<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · Energy</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-energy.xml" rel="self" type="application/rss+xml"/><description>Items affecting energy operators, utilities, grid infrastructure.</description><language>en</language><lastBuildDate>Sat, 18 Jul 2026 04:35:00 +0000</lastBuildDate><item><title>Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC</title><link>https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>auth-bypass</category><category>pre-auth</category><category>no-patch</category><category>cloud</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-47865</category><category>CVE-2026-47867</category><category>CVE-2026-47871</category><category>CVE-2026-47868</category><category>CVE-2026-47866</category><category>CVE-2026-47869</category><category>CVE-2026-47870</category><description><![CDATA[<p>Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an unauthenticated remote attacker reach the Avi Controller control plane by bypassing authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and TLS termination for whatever sits behind the load balancer.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass" data-tags="vulnerabilities auth-bypass pre-auth no-patch cloud" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47865/">CVE-2026-47865 +6</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="vmware-avi-load-balancer-cve-2026-47865-auth-bypass"><a href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround</a></h3><p>Broadcom&#39;s VMSA-2026-0005 (2026-07-14, last updated 2026-07-15) patches seven vulnerabilities in VMware Avi Load Balancer — the load-balancing/application-delivery product formerly sold as NSX Advanced Load Balancer and widely deployed in enterprise and government data-centre fabric across Europe. The load-bearing flaw, <strong>CVE-2026-47865</strong> (CVSS 9.8), is an authentication bypass on the Avi Controller: &quot;a malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism&quot; — no credentials, no user interaction (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>). The advisory ships six companion flaws that require a prior foothold: two high-privilege remote code-execution bugs (CVE-2026-47867, CVE-2026-47869, both CVSS 8.7, PR:H), a low-privilege authenticated directory traversal (CVE-2026-47871, CVSS 8.8), an authorization bypass (CVE-2026-47866, CVSS 8.3), a local-to-root privilege escalation (CVE-2026-47868, CVSS 7.8) and a further privilege escalation (CVE-2026-47870, CVSS 7.1). Broadcom states no workarounds exist (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>); the German trade press summarised it as attackers being able to bypass authentication and authorization (<a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security, 2026-07-17</a>).</p>
<p>No in-the-wild exploitation has been reported, but two facts raise this above the routine patch cycle: the reporter is the NATO NCSC (a direct constituency-provenance signal), and there is no mitigation short of upgrading. Because the Avi Controller is the management and orchestration plane for the load-balancing fabric, an unauthenticated bypass there is a direct path to reconfiguring traffic routing and TLS termination for every service behind the load balancer — an interception and traffic-manipulation position, not merely appliance compromise.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Upgrade the Avi Controller to a fixed release — 32.1.2 (recommended), 31.2.2-2p3 or 30.2.7; the 22.1.x branch must move to at least 30.2.7. Because no workaround exists, until the upgrade lands restrict Controller management-plane reachability to trusted management VLANs/jump hosts and treat any exposure of the Avi Controller to broad or untrusted network segments as the finding in its own right. Detection concept, telemetry-class first: Avi Controller admin/API authentication logs showing control-plane session establishment or API calls with no preceding successful login event, particularly from source ranges outside the management network.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.</p><figcaption class="entry-cite__attr"><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> · <a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security</a></div></article>]]></content:encoded></item><item><title>Volexity attributes the SonicWall SMA 1000 zero-day exploitation to UTA0533 and details the SSRF-to-root chain, on-appliance implants and LDAP credential theft</title><link>https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>Volexity has reconstructed the intrusion behind the actively-exploited SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection), attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22. The chain: an unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, then the actor injects a proxy (Suo5) and a Java webshell (ORANGETAIL) into the appliance&#39;s legitimate workplace process, persists via an init script, captures cleartext LDAP credentials with tcpdump, and pivots into the internal network. Stolen credentials survive patching — the hotfix alone does not remediate a pre-patch compromise.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce auth-bypass" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sonicwall-sma1000-uta0533-exploitation-kill-chain"><a href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533&#39;s full appliance-to-network kill chain</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a> <span class="mono muted">(2026-07-14)</span></p><p>The original entry recorded SonicWall&#39;s confirmation that CVE-2026-15409/-15410 were being exploited as zero-days and directed emergency patching. Volexity has now published the reconstructed intrusion, attributed it to an actor it tracks as <strong>UTA0533</strong>, and shown that patching alone is insufficient — the delta below is the full kill chain, the on-appliance implants, and the compromise-response guidance the terse advisory did not carry (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>).</p>
<p>Volexity was engaged after suspect authentication and lateral movement were seen originating <em>from</em> SonicWall SMA 1000 appliances (models 6210/7210/8200v); the earliest sign of compromise was 2026-06-22, weeks before SonicWall&#39;s 2026-07-14 disclosure (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). SonicWall&#39;s PSIRT confirms it &quot;has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory&quot; (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall SNWLID-2026-0008, 2026-07-14</a>), and Rapid7&#39;s MDR team independently found the same two zero-days under attack (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>).</p>
<p><strong>Initial access (T1190, T1133).</strong> CVE-2026-15409 is a pre-authentication server-side request forgery in the SMA 1000 <code>/wsproxy</code> endpoint. A crafted WebSocket-upgrade request establishes a tunnel from the unauthenticated external attacker straight to services that are supposed to be reachable only on the appliance&#39;s own loopback — Volexity confirms &quot;no valid SMA session cookie was required during this process&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Through the tunnel the actor reached the appliance&#39;s bundled CouchDB/Erlang services and a localhost-only control service; the shipped CouchDB carries hardcoded <code>admin:admin</code> credentials, and the control service&#39;s authentication password is derivable from a device UUID, so the SSRF turns both into part of the external attack surface.</p>
<p><strong>Privilege escalation (T1068).</strong> CVE-2026-15410 is a path traversal in the hotfix-rollback workflow: the <code>sysCtrl.execRemoveHotfix</code> operation builds a rollback path from caller-controlled input and hands it to <code>/usr/local/bin/remove_hotfix</code>, which then executes it. A rollback name containing directory-traversal sequences resolves outside the intended rollback directory and runs an attacker-staged script as root.</p>
<p><strong>Persistence and implants (T1055, T1505.003, T1090.003, T1037.004).</strong> With root, UTA0533 dropped a setuid helper and a Python loader Volexity calls <strong>KNUCKLEBALL</strong>, which injects two JAR archives into the appliance&#39;s legitimate <code>workplace</code> process: the open-source <strong>Suo5</strong> HTTP proxy-forwarder and a Behinder-like Java webshell Volexity calls <strong>ORANGETAIL</strong>. Persistence was established by adding a call to the loader inside the appliance&#39;s <code>workplace</code> init script, and the NGINX Unit configuration was rewritten to add routes that proxy attacker-chosen (arbitrary) request paths to the injected webshell and proxy — so hunting for a fixed URL is the wrong shape; the behaviour is unexpected route entries in the appliance&#39;s own reverse-proxy configuration.</p>
<p><strong>Credential access and lateral movement (T1040, T1059).</strong> The actor ran <code>tcpdump</code> from a script staged in the appliance&#39;s temp directory to capture unencrypted LDAP traffic (TCP 389), harvesting directory credentials off the wire (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Rapid7&#39;s engagement observed the actor then &quot;quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network&quot; (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>). How far that onward movement reached differs across the two IR firms&#39; cases: Volexity concludes that in the appliances <em>it</em> investigated, &quot;available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>) — so treat a foothold on the appliance as a demonstrated launch point for internal movement, but not evidence that deep lateral movement always succeeds.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Patching to the hotfix (12.4.3-03453 / 12.5.0-02835) closes the two CVEs but does nothing about credentials already captured or implants already planted, so any appliance that was exposed and unpatched must be handled as an assume-compromise: SonicWall and both IR firms recommend re-imaging on any indicator, and resetting all account passwords and TOTP seeds. Detection concepts, telemetry-class first: in the appliance&#39;s web/access logs, unauthenticated <code>/wsproxy</code> WebSocket-upgrade requests that return a 101 protocol-upgrade status with no valid session cookie and target an internal (loopback-facing) service port; in the control-service log, hotfix-rollback operations carrying path-traversal sequences in the rollback name; on the network, LDAP binds and other authentication originating <em>from</em> the SMA appliance&#39;s own address, and any egress or lateral connection from an appliance that should only ever terminate inbound VPN sessions. <strong>Triage:</strong> an SMA 1000 legitimately proxies authenticated user sessions inbound — the discriminators are a <code>/wsproxy</code> upgrade with no session cookie reaching a loopback service, and the appliance itself <em>initiating</em> authentication or connections into the internal network, which a remote-access gateway has no benign reason to do.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">No valid SMA session cookie was required during this process.</p><figcaption class="entry-cite__attr"><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network</p><figcaption class="entry-cite__attr"><a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>threat</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> · <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> · <a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a></div></article>]]></content:encoded></item><item><title>Unit 42 publishes a full RUGGEDCOM ROX II exploit chain — file disclosure, feature-key command injection, and task-scheduler persistence to root</title><link>https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>rce</category><category>priv-esc</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2025-40948</category><category>CVE-2025-40947</category><category>CVE-2025-40949</category><description><![CDATA[<p>Palo Alto Unit 42 published (2026-07-17) a three-stage exploit chain against Siemens RUGGEDCOM ROX II operational-technology switches: CVE-2025-40948 (CVSS 6.8) misuses a root-privileged xz invocation to read any file on the device, CVE-2025-40947 (CVSS 7.5) is command injection in the feature-key signature-verification path, and CVE-2025-40949 (CVSS 9.1) lets an authenticated attacker inject commands into the web-management task scheduler for persistent, reboot-surviving root code execution. Siemens patched all three in firmware V2.17.1 (advisories SSA-973901/-078743/-081142); no in-the-wild exploitation is reported. ROX II sits as a network-security/routing boundary inside rail, utility, water and manufacturing networks across Europe.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain" data-tags="vulnerabilities ot-ics rce priv-esc patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-40948/">CVE-2025-40948 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="siemens-ruggedcom-rox-ii-unit42-three-cve-chain"><a href="https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/">CVE-2025-40948/-40947/-40949 — Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root</a></h3><p>Unit 42 published a chained analysis (2026-07-17) of three vulnerabilities in Siemens RUGGEDCOM ROX II, the ruggedised OT switch/router family Siemens positions as a network-security boundary inside industrial networks — rail, utilities, water and manufacturing, including Swiss and European critical infrastructure (<a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-17</a>). The chain moves from information disclosure to persistent root. Stage one, <strong>CVE-2025-40948</strong> (CVSS 6.8), abuses a root-privileged daemon that invokes the <code>xz</code> utility with attacker-supplied parameters: supplying <code>-f</code>, <code>-c</code> and <code>-d</code> together turns <code>xz</code> into a <code>cat</code> equivalent, letting an attacker read any file on the device — configuration, password hashes, private keys (<a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-17</a>). Stage two, <strong>CVE-2025-40947</strong> (CVSS 7.5), is command injection in the feature-key signature-verification routine: the parsed signature string is inserted unsanitised into a <code>gpgv</code> command executed via <code>system()</code> as root, so a crafted feature-key file whose signature field carries a command-injection payload runs attacker code as root (typically after the attacker uploads a script through the web UI&#39;s normal feature-key upload). Stage three, <strong>CVE-2025-40949</strong> (CVSS 9.1), is command injection in the web-management task scheduler — Siemens describes it as an &quot;authenticated remote attacker&quot; injecting commands that &quot;execute arbitrary commands with root privileges&quot; (<a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT SSA-081142, 2026-05-12</a>) — writing malicious entries into the scheduler configuration for persistent, reboot-surviving root execution.</p>
<p>Siemens patched all three in firmware <strong>V2.17.1</strong> across the ROX II family (MX5000/MX5000RE, the RX1400–RX1536 line, RX5000) and published advisories SSA-973901, SSA-078743 and SSA-081142; no in-the-wild exploitation is reported. The transferable lesson beyond this device family, per Unit 42, is the anti-pattern: a device invoking a general-purpose CLI utility (here <code>xz</code>) as root inside its own validation logic is a recurring OT/embedded-appliance weakness worth hunting for elsewhere.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Schedule the V2.17.1 firmware update on ROX II estates; where an OT change window delays it, keep the ROX II web-management and feature-key-upload interfaces isolated from untrusted segments as the interim control. Detection concept, telemetry-class first: on devices exposing shell/audit telemetry, hunt for anomalous <code>xz</code> invocations combining the <code>-f</code>/<code>-c</code>/<code>-d</code> flags, feature-key upload activity outside maintenance windows, and unexpected entries appearing in the task-scheduler configuration (arbitrary interpreters such as <code>python</code>/<code>bash</code> or direct system calls in place of legitimate task functions). <strong>Triage:</strong> legitimate ROX II administration uses the scheduler for periodic maintenance tasks — the discriminator is a scheduled task whose command field invokes a general script interpreter or shell rather than the device&#39;s own task functions, especially one added outside a change window.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks.</p><figcaption class="entry-cite__attr"><a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Ruggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.</p><figcaption class="entry-cite__attr"><a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-081142)</a> <span class="entry-cite__date mono">2026-05-12</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-081142)</a></div></article>]]></content:encoded></item><item><title>HelloNet chains trusted-updater DLL sideloading with raw AFD-IOCTL interception to hide network C2 from user-mode EDR</title><link>https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/</guid><pubDate>Fri, 17 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-17T04:35:00Z</dc:date><category>espionage</category><category>supply-chain</category><category>russia-cis</category><description><![CDATA[<p>Kaspersky GReAT documented &quot;HelloNet,&quot; an active APT campaign that persists by sideloading a malicious wtsapi32.dll into the auto-launched update component of the ViPNet secure-networking suite, then injects a proxy module (HelloProxy) into svchost.exe that uses Microsoft Detours to hook NtDeviceIoControlFile and intercept the raw Ancillary Function Driver IOCTLs (AFD_RECV, AFD_GET_TDI_HANDLES) — which, per Kaspersky, hinders user-mode network-filtering security tools. Direct victimology is Russian government and critical-infrastructure orgs (attributed with low confidence to an unknown Chinese-speaking group); the transferable signal for Swiss/EU defenders is the technique class — abuse of a trusted client&#39;s update mechanism plus AFD-IOCTL interception to degrade EDR network visibility.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl" data-tags="espionage supply-chain" data-regions="russia-cis" data-kind="research" data-priority="notable" data-discovered="2026-07-17T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl"><a href="https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/">Kaspersky: the HelloNet campaign blinds user-mode security tools by hooking raw AFD IOCTLs, persisting via DLL-sideload into a secure-network product&#39;s own auto-updater</a></h3><p>Kaspersky&#39;s GReAT team detailed &quot;HelloNet,&quot; an APT campaign (active since at least May 2026) that abuses the update mechanism of ViPNet — a Russian GOST-certified secure-networking suite — to persist inside targeted Russian government, energy, transport, education, logistics and industrial organizations (<a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-16</a>). The attackers drop a malicious <code>wtsapi32.dll</code> into the ViPNet update directory that the OS-start-launched updater <code>itcsrvup64.exe</code> sideloads. That loader (&quot;HelloInjector&quot;) injects a second stage (&quot;HelloProxy&quot;) into <code>svchost.exe</code> — but only after verifying the target&#39;s name is <code>svchost.exe</code> and its command line carries <code>netsvcs</code>. HelloProxy&#39;s distinguishing move is defense evasion at the socket layer: it uses the Microsoft Detours library to hook <code>NtDeviceIoControlFile</code>, <code>closesocket</code> and <code>shutdown</code>, intercepting the raw AFD IOCTL codes <code>AFD_RECV</code> (0x12017) and <code>AFD_GET_TDI_HANDLES</code> (0x12037) so that, in Kaspersky&#39;s words, it can &quot;hinder security solutions operating in user mode for filtering network connections.&quot; It then acts as a traffic proxy or in-memory loader for further modules — recovered examples include &quot;HelloExecutor&quot; (shell-command execution) and &quot;HelloCleaner&quot; (deletes ViPNet log files to hide activity) — and on one host the operators opened an SSH reverse tunnel using a legitimate Plink binary renamed <code>frontpage.exe</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for this constituency the ViPNet-specific vector is largely irrelevant, but two technique classes generalize directly. First, any third-party secure-network/VPN client with an auto-launched updater in a writable directory is a DLL-sideload persistence surface — treat vendor-updater directories as monitored locations where an unsigned or unexpected DLL write is high-signal. Second, AFD-IOCTL interception is a portable primitive for blinding user-mode network-filtering EDR; a Detours-style hook on <code>NtDeviceIoControlFile</code> in <code>svchost.exe</code> is worth surfacing regardless of the product being abused. <strong>Triage:</strong> a <code>wtsapi32.dll</code> written into a vendor&#39;s update directory has no legitimate reason to be there (the DLL belongs in <code>System32</code>); the vendor&#39;s own updater loading a DLL whose signature does not carry the vendor&#39;s publisher name, and a Plink/PuTTY binary identified by PE metadata rather than filename opening a <code>-R port:addr:port</code> tunnel, are the discriminators Kaspersky&#39;s hunt guidance keys on.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By placing the file in this directory, the attackers implement the DLL Sideloading technique — the ViPNet update system executable file itcsrvup64.exe, which is launched at OS startup, is susceptible to it.</p><p class="entry-cite__quote">These codes are used during socket operations — their interception allows the malware to hinder security solutions operating in user mode for filtering network connections.</p><p class="entry-cite__quote">At present, we link this campaign to the activities of an unknown Chinese-speaking APT group with a low degree of confidence.</p><figcaption class="entry-cite__attr"><a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>research</span><span>17 Jul 04:35Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a></div></article>]]></content:encoded></item><item><title>World Leaks leaks ~858k files from a Kudankulam nuclear-plant contractor breached at a third-party data-centre host — a lesson for energy-CI operators</title><link>https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/</guid><pubDate>Thu, 16 Jul 2026 04:42:00 +0000</pubDate><dc:date>2026-07-16T04:42:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>apac</category><description><![CDATA[<p>The data-theft-extortion group World Leaks (a Hunters International rebrand) posted roughly 858,000 files on its leak site attributed to Reliance Group, a contractor to India&#39;s Kudankulam Nuclear Power Plant; Reuters reviewed ~19,000 sensitive files (2016–2025) purporting to show blueprints, supplier and inspection records. Reliance confirmed a &quot;partial breach&quot; from a server hosted by third-party Indian data-centre provider Yotta; India&#39;s CERT-In is investigating and the leaked files are only claimed — not established — to be authentic. Out-of-nexus (India) but carried for its global critical-infrastructure significance and a transferable third-party-hosting lesson for European energy-CI operators.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach" data-tags="data-breach supply-chain" data-regions="apac" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="worldleaks-kudankulam-reliance-third-party-hosting-breach"><a href="https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/">World Leaks posts ~858,000 files tied to India&#39;s Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach</a></h3><p>The data-theft-extortion group <strong>World Leaks</strong> — the rebrand of Hunters International already tracked in this store — posted roughly <strong>858,000 files</strong> on its dark-web leak site attributed to Reliance Group, a contractor involved in India&#39;s Kudankulam Nuclear Power Plant (KNPP), the country&#39;s largest nuclear facility (<a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week / Reuters, 2026-07-15</a>). Reuters reviewed a subset of about 19,000 files dated 2016–2025 that purport to show facility blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies; the files are only claimed to originate from the plant and their authenticity is not established. Reliance Group confirmed to Reuters that a <strong>&quot;partial breach&quot;</strong> of its data occurred from a server hosted by <strong>Yotta</strong>, a third-party Indian data-centre provider, and that the government has been informed; India&#39;s CERT-In is investigating and a Nuclear Threat Initiative expert warned the exposure could pose a serious plant-safety risk.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the victim and jurisdiction are out of this constituency&#39;s nexus, but the structure is the recurring one — sensitive engineering, inspection and design documentation for a critical-infrastructure facility held on a subcontractor&#39;s externally hosted infrastructure, outside the operator&#39;s own security perimeter, and breached there rather than at the plant. For European energy-CI operators the transferable action is inventory: know which contractors and hosting providers hold facility design, inspection and supplier documentation, contractually bound them to breach notification and log access, and minimise how much of that documentation persists on third-party infrastructure at all. This is the same third-party-exposure pattern behind the Basel utility disclosure this window, at a far higher-consequence asset class.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">They admitted to Reuters that a &quot;partial breach&quot; of its data had taken place from a server hosted by Yotta, a third-party Indian data centre service provider, and that the government has been informed about the incident.</p><p class="entry-cite__quote">19,000 of these files appeared to be highly sensitive, the report added, noting that the documents were dated between 2016 and 2025, and reportedly featured blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies.</p><figcaption class="entry-cite__attr"><a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week (India), relaying Reuters</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:42Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week (India), relaying Reuters</a></div></article>]]></content:encoded></item><item><title>Swiss municipal energy/water/telecom utility IWB discloses a third-party-provider breach exposing ~40,000 customer meter records</title><link>https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</guid><pubDate>Thu, 16 Jul 2026 04:38:00 +0000</pubDate><dc:date>2026-07-16T04:38:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>switzerland</category><description><![CDATA[<p>Industrielle Werke Basel (IWB) — the canton-owned Basel utility supplying electricity, gas, water and telecom — disclosed on 2026-07-15 that an external service provider was compromised and roughly 40,000 customer records (names, addresses, meter numbers and installation characteristics) were exfiltrated. Email addresses, phone numbers, consumption data and payment details were not exposed, IWB&#39;s own systems and supply were unaffected, and the Basel-Stadt data protection officer assessed the misuse risk as low. No provider name, actor or initial-access vector has been disclosed.