.28.1 as fixed (Apache Struts, 2021-02-13) and Strapi names 4.8.0 (Strapi, 2023-04-17).

Triage: conhost.exe and dllhost.exe are legitimate Windows names, so the file's path, signature and network behaviour separate a downloaded SoftEther client from the system binary (FBI IC3, AA26-281A, 2026-10-08).

The activity in the advisory is reported to be consistent with campaigns also publicly known as Flax Typhoon, Ethereal Panda and Red Juliett among others.

NCSC UK 2026-10-08

Integrity Tech has contracts with the PRC government.

U.S. Department of Justice 2026-10-08

Network defenders should include these interfaces when defending against EBurst.

FBI, CISA, NSA, NCSC UK and partners (joint advisory AA26-281A) 2026-10-08

Builds on: A PRC state-enablement platform leasing commercial proxy subscriptions as anonymisation…

threat09 Oct 03:43Zsingle-source · national CERTOpen finding →
NOTABLECVE-2026-107406NATOA2

CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)

Citrix's bulletin CTX697191 describes CVE-2026-107406 as a memory overflow (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway that leads to remote code execution or denial of service; the CVSS 4.0 vector is network, high attack complexity, no privileges, no user interaction, base score 9.5, and Citrix rates the bulletin Critical (Citrix, 2026-10-08). The precondition is a SAML configuration: the appliance must be a SAML service provider or a SAML identity provider (Citrix, 2026-10-08). An appliance configured as a service provider is listed as affected before 14.1-73.37 and 13.1-64.23 (ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.279), and the identity-provider case reaches further: 14.1-73.37 through 14.1-73.41, 13.1-64.23 through 13.1-64.28 and the matching FIPS and NDcPP builds through 14.1-73.41 FIPS and 13.1-37.282 are affected "only when configured as a SAML IdP" (Citrix, 2026-10-08). Those are the builds that Citrix's earlier bulletin CTX697174 named as the fix for CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03), so an identity-provider appliance that followed that guidance is exposed again.

Citrix urges customers to install 14.1-73.46 and later, 13.1-64.29 and later of 13.1, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later (Citrix, 2026-10-08). Secure Private Access Hybrid deployments that use NetScaler instances are also affected, while Citrix upgrades its own cloud services and managed Adaptive Authentication (Citrix, 2026-10-08). The bulletin states no exploitation status, publishes no workaround and gives no indicators of compromise; Citrix's blog of the same day says that as of the bulletin's publication it is not aware of any unmitigated exploits (Citrix, 2026-10-08), and no independent report of exploitation had surfaced as of 2026-10-09. ASD's ACSC added the flaw to its Citrix alert on 2026-10-09, saying the previous patches are insufficient for it and urging the latest patches (ASD's ACSC, 2026-10-09).

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP

Applicable only when configured as a SAML IdP

Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases

Citrix is not aware of any unmitigated exploits of this vulnerability.

Citrix (Cloud Software Group) 2026-10-08

Builds on: Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not… · Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days and…

vulnerability09 Oct 03:42Zsingle-sourceOpen finding →

03Research, reports & policy1 item

NOTABLENATOB2

Cisco Talos: malware now embeds natural-language instructions aimed at LLM triage pipelines, from a copied comment to template-sprayed prompts across four families, and a Russia-aligned group uses it too

Talos, which tracks AI-integrated malware in its CAIRN toolkit, calls the class "AI-analysis evasion": malware that embeds natural-language instructions to influence automated analysis, aimed at the layer above packers and anti-debug checks, the pipeline that extracts text from a sample and submits it to a language model for triage, classification or reverse-engineering help (Cisco Talos, 2026-10-08). It traces four families and 84 samples collected from January 2025 to July 2026: a PowerShell reverse shell (FRUITSHELL) carrying a two-line comment that says there is no need to analyze the file, a comment later reused verbatim in nine further scripts from at least four actors, among them a script set that adds an AMSI bypass and runtime compilation (Cisco Talos, 2026-10-08). PLOTSAFE generates the sentence from a template and keeps it alive in Go builds with a dummy function that references the strings; HOLLOWCLAD repeats one refusal instruction across seven LLM chat-template formats so one copy may match the scanner's own template, and adds fake honeypot and licence warnings; MANTLEMAZE claims invented government contracts and certifications (Cisco Talos, 2026-10-08).

