<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · Telecommunications</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-telco.xml" rel="self" type="application/rss+xml"/><description>Items affecting telecommunications operators and infrastructure.</description><language>en</language><lastBuildDate>Sat, 18 Jul 2026 04:35:00 +0000</lastBuildDate><item><title>Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC</title><link>https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>auth-bypass</category><category>pre-auth</category><category>no-patch</category><category>cloud</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-47865</category><category>CVE-2026-47867</category><category>CVE-2026-47871</category><category>CVE-2026-47868</category><category>CVE-2026-47866</category><category>CVE-2026-47869</category><category>CVE-2026-47870</category><description><![CDATA[<p>Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an unauthenticated remote attacker reach the Avi Controller control plane by bypassing authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and TLS termination for whatever sits behind the load balancer.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass" data-tags="vulnerabilities auth-bypass pre-auth no-patch cloud" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47865/">CVE-2026-47865 +6</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="vmware-avi-load-balancer-cve-2026-47865-auth-bypass"><a href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround</a></h3><p>Broadcom&#39;s VMSA-2026-0005 (2026-07-14, last updated 2026-07-15) patches seven vulnerabilities in VMware Avi Load Balancer — the load-balancing/application-delivery product formerly sold as NSX Advanced Load Balancer and widely deployed in enterprise and government data-centre fabric across Europe. The load-bearing flaw, <strong>CVE-2026-47865</strong> (CVSS 9.8), is an authentication bypass on the Avi Controller: &quot;a malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism&quot; — no credentials, no user interaction (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>). The advisory ships six companion flaws that require a prior foothold: two high-privilege remote code-execution bugs (CVE-2026-47867, CVE-2026-47869, both CVSS 8.7, PR:H), a low-privilege authenticated directory traversal (CVE-2026-47871, CVSS 8.8), an authorization bypass (CVE-2026-47866, CVSS 8.3), a local-to-root privilege escalation (CVE-2026-47868, CVSS 7.8) and a further privilege escalation (CVE-2026-47870, CVSS 7.1). Broadcom states no workarounds exist (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>); the German trade press summarised it as attackers being able to bypass authentication and authorization (<a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security, 2026-07-17</a>).</p>
<p>No in-the-wild exploitation has been reported, but two facts raise this above the routine patch cycle: the reporter is the NATO NCSC (a direct constituency-provenance signal), and there is no mitigation short of upgrading. Because the Avi Controller is the management and orchestration plane for the load-balancing fabric, an unauthenticated bypass there is a direct path to reconfiguring traffic routing and TLS termination for every service behind the load balancer — an interception and traffic-manipulation position, not merely appliance compromise.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Upgrade the Avi Controller to a fixed release — 32.1.2 (recommended), 31.2.2-2p3 or 30.2.7; the 22.1.x branch must move to at least 30.2.7. Because no workaround exists, until the upgrade lands restrict Controller management-plane reachability to trusted management VLANs/jump hosts and treat any exposure of the Avi Controller to broad or untrusted network segments as the finding in its own right. Detection concept, telemetry-class first: Avi Controller admin/API authentication logs showing control-plane session establishment or API calls with no preceding successful login event, particularly from source ranges outside the management network.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.</p><figcaption class="entry-cite__attr"><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> · <a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security</a></div></article>]]></content:encoded></item><item><title>Volexity attributes the SonicWall SMA 1000 zero-day exploitation to UTA0533 and details the SSRF-to-root chain, on-appliance implants and LDAP credential theft</title><link>https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>Volexity has reconstructed the intrusion behind the actively-exploited SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection), attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22. The chain: an unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, then the actor injects a proxy (Suo5) and a Java webshell (ORANGETAIL) into the appliance&#39;s legitimate workplace process, persists via an init script, captures cleartext LDAP credentials with tcpdump, and pivots into the internal network. Stolen credentials survive patching — the hotfix alone does not remediate a pre-patch compromise.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce auth-bypass" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sonicwall-sma1000-uta0533-exploitation-kill-chain"><a href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533&#39;s full appliance-to-network kill chain</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a> <span class="mono muted">(2026-07-14)</span></p><p>The original entry recorded SonicWall&#39;s confirmation that CVE-2026-15409/-15410 were being exploited as zero-days and directed emergency patching. Volexity has now published the reconstructed intrusion, attributed it to an actor it tracks as <strong>UTA0533</strong>, and shown that patching alone is insufficient — the delta below is the full kill chain, the on-appliance implants, and the compromise-response guidance the terse advisory did not carry (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>).</p>