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records" data-tags="data-breach supply-chain" data-regions="switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="iwb-basel-third-party-provider-breach-40k-customer-records"><a href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Basel utility IWB: ~40,000 customer records exfiltrated in a breach of a third-party service provider</a></h3><p>Industrielle Werke Basel (IWB) — the canton-owned Basel multi-utility supplying electricity, gas, water, district heating and telecom/fibre — disclosed on 15 July 2026 that an external service provider it uses was compromised and roughly <strong>40,000 customer records</strong> were exfiltrated from the provider&#39;s environment (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The stolen data comprises customer names and addresses plus technical smart-meter attributes (meter serial numbers and installation characteristics); IWB states that email addresses, phone numbers, energy-consumption data and billing/payment data were <strong>not</strong> part of the exposure, so no consumption-pattern inference is possible from what was taken (<a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-15</a>). IWB&#39;s own IT and OT/grid systems were unaffected and energy/water supply continuity was not disrupted — the compromise is scoped to the provider&#39;s systems and the customer-data feed IWB shares with it (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The provider detected and notified IWB, which audited access, reviewed logs and pre-emptively restricted its data exchange with the affected provider; the Basel-Stadt cantonal data protection officer assessed the misuse risk as low (<a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch, 2026-07-15</a>). No provider name, threat-actor claim or initial-access vector has been disclosed, and no matching leak-site listing was found for Switzerland in-window.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is a textbook trusted-relationship exposure — a home-region critical-infrastructure operator&#39;s customer data reached attackers through a compromised external processor the utility&#39;s own SOC has no telemetry into. For any utility or public-sector body outsourcing metering/billing data, the load-bearing controls are contractual data-minimisation (share only the fields the processor needs), a right to breach notification and log access, and periodic review of what customer data actually sits outside the perimeter. The exposed name+address+meter-number combination is exactly the material for convincing pretext contact, so affected customers should be warned to treat unsolicited approaches referencing their address or meter number — especially demands for money or data under time pressure — with suspicion.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Bei einem Cyberangriff auf einen Dienstleister der Industriellen Werke Basel (IWB) haben Cyberkriminelle rund 40&#39;000 Datensätze von Kundinnen und Kunden des Energieversorgers entwendet.</p><p class="entry-cite__quote">Die IWB-Systeme blieben unversehrt, wie das Unternehmen mitteilt. Auch die Energieversorgung sei nicht beeinträchtigt gewesen.</p><figcaption class="entry-cite__attr"><a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch</a></div></article>]]></content:encoded></item><item><title>A three-year-old KNX Connection Authorization lockout flaw joins CISA KEV as actively exploited — the fix is procedural, not a patch</title><link>https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/</guid><pubDate>Thu, 16 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-16T04:36:00Z</dc:date><category>vulnerabilities</category><category>dos</category><category>actively-exploited</category><category>cisa-kev</category><category>ot-ics</category><category>no-patch</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>no-patch</category><category>mitigation-only</category><category>CVE-2023-4346</category><description><![CDATA[<p>CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on 2026-07-15, marking the KNX Connection Authorization Option-1 account-lockout flaw as known-exploited three years after disclosure. An attacker with network (or physical) access to a KNX installation can purge unprotected devices and set a BCU key, permanently locking legitimate operators out with no reset path; there is no software patch — the fix is procedural. Relevant to any Swiss/European critical-infrastructure or public-sector estate running KNX building automation (HVAC, lighting, access control, BMS).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev" data-tags="vulnerabilities dos actively-exploited cisa-kev ot-ics no-patch" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-16T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2023-4346/">CVE-2023-4346</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="cve-2023-4346-knx-building-automation-lockout-dos-kev"><a href="https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/">CVE-2023-4346 — KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)</a></h3><p>CISA added <strong>CVE-2023-4346</strong> to its Known Exploited Vulnerabilities catalog on 15 July 2026, alongside the Oracle E-Business Suite flaw, and updated the underlying ICS advisory to carry a <em>&quot;known public exploitation&quot;</em> note (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA ICSA-23-236-01, 2026-07-15</a>; <a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA KEV alert, 2026-07-15</a>). The flaw itself is three years old — reported by Felix Eberstaller of Limes Security and published in August 2023 — and had no prior KEV listing until this update. KNX is a widely deployed European building-automation bus protocol (KNX Association is headquartered in Belgium) used for HVAC, lighting, access control and BMS integration, so the exposure sits under any large public-sector or critical-infrastructure estate with smart-building controls.</p>
<p>The design flaw (CWE-645, overly restrictive account-lockout mechanism, CVSS 7.5, availability-only) is in KNX Connection Authorization Option 1: any device that has never had its BCU (Bus Coupling Unit) key set can be purged by an attacker with network access to the KNX installation, who then sets a new BCU key and permanently locks legitimate operators out — with no reset path short of the current password (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA ICSA-23-236-01, 2026-07-15</a>). An attacker with only physical access to the bus can do the same. KNX Association has issued no software fix in three years; the remediation is entirely procedural — set the BCU key during commissioning.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the exposure surface is the IP-KNX router/gateway that bridges the building bus onto an IT or internet-reachable network, so treat any such gateway as a priority segmentation target regardless of patch status. This is a configuration and behavioural signal, not a network signature: monitor KNX/ETS project-management logs and BCU-key-set events for unexpected changes, and confirm every finished project handed over to a building owner has its BCU key set. The KEV addition is the exploitation signal used here; the associated federal remediation deadline carries no operational weight for this audience.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Exploitable remotely/low attack complexity/known public exploitation</p><p class="entry-cite__quote">If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-23-236-01)</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>16 Jul 04:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-23-236-01)</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA</a></div></article>]]></content:encoded></item><item><title>CISA republishes four Rockwell/ABB OT advisories led by a CVSS 10.0 debug-port takeover on an energy/water EtherNet/IP adapter, fixed in firmware 3.011</title><link>https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/</guid><pubDate>Wed, 15 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-15T04:36:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>patch-available</category><category>info-disclosure</category><category>priv-esc</category><category>global</category><category>patch-available</category><category>CVE-2026-10577</category><category>CVE-2025-14771</category><category>CVE-2025-14772</category><category>CVE-2025-14773</category><category>CVE-2025-14774</category><description><![CDATA[<p>CISA published four ICS advisories on 2026-07-14 landing on the energy, water and critical-manufacturing sectors and on Swiss-headquartered ABB. The headline is CVE-2026-10577 in the Rockwell Automation 1715-AENTR EtherNet/IP Adapter (all versions ≤ 3.003, CVSS 10.0): a network-reachable debug port with no authentication lets an unauthenticated attacker read/delete files, stop tasks, modify memory and change I/O states — Rockwell fixes it in firmware 3.011, with network isolation as the interim control. ABB T-MAC Plus 4.0-24 (a fuel/chemical terminal-management system, fixed in 4.0-25) is subject to a four-CVE chain led by CVE-2025-14771 (CVSS 9.9, authenticated file disclosure); ABB also shipped a fix in Ability Edgenius for the previously-disclosed &quot;Copy Fail&quot; kernel flaw (CVE-2026-31431). No in-the-wild exploitation is reported for the newly-disclosed items.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot" data-tags="vulnerabilities ot-ics auth-bypass patch-available info-disclosure priv-esc" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-15T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-10577/">CVE-2026-10577 +4</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="cisa-ics-batch-rockwell-abb-energy-water-ot"><a href="https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/">CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)</a></h3><p>CISA published four Industrial Control Systems advisories on 2026-07-14, each a verbatim republication of a vendor PSIRT bulletin, that land squarely on this constituency&#39;s energy and water sectors and on a Swiss-headquartered vendor (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA, 2026-07-14</a>). The most severe is <strong>CVE-2026-10577</strong> in the <strong>Rockwell Automation 1715-AENTR EtherNet/IP Adapter</strong> (all versions ≤ 3.003), rated CVSS v3.1 10.0 for missing authentication on a critical function (CWE-306): a network-accessible debug port exposes intrusive CLI commands with no authentication, so an unauthenticated remote attacker can &quot;read or delete files, stop tasks, modify memory, and change I/O states&quot; on the device (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA / Rockwell PSIRT, 2026-07-14</a>). The advisory names the affected sectors as Energy, Water and Wastewater, and Critical Manufacturing; Rockwell fixes it in <strong>firmware version 3.011</strong> and CISA additionally recommends network isolation for devices that cannot be upgraded immediately (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA / Rockwell PSIRT SD1785, 2026-07-14</a>). No known public exploitation has been reported to CISA.</p>
<p>Separately, <strong>ABB T-MAC Plus 4.0-24</strong> (fixed in 4.0-25) — a Terminal Management System operating chemical/petroleum terminals, pipeline and refinery tankage, bulk plants and hydrogen terminals — is subject to four flaws responsibly disclosed by Angelo Catalani of Italy&#39;s national cybersecurity agency (ACN): <strong>CVE-2025-14771</strong> (CVSS 9.9, a low-privilege authenticated file disclosure via a crafted HTTP GET against the web application, CWE-552), <strong>CVE-2025-14772</strong> (CVSS 8.8, broken access control letting a low-privilege user perform administrative operations, CWE-639), <strong>CVE-2025-14773</strong> (CVSS 8.0, stored cross-site scripting) and <strong>CVE-2025-14774</strong> (CVSS 7.4, an adjacent-network denial of service of the Card Reader service caused by an unencrypted communication protocol) (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>). ABB states exploitation requires network or physical access to the terminal LAN rather than internet reachability, and that an update resolves the set. The same day, ABB shipped a fix in <strong>Ability Edgenius</strong> (fixed in 3.2.4.1) for the previously-disclosed <strong>CVE-2026-31431</strong> &quot;Copy Fail&quot; Linux-kernel <code>algif_aead</code> local root-escalation flaw — new here only in that a specific Swiss-vendor OT product is now named as an affected instance (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>) — and a low-severity (CVSS 4.4) DLL search-path fix (CVE-2025-13162) in 800xA for Advant Master / Control Builder A (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the Rockwell flaw is the one that changes work this week for OT operators — upgrade the adapter to firmware 3.011, and where an OT change window makes that non-immediate, treat network segmentation as the interim control; because the debug/CLI service is a distinct network service from the normal EtherNet/IP control protocol, the highest-signal telemetry is network-flow monitoring for any connection to that port from a host other than a known engineering workstation; no legitimate remote-management workflow should reach it. <strong>Triage:</strong> on the Rockwell adapter there is no authentication to correlate against, so any inbound session to the debug/CLI port from an unexpected source is itself the indicator; on ABB T-MAC Plus the abuses are authenticated-tier, so the hunt surface is the web-application access log — GET requests probing file paths outside the expected UI structure (the CVE-2025-14771 disclosure path) and administrative API calls issued by accounts holding only low-privilege roles (the CVE-2025-14772 authorization bypass), distinguished from benign admin activity by the mismatch between the session&#39;s role and the operation performed.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.</p><p class="entry-cite__quote">No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-04, republishing Rockwell Automation PSIRT)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>15 Jul 04:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-04, republishing Rockwell Automation PSIRT)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-03, republishing ABB PSIRT)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-02, ABB Ability Edgenius)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-01, ABB Advant Master Online Builder)</a></div></article>]]></content:encoded></item><item><title>SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeover</title><link>https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>SonicWall&#39;s PSIRT confirms active exploitation of two SMA1000 flaws (SNWLID-2026-0008), both added to CISA KEV on 2026-07-14: CVE-2026-15409 (CVSS 10.0), an unauthenticated server-side request forgery in the SMA1000 Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication OS-command code injection in the Appliance Management Console. Any organization running an internet-facing SMA1000 (6210/7210/8200v) must apply the platform hotfix now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited"><a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a></h3><p>SonicWall&#39;s PSIRT advisory SNWLID-2026-0008 (first published 2026-07-14) states it has investigated &quot;multiple cases indicating the active exploitation&quot; of two new SMA1000 flaws (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>); both CVEs carry a same-day CISA KEV listing (recorded in this entry&#39;s CVE status, confirmed against the KEV feed). <strong>CVE-2026-15409</strong> (CVSS 10.0, CWE-918) is a server-side request forgery in the SMA1000 Work Place interface that lets a remote, unauthenticated attacker force the appliance to issue requests to an attacker-chosen location; the scope-changed CVSS vector (S:C) indicates the SSRF reaches beyond the vulnerable component&#39;s own security boundary. <strong>CVE-2026-15410</strong> (CVSS 7.2, CWE-94) is a post-authentication code-injection flaw in the SMA1000 Appliance Management Console (AMC) that lets an authenticated administrator-level session run arbitrary OS commands — read together with the pre-auth SSRF, the pair forms a chain from zero access toward root-equivalent appliance control. The affected firmware is SMA1000 6210/7210/8200v on 12.4.3-03245/03387/03434 and 12.5.0-02283/02624/02800; the fix is platform-hotfix 12.4.3-03453 or 12.5.0-02835, and SonicWall explicitly states neither flaw affects SSL-VPN running on SonicWall firewalls or the SMA100 series (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is the SSL-VPN edge-appliance exploitation pattern that turns into a foothold fast — patch now and, because exploitation is already live, treat an unpatched exposed SMA1000 as a compromise-assessment candidate rather than a clean patch. <strong>Triage:</strong> the pre-auth SSRF surfaces in the appliance&#39;s own request telemetry as outbound requests from the Work Place interface to unexpected internal or external hosts (a legitimate Work Place session does not initiate arbitrary outbound fetches); the code-injection stage surfaces in the control-service log as configuration or hotfix-state manipulation from an admin session — SonicWall&#39;s own detection guidance points at hotfix-rollback entries carrying path-traversal-style names as the anomaly, so rollback activity that does not match a change-managed maintenance window is the discriminator. Per policy no IOCs are reproduced here; consult the vendor advisory for the indicator set.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.</p><p class="entry-cite__quote">A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.</p><p class="entry-cite__quote">Sean Koessel and Steven Adair of Volexity - helped advance SonicWall&#39;s PSIRT investigation, leading to the identification of an additional IOC.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a></div></article>]]></content:encoded></item><item><title>SAP patches an unauthenticated Approuter request-smuggling flaw and a Commerce Cloud public-default-credential exposure; NCSC-CH flags all three</title><link>https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>pre-auth</category><category>patch-available</category><category>auth-bypass</category><category>global</category><category>switzerland</category><category>europe</category><category>patch-available</category><category>CVE-2026-44747</category><category>CVE-2026-27690</category><category>CVE-2026-44761</category><description><![CDATA[<p>SAP&#39;s July 2026 Security Patch Day carries three critical flaws NCSC Switzerland relayed to its constituents: CVE-2026-44747 (CVSS 9.9) memory corruption in the NetWeaver AS ABAP kernel; CVE-2026-27690 (CVSS 9.1) an unauthenticated HTTP request-smuggling flaw in SAP Approuter (non-Cloud-Foundry); and CVE-2026-44761 (CVSS 9.1) a public, hardcoded sample OAuth2 credential left active in SAP Commerce Cloud. No exploitation is reported yet, but the Commerce Cloud item is a config exposure a patch alone does not close.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud" data-tags="vulnerabilities pre-auth patch-available auth-bypass" data-regions="global switzerland europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44747/">CVE-2026-44747 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sap-july-2026-patch-day-netweaver-approuter-commerce-cloud"><a href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication</a></h3><p>SAP&#39;s July 2026 Security Patch Day (14 July) carries three critical flaws NCSC Switzerland&#39;s Cyber Security Hub relayed directly to Swiss constituents, none with reported exploitation at publication (<a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-14</a>; <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>). <strong>CVE-2026-44747</strong> (CVSS 9.9) is a memory-corruption flaw in the SAP NetWeaver Application Server ABAP kernel; SecurityWeek characterises successful exploitation as allowing an attacker to access and modify data and cause system unavailability, and SAP&#39;s only interim workaround (disabling the affected ICF nodes) is impractical because it breaks SAP GUI for HTML, so patching the kernel is the real mitigation (<a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-07-14</a>). <strong>CVE-2026-27690</strong> (CVSS 9.1) is an HTTP request-smuggling flaw in SAP Approuter&#39;s non-Cloud-Foundry deployments: an unauthenticated request desynchronises the request/response stream on a shared front-end, a primitive usable to poison or hijack another user&#39;s request. <strong>CVE-2026-44761</strong> (CVSS 9.1) is a hardcoded sample OAuth2 credential in SAP Commerce Cloud — any customer that ran SAP&#39;s own documented sample configuration and never rotated the shipped secret exposes a publicly-known credential an unauthenticated attacker can use to obtain a valid OCC-API access token (<a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector, finance or utilities SAP estate, sequence by reachability, not CVSS: the Approuter smuggling flaw is unauthenticated and network-reachable, so it patches first; the NetWeaver kernel flaw is authenticated but has enormous blast radius given ABAP&#39;s centrality; and the Commerce Cloud item is an environment-specific configuration exposure — a publicly-known default credential that a routine note roll-out does not remediate, because the exposed secret must be rotated. <strong>Triage:</strong> the Commerce Cloud exposure is a config-audit question (did we deploy the sample OAuth2 client, and is its secret still the shipped default?), answerable from configuration review rather than telemetry; the Approuter smuggling flaw manifests in front-end HTTP access logs as request/response desynchronisation anomalies (ambiguous content-length/transfer-encoding framing, responses mismatched to the requesting session) on a shared Approuter, distinct from the well-formed request stream of normal traffic.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability affects SAP Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization.</p><p class="entry-cite__quote">Exploitation requires that the customer execute the sample script and retain the resulting OAuth2 client in production without replacing the hardcoded secret.</p><p class="entry-cite__quote">Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains.</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC Switzerland — Cyber Security Hub</a> · <a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html" target="_blank" rel="noopener noreferrer">SAP Support Portal</a></div></article>]]></content:encoded></item><item><title>Microsoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>priv-esc</category><category>cisa-kev</category><category>identity</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-56155</category><category>CVE-2026-56164</category><description><![CDATA[<p>Microsoft&#39;s July 2026 Patch Tuesday (its largest ever by CVE count) fixes two zero-days Microsoft confirms were exploited in the wild and CISA added to KEV the same day: CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS), and CVE-2026-56164, an unauthenticated, network-reachable elevation-of-privilege in on-prem SharePoint Server 2016/2019/Subscription Edition. Any organization running on-prem AD FS or SharePoint should treat both as emergency patches.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days" data-tags="vulnerabilities actively-exploited zero-day priv-esc cisa-kev identity patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-56155/">CVE-2026-56155 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="microsoft-july-2026-patch-tuesday-two-exploited-zero-days"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)</a></h3><p>Microsoft&#39;s July 2026 Patch Tuesday is its largest ever by CVE count and carries two zero-days Microsoft confirms were exploited before a fix existed, both added to CISA&#39;s Known Exploited Vulnerabilities catalog the same day (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-14</a>). <strong>CVE-2026-56155</strong> (CVSS 7.8, CWE-1220) is a local elevation-of-privilege in Active Directory Federation Services: an attacker who already holds a low-privileged authorized session on the AD FS host escalates to administrator (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). It is a post-foothold escalation rather than an initial-access vector, and Microsoft&#39;s advisory credits its own DART incident-response team in the acknowledgements — meaning it surfaced during a live intrusion, so an exposed AD FS host should be treated as a candidate for compromise assessment, not merely patched (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). <strong>CVE-2026-56164</strong> (CVSS 5.3, CWE-306) is the more exposed of the two: a missing-authentication flaw in on-prem SharePoint Server that lets an unauthenticated attacker elevate privileges over the network with no user interaction (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). Microsoft&#39;s mitigation guidance — enable AMSI on the SharePoint/IIS worker processes with Request Body Scan set to Full — indicates the trigger is a crafted HTTP POST body, the same class of exposure this pipeline tracked for the CVE-2026-45659 SharePoint deserialization RCE on 2026-07-02, so operators who already tuned AMSI for that flaw have partial coverage.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch both now; for AD FS the low CVSS understates the risk because the bug was caught in real-world incident response — treat internet- or partner-reachable AD FS servers as potentially targeted and pair the patch with a hunt of local process activity on those hosts. <strong>Triage:</strong> the AD FS escalation manifests in host-local process-execution and privilege-transition telemetry on the AD FS server itself (a low-privileged service account acquiring administrator context), not in network logs — normal AD FS operation does not spawn privilege transitions from its service account, so that lineage is the discriminator; the SharePoint escalation surfaces in IIS/SharePoint worker-process telemetry as an unauthenticated request preceding an unexpected privilege context, which AMSI full-body scanning is positioned to catch. No IOCs or exploiting cluster have been published for either.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.</p><p class="entry-cite__quote">Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.</p><figcaption class="entry-cite__attr"><a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener noreferrer">Krebs on Security</a></div></article>]]></content:encoded></item><item><title>Honeypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns</title><link>https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</guid><pubDate>Tue, 14 Jul 2026 12:50:00 +0000</pubDate><dc:date>2026-07-14T12:50:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>auth-bypass</category><category>global</category><category>europe</category><category>us</category><category>exploited</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-2699</category><description><![CDATA[<p>Update to the 2026-07-13 ShareFile shutdown entry. Shadowserver Foundation honeypots first recorded active, in-the-wild exploitation attempts against the ShareFile Storage Zone Controller pre-auth authentication bypass CVE-2026-2699 on Friday 2026-07-10 — the same day Progress issued its emergency power-off order — and the internet-exposed instance count fell from watchTowr&#39;s April tally of ~30,000 to roughly 1,000 by 2026-07-13. A Recorded Future analyst publicly assessed possible Clop involvement; Progress has named no actor and disclosed no root cause. On-prem operators still running Storage Zone Controllers should keep them off.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/progress-sharefile-szc-active-exploitation-confirmed" data-tags="vulnerabilities actively-exploited rce pre-auth auth-bypass" data-regions="global europe us" data-kind="incident" data-priority="high" data-discovered="2026-07-14T12:50:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-2699/">CVE-2026-2699</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="progress-sharefile-szc-active-exploitation-confirmed"><a href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/">Progress orders ShareFile Storage Zone Controller shutdown over a &#39;credible external threat&#39; — day three, no patch or root cause disclosed</a> <span class="mono muted">(2026-07-13)</span></p><p>Two developments harden the picture around Progress&#39;s emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert &quot;arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit&quot; the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This moves the flaw&#39;s status from PoC-public to actively exploited. Second, defenders responded at scale — the number of internet-exposed Storage Zone Controllers fell from watchTowr&#39;s April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (<a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register, 2026-07-13</a>; <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile status, 2026-07-13</a>).</p>