ESET found the technique in the hands of a named group: the Russia-aligned UAC-0099 put a decoy request for guidance on building a nuclear weapon into the comment of a VBScript, aiming to trip the safety guardrails of an LLM-powered code scanner so it stops before the malicious code that downloads the MATCHBOIL loader (ESET, 2026-09-10). Talos tested the strings against five local models, 135 matched pairs per string: its headline figure is that the best techniques steered the outcome in the attacker's favour in about 35% of runs, a net rate (pairs shifted toward benign minus pairs shifted toward malicious, over all pairs), while the cheapest technique, a direct instruction to ignore the sample, worked almost universally and the more complex ones had little effect or backfired by making models more suspicious; Talos calls the overall impact a mixed bag (Cisco Talos, 2026-10-08). It says core conventional detection is unaffected (Cisco Talos, 2026-10-08).

Triage: Talos' discriminator is that legitimate software has no reason to embed instructions telling an analyzer to refuse analysis, invoke copyright law or claim government contracts (Cisco Talos, 2026-10-08).

malware that embeds natural-language instructions to influence automated analysis

Legitimate software has no reason to embed instructions telling an analyzer to refuse analysis, invoke copyright law, or claim government contracts.

Cisco Talos 2026-10-08

no single LLM engine should have the sole authority to decide that a piece of code is safe

ESET 2026-09-10

Builds on: macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst

research09 Oct 03:44Zmulti-sourceOpen finding →
Sources: Cisco Talos · ESET

04Updates to prior coverage3 items

NOTABLEupdatedNATOB2

TraderTraitor (Jade Sleet) backdoors resurface on a non-cryptocurrency IT-services firm in a campaign that delivers malware through weaponized Terraform provider lockfiles, resolving C2 through a Nostr-relay dead drop

First published 2026-09-21 · open finding →

Updaterun 2026-10-09T0255Z-intelsummarytechniquesentitiesaffected_productssourcesevidenceverificationsourcing_notebody

Zscaler ThreatLabz (2026-10-08) independently reports a July 2026 trojanized Terraform provider binary that executes at plugin load and delivers FLATROOF and ROOFDECK on macOS, Linux and Windows, with Telegram, GitHub and webhook command channels and a signed Pastebin dead drop alongside the Nostr fallback; the Terraform delivery path now has a second form, and the malware family a second publisher.

Zscaler ThreatLabz reports a July 2026 campaign that it suspects is TraderTraitor, citing substantial overlap in tactics and targeting but no code, infrastructure or cryptographic links sufficient for attribution with high confidence, in which a Go-built Terraform provider that poses as an AWS provider executes malicious code the moment Terraform loads the plugin: it writes a run-once marker in the temporary directory, downloads a Bash loader from a lookalike of a HashiCorp domain, starts it through a detached sh -c child and keeps behaving like a normal provider (Zscaler ThreatLabz, 2026-10-08). The loader runs on macOS, Linux and Windows with a Unix-like shell, picks a payload by operating system and CPU architecture and recovers an encrypted executable appended after a marker in a file named like a web font; on macOS it removes the quarantine attribute and applies an ad-hoc signature (Zscaler ThreatLabz, 2026-10-08). The delivered FLATROOF is a Rust backdoor with Telegram Bot API, GitHub-polling and HTTP-webhook command channels, persistence as a service on Linux, a zlogout entry on macOS and a registry entry on Windows, and Python stealers for browser data, cookies, keychain or Credential Manager entries, shell history and wallet-extension data; it drops ROOFDECK, which finds its server through a local configuration, then an RSA-signed Pastebin dead drop, with Nostr profile metadata only as the fallback, so its order of resolvers differs from the Nostr-first behaviour SentinelLabs describes above (Zscaler ThreatLabz, 2026-10-08). Zscaler does not know how the provider reached the victim, and notes that SentinelLabs independently reported related activity with weaponized Terraform projects (Zscaler ThreatLabz, 2026-10-08).