<p>Volexity was engaged after suspect authentication and lateral movement were seen originating <em>from</em> SonicWall SMA 1000 appliances (models 6210/7210/8200v); the earliest sign of compromise was 2026-06-22, weeks before SonicWall&#39;s 2026-07-14 disclosure (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). SonicWall&#39;s PSIRT confirms it &quot;has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory&quot; (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall SNWLID-2026-0008, 2026-07-14</a>), and Rapid7&#39;s MDR team independently found the same two zero-days under attack (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>).</p>
<p><strong>Initial access (T1190, T1133).</strong> CVE-2026-15409 is a pre-authentication server-side request forgery in the SMA 1000 <code>/wsproxy</code> endpoint. A crafted WebSocket-upgrade request establishes a tunnel from the unauthenticated external attacker straight to services that are supposed to be reachable only on the appliance&#39;s own loopback — Volexity confirms &quot;no valid SMA session cookie was required during this process&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Through the tunnel the actor reached the appliance&#39;s bundled CouchDB/Erlang services and a localhost-only control service; the shipped CouchDB carries hardcoded <code>admin:admin</code> credentials, and the control service&#39;s authentication password is derivable from a device UUID, so the SSRF turns both into part of the external attack surface.</p>
<p><strong>Privilege escalation (T1068).</strong> CVE-2026-15410 is a path traversal in the hotfix-rollback workflow: the <code>sysCtrl.execRemoveHotfix</code> operation builds a rollback path from caller-controlled input and hands it to <code>/usr/local/bin/remove_hotfix</code>, which then executes it. A rollback name containing directory-traversal sequences resolves outside the intended rollback directory and runs an attacker-staged script as root.</p>
<p><strong>Persistence and implants (T1055, T1505.003, T1090.003, T1037.004).</strong> With root, UTA0533 dropped a setuid helper and a Python loader Volexity calls <strong>KNUCKLEBALL</strong>, which injects two JAR archives into the appliance&#39;s legitimate <code>workplace</code> process: the open-source <strong>Suo5</strong> HTTP proxy-forwarder and a Behinder-like Java webshell Volexity calls <strong>ORANGETAIL</strong>. Persistence was established by adding a call to the loader inside the appliance&#39;s <code>workplace</code> init script, and the NGINX Unit configuration was rewritten to add routes that proxy attacker-chosen (arbitrary) request paths to the injected webshell and proxy — so hunting for a fixed URL is the wrong shape; the behaviour is unexpected route entries in the appliance&#39;s own reverse-proxy configuration.</p>
<p><strong>Credential access and lateral movement (T1040, T1059).</strong> The actor ran <code>tcpdump</code> from a script staged in the appliance&#39;s temp directory to capture unencrypted LDAP traffic (TCP 389), harvesting directory credentials off the wire (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Rapid7&#39;s engagement observed the actor then &quot;quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network&quot; (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>). How far that onward movement reached differs across the two IR firms&#39; cases: Volexity concludes that in the appliances <em>it</em> investigated, &quot;available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>) — so treat a foothold on the appliance as a demonstrated launch point for internal movement, but not evidence that deep lateral movement always succeeds.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Patching to the hotfix (12.4.3-03453 / 12.5.0-02835) closes the two CVEs but does nothing about credentials already captured or implants already planted, so any appliance that was exposed and unpatched must be handled as an assume-compromise: SonicWall and both IR firms recommend re-imaging on any indicator, and resetting all account passwords and TOTP seeds. Detection concepts, telemetry-class first: in the appliance&#39;s web/access logs, unauthenticated <code>/wsproxy</code> WebSocket-upgrade requests that return a 101 protocol-upgrade status with no valid session cookie and target an internal (loopback-facing) service port; in the control-service log, hotfix-rollback operations carrying path-traversal sequences in the rollback name; on the network, LDAP binds and other authentication originating <em>from</em> the SMA appliance&#39;s own address, and any egress or lateral connection from an appliance that should only ever terminate inbound VPN sessions. <strong>Triage:</strong> an SMA 1000 legitimately proxies authenticated user sessions inbound — the discriminators are a <code>/wsproxy</code> upgrade with no session cookie reaching a loopback service, and the appliance itself <em>initiating</em> authentication or connections into the internal network, which a remote-access gateway has no benign reason to do.