<p>Recorded Future analyst Allan Liska publicly assessed that the pattern &quot;smells like CL0P ransomware group activity,&quot; pointing to Clop&#39;s long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This is a named researcher&#39;s hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.</p>
<p><strong>Defender takeaway.</strong> The one-day earlier guidance — treat any exposed SZC as untrusted and keep it powered off rather than patched — is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry&#39;s shutdown and bounded-compromise-check actions still stand unchanged.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.</p><p class="entry-cite__quote">Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.</p><p class="entry-cite__quote">This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and &#39;shut them all down.&#39;</p><figcaption class="entry-cite__attr"><a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>incident</span><span>14 Jul 12:50Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> · <a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register</a> · <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile (vendor status page)</a></div></article>]]></content:encoded></item><item><title>WAGO patches a hidden early-boot diagnostic interface in I/O System Field couplers that lets an unauthenticated remote attacker take full control</title><link>https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/</guid><pubDate>Mon, 13 Jul 2026 12:50:00 +0000</pubDate><dc:date>2026-07-13T12:50:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-4769</category><description><![CDATA[<p>CERT@VDE published advisory VDE-2026-031 / CVE-2026-4769 (2026-07-13) for WAGO I/O System Field coupler devices: certain models activate an undocumented diagnostic capability during the initial boot sequence that is reachable without authentication for a brief early-boot window, letting an unauthenticated remote attacker with network access reach internal system processes and achieve full system compromise (CWE-912 Hidden Functionality; CVSS 9.8). No exploitation is reported (EPSS 0.0) and fixed firmware is available per model. Swiss/European energy, water and industrial-automation OT estates running these couplers should schedule the firmware update and verify these devices are segmented from untrusted networks, especially during maintenance reboots.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor" data-tags="vulnerabilities ot-ics auth-bypass pre-auth patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-13T12:50:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-4769/">CVE-2026-4769</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="wago-io-system-field-cve-2026-4769-early-boot-backdoor"><a href="https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/">CVE-2026-4769 — WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)</a></h3><p>CERT@VDE — Germany&#39;s OT/ICS coordinating CERT, acting as CVE Numbering Authority for the vendor — published advisory VDE-2026-031 / CVE-2026-4769 on 2026-07-13 for WAGO I/O System Field series coupler devices (models 0765-110x, 0765-120x, 0765-150x, 0765-2101, 0765-2102, 0765-410x, 0765-420x, 0765-450x, all variant <code>/0100-0000</code>) (<a href="https://www.certvde.com/en/advisories/VDE-2026-031/" target="_blank" rel="noopener noreferrer">CERT@VDE, 2026-07-13</a>). Certain devices activate an undocumented internal diagnostic capability during the initial boot sequence — functionality outside the publicly documented feature set — which is reachable without authentication for a brief window before the main operating environment and its security controls become fully active (CWE-912 Hidden Functionality). If an attacker has network access to the device during that early-boot window, they can interact with internal system processes normally protected during regular operation, which CERT@VDE describes as resulting in full system compromise. The advisory carries a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8), and the ENISA EU Vulnerability Database entry EUVD-2026-43297 lists a CVSS 4.0 base score of 9.3 (<a href="https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297" target="_blank" rel="noopener noreferrer">ENISA EUVD, 2026-07-13</a>). No exploitation has been reported and EPSS is 0.0. WAGO has released fixed firmware for each affected model.</p>
<p>WAGO I/O System Field devices are modular fieldbus I/O couplers used in industrial automation and building-management deployments, including energy and water-utility OT environments in the constituency&#39;s additional sectors. The practical exploitability is bounded — an attacker must have network reachability to the device precisely during its early-boot window — but the impact if that condition is met is unauthenticated, full compromise of an operational field device, and OT patch cycles are slow, so the exposure can persist. Detection is best framed as OT network monitoring: correlate device power-cycle/reboot events (from maintenance logs or the device&#39;s own uptime telemetry) with any new inbound session to the device&#39;s management/diagnostic ports in the same time window — a connection arriving during a reboot, rather than steady-state operation, is the anomaly this vulnerability creates. Hardening: apply the per-model fixed firmware listed above and, until then, keep these couplers behind VLAN/ACL segmentation from any untrusted network segment, tightening reachability during planned maintenance reboots when the early-boot window is opened deliberately.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.</p><figcaption class="entry-cite__attr">CERT@VDE</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>13 Jul 12:50Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.certvde.com/en/advisories/VDE-2026-031/" target="_blank" rel="noopener noreferrer">CERT@VDE (Germany OT/ICS coordinating CERT, CNA)</a> · <a href="https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297" target="_blank" rel="noopener noreferrer">ENISA EU Vulnerability Database (EUVD-2026-43297)</a></div></article>]]></content:encoded></item><item><title>19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland&#39;s Dec-2025 grid sabotage</title><link>https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</guid><pubDate>Mon, 13 Jul 2026 12:40:00 +0000</pubDate><dc:date>2026-07-13T12:40:00Z</dc:date><category>nation-state</category><category>espionage</category><category>actively-exploited</category><category>cisa-kev</category><category>wiper</category><category>law-enforcement</category><category>ot-ics</category><category>russia-nexus</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2018-0171</category><description><![CDATA[<p>A joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland&#39;s energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory" data-tags="nation-state espionage actively-exploited cisa-kev wiper law-enforcement ot-ics russia-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-13T12:40:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2018-0171/">CVE-2018-0171</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="fsb-centre-16-static-tundra-router-hijacking-advisory"><a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a></h3><p><strong>Background.</strong> The FSB Centre 16 network-device cluster is not new — it has a decade-plus public record under the vendor labels Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly and Ghost Blizzard, and Cisco Talos profiled it in August 2025 as &quot;Static Tundra,&quot; documenting long-term compromise of unpatched and end-of-life network gear for configuration theft and persistent collection (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). What is new is a same-day trio of actions on 2026-07-13: a much fuller TTP disclosure, a formal government attribution of a destructive attack, and the first coordinated EU/UK cyber-sanctions package.</p>
<p>A joint Cybersecurity Advisory carrying 19 authoring and co-sealing agencies across 13 countries — NSA, CISA, FBI and DC3 (US) alongside the cyber and intelligence authorities of Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden — describes FSB Centre 16 opportunistically compromising poorly configured routers across communications, defense industrial base, energy, financial services, government (especially state/local), and healthcare sectors (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA/CISA/FBI joint advisory, 2026-07-13</a>; <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). The advisory notes these TTPs overlap with Salt Typhoon activity, so the hardening below counters more than one actor.</p>
<p>The primary access vector is not a novel exploit but weak SNMP hygiene. The actors scan internet IP ranges for SNMP agents that accept common or default community strings, then issue spoofed-source SNMP Set-Requests carrying object identifiers that instruct the device to copy its running configuration to a file (commonly <code>config.bkp</code> or <code>output.txt</code>) and transfer it, usually over TFTP, to a leased VPS or a compromised FTP server (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). The advisory names the exact OIDs abused — <code>1.3.6.1.4.1.9.9.96.1.1</code> (Cisco Config Copy) and <code>1.3.6.1.4.1.9.9.96.1.1.1.1.5</code> (the destination address for the copied config). A stolen configuration frequently discloses further credentials and additional community strings, feeding lateral movement. Talos&#39;s profile records the actor guessing or reusing insecure read-write community strings such as <code>public</code> and <code>anonymous</code> (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). Secondarily — &quot;occasionally,&quot; per the advisory — the actors exploit known Cisco bugs and the Smart Install (SMI) feature, naming CVE-2018-0171 (the Smart Install pre-auth RCE, in CISA KEV since 2021) and CVE-2008-4128 (end-of-life devices only, no patch). Persistence has historically included the SYNful Knock IOS firmware implant.</p>
<p><strong>The Poland grid attribution.</strong> On the same day, the UK together with EU member states formally attributed the destructive 29 December 2025 attack on Poland&#39;s energy grid to FSB Centre 16 (<a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). CERT Polska&#39;s own incident report describes coordinated destructive activity against 30-plus wind and photovoltaic grid-connection substations — RTU, HMI and protection-relay firmware damaged or system files deleted — and a combined heat-and-power plant serving roughly half a million people, where wiper malware was blocked by the operator&#39;s EDR before detonation; CERT Polska tied the activity to the Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster via VPS, router and anonymizing-infrastructure overlap and called it &quot;the first publicly described destructive activity attributed to this activity cluster&quot; (<a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-01-30</a>). Note the attribution is contested at the cluster-label level: earlier ESET reporting attributed the same DynoWiper attack to the GRU&#39;s Sandworm (<a href="https://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-01-24</a>), and the EU Council statement names FSB Centre 16 as the parent controlling several groups including Turla — so treat &quot;FSB Centre 16&quot; as an umbrella unit rather than a single team.</p>
<p>The sanctions package is the policy layer: the EU designated 9 individuals and 4 entities and the UK designated 24, covering senior GRU figures, the front company IMPULS accused of recruiting hackers for GRU Unit 29155, Lumma Stealer operators, and the disinformation outlet Rybar LLC (<a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government, 2026-07-13</a>; <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-13</a>).</p>
<p><strong>Detection.</strong> The telemetry classes to prioritise on network gear: network-flow and firewall logs for inbound SNMP Set-Requests (especially with spoofed or unfamiliar source addresses) and for outbound TFTP sessions initiated from a router/switch management interface to non-management destinations; device syslog and AAA/TACACS+ logs for unexpected &quot;config copy&quot; events, new local-account creation, and unexplained drops in logging volume — Talos documents the actor tampering with TACACS+ configuration to blind logging and standing up GRE tunnels to redirect victim traffic (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>); and IDS rules keyed to inbound SNMP Set-Requests carrying the config-copy OIDs above, as the advisory recommends (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). Baseline NetFlow for the new GRE tunnel endpoints Talos describes.</p>
<p><strong>Defender takeaway.</strong> For a Swiss or European CI operator this is a router-hygiene mandate with a live destructive precedent next door. Disable Smart Install where it is not in active use, confirm CVE-2018-0171 is patched, migrate management SNMP to v3 with authPriv and disable SNMPv1/v2c (or, where legacy SNMP is unavoidable, replace every default/weak community string and enforce read-only), restrict all management protocols to known stations via out-of-band ACLs, use Cisco password hashing type 8 (never 0/4/7), and treat the device configuration held in your management system — not the device itself — as the source of truth so a tampered config is detectable.</p>
<p><strong>Triage:</strong> legitimate network-management stations poll SNMP on a predictable cadence from a known IP set, almost always read-only GET/GET-NEXT. The signal is a <em>write</em> (SNMP Set-Request) — particularly one carrying the config-copy OIDs — from a source outside the management range or with an inconsistent/spoofed source address, followed by an outbound TFTP transfer from the device; either alone is weak, the sequence config-write-then-TFTP-egress is the discriminator.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication</p><figcaption class="entry-cite__attr"><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The UK together with EU member states has also today formally attributed the December 2025 attack on Poland&#39;s energy grid to Russia&#39;s FSB Centre 16.</p><figcaption class="entry-cite__attr"><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is, however, the first publicly described destructive activity attributed to this activity cluster.</p><figcaption class="entry-cite__attr"><a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> <span class="entry-cite__date mono">2026-01-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.</p><figcaption class="entry-cite__attr"><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 12:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> · <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> · <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> · <a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Dutch NIS2 (Cyberbeveiligingswet) passed the Senate 7 July — entry into force fixed for 15 August 2026, ~8,000 organisations in scope</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</guid><pubDate>Sun, 12 Jul 2026 23:52:00 +0000</pubDate><dc:date>2026-07-12T23:52:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch First Chamber passed the Cyberbeveiligingswet (the NIS2 transposition) and the companion Wet weerbaarheid kritieke entiteiten (CER transposition) on 7 July 2026; both enter into force 15 August 2026. This closes the &#39;slipped past 1 July&#39; status prior weeklies tracked and fixes a hard date. The Cbw covers ~8,000 organisations across 18 sectors with a duty of care including supply-chain risk management, mandatory incident reporting to the CSIRT, entity-register registration, and board-level accountability. For Swiss-domiciled organisations with Dutch subsidiaries, NL critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is now the operative compliance clock.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-netherlands-nis2-in-force" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:52:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-netherlands-nis2-in-force"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a> <span class="mono muted">(2026-07-05)</span></p><p>the Dutch NIS2 transposition status this pipeline tracked as &quot;slipped past its 1 July target, Senate vote set for 7 July&quot; has resolved. On 7 July 2026 the Eerste Kamer (First Chamber) passed both the <strong>Cyberbeveiligingswet</strong> (Cbw, the NIS2 transposition) and the companion <strong>Wet weerbaarheid kritieke entiteiten</strong> (Wwke, the CER-directive transposition) — the Tweede Kamer had passed them on 15 April — and &quot;de wetten treden op 15 augustus 2026 in werking&quot; (&quot;the laws enter into force on 15 August 2026&quot;) (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The parliamentary vote record confirms broad cross-party support (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, 2026-07-07</a>). The Cbw covers roughly 8,000 organisations across 18 designated essential/important sectors and imposes a cybersecurity duty of care (including supply-chain risk management), mandatory registration in the NCSC entity register, significant-incident reporting to the relevant CSIRT, and board-level accountability with director training (<a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a>).</p>
<p><strong>Why this matters to the constituency:</strong> beyond direct applicability to any covered Dutch entity, this is a concrete datapoint for the deployment&#39;s standing EU NIS2-transposition watch — a member state moving from indefinite slip to a fixed enforcement date. For Swiss-domiciled organisations with Dutch subsidiaries, NL-incorporated critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is the operative clock, five weeks out from this brief. The next checkpoint is confirmation the NCSC-NL entity register is live and accepting registrations ahead of the date.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De wetten treden op 15 augustus 2026 in werking.</p><figcaption class="entry-cite__attr"><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal</a> · <a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a></div></article>]]></content:encoded></item><item><title>CH/EU government under broad attack this week — Latvia forestry ransomware, Swiss cantonal mailbox compromise, e-gov watering-hole, Ghostwriter phishing</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/</guid><pubDate>Sun, 12 Jul 2026 23:30:00 +0000</pubDate><dc:date>2026-07-12T23:30:00Z</dc:date><category>data-breach</category><category>espionage</category><category>ransomware</category><category>phishing</category><category>switzerland</category><category>europe</category><description><![CDATA[<p>The constituency&#39;s core sector was hit from several directions in 2026-W28: a ransomware crew breached Latvia&#39;s state forestry operator LVM via a two-year-unpatched service (CERT.LV, an EU/NATO-shared-threat framing); Psychiatrische Dienste Aargau (a Swiss cantonal health authority) had email accounts phished and abused as a spam relay; espionage actors weaponised a citizen-facing e-government complaint portal as a watering hole; Armored Likho hit government and electric-power targets with an AI-generated loader; and UNC1151/Ghostwriter ran real-time 2FA-relay Gmail phishing against officials (CERT Polska). The common thread is not one actor but the breadth of pressure on public-sector identity, exposed services and citizen-facing web.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-government-public-admin-targeting" data-tags="data-breach espionage ransomware phishing" data-regions="switzerland europe" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:30:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-government-public-admin-targeting"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing</a></h3><p>Government and public administration — the profiled constituency&#39;s core — absorbed an unusually broad spread of activity in 2026-W28, notable less for any single incident than for how many different attack classes landed on the sector in one week.</p>
<p>On the <strong>ransomware</strong> front, CERT.LV disclosed that a crew breached Latvijas Valsts Meži (LVM), Latvia&#39;s state forestry operator, through a service left unpatched for roughly two years, and framed it explicitly as an EU/NATO-shared-threat matter for a state-owned critical operator (<a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV, 2026-06</a>). In Switzerland, <strong>Psychiatrische Dienste Aargau (PDAG)</strong>, a cantonal health authority, had staff email accounts compromised via phishing and abused to relay spam — a low-sophistication but high-frequency pattern against public-sector mailboxes (<a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-09</a>). On the <strong>espionage</strong> axis, SentinelLabs documented converging China- and India-nexus operations weaponising a citizen-facing e-government complaint portal as a watering hole with a CMS implant (<a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs, 2026-07-10</a>); Kaspersky profiled <strong>Armored Likho</strong> hitting government and electric-power targets with an AI-generated loader and the BusySnake stealer (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-11</a>); and CERT Polska tracked <strong>UNC1151/Ghostwriter</strong> moving to Gmail with real-time 2FA-relay phishing against officials (<a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-06</a>).</p>
<p><strong>Why this is a sector pattern for the constituency:</strong> two of the five strands carry a direct home-region or EU-critical-operator nexus (a Swiss cantonal authority and a Latvian state operator); the e-government watering-hole targeted a Pakistani law-enforcement programme (EU-funded but with no direct European victim nexus) and is carried for its transferable technique, while the remaining two are actors whose targeting profile — government and energy — matches the constituency. The exposed surfaces recur: unpatched internet-facing services, public-sector email identity, and citizen-facing web applications.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the week&#39;s public-sector lesson is coverage of the unglamorous basics — an authoritative patch SLA for internet-facing services (the LVM two-year gap is the cautionary case), phishing-resistant MFA on staff mail to break both spam-relay abuse and 2FA-relay phishing, and integrity monitoring on citizen-facing CMS platforms that make natural watering holes. <strong>Triage:</strong> a compromised public-sector mailbox used as a relay shows a sudden outbound-volume spike and sends to external recipients with no prior correspondence; a watering-hole CMS implant shows unexpected file writes to web-root and template/plugin directories outside a deployment window.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat/">2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/pdag-aargau-email-account-compromise-spam-relay/">2026-07-09/pdag-aargau-email-account-compromise-spam-relay</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/e-government-portal-watering-hole-cms-implant-espionage/">2026-07-10/e-government-portal-watering-hole-cms-implant-espionage</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/">2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs</a> · <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> · <a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska</a></div></article>]]></content:encoded></item><item><title>2026-W28 vuln roll-up — exploited: ColdFusion, CitrixBleed 2, Gitea, Langflow, Joomla wave; notable: HTTP.sys mechanics, KVM escape, Siemens SICAM 8, MOVEit</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/</guid><pubDate>Sun, 12 Jul 2026 23:26:00 +0000</pubDate><dc:date>2026-07-12T23:26:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>rce</category><category>priv-esc</category><category>ot-ics</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>Consolidated status view of the week&#39;s vulnerabilities that demand action beyond the routine patch cycle. Confirmed exploited / KEV this week: Adobe ColdFusion CVE-2026-48282, Citrix NetScaler CitrixBleed 2 CVE-2025-5777, Gitea CVE-2026-20896, Langflow CVE-2026-55255, and the Joomla extension file-upload wave (CVE-2026-48908/56290/56291/48939). Public-exploit or full-mechanics disclosures raising urgency without confirmed ITW use: GhostLock Linux kernel LPE CVE-2026-43499 (public reliable exploit), Windows HTTP.sys CVE-2026-47291 (ZDI published exploitation mechanics), Linux KVM &#39;Januscape&#39; CVE-2026-53359 (guest-to-host escape), BeyondTrust RS/PRA CVE-2026-40138 cluster. OT/CI note: Siemens SICAM 8 grid RTU firmware-signing bypass (CVE-2026-54798-801). See the linked operational entries for per-CVE detail.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-vuln-status-rollup" data-tags="vulnerabilities actively-exploited cisa-kev rce priv-esc ot-ics" data-regions="switzerland europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-12T23:26:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-vuln-status-rollup"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band</a></h3><p>This roll-up consolidates the 2026-W28 vulnerabilities that cross the out-of-band-action bar — actively exploited, at imminent mass exploitation, or otherwise demanding a response the routine monthly cycle does not give. Per-CVE facts, CVSS, and affected/fixed versions live in the linked operational entries; this entry is the status trajectory a reader uses to sequence the week&#39;s patching.</p>