The telemetry that follows from the provider path is the Terraform provider plugin process making an HTTPS download from a host that is not the Terraform registry, writing a script to the temporary directory and starting it through sh -c; Zscaler advises restricting untrusted Terraform providers, verifying provider checksums and monitoring unexpected process activity (Zscaler ThreatLabz, 2026-10-08).

CRITICALCVE-2026-88771 +7exploitedupdatedNATOA1

CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)

First published 2026-09-28 · open finding →

Improvementrun 2026-10-09T0255Z-intelsummaryimmediate_actionactionssourcesbody

The pointers to the SAML builds now carry the 2026-10-08 bulletin CTX697191: identity-provider appliances need 14.1-73.46 or 13.1-64.29 (or the FIPS builds) after the 14.1-73.41 and 13.1-64.28 builds, which Citrix lists as affected by CVE-2026-107406.

The pointers above to the 14.1-73.41 and 13.1-64.28 builds for SAML-configured appliances are not the end of the upgrade path for identity providers: Citrix's bulletin CTX697191 of 2026-10-08 lists those builds as affected by CVE-2026-107406 when the appliance is a SAML identity provider, and names 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1.37.283 and later as fixed (Citrix, 2026-10-08).

HIGHCVE-2026-88779exploitedupdatedNATOA2

CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)

First published 2026-10-04 · open finding →

Updaterun 2026-10-09T0255Z-intelsummaryactionsreferencessourcesevidencebody

Citrix's bulletin CTX697191 (2026-10-08) discloses CVE-2026-107406, a further SAML memory overflow rated 9.5 that can lead to code execution, and lists the 14.1-73.41 and 13.1-64.28 builds that fix this flaw as affected when the appliance is a SAML identity provider; those appliances now need 14.1-73.46, 13.1-64.29 or the FIPS builds.

Citrix published bulletin CTX697191 on 2026-10-08 for CVE-2026-107406, a memory overflow in customer-managed NetScaler ADC and Gateway that leads to remote code execution or denial of service (CVSS 4.0 9.5) and applies to the same SAML configurations (Citrix, 2026-10-08). For an appliance configured as a SAML identity provider the affected builds run through 14.1-73.41, 13.1-64.28 and the FIPS and NDcPP equivalents (Citrix, 2026-10-08), and those are the builds named above as the fix for CVE-2026-88779 (Citrix, 2026-10-03); the fixed builds for the new flaw are 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1.37.283 and later (Citrix, 2026-10-08). An appliance that is only a SAML service provider is listed as affected only before 14.1-73.37 and 13.1-64.23, so the 14.1-73.41 and 13.1-64.28 builds remain enough for it (Citrix, 2026-10-08). Citrix's blog of the same day says that as of the bulletin's publication it is not aware of any unmitigated exploits of the new flaw (Citrix, 2026-10-08).