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">No valid SMA session cookie was required during this process.</p><figcaption class="entry-cite__attr"><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network</p><figcaption class="entry-cite__attr"><a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>threat</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> · <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> · <a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a></div></article>]]></content:encoded></item><item><title>Italian DPA fines Wind Tre EUR 1.7M — retail-staff vishing led to enumeration of an unprotected secondary API (365,048 customers)</title><link>https://ctipilot.ch/entries/2026-07-17/garante-wind-tre-vishing-api-enumeration-fine/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-17/garante-wind-tre-vishing-api-enumeration-fine/</guid><pubDate>Fri, 17 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-17T04:35:00Z</dc:date><category>data-breach</category><category>phishing</category><category>identity</category><category>europe</category><description><![CDATA[<p>Italy&#39;s Garante published (2026-07-16) its 14 May 2026 decision fining Wind Tre S.p.A. EUR 1,715,600 over two 2025 breaches with an unusually complete technical account: attackers vished retail point-of-sale staff into granting remote access, harvested a stored client digital certificate and credentials, used them as valid MFA&#39;d access to a customer web application, then pivoted from the protected primary search API to an unprotected secondary API and ran ~2,000,000 sequential customerId requests, exfiltrating data on 365,048 customers (payment data for 41,359). The transferable lesson for any Swiss/EU telco, utility or public body with a POS/field-agent access model: an enumeration-reachable secondary endpoint that pentesting never exercised.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-17/garante-wind-tre-vishing-api-enumeration-fine" data-tags="data-breach phishing identity" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-07-17T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="garante-wind-tre-vishing-api-enumeration-fine"><a href="https://ctipilot.ch/entries/2026-07-17/garante-wind-tre-vishing-api-enumeration-fine/">Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers</a></h3><p>The Garante&#39;s decision gives a rare, fully technical account of a telco breach. Initial access was voice social engineering: attackers phoned staff at two retail points of sale, posed as internal support technicians, and &quot;convinced operators at two retail points of sale to allow access to company systems&quot; (<a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10272004" target="_blank" rel="noopener noreferrer">Garante, 2026-07-16</a>). That remote access yielded the point-of-sale device&#39;s installed client digital certificate plus login credentials — reportedly recoverable in cleartext from the desktop or browser rather than held in an OS certificate store — which the attackers then used as valid, MFA-satisfied access to a customer-facing web application. In the first incident that access ran 66 targeted lookups (~23 customers). In the second, days later, the attackers pivoted from the primary (protected) search API to an unprotected secondary API invoked by the same search function and &quot;executed about 2 million total requests following an enumeration logic, i.e. progressively incrementing the customer code identifier (&#39;customerId&#39;),&quot; compromising 365,048 customers and, for 41,359 of them, payment-instrument data (<a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10263796" target="_blank" rel="noopener noreferrer">Garante, 2026-07-16</a>). The Garante rejected Wind Tre&#39;s defense that its API design followed OWASP practice, finding the enumeration-reachable secondary endpoints were &quot;reasonably identifiable&quot; by a vulnerability assessment and penetration test scoped to the API surface — not just the primary documented interfaces.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the chain is entirely transferable to any organization with a retail/field-agent access model and a customer-lookup web application, and it turns on two failures a SOC can act on independent of Wind Tre. First, credential/certificate custody: client certificates and service credentials recoverable in cleartext from an endpoint are stealable via a single social-engineered remote-access session — they belong in an encrypted store, KMS or HSM. Second, the object-level-authorization gap on a secondary API that the primary UI silently calls: security testing that exercises only documented primary interfaces misses exactly the endpoint an attacker finds by observing the app&#39;s own client behaviour. <strong>Triage:</strong> benign customer-lookup traffic is bounded and non-sequential; the discriminator here is volume and sequence — a single authenticated session issuing hundreds of thousands to millions of requests that increment an object identifier monotonically, against an endpoint with no rate-limiting or CAPTCHA, is enumeration, not use.