<p><strong>Confirmed exploited / on CISA KEV this week.</strong> <em>Adobe ColdFusion</em> CVE-2026-48282 (one of the 1 July CVSS 10.0 unauthenticated RCEs) — exploited within two hours of public detail, KEV-listed 7 July (<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). <em>Citrix NetScaler</em> CitrixBleed 2 CVE-2025-5777 — weaponised into a repeatable initial-access-broker kill chain ending in DragonForce ransomware; patch plus session termination required. <em>Gitea</em> CVE-2026-20896 — NCSC-CH escalated to &quot;Actively Exploited, Proof of Concept Available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-10</a>). <em>Langflow</em> CVE-2026-55255 — cross-tenant IDOR chained with pre-auth RCE, first exploited 25 June, now KEV. <em>Joomla extension file-upload wave</em> — CVE-2026-48908 / 56290 / 56291 / 48939 exploited as zero-days (see the dedicated top-story), CVE-2026-57827/57828 patched without confirmed exploitation yet.</p>
<p><strong>Urgency raised by public exploit or full mechanics, no confirmed ITW use.</strong> <em>GhostLock</em> CVE-2026-43499 — Linux kernel rtmutex use-after-free with a public ~97%-reliable local-privilege-escalation exploit. <em>Windows HTTP.sys</em> CVE-2026-47291 (pre-auth RCE, CVSS 9.8) — ZDI published full exploitation mechanics for the June Patch Tuesday flaw, collapsing the reverse-engineering barrier. <em>Linux KVM/x86 &#39;Januscape&#39;</em> CVE-2026-53359 — shadow-MMU use-after-free enabling guest-to-host VM escape, relevant to multi-tenant virtualisation. <em>BeyondTrust Remote Support / Privileged Remote Access</em> — the CVE-2026-40138 pre-auth bypass cluster on a remote-access product class that is itself a high-value target.</p>
<p><strong>OT / critical-infrastructure note.</strong> <em>Siemens SICAM 8</em> grid RTUs (A8000/EGS/S8000) — a firmware-signature-validation bypass (CVE-2026-54798-801) on devices deployed in European energy grids; slow patch cycles make network isolation and OT-segment monitoring the near-term control. <em>Progress MOVEit Transfer</em> — pre-auth SFTP DoS (CVE-2026-10699) plus admin scope-bypass fixes, notable given MOVEit&#39;s history as a mass-exfiltration target.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">sequence by exploitation evidence, then exposure — the KEV/exploited set above is this week&#39;s out-of-band queue; the public-exploit set is next in line before it is weaponised; the OT items are isolate-and-monitor where an immediate patch is impractical.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev/">2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update/">2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce/">2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe/">2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster/">2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/">2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903</a></p><div class="prov"><span>vulnerability</span><span>12 Jul 23:26Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a></div></article>]]></content:encoded></item><item><title>Kaspersky names Armored Likho — spear-phishing into an LLM-written loader chain that stages a full Python runtime and a PyArmor-protected stealer</title><link>https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/</guid><pubDate>Sat, 11 Jul 2026 17:40:00 +0000</pubDate><dc:date>2026-07-11T17:40:00Z</dc:date><category>espionage</category><category>phishing</category><category>infostealer</category><category>ai-abuse</category><category>russia-cis</category><category>latam</category><description><![CDATA[<p>Kaspersky documented (2026-07-03) Armored Likho (aka Eagle Werewolf), a previously unknown APT targeting government agencies and the electric-power sector across Russia, Brazil and Kazakhstan. Spear-phishing delivers an NSIS dropper or a ZDI-CAN-25373 LNK lure whose loader — assessed as LLM-generated — stages a bundled Python 3.12 runtime and the PyArmor-protected BusySnake Stealer from rotating GitHub repositories. Campaign active at publication; concrete low-noise hunt pivots exist. Published as an audit-recovered item: the primary fell inside the 2026-07-07 scheduler outage&#39;s backfill blind spot.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer" data-tags="espionage phishing infostealer ai-abuse" data-regions="russia-cis latam" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T17:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="armored-likho-busysnake-ai-generated-loader-python-stealer"><a href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python &#39;BusySnake&#39; stealer</a></h3><p>Kaspersky&#39;s threat-monitoring team published a full analysis of a previously unknown APT it dubs Armored Likho (also tracked, on circumstantial evidence, as Eagle Werewolf), which mixes financially motivated campaigns against individuals with targeted espionage against organizations — the current campaign, still active at publication, concentrates on government agencies and electric-power-sector organizations in Russia, Brazil and Kazakhstan (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>). Initial access is spear-phishing with government-notice and social-program themes carrying archive attachments. One variant drops an NSIS self-extracting dropper that shows a decoy &quot;psychological test&quot; survey, writes a legitimate <code>pnx.exe</code> to a temp directory and injects loader code into its process memory; the other abuses the ZDI-CAN-25373 Windows shortcut-display weakness — whitespace/line-break padding that hides the LNK&#39;s real command line from the user — to launch obfuscated PowerShell. Both paths converge on a loader that Kaspersky assesses was written by an LLM (verbose comments and bullet-point emojis &quot;highly uncharacteristic of human-developed malware&quot;) — a concrete case of AI-generated first-stage tooling blurring the actor&#39;s TTP fingerprint and complicating attribution (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>).</p>
<p>The loader pulls its payload packages from attacker-controlled GitHub repositories whose contents and names rotate automatically, then stages everything under <code>%APPDATA%\WindowsHelper</code>: a bundled Python 3.12 interpreter, <code>get-pip.py</code> for dependency installation, and the primary payload <code>module.pyw</code> — BusySnake Stealer, a Python infostealer obfuscated with PyArmor Pro 9.2.0 that decrypts each function&#39;s bytecode only at call time and re-encrypts it afterward. Persistence is a VBScript launcher (<code>run.vbs</code>) registered as a scheduled task re-executing the payload every five minutes; a companion <code>wh_selfdelete.vbs</code> wipes the initial loader. On tasking from its C2, the stealer harvests Chromium credentials via DPAPI and Firefox credentials via <code>PK11SDR_Decrypt</code>, steals browser cookies (in one command variant by installing a browser extension), scrapes the clipboard and local files for 64-character hex keys and <code>otpauth://</code> OTP seeds, inventories and exfiltrates user documents under 5 MB, captures screenshots, packages Telegram <code>tdata</code> session stores after force-killing <code>telegram.exe</code>, hunts cryptocurrency-wallet JSON files, opens a reverse-SSH tunnel with a C2-supplied key, and abuses RustDesk — downloading it if absent, or restarting it to make the user re-enter their ID/password while screenshotting the credentials (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the chain is long but noisy in telemetry classes most estates already collect. In process-creation telemetry, alert on script interpreters or unknown binaries spawning a bundled/user-writable Python interpreter (<code>python.exe</code>/<code>pythonw.exe</code> executing from <code>%APPDATA%</code>), on <code>.pyw</code> files registered in scheduled tasks, and on <code>wscript.exe</code> launching from <code>%APPDATA%\WindowsHelper</code>-style working directories; in network telemetry, surface hosts fetching archives from GitHub release repositories outside development context, and outbound SSH from hosts with no SSH business. <strong>Triage:</strong> developer machines legitimately run user-installed Python — the discriminators are the scheduled-task-driven five-minute re-execution cadence, the interpreter living under <code>%APPDATA%</code> rather than a managed install path, and RustDesk (re)starts the user did not initiate; any one alone is weak, the combination is the signal. For the profiled constituency this is transferable tradecraft knowledge, not an active home-region threat — no Swiss or EU targeting is reported.</div></aside>
<p><em>Provenance note: this entry was published by the 2026-07-11 full-store quality audit, which found the item had fallen into the 2026-07-07 scheduler outage&#39;s backfill blind spot (research-blog publications do not route through the KEV/CERT catch-up paths the backfill run swept — pipeline fix shipped as prompts v3.21).</em></p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">This targeted campaign focuses heavily on government agencies and the electric power sector. The geographical footprint of these attacks spans Russia, Brazil, and Kazakhstan, establishing the group as a global threat actor.</p><p class="entry-cite__quote">This coding style is highly uncharacteristic of human-developed malware. It strongly indicates that the group is leveraging LLMs to generate their malicious payloads.</p><figcaption class="entry-cite__attr"><a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> <span class="entry-cite__date mono">2026-07-03</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 17:40Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a></div></article>]]></content:encoded></item><item><title>Symantec: a driver built malicious from the outset — yet WHCP-signed — defeats code-signing allowlisting to kill EDR before GodDamn encrypts</title><link>https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>ransomware</category><category>organized-crime</category><category>identity</category><category>global</category><description><![CDATA[<p>Symantec attributes GodDamn ransomware (first seen 2026-05-21) to the Hyadina developer behind the Monster→Beast lineage, and documents a June 2026 intrusion where the operators loaded PoisonX (g11.sys) — a kernel driver they got signed under Microsoft&#39;s Windows Hardware Compatibility Publisher program despite it being malicious by design — to terminate security processes and strip user-mode API hooks before encrypting. The signed-malicious-driver twist means code-signing allowlisting will not stop it; detection must be behavioural.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver" data-tags="ransomware organized-crime identity" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="goddamn-ransomware-poisonx-microsoft-signed-driver"><a href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">GodDamn ransomware (Beast/Monster rebrand) blinds EDR with &#39;PoisonX&#39;, a malicious kernel driver Microsoft signed</a></h3><p>Symantec&#39;s Threat Hunter Team assesses that GodDamn — surfaced as a &quot;new&quot; ransomware, first observed 2026-05-21 — is the latest rebrand in a lineage it tracks to a developer called Hyadina: Monster (2022) → Beast → GodDamn, the last sharing significant code overlap with Beast (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>). The investigated early-June intrusion is a conventional human-operated ransomware kill chain with one standout component. AnyDesk appeared on the first host staged under the user&#39;s Music folder — a placement Symantec reads as manual attacker delivery, not a normal install — and began beaconing to relay infrastructure. The operators then dropped a defence-evasion binary masquerading as a Symantec product, which installed the PoisonX kernel driver (<code>g11.sys</code>) into the system driver store, staged a 14-tool credential-harvesting kit (13 NirSoft utilities plus Mimikatz) under the profile, moved laterally across 10-plus hosts via PsExec while re-installing AnyDesk on each for unattended access (writing <code>ad.security.interactive_access=2</code> to suppress the consent prompt and registering it as auto-start services), disabled Windows Defender real-time monitoring, and finally deployed the encrypter (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>; <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-09</a>).</p>
<p>PoisonX is what distinguishes this case from routine bring-your-own-vulnerable-driver tradecraft. Rather than abusing a flaw in a legitimate signed driver, PoisonX is a driver built to be malicious that its developers nonetheless got signed under Microsoft&#39;s &quot;Windows Hardware Compatibility Publisher&quot; program; once loaded it terminates security-product processes and strips user-mode API hooks, so it disables EDR visibility rather than merely evading it. It was first documented earlier in 2026 killing the CrowdStrike Falcon service via a crafted IOCTL to an undocumented driver interface (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">because the driver carries a valid Microsoft signature, code-signing allowlists and reputation checks pass it — detection has to be behavioural. <strong>Triage:</strong> legitimate driver installs do not co-occur with mass termination of security services, so the load of a rarely-seen driver immediately followed by security-product process/service stops and the loss of user-mode hooks on the same host is the discriminator; AnyDesk running from a personal media folder (versus IT-managed Program Files) and configured for unattended access is a second, independent pivot.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">the PoisonX driver seems to be slightly more unusual, in that it appears to be a malicious driver that its developers succeeded in getting signed by Microsoft, and it is now being used by ransomware attackers.</p><p class="entry-cite__quote">Placing AnyDesk under the user Music folder rather than a standard installation directory is consistent with manual delivery by an attacker who had already obtained access to the host by an earlier means.</p><figcaption class="entry-cite__attr"><a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> · <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.infosecurity-magazine.com/news/ransomware-removes-cybersecurity/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>Microsoft dissects GigaWiper — destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an &#39;OneDrive Update&#39; persistence tell</title><link>https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>wiper</category><category>ransomware</category><category>nation-state</category><category>infostealer</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented GigaWiper (2026-07-09), a Go destructive backdoor that combines a raw-disk wiper, a Crucio-derived encryptor whose keys are never saved, and a FlockWiper-derived secure-wipe module as on-demand commands, tasked over RabbitMQ/Redis with MinIO exfiltration. First seen October 2025; concrete low-noise hunt pivots exist. Relevant to any Windows critical-infrastructure estate as transferable destructive tradecraft.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper" data-tags="wiper ransomware nation-state infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="gigawiper-golang-destructive-backdoor-modular-wiper"><a href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant</a></h3><p>Microsoft Threat Intelligence first identified GigaWiper in October 2025 and has now published a code-level analysis of it: a Golang backdoor notable less for any single capability than for its construction — at least three previously separate destructive families folded into one implant as on-demand commands, so an operator can pick the mode of destruction at task time (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>). The raw-disk wiper command enumerates physical drives over WMI, identifies and spares the Windows installation drive, strips partition metadata from the other drives via <code>DeviceIoControl</code>/<code>IOCTL_DISK_CREATE_DISK</code>, overwrites disk content in 0xA00000-byte chunks (randomising only the first byte of each buffer to dodge naïve all-zero-wipe detections), then forces an immediate reboot. A second command reuses Crucio ransomware code to AES-encrypt files with per-run keys that are never saved and drops no ransom note — destruction wearing an extortion costume — while a third reimplements the C-based FlockWiper in Go for multi-pass secure wiping of the Windows drive. Microsoft ties the families together by code overlap and assesses that the same developer built GigaWiper and Crucio; it withholds actor attribution beyond that lineage. Google&#39;s Threat Intelligence Group and Binary Defense track the same activity as BLUERABBIT (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>; <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-07-10</a>).</p>
<p>Operationally the implant is quieter than its payload. It persists as a scheduled task named <code>OneDrive Update</code> (configured to run roughly every minute and once at startup) and tracks its own execution count in a <code>HKCU\SOFTWARE\OneDrive\Environment</code> registry value, masquerading as Microsoft&#39;s sync client. For command-and-control it skips ordinary HTTP: tasking arrives over RabbitMQ/AMQP — a fanout exchange named <code>All</code> for broadcast to every infected client plus a topic exchange for targeted commands — status and output are polled back through a Redis server, and MinIO object storage carries exfiltration, alongside keylogging and screen-capture modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the persistence footprint and the C2 protocol mix are both high-value, low-false-positive hunt anchors — legitimate OneDrive never lives under that task name or registry path, and a standard workstation has no reason to speak AMQP, Redis and MinIO outbound. <strong>Triage:</strong> genuine OneDrive does run scheduled sync tasks, so the discriminator is the exact task name (<code>OneDrive Update</code>) and the <code>HKCU\SOFTWARE\OneDrive\Environment</code> key rather than the presence of a OneDrive-named task per se; pair that with outbound RabbitMQ/Redis/MinIO from a host with no such workload and the two together are the signal. Because the encryptor discards its keys, defence is recovery-first: this is a data-destruction threat, and the only meaningful mitigation for an exposed Windows estate is tested, offline backups.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction</p><p class="entry-cite__quote">The key and initialization vector (IV) that the malware uses to encrypt files are random and are not saved anywhere</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>ZDI details the HTTP.sys integer-overflow trigger — weaponisation bar drops for a pre-auth RCE reachable on any IIS/HTTPS listener</title><link>https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>poc-public</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-47291</category><description><![CDATA[<p>Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the HTTP.sys pre-auth kernel RCE patched in Microsoft&#39;s June 2026 cycle, documenting the exact integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the wild, but the mechanics — and a concrete network-detection heuristic — are now public, so anyone running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as newly weaponisable.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics" data-tags="vulnerabilities rce pre-auth poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47291/">CVE-2026-47291</a><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="cve-2026-47291-httpsys-zdi-exploitation-mechanics"><a href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut/">CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)</a> <span class="mono muted">(2026-06-10)</span></p><p>CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative&#39;s TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches <code>0xFFFB</code>, so the next increment wraps to <code>0x0000</code>; the subsequent reference addition then allocates a 40-byte buffer but <code>memmove</code>s roughly 524,256 bytes into it — a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS — HTTP/2 and HTTP/3 use a different parser and are unaffected (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The write-up also corrects the exposure picture the original advisory left fuzzy: the default <code>MaxRequestBytes</code> of 16,384 bytes caps a request at roughly 4,000 header lines — far short of the ~65,536 references needed — so only hosts that raised <code>MaxRequestBytes</code> to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE &quot;Exploitation More Likely&quot;; no in-the-wild exploitation is reported as of ZDI&#39;s publication (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-06-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the patch remains the only reliable fix, but the newly-public mechanics hand defenders a durable network signature — a single HTTP/1.x request bearing more than ~1,000 header lines (visible with TLS inspection), or an HTTPS connection emitting more than ~1,000 tiny TLS records over ~11 minutes (visible without decryption). <strong>Triage:</strong> ordinary browsers and proxies coalesce headers into a few records and never approach that line count, so a single long-lived HTTPS connection feeding one IIS/HTTP.sys request with hundreds-to-thousands of one-line TLS records is the discriminator; a kernel bugcheck on an internet-facing IIS box following such traffic warrants triage against this CVE.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="entry-cite__quote">If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><figcaption class="entry-cite__attr">Zero Day Initiative</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article>]]></content:encoded></item><item><title>Siemens patches a firmware-signing bypass and an insecure OPC UA default in SICAM 8 grid-protection controllers — plan the out-of-band OT update</title><link>https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>priv-esc</category><category>auth-bypass</category><category>patch-available</category><category>europe</category><category>global</category><category>patch-available</category><category>CVE-2026-54799</category><category>CVE-2026-54801</category><category>CVE-2026-54800</category><category>CVE-2026-54798</category><description><![CDATA[<p>Siemens ProductCERT advisory SSA-229470 (2026-07-09), republished in-window by CERT-FR/ANSSI as CERTFR-2026-AVI-0860, patches four vulnerabilities in the CPCI85 and SICORE firmware of SICAM A8000, SICAM EGS and SICAM S8000 remote terminal units — controllers Siemens frames for transmission and distribution system operators. The most consequential are a firmware-update signature-validation flaw enabling persistent malicious firmware and an OPC UA default configuration that disables all OPC UA security. No exploitation is reported. Energy-sector operators running SICAM 8 should schedule the V26.20 firmware update and review OPC UA exposure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass" data-tags="vulnerabilities ot-ics priv-esc auth-bypass patch-available" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-54799/">CVE-2026-54799 +3</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="siemens-sicam-8-ssa-229470-firmware-signing-bypass"><a href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)</a></h3><p>Siemens ProductCERT&#39;s SSA-229470 covers four flaws in the SICORE base system and CPCI85 central processing/communication firmware that underpin the SICAM A8000 (CP-8010/CP-8012 on SICORE; CP-8031/CP-8050 on CPCI85), SICAM EGS (CPCI85) and SICAM S8000 (SICORE) remote terminal units (<a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT, 2026-07-09</a>). The advisory&#39;s stated aggregate impact is denial of service, but the individual issues span further: CVE-2026-54799 (CVSS v3.1 6.7, AV:L/PR:H) is a firmware-update signature-validation flaw that lets an attacker who already holds high privileges install malicious firmware for persistent code execution; CVE-2026-54801 (v3.1 7.2) lets an authenticated attacker bypass credential validation when the web API processes administrative-account modifications and gain elevated privileges; CVE-2026-54800 (v3.1 4.8) is an insecure default that disables all OPC UA security, letting a network attacker reach control functions; and CVE-2026-54798 (v3.1 6.5) is an HTTP-reachable debug interface an authenticated attacker can use to crash the web process. All are fixed in CPCI85 V26.20 / SICORE V26.20.0. CERT-FR/ANSSI republished the advisory the next day as CERTFR-2026-AVI-0860, giving European energy-sector operators a home-region authority citation (<a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860/" target="_blank" rel="noopener noreferrer">CERT-FR/ANSSI, 2026-07-10</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">none of the four is a remote pre-authentication vector — the firmware-signing bypass requires prior high privilege on the device and the admin-API and debug flaws require authentication — so this is a defence-in-depth and supply-chain-integrity concern for grid-protection equipment rather than an emergency, but SICAM 8 sits on the power-grid boundary at TSOs and DSOs across Europe including Switzerland, where firmware updates are inherently planned out-of-band events rather than routine patch-cycle work. The load-bearing exposure to close proactively is CVE-2026-54800: because OPC UA security is off in the shipped configuration, any SICAM 8 device whose OPC UA interface is reachable from a less-trusted network segment is exposed to unauthorized control-function access without exploiting anything — a configuration review, not a patch, closes that one immediately. Siemens&#39; own guidance stresses that grid resilience through redundant secondary protection schemes limits the reliability impact of any single compromised controller.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The affected application contains a vulnerability in its firmware update mechanism&#39;s signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.</p><p class="entry-cite__quote">The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.</p><figcaption class="entry-cite__attr"><a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-229470)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-229470)</a> · <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860/" target="_blank" rel="noopener noreferrer">CERT-FR / ANSSI</a></div></article>]]></content:encoded></item><item><title>SANS ISC: a phishing page pads itself with ~430k repeated characters to dilute the payload below an AI classifier&#39;s threshold or exhaust an LLM&#39;s token budget</title><link>https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>phishing</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>A SANS Internet Storm Center diary analysed a phishing email whose HTML attachment was ~2.5 MB but whose functional credential-harvesting payload was only ~11 KB — the remainder a single HTML comment of ~430,000 repeated &quot;X&quot; characters placed after the payload. The analyst assesses the padding is aimed at AI/NLP-based email security: either diluting the malicious content&#39;s statistical weight until a probability classifier drops below its flag threshold, or inflating the token count until an LLM-based scanner exceeds its per-message time/size budget and cuts analysis short. The concept matters as AI content-scoring spreads across public-sector mail gateways; the defence is a non-AI fallback rule keyed on the anomalous oversized-single-character-run signature.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion" data-tags="phishing ai-abuse" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="comment-stuffing-html-phishing-ai-email-scanner-evasion"><a href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">&#39;Comment stuffing&#39; — HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners</a></h3><p>A SANS Internet Storm Center diary (2026-07-10, Jan Kopriva) dissects a phishing email that presented as a Microsoft Teams/SharePoint document notification and carried a <code>.xls.html</code> double-extension attachment weighing ~2.5 MB — anomalously large for a self-contained HTML page (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). Decoded from a <code>\uXXXX</code>-escaped <code>document.write()</code> wrapper, the file was ~431 KB, of which only the first ~11 KB was a working SharePoint-themed credential-harvesting page; the rest was a single HTML comment holding roughly 430,000 repeated &quot;X&quot; characters, placed <em>after</em> the functional payload, accounting for ~97% of the file.</p>