05Action items8 items

Verification & coverage notes1 run

2026-10-09T0255Z-intel · Sonnet 5.5 · window 25 h · 5 entries published

Verification & coverage notes

  • Window: 25 h (gap 22.9 h to 2026-10-08T0404Z-intel), a standard window. Five new entries and three changelog records (two update, one improvement). No deep dive: no candidate cleared the Phase 3 bar (exploitation with constituency exposure, or substantive analysis of extreme relevance).
  • KEV sweep (work/2026-10-09T0255Z-intel/kev-window.txt): five additions dated 2026-10-08, all NOT COVERED at the start of the run (ProFTPD CVE-2015-3306, ISC BIND CVE-2015-5477, Apache Struts CVE-2016-3081, ONLYOFFICE Docs CVE-2021-3199, Strapi CVE-2023-22894). All five are listed as successfully exploited in joint advisory AA26-281A (Appendix B), which is the "what changed"; each is carried in the 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft entry's cves[] as exploited and cisa-kev, together with the advisory's three older listed CVEs. No KEV addition dated 2026-10-09 existed at 03:30 UTC (catalog 2026.10.08). The ransomware-flag cross-check printed no row.
  • Backlog (state/coverage_backlog.md, six open rows, all re-gated on today's facts, all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (S1: none in KEV catalog 2026.10.08, no exploitation report or PoC; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (S1: CISA now says "<7.24 / update to 7.24 or later", MikroTik's changelogs still do not name the CVE, no KEV; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (S1: three further unauthenticated 9.8 Guardium CVEs published 2026-10-08, still no KEV or IBM exploitation statement, dated note appended; expiry 2026-10-14); SafePay ARA-Region Lyss-Limpachtal and Payload Netech (S4: no victim statement or press report; no note appended, nothing changed; expiry 2026-10-14); Beyond Gravity (S2: neither BACS, the company nor any report names a vector, an actor or the data affected; nothing changed; expiry 2026-10-20).
  • Updates: NetScaler CVE-2026-88779 (update: Citrix bulletin CTX697191 lists the .41 and .28 builds that fix it as affected by CVE-2026-107406 on SAML identity-provider appliances; summary, actions, references, sources and the takeaway moved; the entry keeps its own SAML upgrade task and points identity providers to the new builds); NetScaler CVE-2026-88771 (improvement: pointers to the SAML builds now carry the later flaw; no float); TraderTraitor Terraform entry (update: Zscaler ThreatLabz independently describes a trojanized provider binary that executes at plugin load and delivers FLATROOF and ROOFDECK on macOS, Linux and Windows; a second delivery form and a second publisher).
  • New entries: Publica and PK Softech (routine, trimmed to the incident floor after verifier iteration 1; PD-11 (c): confirmed supplier intrusion and data outflow touching the staff of the federal administration and the ETH domain, Federal Prosecutor's Office investigating, the strongest home-region item of the window, but no vector, actor or behaviour is public; its two actions and the Defender takeaway carry the decision; mapped to T1199 as the closest available id, which describes use of a trusted third party that no source says the attackers made against Publica), Citrix CVE-2026-107406 (notable after iteration 1: pre-authentication code-execution-capable memory overflow on an internet-facing SAML gateway that reaches the builds Citrix named as the fix five days earlier, but unexploited per Citrix's own blog, AC:H and a SAML precondition, so the high disqualifiers apply), AA26-281A (notable; PD-11 (c) and (d): a joint advisory on a China-linked enabler whose actors spray Exchange and Microsoft 365 and steal mail from government, law-enforcement and healthcare targets; no Swiss victim named), Talos AI-analysis evasion (notable; PD-11 (d): a detection surface and a pipeline-hardening rule for SOCs that use LLM triage; Talos itself calls the effect mixed), ReliaQuest agent-driven intrusion (notable; PD-11 (d): detection-grade mechanics on an unauthenticated job-submission feature on Tomcat; the agent-driven reading is ReliaQuest's assessment).
  • Single-source: Citrix CVE-2026-107406 rests on the vendor bulletin and Citrix's own blog (single-source, A2; no CERT or outlet had covered it when composed, and ASD's ACSC has since restated the disclosure without adding an observation); ReliaQuest rests on ReliaQuest alone (single-source, medium confidence, lookback item: published 2026-10-07 and first coverage from a rotational record); AA26-281A is single-source-national-cert because the advisory, the Justice Department release and the NCSC UK page all rest on the FBI's investigations.