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">gli hacker, fingendosi tecnici dell&#39;assistenza, hanno convinto gli operatori di due punti vendita a consentire l&#39;accesso ai sistemi aziendali</p><figcaption class="entry-cite__attr"><a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10272004" target="_blank" rel="noopener noreferrer">Garante per la protezione dei dati personali (Newsletter n.549)</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">gli attaccanti sono riusciti ad eseguire circa 2 milioni di richieste totali seguendo una logica di enumeration, ovvero andando ad aumentare progressivamente l&#39;identificativo del codice cliente (c.d. &quot;customerId&quot;) violando i dati personali di 365.048 clienti</p><figcaption class="entry-cite__attr"><a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10263796" target="_blank" rel="noopener noreferrer">Garante per la protezione dei dati personali (Provvedimento n.348, 14 May 2026)</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>incident</span><span>17 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-17/garante-wind-tre-vishing-api-enumeration-fine/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10272004" target="_blank" rel="noopener noreferrer">Garante per la protezione dei dati personali (Newsletter n.549)</a> · <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10263796" target="_blank" rel="noopener noreferrer">Garante per la protezione dei dati personali (Provvedimento n.348, 14 May 2026)</a> · <a href="https://www.ansa.it/english/news/business/2026/07/16/privacy-watchdog-fines-wind-tre-1.7-million_43961a24-11d7-4652-9659-f09f4cd78659.html" target="_blank" rel="noopener noreferrer">ANSA (English)</a></div></article>]]></content:encoded></item><item><title>Swiss municipal energy/water/telecom utility IWB discloses a third-party-provider breach exposing ~40,000 customer meter records</title><link>https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</guid><pubDate>Thu, 16 Jul 2026 04:38:00 +0000</pubDate><dc:date>2026-07-16T04:38:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>switzerland</category><description><![CDATA[<p>Industrielle Werke Basel (IWB) — the canton-owned Basel utility supplying electricity, gas, water and telecom — disclosed on 2026-07-15 that an external service provider was compromised and roughly 40,000 customer records (names, addresses, meter numbers and installation characteristics) were exfiltrated. Email addresses, phone numbers, consumption data and payment details were not exposed, IWB&#39;s own systems and supply were unaffected, and the Basel-Stadt data protection officer assessed the misuse risk as low. No provider name, actor or initial-access vector has been disclosed.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records" data-tags="data-breach supply-chain" data-regions="switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="iwb-basel-third-party-provider-breach-40k-customer-records"><a href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Basel utility IWB: ~40,000 customer records exfiltrated in a breach of a third-party service provider</a></h3><p>Industrielle Werke Basel (IWB) — the canton-owned Basel multi-utility supplying electricity, gas, water, district heating and telecom/fibre — disclosed on 15 July 2026 that an external service provider it uses was compromised and roughly <strong>40,000 customer records</strong> were exfiltrated from the provider&#39;s environment (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The stolen data comprises customer names and addresses plus technical smart-meter attributes (meter serial numbers and installation characteristics); IWB states that email addresses, phone numbers, energy-consumption data and billing/payment data were <strong>not</strong> part of the exposure, so no consumption-pattern inference is possible from what was taken (<a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-15</a>). IWB&#39;s own IT and OT/grid systems were unaffected and energy/water supply continuity was not disrupted — the compromise is scoped to the provider&#39;s systems and the customer-data feed IWB shares with it (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The provider detected and notified IWB, which audited access, reviewed logs and pre-emptively restricted its data exchange with the affected provider; the Basel-Stadt cantonal data protection officer assessed the misuse risk as low (<a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch, 2026-07-15</a>). No provider name, threat-actor claim or initial-access vector has been disclosed, and no matching leak-site listing was found for Switzerland in-window.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is a textbook trusted-relationship exposure — a home-region critical-infrastructure operator&#39;s customer data reached attackers through a compromised external processor the utility&#39;s own SOC has no telemetry into. For any utility or public-sector body outsourcing metering/billing data, the load-bearing controls are contractual data-minimisation (share only the fields the processor needs), a right to breach notification and log access, and periodic review of what customer data actually sits outside the perimeter. The exposed name+address+meter-number combination is exactly the material for convincing pretext contact, so affected customers should be warned to treat unsolicited approaches referencing their address or meter number — especially demands for money or data under time pressure — with suspicion.