<p>The placement rules out the classic goal. Padding after the payload does nothing to conceal the malicious code, and at 2.5 MB the file falls well short of the tens-of-megabytes scan-size limits modern mail security uses, so this is not the MITRE &quot;Binary Padding&quot; scan-size-evasion play. The handler&#39;s assessment — explicitly flagged as informed speculation — is that the target is AI/NLP-based content scanning, which a growing number of gateways now run. Citing KnowBe4&#39;s earlier &quot;NLP obfuscation&quot; work, the diary notes that &quot;if a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence&quot;, and that &quot;the same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely&quot; (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). The author judges the token-budget-exhaustion goal the more likely of the two here, since a featureless block of one character works as well as crafted filler for that purpose. He is candid that against a well-tuned model the tactic is blunt — &quot;the padding is also about as low-entropy as any data can get, which means it wouldn&#39;t help the file blend in with benign content on a statistical level either&quot; — which is precisely why a simple non-AI signature catches it.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">as AI/NLP scoring becomes a load-bearing control in mail security, adversaries gain an incentive to attack the classifier&#39;s decision budget rather than hide from signatures — dilution below a confidence threshold, or token-count inflation past a per-message time budget that makes the gateway fail open. <strong>Triage:</strong> benign HTML mail and marketing content can be large, but a single repeated-character run or one HTML comment in the hundreds of kilobytes is not something legitimate senders produce — that oversized low-entropy block, and a large decompressed-vs-declared-size ratio, are the discriminators, and both are detectable without relying on the AI layer the padding is trying to defeat.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence.</p><p class="entry-cite__quote">The same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely.</p><p class="entry-cite__quote">The padding is also about as low-entropy as any data can get, which means it wouldn’t help the file blend in with benign content on a statistical level either</p><figcaption class="entry-cite__attr"><a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 12:53Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a></div></article>]]></content:encoded></item><item><title>Huntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware</title><link>https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>ransomware</category><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>lpe</category><category>identity</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2025-5777</category><description><![CDATA[<p>Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and — in the most progressed case — DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725" data-tags="ransomware vulnerabilities actively-exploited pre-auth lpe identity" data-regions="global" data-kind="threat" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-5777/">CVE-2025-5777</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="citrixbleed-2-dragonforce-iab-kill-chain-stac3725"><a href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)</a></h3><p>Across the first half of 2026 the Huntress Tactical Response unit worked at least six intrusions at unrelated organisations that reproduced the same seven-step kill chain so faithfully that analysts could predict the next artefact before pulling the log — the basis for their high-confidence assessment that an initial-access broker (IAB) has productised the path from an internet-facing Citrix box to domain-wide encryption, a cluster Sophos independently tracks as STAC3725 (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>; <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops, 2026-04-16</a>). Initial access is pre-auth exploitation of CitrixBleed 2 (<code>CVE-2025-5777</code>), a memory over-read in NetScaler ADC/Gateway configured as a Gateway or AAA virtual server: a POST to the login endpoint (<code>/p/u/doAuthentication.do</code> and equivalents) with the login form variable present but empty makes the appliance serialise roughly 127 bytes of adjacent process memory into the response, and sprayed at volume this yields live session tokens (<code>T1190</code>, <code>T1550.001</code>). In one reconstructed case a user authenticated normally over LDAP+MFA from a known-good IP at 13:07 UTC; twenty-one minutes later the same session was driven from the attacker&#39;s IP with no successful authentication from that IP anywhere in the logs — token replay, with MFA already satisfied and therefore irrelevant (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The privilege-escalation primitive is what makes the cluster unmistakable, because the hijacked session usually belongs to an unprivileged employee and the operator carries a portable, unsigned LPE tool (dropped to working paths such as <code>C:\temp</code> and renamed per victim — <code>eng.exe</code>, <code>legal.exe</code>, <code>as.exe</code> — often inside a password-protected archive pulled from <code>temp.sh</code>). The tool plants a <code>REG_LINK</code> <code>SymbolicLinkValue</code> under the RdpBus device-class key <code>{28d78fad-5a12-11d1-ae5b-0000f803a8c2}</code> that redirects into the Group Policy state hierarchy (<code>T1112</code>); running <code>gpupdate</code> forces the SYSTEM-context Group Policy engine to write through the planted link into a protected key, and <code>sc start AppMgmt</code> then makes the Service Control Manager relaunch the dropper as <code>NT AUTHORITY\SYSTEM</code>, which creates a backdoor administrator via <code>net user … /add</code> and <code>net localgroup Administrators … /add</code> (<code>T1068</code>, <code>T1136.001</code>, <code>T1098</code>). AppMgmt is chosen because it is always present, normally dormant, and plausibly related to policy processing. Before detonating, the tool snapshots the original key tree and restores it afterwards, leaving the registry indistinguishable from its pre-exploit state to erase the artefacts a responder would key on (<code>T1070</code>). Persistence then rides legitimate remote-management software — ScreenConnect and Zoho Assist, in one case Netbird plus Atera (<code>T1219</code>) — and in the most advanced case the operator used PsExec, Impacket and Mimikatz for lateral movement and credential access (<code>T1003</code>, <code>T1570</code>) before deploying DragonForce ransomware, contained to a single host (<code>T1486</code>). Huntress declines a firm DragonForce-affiliate-versus-IAB attribution given the tactic overlap, and ruled out an alternative NetScaler session-management race-condition flaw because the affected build and the required already-authenticated session to race against did not fit the evidence.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch NetScaler to the fixed builds and, critically, terminate every live session afterwards — harvested tokens survive the patch, which is the single most common post-patch reinfection path for this bug. On the appliance, the load-bearing detection is not the paired diagnostic breadcrumbs (&quot;Login request is not expected to be encrypted&quot;, &quot;X509 cert not found&quot;), which Huntress calls necessary but nowhere near sufficient, but the binary/unprintable data leaking through the ns.log AAA <code>LOGIN_FAILED</code> User field and — the cleanest signal — an authenticated session that has no corresponding successful login event. A default Citrix behaviour also fingerprints the operator: published-desktop sessions auto-create client printer mappings that embed the client workstation name (the same <code>WIN-</code> hostnames recurred case after case), correlatable by pivoting the <code>Microsoft-Windows-TerminalServices-LocalSessionManager/Operational</code> channel (source IP + session ID) against the <code>MetaFrameEvents</code> provider in the Application log (session ID + leaked client name). <strong>Triage:</strong> a NetScaler login flood looks like ordinary password spraying and is routinely dismissed as such — the discriminator is that the &quot;usernames&quot; are leaked heap memory (unprintable bytes, X.509/ASN.1 fragments, internal <code>Citrix-ns-orig-srcip</code> proxy headers), not guessed account names; and on the endpoint, a <code>gpupdate</code> → <code>AppMgmt</code> start → new-SYSTEM-process → local-admin-creation sequence within seconds is the signal, whereas legitimate Group Policy refreshes do not spawn a fresh SYSTEM binary that immediately creates an account.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><p class="entry-cite__quote">The cleanup serves to evade detection: by leaving the registry indistinguishable from its pre-exploit state, the tool removes the artifacts a responder would normally key on.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment.</p><figcaption class="entry-cite__attr"><a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> · <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops</a></div></article>]]></content:encoded></item><item><title>Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June</title><link>https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</guid><pubDate>Thu, 09 Jul 2026 20:38:00 +0000</pubDate><dc:date>2026-07-09T20:38:00Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>switzerland</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-50656</category><description><![CDATA[<p>NCSC-CH&#39;s Nightmare Eclipse tracker was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59) local privilege escalation in the Microsoft Malware Protection Engine behind Defender that lets a local attacker reach SYSTEM; Microsoft&#39;s MSRC record shows the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE sat in &quot;no fix&quot; for over three weeks. The engine auto-updates, so most estates are already current — but WSUS-gated, offline or OT-adjacent estates should explicitly verify the installed engine build.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50656/">CVE-2026-50656</a></div><h3 class="f-h" id="ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed"><a href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">CVE-2026-50656 — Microsoft Defender engine &#39;RoguePlanet&#39; local privilege escalation now patched; NCSC-CH tracks the ongoing &#39;Nightmare Eclipse&#39; zero-day series</a></h3><p>NCSC-CH&#39;s running tracker on the &quot;Nightmare Eclipse&quot; (aka Chaotic Eclipse) researcher&#39;s 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to <strong>RoguePlanet</strong>: <strong>CVE-2026-50656</strong>, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / &quot;link following&quot;) in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker &quot;execute arbitrary code or spawn a command shell with SYSTEM-level privileges&quot; (<code>T1068</code>), at which point NCSC-CH logged its status as &quot;Proof of Concept Available, no patch available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). Microsoft&#39;s own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, <code>AV:L/AC:L/PR:L/UI:N</code>, rated &quot;Exploitation More Likely&quot;, exploitation status &quot;No&quot;) and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it — last vulnerable Malware Protection Engine build <strong>1.1.26050.11</strong>, first fixed build <strong>1.1.26060.3008</strong> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>).</p>
<p>Because the Malware Protection Engine (<code>mpengine.dll</code>) auto-updates multiple times a day by default, most estates will already carry the fixed build — Microsoft&#39;s guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. <strong>Triage:</strong> the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, <code>MsMpEng.exe</code> (the engine&#39;s scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence — the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656.</p><p class="entry-cite__quote">Improper link resolution before file access (&#39;link following&#39;) in Microsoft Defender allows an authorized attacker to elevate privileges locally.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch Cyber Security Hub</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a></div></article>]]></content:encoded></item><item><title>CISA ICS advisory: an authenticated file-write in OpenPLC&#39;s legacy web UI reaches native code execution, with no fixed version cited</title><link>https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/</guid><pubDate>Thu, 09 Jul 2026 20:36:00 +0000</pubDate><dc:date>2026-07-09T20:36:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>rce</category><category>no-patch</category><category>global</category><category>no-patch</category><category>CVE-2026-14480</category><description><![CDATA[<p>CISA&#39;s ICS advisory ICSA-26-190-01 (2026-07-09) covers CVE-2026-14480, an authenticated arbitrary file-write in OpenPLC Runtime v3&#39;s legacy web UI that escalates to native code execution: the runtime auto-compiles every C++ source file in its core directory into the executable, so writing a malicious .cpp there and triggering a normal program compile runs attacker code as the OpenPLC runtime user. CVSS 3.1 9.9, network-facing; CISA cites no fixed version, only network-isolation mitigations — treat as unpatched. No known exploitation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/openplc-cve-2026-14480-file-write-rce" data-tags="vulnerabilities ot-ics rce no-patch" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-14480/">CVE-2026-14480</a></div><h3 class="f-h" id="openplc-cve-2026-14480-file-write-rce"><a href="https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/">CVE-2026-14480 — OpenPLC v3 Runtime: authenticated arbitrary file write escalates to native RCE via the auto-compile pipeline (CVSS 9.9)</a></h3><p>CISA published ICS advisory <strong>ICSA-26-190-01</strong> (2026-07-09) for <strong>OpenPLC Runtime v3</strong>, the widely used open-source PLC runtime CISA tags across the Critical Manufacturing, Energy, Transportation Systems, and Water/Wastewater sectors (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-09</a>). <strong>CVE-2026-14480</strong> (CWE-73, External Control of File Name or Path; CVSS 3.1 9.9 <code>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</code>, CVSS 4.0 8.7) is an authenticated arbitrary file-write in the legacy web UI&#39;s program-upload workflow: the application stores an attacker-supplied filename (the <code>prog_file</code> parameter) directly into the <code>Programs.File</code> database field and later uses that value as the destination write path without validation, and because the underlying Python <code>os.path.join()</code> honors an attacker-controlled absolute path, any authenticated user can write files anywhere the webserver process can reach (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-09</a>). The escalation is specific to OpenPLC&#39;s build model: all <code>.cpp</code> source files in the runtime&#39;s core directory are automatically compiled into the executable runtime binary, so writing a malicious <code>.cpp</code> there and then triggering a normal program compile-and-start — an ordinary operator action, not an exploit primitive — executes attacker code as the OpenPLC runtime user (<code>T1190</code>). The bug was reported to CISA by researcher Grady DeRosa, and CISA states no known public exploitation at this time.</p>
<p>CISA cites <strong>no fixed release version</strong> — its only stated mitigations are the standard ICS hardening set (minimise network exposure, keep control-system devices off the internet, place them behind firewalls isolated from business networks, use VPN for remote access) — so this should be treated as unpatched until the OpenPLC project ships guidance. Because exploitation requires authentication, the practical exposure hinges on how reachable and how loosely authenticated the web UI is: an internet-exposed or shared-credential OpenPLC instance is effectively RCE-exposed, while one confined to a trusted out-of-band network with per-operator accounts is not. <strong>Triage:</strong> the compile step itself is legitimate operator activity, so the discriminator is <em>what</em> is being compiled and <em>who</em> spawned it — new or modified <code>.cpp</code> files appearing in the runtime core directory outside a maintainer deploy, and the compiler toolchain being invoked by the OpenPLC webserver process or its children rather than by an engineer-initiated build from an authorised workstation; parent-process lineage (webserver → <code>gcc</code>/<code>g++</code>) is the signal.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user.</p><p class="entry-cite__quote">In the default build pipeline, all C++ source files within the OpenPLC runtime core directory are automatically compiled into the executable runtime binary.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-190-01)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-190-01)</a></div></article>]]></content:encoded></item><item><title>Two Golang DDoS botnets, Apex2 and c2c/meow, flood exposed Telnet/SSH Linux and IoT with fake-systemd persistence and passwordless-sudo escalation</title><link>https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</guid><pubDate>Thu, 09 Jul 2026 12:33:00 +0000</pubDate><dc:date>2026-07-09T12:33:00Z</dc:date><category>botnet</category><category>ddos</category><category>ot-ics</category><category>global</category><description><![CDATA[<p>Nozomi Networks Labs details two Golang DDoS botnet families caught via honeypots this spring: Apex2 (Telnet brute-force, Linux+Windows builds, a Cloudflare-bypass HTTP flood plus UDP/TLS floods) and c2c/meow (SSH-delivered, escalates via passwordless sudo, persists as a fake systemd &#39;cpufreqd&#39; service). Neither is sophisticated, but the point for defenders is the pace: exposed Telnet/SSH management interfaces on IoT and embedded-Linux keep getting repurposed for DDoS faster than before — directly relevant to OT-adjacent estates in energy, water and transport.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets" data-tags="botnet ddos ot-ics" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-09T12:33:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets"><a href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Nozomi documents two new Golang IoT/Linux DDoS botnets (Apex2, c2c/meow) built for speed and reuse over sophistication</a></h3><p>Nozomi Networks Labs&#39; AI-assisted honeypot triage flagged two Golang-based DDoS botnet samples this spring that stand out from the routine volume of Mirai-derived variants: Apex2 and c2c (distributed under the filename &quot;meow&quot;) (<a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs, 2026-07-06</a>). Apex2 is a direct structural evolution of the earlier Apex botnet: infection begins with Telnet connections and credential brute-forcing, followed by download-and-execute of the Golang payload, which registers with its C2 over a plaintext protocol (host OS/architecture) and ships builds for Linux (arm, arm64, mipsle, ppc64) and Windows (386, amd64). Its named flood commands include <code>cf</code> (an HTTP(S) flood specifically tuned to bypass Cloudflare via randomized User-Agent lists and long keep-alive timeouts), <code>udp</code>/<code>pps</code>, <code>discord</code>/<code>game</code> UDP floods, and three TLS-flood variants (<code>tls</code>, <code>tlsplus</code>, <code>tlsplusbypass</code>). c2c/meow is architecturally simpler — a Golang flooder with no built-in propagation (a separate SSH scanner handles brute-forcing and delivery) that authenticates to a hardcoded C2 over plaintext JSON-over-TCP, checks for passwordless sudo (<code>sudo -n true</code>) to self-escalate, then persists by copying itself to <code>/usr/local/bin/cpufreqd</code> and registering a fake systemd unit masquerading as a &quot;CPU Frequency Daemon&quot; — supporting ten flood-module types (icmp, dnsudp, udp, http, directhttp, fasthttp, betterhttp, tcp, tcphandshake, dnstcp).</p>
<p>Nozomi&#39;s stated point for defenders is that neither family is sophisticated — both lean on commodity Golang tooling, weak/default credentials and exposed Telnet/SSH interfaces rather than novel exploitation — and that the lack of sophistication does not reduce the risk at scale, because the build-and-deploy cycle for such botnets is getting faster. ATT&amp;CK mapping: <code>T1110 Brute Force</code> (Telnet/SSH), <code>T1105 Ingress Tool Transfer</code>, <code>T1548.003 Abuse Elevation Control Mechanism: Sudo</code> (c2c&#39;s passwordless-sudo self-escalation), <code>T1543.002 Create or Modify System Process: Systemd Service</code> with <code>T1036.005 Masquerading</code> (the fake cpufreqd unit), and <code>T1498 Network Denial of Service</code> for the flood modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is not a novel threat but a concrete hunt package for the OT-adjacent and embedded-Linux estates in the constituency&#39;s energy, water and transport remit — the fake-systemd-service naming, the <code>sudo -n true</code> escalation probe, and plaintext-JSON C2 are all cheap, durable detections, and the durable fix is the unglamorous one of removing internet-exposed Telnet/SSH and default credentials on IoT and embedded devices.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It checks whether passwordless sudo is available by running sudo -n true and evaluating the return value. If successful, it relaunches itself with increased privileges, copies to /usr/local/bin/cpufreqd, and creates a fake systemd service named &quot;CPU Frequency Daemon&quot;</p><p class="entry-cite__quote">In both cases, the emphasis is not on sophistication, but on speed, reuse and scalability.</p><figcaption class="entry-cite__attr"><a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> <span class="entry-cite__date mono">2026-07-06</span></figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 12:33Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> · <a href="https://industrialcyber.co/ransomware/nozomi-identifies-apex2-and-c2c-golang-malware-driving-faster-iot-botnet-attacks-raising-risks-for-ot-environments/" target="_blank" rel="noopener noreferrer">Industrial Cyber</a></div></article>]]></content:encoded></item><item><title>Sygnia IR: an AI-assisted AWS intrusion ran four parallel workstreams per stolen key and used four accounts&#39; keys in one second</title><link>https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>cloud</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>Sygnia&#39;s incident response into a financially-motivated AWS intrusion found no novel malware or zero-day — every technique maps to a known MITRE ATT&amp;CK ID — but the tempo and parallelism point to AI-assisted/agentic tooling: initial access to broad compromise in ~72h, and four access keys from four separate accounts used from one source IP and user-agent within a single observed second. The detection signal is the orchestration, not the individual actions. Defenders should pre-build minutes-not-hours containment and alert on one source authenticating with multiple distinct keys in a tight window.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h" data-tags="ai-abuse cloud organized-crime" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="sygnia-ai-orchestrated-aws-cloud-intrusion-72h"><a href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours — four keys from four accounts used from one source in the same second</a></h3><p>Sygnia&#39;s incident-response investigation of a financially-motivated AWS cloud intrusion found no novel malware or zero-day — every individual technique maps to a long-tracked MITRE ATT&amp;CK ID — but the operationalisation was materially faster than typical manual intrusions, which Sygnia attributes to AI-assisted or agentic tooling (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>). After obtaining an initial access key via a weakness in an internet-facing application, the actor ran four workstreams in parallel — secrets theft (ECS/EC2 environment variables, GitHub/Bitbucket CI/CD runner env vars, S3 plaintext secrets, Secrets Manager, SSM Parameter Store); persistence (new IAM users, EC2/ECS reverse shells, modified deployment files); RDS exfiltration via several hundred distinct SQL queries across dozens of databases; and reversible impact (S3 access denial, ECS scaled to zero, SQS purges) used purely as extortion leverage — and repeated the full playbook on every newly obtained credential rather than progressing linearly. The most striking artefact: four different AWS access keys from four separate accounts were used from the same source IP and user-agent within a single observed second, which Sygnia assesses is very hard to explain as manual operation (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>).</p>