  • Dedup: the AA26-281A entry references 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown (an earlier PRC enabler takedown; no CVE overlap). The ReliaQuest entry deliberately does not key tool:cairn-exploitation-engine: that record is Gambit's Cairn and neither source links the two projects that share the name.
  • borderline-drop: Cisco 2026-10-07 batch (35 CVEs; NX-API, NGOAM and MPLS OAM RCE flaws are feature-gated, License On-Prem is a management server, none exploited, no KEV, regular cycle under PD-11 (b)); HPE ClearPass and AOS-S HPESBNW05156 and -05158 (unauthenticated 9.8 flaws on management planes, no exploit code, regular cycle); IBM Verify Access, DataPower and Guardium bulletins of 2026-09-18 to 2026-10-08 (unauthenticated 9.8 flaws, no exploitation statement, no constituency deployment shown); Splunk Enterprise SVD-2026-1001 and -1002 (CVE-2026-76268 needs reach to the Patroni REST API of a search-head-cluster member, 10.4 and 10.2 only, internal); ILIAS 9.24, 10.12 and 11.5 (RCE paths need authentication, no CVE ids, no exploitation; published 19 h before the window and dropped by the previous fire).
  • borderline-drop: WatchGuard Fireware 2026-09-29 builds (every pre-auth item needs attacker control of a VPN peer, adjacency or prior write access), Veeam Backup and Replication 12.3.2 P4 (needs the Backup Viewer role), Exchange out-of-band CVE-2026-96940 (needs a click, not exploited, dated 2026-10-02), Microsoft cloud-service CVEs of 2026-10-08 (no customer action), Android bulletin 2026-10-01, OpenSSH 10.6, Ollama CVE-2026-103663 (CERT Polska, no exploitation, ambiguous range), HPE IMC CVE-2026-79842, Hazelcast, fast-jwt, SGLang, Jackrabbit, Movable Type and Tenable Identity Exposure (no exploitation signal or constituency nexus).
  • borderline-drop: ChainDrop npm worm reaches the tensorlake package (a new, low-footprint package in a covered campaign; the existing entry already carries the dead-man-switch and rotation guidance), Talos UAT-11985 (Taiwan research bodies, a Google-themed relay kit, technique class only), .gh, .sl and .as registry hijacks (no Swiss nexus, previously dropped), DNSSEC root KSK rollover of 2026-10-11 (an operational deadline and not threat activity; ICANN reports more than 95 percent of reporting resolvers ready, no Swiss authority notice; returned by S2 and S3, dropped as a considered borderline), KrebsOnSecurity on the ShinyHunters suspect in Jordan (the Jordan detention is already carried in the FBI entry), CrowdStrike ARTEX (South Korean banks, infrastructure and prompt history only), EDPB publication of the Miljodata and E.E.T.A.A. decisions (GDPR does not bind Swiss bodies; decisions dated 22 September and 28 July), Fox-IT Cobalt Strike Beacon corpus (research dataset, no Swiss nexus), Kiteworks NCSC-NL bundle of 61 CVE ids (improvement-only: no exploitation or fix change, most need administrator authentication).
  • borderline-drop: IDC Frontier cloud ransomware in Japan (no vector or actor), ASOS push-notification extortion (UK retailer, vector now stated but no public-sector nexus), T-Systems and SafePay (a victim statement now exists: a small test system, nothing sensitive; below the incident floor), Arizona courts, France Travail sale claim, Saint-Pierre-des-Corps, AP-HP and Dedalus, Eau Coeur d'Essonne and other claim-only French items, the Polish FELG breach (outside window, nexus or both). Claim-only watch for the next fire: Leadec and the University of Rostock, still no notice or press.
  • Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 (the profile configures none).
  • Coverage gaps: ilias-vendor-security-blog (captcha; versions read from BSI), citrix-community-blog-permalinks (403 on the direct transports, read through the reader and cited), watchguard-psirt (one per-CVE page 403), cisa.gov AA26-281A PDF (403, read through the FBI IC3 mirror), cyberinsider (undated listing), ssd-disclosure not in this slice.
  • Source rotation: the previous two fires' attempts (111 records) were excluded from the S1, S2 and S3 slices as a belt-and-braces measure and the cursor-ranked pool supplied the slices; S4's pool of 19 breach sources was allocated oldest-cursor first without that exclusion because every breach source had been attempted by the previous two fires. S1, S2, S3 and S4 returned complete ledgers (25, 18, 14 and 12 rows); no continuation was needed. Promotions: cccs-alerts and sonicwall-psirt (promotion_due). Candidates added: splunk-advisories and hpe-networking-psirt (first-party vendor PSIRT tables).
  • For the audit: S3 reports natto-thoughts (Natto Team: China commercial-hacking analysis) as a candidate, not added this fire; CERT-UA article pages are an SPA (feed https://cert.gov.ua/api/articles/rss works); the bsi-rss cap is flooded by bulk [UPDATE] refreshes; the Kiteworks entry carries 8 of NCSC-NL's 61 CVE ids (nine rated 9.1 to 9.8, none exploited, most administrator-authenticated), an improvement-only enrichment no reader decision turns on.