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Bei einem Cyberangriff auf einen Dienstleister der Industriellen Werke Basel (IWB) haben Cyberkriminelle rund 40&#39;000 Datensätze von Kundinnen und Kunden des Energieversorgers entwendet.</p><p class="entry-cite__quote">Die IWB-Systeme blieben unversehrt, wie das Unternehmen mitteilt. Auch die Energieversorgung sei nicht beeinträchtigt gewesen.</p><figcaption class="entry-cite__attr"><a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch</a></div></article>]]></content:encoded></item><item><title>A fake client_id on Entra ID&#39;s ROPC token endpoint lets attackers enumerate and validate credentials while leaving a blank application name in the sign-in log</title><link>https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/</guid><pubDate>Wed, 15 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-15T04:36:00Z</dc:date><category>identity</category><category>cloud</category><category>phishing</category><category>global</category><description><![CDATA[<p>Proofpoint (2026-07-13) documented OAuth client ID spoofing against Microsoft Entra ID, independently weaponised by two clusters. An attacker POSTs credentials to the /common/oauth2/token endpoint using the legacy ROPC flow with an arbitrary unregistered GUID as client_id; Entra ID&#39;s differential AADSTS error responses leak username and password validity, and AADSTS700016 (&quot;application not found&quot;) is returned when the credentials are BOTH correct — turning a code defenders read as a harmless misconfiguration into a credential-validity oracle. Because the client_id is unregistered, the sign-in log entry (where one appears at all) carries a blank application name, defeating detections that correlate authentication spikes by app. The concrete fix is to block the ROPC grant type outright, because Conditional Access policies scoped to specific applications are the exact control this technique sidesteps.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion" data-tags="identity cloud phishing" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-15T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="proofpoint-oauth-client-id-spoofing-entra-id-evasion"><a href="https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/">Proofpoint: OAuth client ID spoofing validates stolen Entra ID credentials at scale without writing a successful sign-in log</a></h3><p>Proofpoint&#39;s Threat Research team documented a stealthy authentication-evasion technique — <strong>OAuth client ID spoofing</strong> — being independently weaponised by two distinct clusters against <strong>Microsoft Entra ID</strong> (<a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-07-13</a>). The mechanism abuses the legacy Resource Owner Password Credentials (ROPC) flow: an attacker POSTs a username and password to Entra ID&#39;s <code>/common/oauth2/token</code> endpoint while supplying an arbitrary, unregistered GUID as the <code>client_id</code> parameter instead of a real application ID. Entra ID&#39;s differential error responses then leak validity regardless of whether the client_id is legitimate — <code>AADSTS50034</code> for a non-existent username, <code>AADSTS50126</code> for a valid username with the wrong password, and, critically, <code>AADSTS700016</code> (&quot;application not found in directory&quot;) when the username <em>and</em> password are both correct, because Entra ID validates the credential before it fails on the unrecognised client. The result is a credential-validity oracle that most defenders misread: <code>AADSTS700016</code> is ordinarily dismissed as a harmless misconfigured-app error, which is precisely the blind spot both clusters exploited (<a href="https://www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-07-13</a>).</p>
<p>The evasion value is in the telemetry: none of these code paths writes a successful sign-in event, and because the client_id is unregistered, the sign-in log entry carries no application name at all — &quot;detections that look for surges against a specific application name may miss this activity entirely, as the field is blank&quot; (<a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-07-13</a>). Proofpoint attributes two campaigns of opportunistic mass enumeration: <strong>UNK_pyreq2323</strong> (January–March 2026, AWS-hosted, 700,000+ distinct spoofed client IDs) and <strong>UNK_OutFlareAZ</strong> (December 2025–March 2026, Cloudflare-fronted, 3.7M distinct spoofed IDs), whose divergent tooling and client-ID-generation strategies point to parallel invention rather than shared code (<a href="https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-13</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the concrete detection-logic change is to stop treating <code>AADSTS700016</code> against a valid username as harmless and start treating a burst of them — especially from a single ASN or cloud-hosting range across many usernames — as equivalent in severity to a successful credential-stuffing hit; sign-in entries with a blank application ID on ROPC token requests are the anomaly to hunt. <strong>Triage:</strong> legitimate ROPC usage (some line-of-business apps, service accounts and CI/CD pipelines still use it deliberately) shows a registered, named application in the sign-in log — a genuinely blank application-name field on a <code>/common/oauth2/token</code> request, at volume against many distinct usernames, is what separates the attack from benign legacy authentication. The durable fix is to block the ROPC grant type outright, since per-application Conditional Access scoping is the exact control this technique defeats.