<p>Scripts, structured reporting output, and commit messages/branch names framing the activity as an authorized &quot;pentest&quot;/&quot;red team&quot; with a fabricated CEO sign-off are consistent with LLM-generated tooling — possibly including prompt-framing meant to reduce refusal from AI assistants being abused by the operator. Sygnia maps the case onto the same tactic distribution (Execution, Discovery, Credential Access, Collection, Defense Evasion) that Anthropic&#39;s June 2026 LLM ATT&amp;CK research found concentrated in banned AI-abuse accounts. Relevant IDs per Sygnia include <code>T1651 Cloud Administration Command</code>, <code>T1552/T1528</code> (credential/token harvesting), <code>T1087/T1580/T1619</code> (account/cloud-infra/storage discovery re-run per key), <code>T1578</code> (modify cloud compute infra) and <code>T1078 Valid Accounts</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector estate mid-cloud-migration running AWS with GitHub/Bitbucket CI/CD, the lesson is tempo. The ATT&amp;CK-mappable individual actions are not the alarm — the orchestration is: one source authenticating with multiple distinct keys/accounts in seconds, and the same secrets-harvesting sequence re-firing on each new credential. Because manual response cannot keep pace, containment (network isolation, credential rotation, session revocation) has to be pre-built to run in minutes, and every exposed credential must be assumed used instantly and at scale.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In one observed second, four different access keys belonging to four separate accounts were used from the same source IP address and the same user-agent</p><p class="entry-cite__quote">The intrusion progressed from initial access to broad cloud compromise within approximately 72 hours.</p><p class="entry-cite__quote">multiple attacker-created artifacts were framed as part of a &#39;pentest&#39; or a &#39;red team&#39;. This framing appeared in branch names, commit messages, and other artifacts, including references suggesting the activity was approved by a non-existent CEO.</p><figcaption class="entry-cite__attr"><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a></div></article>]]></content:encoded></item><item><title>Mandiant recovers a live ADFS signing key from Machine DPAPI — a Golden SAML variant that sidesteps the WID/DKM path and LSASS-watching detection</title><link>https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>identity</category><category>espionage</category><category>cloud</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Mandiant documented an ADFS Golden SAML variant: when AutoCertificateRollover is disabled and certificates are rotated manually, the WID configuration database drifts to a stale &quot;ghost&quot; certificate while the active token-signing key sits in the machine CAPI store protected by Machine DPAPI. A SYSTEM-level attacker recovers it with SharpDPAPI /machine — without touching the WID/DKM path or LSASS — and forges a Global Administrator SAML assertion that Entra ID accepts, bypassing MFA and conditional access. The drift is observable via ADFS Event ID 385; treat ADFS as Tier 0.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery" data-tags="identity espionage cloud" data-regions="global europe switzerland" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="mandiant-adfs-machine-dpapi-golden-saml-key-recovery"><a href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Mandiant &quot;Ghost in the Database&quot;: recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails</a></h3><p><strong>Background.</strong> Golden SAML — forging SAML assertions by stealing an identity provider&#39;s token-signing key — has been public tradecraft since CyberArk&#39;s 2017 disclosure (<a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" target="_blank" rel="noopener noreferrer">CyberArk, 2017</a>), and Mandiant previously documented network-based extraction of ADFS secrets during the UNC2452/SolarWinds intrusions (<a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network" target="_blank" rel="noopener noreferrer">Mandiant</a>). The standard extraction path pulls the encrypted signing key from the ADFS Windows Internal Database (WID) and decrypts it with Distributed Key Manager (DKM) material stored in Active Directory. This new Mandiant write-up documents a variant that defeats that assumption when ADFS configuration has drifted.</p>
<p>During a red-team engagement, Mandiant found that ADFS deployments with <code>AutoCertificateRollover</code> disabled (<code>Get-AdfsProperties</code> → <code>AutoCertificateRollover: False</code>) and certificates rotated manually can leave the WID configuration database holding only a stale &quot;ghost&quot; certificate record, while the ADFS service actually signs tokens with a newer certificate whose private key lives in the machine CAPI store (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). In that state the classic path still &quot;works&quot; mechanically — the WID blob decrypts via DKM — but Entra ID rejects the resulting token with <strong>AADSTS500172</strong> because the key is no longer the one in use.</p>
<p><strong>The key&#39;s real location and protection.</strong> The active private key sits under <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code>, with the certificate enrolled in the <code>LocalMachine\My</code> store. It is protected by <strong>Machine DPAPI</strong> (not user-bound DPAPI): the <code>DPAPI_SYSTEM</code> LSA secret plus machine masterkeys under the <code>S-1-5-18</code> (SYSTEM) context at <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>. Machine-scoping is deliberate — it keeps the key usable across service-account password changes, gMSA rotations and reboots — but it also means a SYSTEM-level actor can recover the key entirely from the host. Mandiant confirmed recovery with <code>SharpDPAPI /machine</code>, which enumerated the active key material under that path (the CNG <code>Crypto\Keys</code> store was not in use in the assessed environment) — no interaction with the live ADFS process or LSASS is required, reducing visibility for defenses that watch only credential-dumping/process-memory access (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Kill chain (ATT&amp;CK).</strong> SYSTEM-level foothold on the ADFS host → recover Machine-DPAPI-protected masterkeys and the CAPI signing key (<code>T1552 Unsecured Credentials</code>, via <code>SharpDPAPI /machine</code>) → forge a SAML assertion impersonating a Global Administrator (<code>T1606.002 Forge Web Credentials: SAML Tokens</code>) → Entra ID accepts it as a valid federated authentication assertion, yielding Global Administrator access to the Microsoft 365 tenant with MFA and conditional access fully bypassed (<code>T1078.004 Valid Accounts: Cloud Accounts</code>). Because the forged assertion is honoured for <strong>all SAML relying-party trusts</strong>, the blast radius extends to every SaaS platform federated through the same ADFS, not just Microsoft services.</p>
<p><strong>Hunt and detection.</strong> The drift condition itself is observable: <strong>ADFS Event ID 385</strong> fires when the WID record and the actively-used signing certificate diverge, and self-resolves only once <code>AutoCertificateRollover</code> is re-enabled and a rollover runs. For key-theft detection, Mandiant recommends SACL-based object-access auditing (Security <strong>Event ID 4663</strong>) on <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code> and <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>, treated as correlation evidence rather than a standalone signal. The strongest analytic is cross-source: correlate ADFS token-issuance/claims events (Event IDs 299 and the 1200-series, version-dependent) against Entra ID sign-in logs to surface federated sign-ins with no matching upstream authentication context, baselining claim sets, IP ranges and user-agents per relying-party trust for privileged accounts — neither log source alone is sufficient (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Hardening.</strong> Migrate token-signing certificates to an HSM to eliminate the software-accessible key and thus the Machine DPAPI extraction path entirely; run ADFS under gMSA to reduce manual-rotation drift; govern ADFS servers as <strong>Tier 0</strong> (restricted admin paths, dedicated PAWs, separation from general server administration). When <code>AutoCertificateRollover</code> is disabled, a manual rotation must include <code>Set-AdfsCertificate</code> — installing the certificate alone is insufficient — and be validated with <code>Get-AdfsCertificate</code>; a subsequent Event ID 385 signals lingering inconsistency. Organisations migrating to native OIDC federation remove this attack path altogether (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). ADFS remains widely deployed for on-prem/hybrid identity across Swiss and EU public-sector estates mid-migration to Entra ID, making this a direct Tier 0 hardening item for the constituency.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication</p><p class="entry-cite__quote">The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion</p><p class="entry-cite__quote">Configure object access auditing via SACLs on C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\ and C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\. When configured correctly, this generates Security Event ID 4663 for file access attempts.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> · <a href="https://itbrief.co.uk/story/mandiant-finds-way-to-recover-active-adfs-signing-keys" target="_blank" rel="noopener noreferrer">itbrief.co.uk</a></div></article>]]></content:encoded></item><item><title>CISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend — a transferable lesson for any charge-point operator</title><link>https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/</guid><pubDate>Wed, 08 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-08T20:35:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>dos</category><category>no-patch</category><category>global</category><category>mitigation-only</category><category>CVE-2026-20744</category><category>CVE-2026-42952</category><category>CVE-2026-44383</category><description><![CDATA[<p>CISA advisory ICSA-26-188-01 discloses an unauthenticated OCPP WebSocket endpoint (CVE-2026-20744, CVSS 9.8) in the backend of Hydro-Québec&#39;s EV-charging network, plus two companion DoS flaws. Hydro-Québec&#39;s fix is operational (OCPP disabled / auth added), not a version patch. The transferable weakness — an unauthenticated OCPP management channel — applies to any charge-point operator, including Swiss/EU public charging infrastructure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket" data-tags="vulnerabilities ot-ics auth-bypass dos no-patch" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-08T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20744/">CVE-2026-20744 +2</a></div><h3 class="f-h" id="cve-2026-20744-hydro-quebec-ocpp-unauth-websocket"><a href="https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/">CVE-2026-20744 — Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation</a></h3><p>CISA published ICS advisory ICSA-26-188-01 for the backend of Hydro-Québec&#39;s &quot;Le Circuit Électrique&quot; EV-charging network, disclosing three flaws reported by an anonymous researcher (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-07</a>). The headline flaw, CVE-2026-20744 (CVSS v3.1 9.8, CWE-284 Improper Access Control), is in the charging-station WebSocket endpoint that speaks OCPP (Open Charge Point Protocol, the industry-standard charge-point-to-backend management protocol): the endpoint accepts connections with no authentication, letting a remote unauthenticated actor escalate privileges against the backend (<code>T1190</code>). Two companion flaws compound the exposure — CVE-2026-42952 (CVSS 7.5, CWE-307, no throttling on repeated authentication attempts → brute-force/DoS) and CVE-2026-44383 (CVSS 7.5, CWE-613, the backend allows multiple simultaneous connections under the same charging-station identifier, enabling session-exhaustion DoS via duplicate OCPP clients). There is no version-numbered software patch; Hydro-Québec&#39;s remediation is operational — OCPP has been disabled on most charging stations and authentication added for the remainder still using it — and CISA reports no known public exploitation (<a href="https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json" target="_blank" rel="noopener noreferrer">CISA CSAF, 2026-07-07</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the advisory scopes to a single Canadian operator, but the underlying weakness class — an unauthenticated OCPP WebSocket management channel — is a protocol-implementation pattern relevant to every EV-charging network operator, and OCPP is the near-universal charge-point management standard across Swiss/EU public charging infrastructure; the fix is a configuration/security-profile decision (enforce OCPP Security Profile 2/3, one session per charge-point identity), and because the hardware carries no agent, monitoring is necessarily backend/network-telemetry-based.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.</p><p class="entry-cite__quote">No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-188-01)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>08 Jul 20:35Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-188-01)</a> · <a href="https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json" target="_blank" rel="noopener noreferrer">CISA CSAF machine-readable advisory</a></div></article>]]></content:encoded></item><item><title>Netherlands NIS2 (Cyberbeveiligingswet) slips — Senate vote 7 July, entry into force now 15 August 2026</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</guid><pubDate>Sun, 05 Jul 2026 23:42:00 +0000</pubDate><dc:date>2026-07-05T23:42:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch NIS2 transposition (Cyberbeveiligingswet) missed the 1 July 2026 entry-into-force target reported in prior coverage. The Eerste Kamer (Senate) tabled its response to the second committee report on 29 June — the last written step before debate — and its bill-tracking page now sets the floor vote for 7 July, with the government&#39;s revised entry-into-force target 15 August 2026. Substantive scope is unchanged (NCSC-NL supervisor, 24h/72h/1-month notification, fines to EUR 10M/2%, board liability, ~1,000→~8,000 in-scope entities).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-netherlands-nis2-slip" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-05T23:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="weekly-w27-netherlands-nis2-slip"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a> <span class="mono muted">(2026-06-29)</span></p><p>the Dutch NIS2 transposition — the Cyberbeveiligingswet (Cbw) plus the companion Wet weerbaarheid kritieke entiteiten — has missed the 1 July 2026 entry-into-force target the prior weekly reported as the government&#39;s goal.</p>
<p>The Eerste Kamer (Senate) tabled its government response to the second committee report (&quot;nota naar aanleiding van het tweede verslag&quot;) on 29 June 2026 — the last written-preparation step before plenary debate — and the Senate&#39;s own bill-tracking page now states the floor vote will take place on <strong>7 July 2026</strong>, noting the bill was adopted by the Tweede Kamer on 15 April 2026 (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>). iBestuur reports the government&#39;s revised entry-into-force target is now <strong>15 August 2026</strong>, roughly six weeks later than previously communicated (<a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur, 2026-07-01</a>).</p>
<p>The substantive scope is unchanged from prior coverage: NCSC-NL as designated supervisor, a three-step 24h/72h/one-month incident-notification protocol, essential-entity fines up to EUR 10M or 2% of global turnover, personal board liability for security-measure oversight, and an expansion of in-scope Dutch entities from roughly 1,000 to roughly 8,000. This is the fourth documented slip in the Dutch NIS2 timetable (originally targeted Q3 2025).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the only action for a Swiss/EU reader is administrative — re-anchor readiness milestones and contractual compliance-date references onto 15 August 2026 for any Dutch group entities, hosting, or counterparties. No technical control change follows from the date shift itself.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De stemming in de Eerste Kamer vindt plaats op 7 juli 2026.</p><p class="entry-cite__quote">Het voorstel (EK, A) is op 15 april 2026 aangenomen door de Tweede Kamer.</p><figcaption class="entry-cite__attr"><a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>05 Jul 23:42Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a> · <a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur</a></div></article>]]></content:encoded></item><item><title>FortiBleed status — now attributed to INC Ransom / Lynx; 409 admin-access, 12 ransomware deployments</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</guid><pubDate>Sun, 05 Jul 2026 23:41:00 +0000</pubDate><dc:date>2026-07-05T23:41:00Z</dc:date><category>ransomware</category><category>data-breach</category><category>organized-crime</category><category>identity</category><category>global</category><category>europe</category><category>dach</category><description><![CDATA[<p>SOCRadar&#39;s Threat Research Unit published attribution evidence this week tying the FortiBleed FortiGate credential-theft infrastructure to the INC Ransom / Lynx ransomware operation — an operator was found logged into both groups&#39; negotiation panels and FortiBleed victim data overlaps INC&#39;s leak site. STRU revised the scale to ~11,250 FortiGate portals scanned, 409 admin-level, 354 full-domain compromises and at least 12 ransomware deployments, and claims the group holds an undisclosed Nextcloud zero-day (single-source, pending vendor disclosure — track, do not action).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution" data-tags="ransomware data-breach organized-crime identity" data-regions="global europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:41:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-fortibleed-inc-lynx-attribution"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a> <span class="mono muted">(2026-06-29)</span></p><p>FortiBleed — the FortiGate credential-exposure campaign the prior two weeklies tracked from disclosure (86,644+ then 73,932+ exposed credentials) through the Golang &quot;FortigateSniffer&quot; tool (abusing FortiOS&#39;s native <code>diagnose sniffer packet</code>) and an AD-domain-takeover at a NATO-aligned defence contractor — gained a ransomware attribution and a scale revision this week.</p>
<p><strong>Attribution to INC Ransom / Lynx.</strong> SOCRadar&#39;s Threat Research Unit published evidence tying FortiBleed&#39;s infrastructure directly to two active ransomware operations: an operator with access to FortiBleed infrastructure was found logged into the negotiation panels of both <strong>INC Ransom</strong> and <strong>Lynx</strong> (which SOCRadar assesses, per other researchers, to be an INC rebrand rather than a distinct group), and FortiBleed victim data overlaps victims on INC Ransom&#39;s leak site — the first direct evidence linking the mass FortiGate credential theft to a specific ransomware-deployment pipeline (<a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar STRU, 2026-07-01</a>; <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-01</a>). STRU characterises the operation as an ~20-person Initial Access Broker business with a tiered internal structure exposed via an opsec lapse.</p>
<p><strong>Scale revision.</strong> STRU reports scanning against ~11,250 FortiGate portals across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 confirmed ransomware deployments to date — sharpening the risk picture from &quot;credential exposure&quot; to &quot;credential exposure feeding an active RaaS deployment pipeline.&quot;</p>
<p><strong>Unconfirmed Nextcloud zero-day (track, do not action).</strong> STRU further states the group possesses at least one undisclosed Nextcloud zero-day, with SOCRadar coordinating responsible disclosure. This is a single-source claim pending vendor confirmation and carries no CVE — but given Nextcloud&#39;s data-sovereignty-driven prevalence in Swiss and German public-sector and SME estates, it belongs on the watch list for an immediate patch once Nextcloud publishes. The durable defender action is unchanged: treat any FortiGate exposed in the May–June window as having leaked credentials, rotate, and hunt the sniffer technique. New registry entity this run: <code>actor:inc-ransom</code> (aliases INC Ransomware, Lynx).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets</p><figcaption class="entry-cite__attr"><a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">During the investigation of that server, analysis of the collected artifacts revealed that the threat actor had accessed the ransomware negotiation panels of both the Lynx / INC ransomware group.</p><figcaption class="entry-cite__attr">BleepingComputer (citing SOCRadar)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>05 Jul 23:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets</title><link>https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/</guid><pubDate>Tue, 30 Jun 2026 05:10:34 +0000</pubDate><dc:date>2026-06-30T05:10:34Z</dc:date><category>espionage</category><category>nation-state</category><category>china-nexus</category><category>cloud</category><category>apac</category><category>europe</category><description><![CDATA[<p>Acronis Threat Research Unit documented two coordinated June 12–22 campaigns by China-aligned Mustang Panda (also tracked TA416 / HIVE0154 / BRONZE PRESIDENT) against Indian government bodies and hydropower-sector entities (Acronis TRU, 2026-06-29 · The Hacker News, 2026-06-29).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe" data-tags="espionage nation-state china-nexus cloud" data-regions="apac europe" data-kind="threat" data-priority="notable" data-discovered="2026-06-30T05:10:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe"><a href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets</a></h3><p>Acronis Threat Research Unit documented two coordinated June 12–22 campaigns by China-aligned Mustang Panda (also tracked TA416 / HIVE0154 / BRONZE PRESIDENT) against Indian government bodies and hydropower-sector entities (<a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis TRU, 2026-06-29</a> · <a href="https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-29</a>). Initial access is spear-phishing with ZIP-delivered lures (a hydropower cooperation proposal; an India–Taiwan memorandum of understanding). The toolkit introduces SHARDLOADER (DLL side-loading through a legitimate Solid PDF Creator / Citrix Receiver binary, loading shellcode from fragmented files to defeat static scanning — <code>T1574.002</code>), MINIRECON (a reworked Toneshell variant beaconing over <code>wss://</code>), and ZOHOMURK, which carries hardcoded Zoho OAuth credentials to drive an attacker-controlled WorkDrive account as a dead-drop resolver (<code>T1102.001</code>) — reading operator commands from an &quot;inbox&quot; folder and writing exfiltrated output to an &quot;outbox&quot;, blending all C2 with legitimate <code>workdrive.zoho.com</code> API traffic.</p>
<p><strong>Why it matters to us:</strong> Abusing a legitimate SaaS platform&#39;s API for C2 defeats egress controls that allowlist well-known cloud providers — the traffic blends with sanctioned <code>workdrive.zoho.com</code> calls. EU public-sector SOCs should extend CASB/DLP allowlisting to less-obvious SaaS such as Zoho WorkDrive and alert on OAuth token grants for cloud apps that are not sanctioned business tools.</p><div class="prov"><span>threat</span><span>30 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis Threat Research Unit</a> · <a href="https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>The Gentlemen</title><link>https://ctipilot.ch/entries/2026-06-29/the-gentlemen/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/the-gentlemen/</guid><pubDate>Mon, 29 Jun 2026 00:21:21 +0000</pubDate><dc:date>2026-06-29T00:21:21Z</dc:date><category>ransomware</category><category>organized-crime</category><category>russia-nexus</category><category>switzerland</category><category>dach</category><category>europe</category><description><![CDATA[<p>The Gentlemen ransomware makes Switzerland the second-most-targeted European country, claims 478 victims and adds worm propagation — ESET&#39;s leaked-data deep-dive shows victims are chosen on FortiGate misconfiguration, tying the pipeline to FortiBleed reconnaissance. (daily 06-27, inside-it.ch)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/the-gentlemen" data-tags="ransomware organized-crime russia-nexus" data-regions="switzerland dach europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:21Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="the-gentlemen"><a href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">The Gentlemen</a></h3><p>The W25 multi-day item now has primary-evidence depth (the ESET deep-dive, § 7) and a sharp Swiss angle: Check Point data, reported by Swiss tech press, makes <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">Switzerland the second-most-targeted European country</a> for the operation, which now claims 478 victims and has added worm propagation. The operationally important link is that victim selection runs on FortiGate misconfiguration scanning — so a Swiss organisation&#39;s FortiBleed exposure (above) is also its Gentlemen-victim-selection exposure. Outstanding for defenders: the same FortiGate hardening that closes FortiBleed reduces Gentlemen targeting, and EDR-tamper-protection plus driver-blocklist enforcement is the GentleKiller counter.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">inside-it.ch</a> · <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a></div></article>]]></content:encoded></item><item><title>ESET &quot;Killing me gently&quot; — a de-facto mid-year RaaS-tooling report</title><link>https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/</guid><pubDate>Mon, 29 Jun 2026 00:21:17 +0000</pubDate><dc:date>2026-06-29T00:21:17Z</dc:date><category>ransomware</category><category>organized-crime</category><category>russia-nexus</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Background. The Gentlemen emerged in late 2025 as a RaaS operation founded by &quot;hastalamuerte&quot; (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo" data-tags="ransomware organized-crime russia-nexus" data-regions="global europe switzerland" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo"><a href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">ESET &quot;Killing me gently&quot; — a de-facto mid-year RaaS-tooling report</a></h3><p><strong>Background.</strong> The Gentlemen emerged in late 2025 as a RaaS operation founded by &quot;hastalamuerte&quot; (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT). ESET first hypothesised an in-house EDR-killer in February 2026; Group-IB and Check Point independently corroborated before the gang&#39;s own internal data leaked. By April 2026 the group accounted for ~10% of global ransomware activity, and Krebs (06-10) linked the alias to a named individual in Izhevsk, Russia.</p>
<p>ESET&#39;s 06-26 deep-dive into the leaked internal data is the most substantive published-in-window documentation of RaaS tooling structure, and reads as a mid-year complement to the W25 Check Point State of Ransomware Q1 2026. Three structural findings a detection engineer should register: (1) GentleKiller is a modular in-house framework with at least eight BYOVD variants, each impersonating a different vendor and abusing a different kernel driver — driver allow-listing alone is insufficient without process-injection-chain detection; (2) the group integrates <em>rival gangs&#39;</em> EDR killers (HexKiller from Warlock, ThrottleBlood shared with MedusaLocker/DragonForce, HavocKiller), so tooling overlap no longer implies operational overlap; (3) victims are selected centrally on FortiGate misconfiguration rather than geography, tying the Gentlemen victim pipeline directly to FortiBleed-style reconnaissance (§ 8). New BYOVD PoCs are operationalised within days of public release. (<a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.eset.com/us/about/newsroom/research/eset-research-gentlemen-ransomware-gang-edr-killers/" target="_blank" rel="noopener noreferrer">ESET Newsroom</a></div></article>]]></content:encoded></item><item><title>CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)</title><link>https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/</guid><pubDate>Mon, 29 Jun 2026 00:21:00 +0000</pubDate><dc:date>2026-06-29T00:21:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>pre-auth</category><category>rce</category><category>ot-ics</category><category>patch-available</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2025-67038</category><description><![CDATA[<p>Forescout Vedere Labs&#39; BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth rce ot-ics patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-67038/">CVE-2025-67038</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)</a></h3><p>Forescout Vedere Labs&#39; <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">BRIDGE:BREAK research</a> documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call. The in-window development is its CISA KEV listing on 2026-06-23 with confirmed in-the-wild exploitation (covered in <a href="https://ctipilot.ch/briefs/2026-06-24/" target="_blank" rel="noopener noreferrer">daily 06-24</a>) — the first BRIDGE:BREAK flaw to flip from research to active abuse. Serial-to-IP converters sit in front of OT, building-management and medical serial devices; firmware 2.0.0R1 closes it. This is an energy/water/healthcare exposure, not an IT one.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Forescout Vedere Labs&#39; BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Forescout Vedere Labs — BRIDGE:BREAK</a> · <a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>Unit 42: Chinese-speaking cluster CL-STA-1062 deploys the new TinyRCT .NET backdoor against SE-Asian government and energy targets via AppDomainManager</title><link>https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/</guid><pubDate>Sun, 28 Jun 2026 05:05:41 +0000</pubDate><dc:date>2026-06-28T05:05:41Z</dc:date><category>nation-state</category><category>espionage</category><category>china-nexus</category><category>apac</category><category>global</category><description><![CDATA[<p>Palo Alto Unit 42 (2026-06-25) documented CL-STA-1062, a Chinese-speaking cluster overlapping with Cisco Talos&#39;s UAT-7237, targeting government and state-owned energy infrastructure across Southeast Asia (Unit 42, 2026-06-25; The Hacker News, 2026-06-26).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new" data-tags="nation-state espionage china-nexus" data-regions="apac global" data-kind="research" data-priority="notable" data-discovered="2026-06-28T05:05:41Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new"><a href="https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/">Unit 42: Chinese-speaking cluster CL-STA-1062 deploys the new TinyRCT .NET backdoor against SE-Asian government and energy targets via AppDomainManager injection</a></h3><p>Palo Alto Unit 42 (2026-06-25) documented <strong>CL-STA-1062</strong>, a Chinese-speaking cluster overlapping with Cisco Talos&#39;s UAT-7237, targeting government and state-owned energy infrastructure across Southeast Asia (<a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-06-25</a>; <a href="https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-26</a>). Initial access is via internet-facing web apps and ASPX web shells (<code>T1505.003</code>), pivoting to a custom .NET backdoor, <strong>TinyRCT</strong>, delivered through AppDomainManager injection (<code>T1574.014</code>): a benign signed <code>chrome_setup.exe</code> ships in a ZIP alongside a malicious <code>chrome_setup.exe.config</code>, causing the .NET CLR to load <code>MyAppDomainManager.dll</code> from the same directory and bootstrap TinyRCT <em>in-process</em> — no child process, so it is low-visibility to EDR. TinyRCT beacons over HTTP with AES-128-CBC payloads, supports command execution via <code>cmd.exe</code>, chunked file exfiltration, and screen capture, and self-terminates unless run from <code>%LOCALAPPDATA%</code> or <code>%USERPROFILE%\Downloads</code> (anti-sandbox). Observed tooling includes Mimikatz, JuicyPotato and SoftEther VPN masqueraded as <code>vmtools.exe</code>. The defender value is the technique: <code>T1574.014</code> AppDomainManager injection is widely under-detected, and the same web-shell-to-in-process-.NET pattern is directly applicable to European public-sector web estates. Hunt for .NET <code>.config</code> files written into user-writable directories adjacent to signed executables, and DLL loads of <code>MyAppDomainManager.dll</code> from a signed PE&#39;s own directory (Sysmon EID 7).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">TinyRCT is a .NET-based RAT with capabilities including arbitrary command execution, file enumeration and exfiltration, screen capture, and self-destruct functionality. The malware communicates via HTTP with AES-128 encrypted payloads.</p><p class="entry-cite__quote">CL-STA-1062 represents a sustained, sophisticated threat targeting critical infrastructure across Asia-Pacific.</p><figcaption class="entry-cite__attr">Unit 42</figcaption></figure></div><div class="prov"><span>research</span><span>28 Jun 05:05Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV</title><link>https://ctipilot.ch/entries/2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau/</guid><pubDate>Wed, 24 Jun 2026 05:11:50 +0000</pubDate><dc:date>2026-06-24T05:11:50Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>pre-auth</category><category>rce</category><category>ot-ics</category><category>patch-available</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2025-67038</category><description><![CDATA[<p>CVE-2025-67038 (CVSS 9.8) is an OS command-injection flaw in the Lantronix EDS5000-series serial-to-IP device servers (EDS5008/5016/5032): the HTTP management interface concatenates an unsanitised request parameter into a shell command, letting an unauthenticated remote attacker execute commands as root.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth rce ot-ics patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-24T05:11:50Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-67038/">CVE-2025-67038</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau"><a href="https://ctipilot.ch/entries/2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau/">CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV</a></h3><p><strong>CVE-2025-67038</strong> (CVSS 9.8) is an OS command-injection flaw in the Lantronix EDS5000-series serial-to-IP device servers (EDS5008/5016/5032): the HTTP management interface concatenates an unsanitised request parameter into a shell command, letting an unauthenticated remote attacker execute commands as root. It is one of the 22 vulnerabilities Forescout Vedere Labs disclosed in April 2026 as <strong>BRIDGE:BREAK</strong>, covering Lantronix and Silex serial-to-Ethernet converters (<a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Forescout Vedere Labs, 2026-04-21</a>; <a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-04-20</a>). CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog on 2026-06-23 — the first confirmed in-the-wild exploitation of any BRIDGE:BREAK CVE, which makes it a priority for any operator who deferred the April advisory. EDS5000 units bridge legacy serial OT/ICS equipment (PLCs, relays, meters) onto IP networks, so a compromise yields a foothold adjacent to field devices, not just the converter. Forescout&#39;s disclosure cites fixed firmware <strong>2.0.0R1</strong> for the EDS5000 series; because the KEV-era advisory references later builds (, confirm the running firmware against Lantronix&#39;s current advisory rather than a single version number. Maps to <code>T1190</code> (Exploit Public-Facing Application). Mitigations: patch to the current EDS5000 firmware, replace default credentials, and segment serial-to-IP converters off any internet-reachable or flat OT segment; hunt management-interface auth logs for shell metacharacters in request fields and unexpected scans of TCP/80/443 on these devices.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerabilities, collectively tracked as BRIDGE:BREAK, can be exploited for OS command injection and remote code execution, firmware tampering, denial-of-service (DoS) attacks, and device takeovers.</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Lantronix has released two firmware updates that address the issues: 2.0.0R1 for EDS5000 series</p><figcaption class="entry-cite__attr">Forescout Vedere Labs</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>24 Jun 05:11Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Forescout Vedere Labs — BRIDGE:BREAK</a> · <a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>Energy, water &amp; OT — perimeter and process failures, with an OT-adjacent halt</title><link>https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/</guid><pubDate>Mon, 22 Jun 2026 00:14:51 +0000</pubDate><dc:date>2026-06-22T00:14:51Z</dc:date><category>data-breach</category><category>ot-ics</category><category>apac</category><category>global</category><description><![CDATA[<p>Critical-infrastructure exposure ran from cyber intrusion to physical mishandling.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad" data-tags="data-breach ot-ics" data-regions="apac global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:51Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="energy-water-ot-perimeter-and-process-failures-with-an-ot-ad"><a href="https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/">Energy, water &amp; OT — perimeter and process failures, with an OT-adjacent halt</a></h3><p>Critical-infrastructure exposure ran from cyber intrusion to physical mishandling. Handala&#39;s Cal Water breach (above) and the Rockwell ICS advisory batch (§ 3) bracket the cyber end; at the process end, a Kyushu Electric subsidiary lost an unencrypted portable SSD holding ~10.9M customer records — reportedly Japan&#39;s largest personal-data breach (<a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-14</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). The Gentlemen&#39;s Mackay Sugar claim (§ 2) halted milling at two of three mills — an OT-adjacent production impact even without confirmed OT-network compromise.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer — Kyushu Electric</a></div></article>]]></content:encoded></item><item><title>CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH</title><link>https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/</guid><pubDate>Mon, 22 Jun 2026 00:14:46 +0000</pubDate><dc:date>2026-06-22T00:14:46Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>dos</category><category>pre-auth</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-0647</category><category>CVE-2026-0646</category><category>CVE-2026-11317</category><category>CVE-2025-13036</category><description><![CDATA[<p>Rockwell disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 and CISA ICS-CERT, headlined by an unauthenticated FLEX I/O password reset (CVE-2026-0647, 9.4) and Logix CIP denial-of-service flaws (CISA ICS-CERT ICSA-26-167-05; NCSC-CH Security Hub; daily 06-18).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic" data-tags="vulnerabilities ot-ics auth-bypass dos pre-auth" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:46Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0647/">CVE-2026-0647 +3</a></div><h3 class="f-h" id="cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH</a></h3><p>Rockwell disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 and CISA ICS-CERT, headlined by an unauthenticated FLEX I/O password reset (CVE-2026-0647, 9.4) and Logix CIP denial-of-service flaws (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-05</a>; <a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). Directly relevant to Swiss/EU energy, water and manufacturing OT operators. Patch on the OT change-management cycle and verify these controllers are not reachable from IT networks.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-05</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article>]]></content:encoded></item><item><title>CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH</title><link>https://ctipilot.ch/entries/2026-06-18/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-18/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/</guid><pubDate>Thu, 18 Jun 2026 05:10:32 +0000</pubDate><dc:date>2026-06-18T05:10:32Z</dc:date><category>ot-ics</category><category>vulnerabilities</category><category>auth-bypass</category><category>dos</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-0647</category><category>CVE-2026-0646</category><category>CVE-2026-11317</category><category>CVE-2025-13036</category><description><![CDATA[<p>Rockwell FLEX I/O adapters: unauthenticated web-interface password reset (CVE-2026-0647, CVSS 9.4), flagged by NCSC-CH. A crafted HTTP GET resets the admin password on 1794-AENTR/AENTRXT EtherNet/IP adapters; companion CVEs crash Logix controllers via malformed CIP (CISA ICS-CERT, 2026-06-16). Fixed in firmware 2.013; segment OT now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-18/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic" data-tags="ot-ics vulnerabilities auth-bypass dos pre-auth patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-18T05:10:32Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0647/">CVE-2026-0647 +3</a></div><h3 class="f-h" id="cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic"><a href="https://ctipilot.ch/entries/2026-06-18/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH</a></h3><p>Rockwell Automation disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 (<a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub, 2026-06-17</a>). <strong>CVE-2026-0647</strong> (CVSS 9.4) lets an unauthenticated attacker reset the admin password on 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP adapters (firmware ≤ V2.012) by sending a crafted HTTP GET to the adapter&#39;s embedded web server, enabling full takeover and I/O disruption (<code>T0866</code>) (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT, 2026-06-16</a>). Companion <strong>CVE-2026-0646</strong> (CVSS 7.5) is a CIP-handling DoS on the same adapter requiring a manual reset; <strong>CVE-2026-11317</strong> (CVSS 7.5) causes a major non-recoverable fault on CompactLogix/ControlLogix 5370/5570 controllers via a crafted CIP message, requiring a full program download to recover (<code>T0814</code>) (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03" target="_blank" rel="noopener noreferrer">CISA ICS-CERT, 2026-06-16</a>); and <strong>CVE-2025-13036</strong> (CVSS 7.7) is an authentication bypass in FactoryTalk Historian Site Edition. FLEX I/O fixes ship in firmware 2.013 (Rockwell SD1775); exploitation status is unknown for all. Where firmware cannot be applied immediately, restrict CIP and HTTP/HTTPS access to these devices to engineering workstations via OT segmentation.</p><div class="prov"><span>vulnerability</span><span>18 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-18/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-05</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-03</a></div></article>]]></content:encoded></item><item><title>Healthcare &amp; energy — large-scale personal-data exposure from theft and from mishandling</title><link>https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/</guid><pubDate>Sun, 14 Jun 2026 23:57:29 +0000</pubDate><dc:date>2026-06-14T23:57:29Z</dc:date><category>data-breach</category><category>apac</category><description><![CDATA[<p>Two contrasting root causes in one week. Novo Nordisk disclosed the theft of non-public data including personal data after an external party accessed internal systems (§ 5) — a deliberate intrusion against pharma.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th" data-tags="data-breach" data-regions="apac" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-energy-large-scale-personal-data-exposure-from-th"><a href="https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/">Healthcare &amp; energy — large-scale personal-data exposure from theft and from mishandling</a></h3><p>Two contrasting root causes in one week. Novo Nordisk disclosed the theft of non-public data including personal data after an external party accessed internal systems (§ 5) — a deliberate intrusion against pharma. At the other end, Kyushu Electric&#39;s transmission/distribution subsidiary lost an <strong>unencrypted</strong> portable SSD holding personal records for roughly 10.9 million customers — reportedly Japan&#39;s largest personal-data breach, and an entirely preventable one (<a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). For utilities and healthcare data custodians the joint lesson is unglamorous: full-disk encryption on removable media is still the control that turns a lost-device headline into a non-event.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2</title><link>https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/</guid><pubDate>Sun, 14 Jun 2026 05:00:05 +0000</pubDate><dc:date>2026-06-14T05:00:05Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>ai-abuse</category><category>identity</category><category>europe</category><category>global</category><description><![CDATA[<p>APT28 (GRU Unit 26165) tradecraft has moved to LLM-driven and cloud-native evasion. Sekoia documents LameHug — the first APT28 stealer that generates exfiltration code at runtime via a hosted LLM — plus BeardShell C2 over consumer cloud-storage providers and the FrostArmada SOHO-router DNS-hijack AiTM campaign against Microsoft 365 (Sekoia TDR, 2026-06-11).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat" data-tags="nation-state espionage russia-nexus ai-abuse identity" data-regions="europe global" data-kind="research" data-priority="high" data-discovered="2026-06-14T05:00:05Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat"><a href="https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/">Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2</a></h3><p>Sekoia&#39;s Threat Detection &amp; Research team published a tradecraft-evolution retrospective on APT28 (Fancy Bear / Forest Blizzard), and the operationally relevant material is the 2025–2026 tooling (<a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-11</a>). Three developments stand out for European defenders. <strong>LameHug</strong> is the first documented APT28 infostealer that delegates its logic to a large language model: base64-encoded prompts are sent to Alibaba&#39;s Qwen 2.5-Coder model via the Hugging Face inference API to generate collection and exfiltration code on the fly, observed against Ukrainian government targets — meaning the malicious behaviour is not statically present in the binary. <strong>BeardShell</strong> is a C++ backdoor that rotates its command-and-control across consumer cloud-storage providers (Koofr, Icedrive, Filen), defeating domain/IP blocklisting because the traffic is ordinary HTTPS to legitimate services. <strong>FrostArmada</strong> (April 2026) is a SOHO-router DNS-hijack campaign — 18,000-plus unique IPs across 120-plus countries — that rewrites DHCP/DNS on MikroTik and TP-Link devices to mount adversary-in-the-middle attacks against Microsoft 365 sign-ins (<code>T1557</code> Adversary-in-the-Middle, <code>T1071.001</code> Web Protocols for the cloud C2). Sekoia notes APT28&#39;s GooseEgg implant (CVE-2022-38028) ran for roughly five years before public disclosure — a reminder that current tools likely carry a similar blind-spot horizon.</p>
<p><strong>Why it matters to us:</strong> NATO European ministries, defence suppliers and critical-infrastructure operators are named in the targeting. The detection priorities are concrete and IoC-free: hunt cloud-storage beaconing to Koofr/Icedrive/Filen from non-user workstations, alert on outbound traffic to Hugging Face inference endpoints from Windows hosts, monitor MikroTik/TP-Link DNS-setting changes in network-device logs, and treat Office documents delivered through Signal Desktop as a Mark-of-the-Web bypass risk — Sekoia notes APT28 uses the messenger to deliver Office lures that arrive without the Mark-of-the-Web protection.</p><div class="prov"><span>research</span><span>14 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a></div></article>]]></content:encoded></item><item><title>Kyushu Electric subsidiary loses an unencrypted SSD with 10.9 million customer records — reportedly Japan&#39;s largest personal-data breach</title><link>https://ctipilot.ch/entries/2026-06-14/kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-14/kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10/</guid><pubDate>Sun, 14 Jun 2026 05:00:02 +0000</pubDate><dc:date>2026-06-14T05:00:02Z</dc:date><category>data-breach</category><category>insider-threat</category><category>apac</category><description><![CDATA[<p>Kyushu Electric Power Transmission and Distribution disclosed on 8 June that a palm-sized portable SSD holding personal records for roughly 10.9 million customers went missing from a restricted server room; a contractor had backed up data to the drive on 27 April and stored it in a cabinet that was found unlocked and …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-14/kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10" data-tags="data-breach insider-threat" data-regions="apac" data-kind="incident" data-priority="notable" data-discovered="2026-06-14T05:00:02Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10"><a href="https://ctipilot.ch/entries/2026-06-14/kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10/">Kyushu Electric subsidiary loses an unencrypted SSD with 10.9 million customer records — reportedly Japan&#39;s largest personal-data breach</a></h3><p>Kyushu Electric Power Transmission and Distribution disclosed on 8 June that a palm-sized portable SSD holding personal records for roughly 10.9 million customers went missing from a restricted server room; a contractor had backed up data to the drive on 27 April and stored it in a cabinet that was found unlocked and empty on 26 May (<a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-11</a>). The drive held names, service addresses, phone numbers, electricity-usage data and retail-supplier names — all stored unencrypted and without password protection; no financial data was included (<a href="https://www.techtimes.com/articles/318287/20260612/japan-data-breach-kyushu-electric-loses-unencrypted-ssd-109-million-customer-records.htm" target="_blank" rel="noopener noreferrer">TechTimes, 2026-06-12</a>). Kyushu Electric notified Japan&#39;s Personal Information Protection Commission and METI, which set an 8 July deadline for a full account.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">This is a pure physical-media-control failure, the kind of exposure EU operators owe under NIS2 Article 21(2)(h). Audit whether backup media that leaves a server room is encrypted at rest with hardware-enforced AES, asset-tagged and access-logged — a single unlocked cabinet here produced a regulatory incident and total exposure with no remote attacker involved.</div></aside><div class="prov"><span>incident</span><span>14 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/kyushu-electric-subsidiary-loses-an-unencrypted-ssd-with-10/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.techtimes.com/articles/318287/20260612/japan-data-breach-kyushu-electric-loses-unencrypted-ssd-109-million-customer-records.htm" target="_blank" rel="noopener noreferrer">TechTimes</a></div></article>]]></content:encoded></item><item><title>Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman&#39;s 4× surge against Romanian energy, and the IT-adjacent intrusion</title><link>https://ctipilot.ch/entries/2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri/</guid><pubDate>Wed, 10 Jun 2026 05:00:19 +0000</pubDate><dc:date>2026-06-10T05:00:19Z</dc:date><category>ransomware</category><category>ot-ics</category><category>organized-crime</category><category>iran-nexus</category><category>europe</category><category>global</category><description><![CDATA[<p>Dragos&#39; quarterly industrial-ransomware report (published 3 June) is the single periodic landscape report treated in this brief; the focus below is only on what changes a Swiss/EU public-sector and critical-infrastructure SOC&#39;s posture, not the full survey (Dragos, 2026-06-03).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri" data-tags="ransomware ot-ics organized-crime iran-nexus" data-regions="europe global" data-kind="threat" data-priority="notable" data-discovered="2026-06-10T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="dragos-q1-2026-industrial-ransomware-analysis-1-020-industri"><a href="https://ctipilot.ch/entries/2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri/">Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman&#39;s 4× surge against Romanian energy, and the IT-adjacent intrusion pattern</a></h3><p>Dragos&#39; quarterly industrial-ransomware report (published 3 June) is the single periodic landscape report treated in this brief; the focus below is only on what changes a Swiss/EU public-sector and critical-infrastructure SOC&#39;s posture, not the full survey (<a href="https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026" target="_blank" rel="noopener noreferrer">Dragos, 2026-06-03</a>). This treatment is logged once under the annual/periodic-report rule and will not be re-summarised; specific findings may be cited as context in later briefs.</p>
<p><strong>The shape of the quarter.</strong> Dragos recorded 1,020 ransomware incidents against industrial organisations in Q1 2026, with manufacturing accounting for 62% of victims and Europe representing roughly a quarter of all incidents (<a href="https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026" target="_blank" rel="noopener noreferrer">Dragos, 2026-06-03</a>). The defining operational characteristic — and the most important point for defenders — is that the overwhelming majority of these incidents struck enterprise IT systems adjacent to OT rather than ICS-specific malware touching SCADA/PLC logic; OT processes generally remained technically intact even where operational disruption occurred. The practical implication is that the OT ransomware threat for European operators is, in the near term, an IT-segmentation and identity problem at the IT/OT boundary, not a protocol-level ICS-exploitation problem.</p>
<p><strong>Initial-access and post-compromise tradecraft.</strong> The dominant access vectors Dragos attributes are exploitation of internet-facing services, credentials harvested by infostealers, and abuse of VPN infrastructure — the same access classes this brief covers daily (edge-appliance RCE, infostealer credential theft, VPN auth bypass). Post-compromise, operators leaned on legitimate remote-management tooling — AnyDesk, SimpleHelp, Atera, N-able, ConnectWise ScreenConnect — for persistence and lateral movement, which is the detection-engineering takeaway: RMM-tool execution is the high-yield hunt surface (T1133 External Remote Services, T1078 Valid Accounts, T1219 Remote Access Software, T1486 Data Encrypted for Impact). Notably, ICS engineering firms (≈90 incidents) and equipment manufacturers (≈49) were disproportionately hit — these are supply-chain stepping-stones into operator networks, so European operators should treat their ICS integrators and engineering-services vendors as part of their own attack surface.</p>
<p><strong>The European energy signal.</strong> The quarter&#39;s sharpest regional finding is the surge of &quot;The Gentleman&quot; RaaS, which more than quadrupled from Q4 2025 to 83 incidents and explicitly targeted Romanian energy and water infrastructure: coal producer Complexul Energetic Oltenia (December 2025), national water authority Apele Române (≈1,000 systems), and — alongside Qilin — oil-pipeline operator Conpet (February 2026) (<a href="https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026" target="_blank" rel="noopener noreferrer">Dragos, 2026-06-03</a>). Qilin (198 incidents) led overall, followed by Akira (100), The Gentleman (83), LockBit 5.0 (71) and Play (53). Dragos also flags the Iranian-linked Pay2Key RaaS intensifying since the July 2025 Israel-Iran conflict resumption — a geopolitical-nexus actor worth tracking for European critical-infrastructure operators given spillover targeting patterns.</p>
<p><strong>Defender actions this report supports.</strong> Treat the IT/OT boundary as the primary ransomware containment line: enforce strict segmentation and unidirectional/jump-host access between enterprise IT and OT, deny RMM tooling on OT-adjacent hosts by default and alert on any execution, and prioritise the same internet-facing-service and VPN patching this brief tracks for OT-adjacent enterprise estates. For operators dependent on ICS engineering/integration vendors, extend monitoring and access controls to those vendors&#39; remote-access paths. [SINGLE-SOURCE] — Dragos is a HIGH-reliability OT/ICS specialist; specific victim attributions trace to Dragos&#39; own reporting.</p><div class="prov"><span>threat</span><span>10 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026" target="_blank" rel="noopener noreferrer">Dragos, 2026-06-03</a></div></article>]]></content:encoded></item><item><title>ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity</title><link>https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/</guid><pubDate>Mon, 01 Jun 2026 05:00:16 +0000</pubDate><dc:date>2026-06-01T05:00:16Z</dc:date><category>hacktivism</category><category>nation-state</category><category>vulnerabilities</category><category>europe</category><description><![CDATA[<p>NCSC-CH pre-event advisory: hacktivist DDoS against Swiss and event-linked infrastructure expected 15–17 June (G7 Évian). NoName057(16) Bürgenstock 2024 pattern; public-sector digital services at direct elevated risk — pre-stage mitigations now. (daily, NCSC-CH)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten" data-tags="hacktivism nation-state vulnerabilities" data-regions="europe" data-kind="annual-report" data-priority="high" data-discovered="2026-06-01T05:00:16Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten"><a href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity</a></h3><p>Published 28 May 2026 (<a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA</a>; follow-up coverage 2 June in <a href="https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>). The headline finding is structural: a persistent &quot;risk zone&quot; where criticality exceeds maturity comprising public administration, health, railway, maritime, ICT service management, space, and drinking/waste water. Public administration receives <strong>nearly 63% of all EU hacktivist attacks</strong> and is the most consistently targeted sector, yet roughly one-third of entities lack structured cybersecurity expertise at management level and about half provide no cybersecurity training to management. Water sector: one in three entities has never conducted a risk assessment. The high-maturity sectors — banking, electricity, telecoms, trust services, aviation, financial market infrastructures — share a common driver: regulatory pressure backed by supervisory capacity with real enforcement. Only 16% of NIS2-affected entities consider themselves fully compliant; 41% face uncertainty about national obligations. For NIS2 national authorities: sectors without comparable oversight structures (ICT service management, space) lag structurally. For public-sector SOC managers specifically: the elevated hacktivist pressure confirmed by ENISA should cross-reference directly against current threat-model assumptions and DDoS mitigation capacity, particularly in the June 15–17 G7 Évian window.</p><div class="prov"><span>annual-report</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA NIS360 2026</a> · <a href="https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html" target="_blank" rel="noopener noreferrer">Security Affairs</a></div></article>]]></content:encoded></item><item><title>ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset</title><link>https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/</guid><pubDate>Sat, 30 May 2026 05:00:06 +0000</pubDate><dc:date>2026-05-30T05:00:06Z</dc:date><category>nation-state</category><category>espionage</category><category>supply-chain</category><category>russia-nexus</category><category>north-korea-nexus</category><category>china-nexus</category><category>europe</category><category>global</category><description><![CDATA[<p>ESET APT Activity Report Q4 2025–Q1 2026: Sandworm wiper targets Polish NATO energy company; Lazarus targets European drone manufacturers; UNC5221 deploys a new SPAWN toolset implant against Ivanti VPN appliances (ESET WeLiveSecurity, 2026-05-28).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na" data-tags="nation-state espionage supply-chain russia-nexus north-korea-nexus china-nexus" data-regions="europe global" data-kind="annual-report" data-priority="high" data-discovered="2026-05-30T05:00:06Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na"><a href="https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/">ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset</a></h3><p>ESET published its APT Activity Report covering October 2025 through March 2026 on 28 May 2026 (<a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity, 2026-05-28</a>). EU- and NATO-relevant findings for public-sector defenders: Sandworm (Russia/GRU) intensified destructive winter operations against Ukrainian infrastructure and targeted a Polish energy company in December 2025 — a NATO member state critical-infrastructure attack attributed with medium confidence; this represents continued Sandworm willingness to conduct wiper operations beyond Ukraine&#39;s borders. Sednit/APT28 deployed Covenant and BeardShell implants against Ukrainian military, drone manufacturers, and logistics companies. Lazarus Group ran Operation DreamJob targeting European drone manufacturers — ESET assesses this as technology acquisition for North Korea&#39;s weapons programme. Operation DangerousPassword compromised the axios JavaScript library (100+ million weekly npm downloads), injecting trojanised code and demonstrating ongoing North Korea supply-chain interest in developer ecosystem targeting. UNC5221 (China-nexus) deployed a new implant assessed as part of the SPAWN toolset, specifically targeting Ivanti VPN appliances (Connect Secure, Policy Secure); organisations running unpatched Ivanti VPN should audit for SPAWN toolset artefacts including SPAWNANT installer, SPAWNMOLE tunneller, SPAWNSNAIL SSH backdoor, and SPAWNSLOTH log-tampering utility. The report PDF is available at <code>https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf</code>. Key defender actions: (a) confirm Sandworm wiper detection capability (file-destruction followed by MBR/VBR overwrite patterns, VSS deletion); (b) review Ivanti VPN logs for SPAWN footprints per <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a" target="_blank" rel="noopener noreferrer">CISA AA24-060A</a> indicators; (c) audit npm dependency trees for axios versions &lt;1.8.0 or 0.x released after the DangerousPassword campaign window.</p><div class="prov"><span>annual-report</span><span>30 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain</title><link>https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain/</guid><pubDate>Fri, 29 May 2026 05:00:15 +0000</pubDate><dc:date>2026-05-29T05:00:15Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>auth-bypass</category><category>infostealer</category><category>supply-chain</category><category>cisa-kev</category><category>europe</category><category>switzerland</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-35616</category><description><![CDATA[<p>Background. CVE-2026-35616 is the improper-access-control (CWE-284) flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6 disclosed on 2026-04-04 and added to the CISA KEV catalog on 2026-04-06; vendor coverage at disclosure focused on the auth-bypass primitive, with Arctic Wolf&#39;s 2026-05-27 publication being the …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain" data-tags="vulnerabilities actively-exploited pre-auth auth-bypass infostealer supply-chain cisa-kev" data-regions="europe switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-29T05:00:15Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35616/">CVE-2026-35616</a><span class="b exp">exploited</span></div><h3 class="f-h" id="forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain"><a href="https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain/">FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain</a></h3><p><strong>Background.</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer"><code>CVE-2026-35616</code></a> is the <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35616" target="_blank" rel="noopener noreferrer">improper-access-control (CWE-284)</a> flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6 disclosed on 2026-04-04 and added to the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA KEV catalog</a> on 2026-04-06; vendor coverage at disclosure focused on the auth-bypass primitive, with <a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" target="_blank" rel="noopener noreferrer">Arctic Wolf&#39;s 2026-05-27 publication</a> being the first public exploitation-chain narrative tying the bypass to a downstream credential-theft payload (EKZ Infostealer). The vulnerability class — header-spoofing trust against a fronting reverse proxy — is the same shape as Microsoft&#39;s <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659" target="_blank" rel="noopener noreferrer"><code>CVE-2026-45659</code></a> (separate product, same <code>X-Forwarded-*</code> trust pattern), and the EKZ delivery via the trusted EMS management channel is a defender-relevant escalation of the <em>trusted-update-channel-as-supply-chain</em> pattern previously associated with vendor-update vehicles.</p>
<p><strong>Vulnerable component.</strong> The FortiClient EMS server&#39;s management API trusts the HTTP request header <code>X-SSL-CLIENT-VERIFY</code> to convey client-certificate validation state — the <a href="https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-35616.yaml" target="_blank" rel="noopener noreferrer">ProjectDiscovery Nuclei template for CVE-2026-35616</a> sends exactly that header with value <code>SUCCESS</code> as the entire exploit payload. The intended deployment model is that a fronting reverse proxy or load balancer performs the mutual-TLS handshake and stamps that header into the upstream request before forwarding to EMS. The server does not independently confirm that the negotiating peer presented a valid client certificate; it accepts the header as-is. An unauthenticated attacker on a network path to the EMS management plane spoofs <code>X-SSL-CLIENT-VERIFY: SUCCESS</code> and reaches privileged API endpoints without authenticating. CVSS:3.1 base 9.1 (<code>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</code>). EPSS 43.2 % at the 97.6th percentile.</p>
<p><strong>Exploitation prerequisites.</strong> Network reach to the EMS management API (typically over the management VLAN or, in misconfigured deployments, directly on the internet); a vulnerable EMS server version 7.4.5 or 7.4.6; no other authentication. AD-joined EMS, MFA-protected EMS console accounts, and other authentication controls applied to interactive logons are <strong>not</strong> in the request path the spoofed header bypasses.</p>
<p><strong>Exploitation chain in the Arctic Wolf campaign.</strong> Mapped to MITRE ATT&amp;CK throughout. Initial access: header-spoofing against EMS management API (<a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a> Exploit Public-Facing Application). Persistence and distribution: attackers modify Remote Access Profile configurations through the now-privileged API endpoint to push an <em>Update task</em> to managed FortiClient endpoints — the malicious PowerShell payload is delivered through the EMS update channel under the trusted <code>fortitray.exe</code> parent process and is therefore signed in the operational sense (<a href="https://attack.mitre.org/techniques/T1195/002/" target="_blank" rel="noopener noreferrer">T1195.002</a> Compromise Software Supply Chain — EMS as distribution vector; <a href="https://attack.mitre.org/techniques/T1218/" target="_blank" rel="noopener noreferrer">T1218</a> System Binary Proxy Execution via the trusted FortiTray binary). The PowerShell payload fetches <code>FortiEndpoint_Patch.exe</code>, presented to operators and AV as a legitimate Fortinet patch — actually the EKZ Infostealer. Defense evasion: EKZ copies itself into per-browser profile directories under each user&#39;s <code>AppData\Local\Google\Chrome\User Data\&lt;profile&gt;</code>, <code>AppData\Roaming\Mozilla\Firefox\Profiles\&lt;profile&gt;</code> and equivalents for Microsoft Edge, LibreWolf, Waterfox, Pale Moon, Thunderbird, defeating elevation-validation checks that gate access to encrypted credential and cookie stores via <a href="https://attack.mitre.org/techniques/T1555/003/" target="_blank" rel="noopener noreferrer"><code>nss3.dll</code></a> (<a href="https://attack.mitre.org/techniques/T1555/003/" target="_blank" rel="noopener noreferrer">T1555.003</a> Credentials from Web Browsers). Collection and exfiltration: encrypted credential stores and session cookies dumped, then exfiltrated via HTTP POST to actor infrastructure (<a href="https://attack.mitre.org/techniques/T1071/001/" target="_blank" rel="noopener noreferrer">T1071.001</a>, <a href="https://attack.mitre.org/techniques/T1041/" target="_blank" rel="noopener noreferrer">T1041</a>). The single-server-to-fleet cascade is the campaign&#39;s defining property: one compromised EMS server simultaneously distributes EKZ to <em>every</em> managed endpoint in the deployment.</p>
<p><strong>Affected and patched versions.</strong> Affected: FortiClient EMS 7.4.5 and 7.4.6 — only those two builds; earlier branches and 7.4.7+ are not vulnerable. Patched: FortiClient EMS 7.4.7. The <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-099</a> advisory carries the vendor&#39;s complete affected-version matrix and the out-of-band hotfix references for organisations that cannot move to 7.4.7 in their change window.</p>
<p><strong>Detection concepts.</strong> None of these require IOC sharing — they are behavioural patterns against the campaign&#39;s mechanics.</p>
<ul><li><strong>EMS management-API access without proper mTLS handshake.</strong> Where the EMS server logs <code>X-SSL-CLIENT-VERIFY</code> along with peer-certificate fingerprint, alert on any request carrying <code>SUCCESS</code> with no fingerprint or a fingerprint not from the operator-trusted CA. Where the reverse proxy in front of EMS logs the mTLS state, alert on EMS log records claiming success that do not correspond to a proxy log line with a matched negotiation.</li><li><strong>Unsolicited Remote Access Profile modification.</strong> Alert on any modification to RAP / endpoint-policy XML or its API equivalents that was not initiated from an EMS admin console session in the change-management window.</li><li><strong>Push-from-EMS installers that are unsigned or have anomalous filenames.</strong> EMS-pushed installers that are neither <code>FortiClientSetup_*.exe</code> nor a vendor-signed update should never reach a managed endpoint; alert on Sysmon EID 1 where parent process is the FortiClient managed-service binary and child is an unsigned binary with <code>--silent</code> install flags. The fake <code>FortiEndpoint_Patch.exe</code> name from this campaign deviates from the genuine <code>FortiClientSetup_*.exe</code> naming convention.</li><li><strong>Browser-profile-directory writes from non-browser processes.</strong> Sysmon EID 11 (<code>FileCreate</code>) targeting <code>AppData\Local\Google\Chrome\User Data\&lt;profile&gt;</code> (and equivalents), where the source image is not the browser binary itself, the parent process is not a known package manager, and the file extension is <code>.exe</code> / <code>.dll</code>. This is the EKZ self-copy primitive.</li><li><strong><code>fortitray.exe</code> spawning PowerShell with <code>-EncodedCommand</code> / <code>-enc</code>.</strong> PowerShell <code>-enc</code> from a Fortinet trusted-binary parent process is the in-campaign behaviour Arctic Wolf documents and is not expected operationally.</li><li><strong>Outbound HTTP POST from an EMS-service account to non-Fortinet endpoints.</strong> Easy network-layer signal on egress firewall / SWG logs.</li></ul>
<p><strong>Hardening.</strong> Patch is the only complete remediation. Immediately upgrade FortiClient EMS to 7.4.7. While the change window is being scheduled, compensating controls: (1) block EMS management API ports from the internet completely, restricting access to a defined management network; (2) enforce mTLS termination at the proxy and have the proxy strip / overwrite the <code>X-SSL-CLIENT-VERIFY</code> header before forwarding to EMS, removing the spoof primitive entirely; (3) require admin-access MFA for the EMS console and rotate EMS service-account credentials post-patch; (4) audit all RAP / endpoint-policy XML against a known-good baseline. Post-incident: assume managed endpoints in any environment running 7.4.5 / 7.4.6 may have received EKZ; rotate cached browser credentials for sensitive accounts and treat session cookies in managed-endpoint browser stores as compromised.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Arctic Wolf has observed threat actors actively exploiting CVE-2026-35616 in the FortiClient EMS management API to deliver a novel infostealer payload</p><figcaption class="entry-cite__attr">Arctic Wolf</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Threat actors leveraged this weakness to modify Remote Access Profile configurations and inject malicious PowerShell scripts into managed endpoints. The payload, designated EKZ Infostealer, was disguised as a legitimate Fortinet patch</p><figcaption class="entry-cite__attr">Arctic Wolf Labs</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" target="_blank" rel="noopener noreferrer">Arctic Wolf — EKZ Infostealer campaign</a> · <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-099</a> · <a href="https://thehackernews.com/2026/05/threat-actors-exploit-critical.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-28</a></div></article>]]></content:encoded></item><item><title>FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel</title><link>https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek/</guid><pubDate>Fri, 29 May 2026 05:00:01 +0000</pubDate><dc:date>2026-05-29T05:00:01Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>auth-bypass</category><category>cisa-kev</category><category>infostealer</category><category>supply-chain</category><category>europe</category><category>switzerland</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-35616</category><description><![CDATA[<p>Arctic Wolf documents active ITW exploitation of CVE-2026-35616 (Fortinet FortiClient EMS 7.4.5–7.4.6, CVSS 9.1, CISA KEV since 2026-04-06). The pre-auth X-SSL-CLIENT-VERIFY header bypass is being abused to push the EKZ Infostealer to managed endpoints as a fake FortiEndpoint_Patch.exe signed under the legitimate fortitray.exe parent. Anything on 7.4.5/7.4.6 must move to 7.4.7 immediately; managed endpoints need browser-profile-write hunts.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-29/forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek" data-tags="vulnerabilities actively-exploited pre-auth auth-bypass cisa-kev infostealer supply-chain" data-regions="europe switzerland global" data-kind="threat" data-priority="high" data-discovered="2026-05-29T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35616/">CVE-2026-35616</a><span class="b exp">exploited</span></div><h3 class="f-h" id="forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek"><a href="https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek/">FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel</a></h3><p>Arctic Wolf Labs published technical evidence on 2026-05-27 of an <a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" target="_blank" rel="noopener noreferrer">in-the-wild campaign abusing CVE-2026-35616</a>, the <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer">CWE-284 improper-access-control flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6</a> (CVSS 9.1; on <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35616" target="_blank" rel="noopener noreferrer">CISA KEV since 2026-04-06</a>). The vulnerable code path trusts the <code>X-SSL-CLIENT-VERIFY</code> HTTP header set by a fronting reverse proxy or load balancer instead of validating client-certificate state itself; an unauthenticated attacker on the network spoofs the header to reach privileged management APIs. In the observed campaign, attackers modify Remote Access Profile configurations to push a PowerShell payload signed under the trusted <code>fortitray.exe</code> binary that fetches <code>FortiEndpoint_Patch.exe</code> — actually the EKZ Infostealer. EKZ copies itself into Chromium/Gecko browser-profile directories (Chrome, Microsoft Edge, Firefox, LibreWolf, Waterfox, Pale Moon, Thunderbird) to clear elevation-validation checks, then dumps encrypted credential and cookie stores via <code>nss3.dll</code>. Compromise of a single EMS server cascades to every managed endpoint. Patch is FortiClient EMS 7.4.7.</p>
<p><strong>Why it matters to us:</strong> FortiClient EMS is widely deployed across Swiss federal and cantonal network-security estates and across EU public-sector networks. Deep-dive treatment in § 5 below.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Arctic Wolf Labs published technical evidence on 2026-05-27 of an in-the-wild campaign abusing CVE-2026-35616, the CWE-284 improper-access-control flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6 (CVSS 9.1; on CISA KEV since 2026-04-06).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>threat</span><span>29 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-29/forticlient-ems-cve-2026-35616-actively-exploited-to-push-ek/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" target="_blank" rel="noopener noreferrer">Arctic Wolf — EKZ Infostealer campaign</a> · <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-099</a> · <a href="https://thehackernews.com/2026/05/threat-actors-exploit-critical.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-28</a></div></article>]]></content:encoded></item><item><title>CVE-2026-9642 — Delta Electronics DIAView SCADA: incomplete fix for prior unauthenticated remote database access (CVE-2025-62582)</title><link>https://ctipilot.ch/entries/2026-05-27/cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-27/cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix/</guid><pubDate>Wed, 27 May 2026 05:00:02 +0000</pubDate><dc:date>2026-05-27T05:00:02Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>pre-auth</category><category>info-disclosure</category><category>no-patch</category><category>global</category><category>no-patch</category><category>CVE-2026-9642</category><description><![CDATA[<p>Tenable Research disclosed that the vendor&#39;s mitigation for CVE-2025-62582 (unauthenticated remote database access in Delta Electronics DIAView, an HMI/SCADA application) is bypassable: an unauthenticated remote attacker can still reach the databases configured in a DIAView project despite the prior fix (CVSS 3.1 = …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-27/cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix" data-tags="vulnerabilities ot-ics pre-auth info-disclosure no-patch" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-27T05:00:02Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-9642/">CVE-2026-9642</a></div><h3 class="f-h" id="cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix"><a href="https://ctipilot.ch/entries/2026-05-27/cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix/">CVE-2026-9642 — Delta Electronics DIAView SCADA: incomplete fix for prior unauthenticated remote database access (CVE-2025-62582)</a></h3><p>Tenable Research disclosed that the vendor&#39;s mitigation for CVE-2025-62582 (unauthenticated remote database access in Delta Electronics DIAView, an HMI/SCADA application) is bypassable: an unauthenticated remote attacker can still reach the databases configured in a DIAView project despite the prior fix (CVSS 3.1 = 9.8) (<a href="https://www.tenable.com/security/research/tra-2026-44" target="_blank" rel="noopener noreferrer">Tenable Research TRA-2026-44, 2026-05-26</a>). Delta is a major industrial-automation vendor with installations across EU manufacturing and energy OT estates, and Switzerland has a sizeable Delta customer base in precision manufacturing. Because the original CVE-2025-62582 fix is incomplete, organisations that believed they had remediated remain exposed (<code>T1190</code> Exploit Public-Facing Application against the OT historian/database layer). Treat any DIAView project reachable from IT or internet segments as still vulnerable: confirm a corrected fix directly with Delta rather than assuming the earlier patch closed the path, enforce strict IT/OT segmentation so the historian database tier is unreachable from general networks, and monitor for connections to DIAView database listener ports from non-engineering workstations. Single-source on Tenable Research as of this run; no second independent report located in-window.</p>
<h4 id="cve-summary-table">CVE Summary Table</h4>
<div class="table-wrap"><table>
<thead><tr>
<th style="text-align:left">CVE</th>
<th style="text-align:left">Product</th>
<th style="text-align:left">CVSS</th>
<th style="text-align:left">EPSS</th>
<th style="text-align:left">KEV</th>
<th style="text-align:left">Exploited</th>
<th style="text-align:left">Patch</th>
<th style="text-align:left">Source</th>
</tr></thead><tbody>
<tr>
<td style="text-align:left">CVE-2026-9312</td>
<td style="text-align:left">GitHub Enterprise Server &lt; 3.22</td>
<td style="text-align:left">9.2 (v4.0)</td>
<td style="text-align:left">0.0%</td>
<td style="text-align:left">No</td>
<td style="text-align:left">No</td>
<td style="text-align:left">3.16.20 / 3.17.17 / 3.18.11 / 3.19.8 / 3.20.4 / 3.21.1</td>
<td style="text-align:left"><a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-32027" target="_blank" rel="noopener noreferrer">ENISA EUVD</a></td>
</tr>
<tr>
<td style="text-align:left">CVE-2026-9642</td>
<td style="text-align:left">Delta Electronics DIAView SCADA</td>
<td style="text-align:left">9.8 (v3.1)</td>
<td style="text-align:left">n/a</td>
<td style="text-align:left">No</td>
<td style="text-align:left">No</td>
<td style="text-align:left">Incomplete (bypass of CVE-2025-62582 fix)</td>
<td style="text-align:left"><a href="https://www.tenable.com/security/research/tra-2026-44" target="_blank" rel="noopener noreferrer">Tenable TRA-2026-44</a></td>
</tr>
</tbody></table></div><div class="prov"><span>vulnerability</span><span>27 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-27/cve-2026-9642-delta-electronics-diaview-scada-incomplete-fix/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.tenable.com/security/research/tra-2026-44" target="_blank" rel="noopener noreferrer">Tenable Research TRA-2026-44, 2026-05-26</a></div></article>]]></content:encoded></item></channel></rss>