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">When a spoofed client ID is used, no corresponding application name is recorded in the sign-in log. This means that detections that look for surges against a specific application name may miss this activity entirely, as the field is blank.</p><p class="entry-cite__quote">By fragmenting authentication attempts across many fictional applications, activity becomes harder to correlate and may evade per-application detections and rate limiting.</p><figcaption class="entry-cite__attr"><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint Threat Research</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>research</span><span>15 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint Threat Research</a> · <a href="https://www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeover</title><link>https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>SonicWall&#39;s PSIRT confirms active exploitation of two SMA1000 flaws (SNWLID-2026-0008), both added to CISA KEV on 2026-07-14: CVE-2026-15409 (CVSS 10.0), an unauthenticated server-side request forgery in the SMA1000 Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication OS-command code injection in the Appliance Management Console. Any organization running an internet-facing SMA1000 (6210/7210/8200v) must apply the platform hotfix now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited"><a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a></h3><p>SonicWall&#39;s PSIRT advisory SNWLID-2026-0008 (first published 2026-07-14) states it has investigated &quot;multiple cases indicating the active exploitation&quot; of two new SMA1000 flaws (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>); both CVEs carry a same-day CISA KEV listing (recorded in this entry&#39;s CVE status, confirmed against the KEV feed). <strong>CVE-2026-15409</strong> (CVSS 10.0, CWE-918) is a server-side request forgery in the SMA1000 Work Place interface that lets a remote, unauthenticated attacker force the appliance to issue requests to an attacker-chosen location; the scope-changed CVSS vector (S:C) indicates the SSRF reaches beyond the vulnerable component&#39;s own security boundary. <strong>CVE-2026-15410</strong> (CVSS 7.2, CWE-94) is a post-authentication code-injection flaw in the SMA1000 Appliance Management Console (AMC) that lets an authenticated administrator-level session run arbitrary OS commands — read together with the pre-auth SSRF, the pair forms a chain from zero access toward root-equivalent appliance control. The affected firmware is SMA1000 6210/7210/8200v on 12.4.3-03245/03387/03434 and 12.5.0-02283/02624/02800; the fix is platform-hotfix 12.4.3-03453 or 12.5.0-02835, and SonicWall explicitly states neither flaw affects SSL-VPN running on SonicWall firewalls or the SMA100 series (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is the SSL-VPN edge-appliance exploitation pattern that turns into a foothold fast — patch now and, because exploitation is already live, treat an unpatched exposed SMA1000 as a compromise-assessment candidate rather than a clean patch. <strong>Triage:</strong> the pre-auth SSRF surfaces in the appliance&#39;s own request telemetry as outbound requests from the Work Place interface to unexpected internal or external hosts (a legitimate Work Place session does not initiate arbitrary outbound fetches); the code-injection stage surfaces in the control-service log as configuration or hotfix-state manipulation from an admin session — SonicWall&#39;s own detection guidance points at hotfix-rollback entries carrying path-traversal-style names as the anomaly, so rollback activity that does not match a change-managed maintenance window is the discriminator. Per policy no IOCs are reproduced here; consult the vendor advisory for the indicator set.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.</p><p class="entry-cite__quote">A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.</p><p class="entry-cite__quote">Sean Koessel and Steven Adair of Volexity - helped advance SonicWall&#39;s PSIRT investigation, leading to the identification of an additional IOC.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a></div></article>]]></content:encoded></item><item><title>Microsoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>priv-esc</category><category>cisa-kev</category><category>identity</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-56155</category><category>CVE-2026-56164</category><description><![CDATA[<p>Microsoft&#39;s July 2026 Patch Tuesday (its largest ever by CVE count) fixes two zero-days Microsoft confirms were exploited in the wild and CISA added to KEV the same day: CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS), and CVE-2026-56164, an unauthenticated, network-reachable elevation-of-privilege in on-prem SharePoint Server 2016/2019/Subscription Edition. Any organization running on-prem AD FS or SharePoint should treat both as emergency patches.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days" data-tags="vulnerabilities actively-exploited zero-day priv-esc cisa-kev identity patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-56155/">CVE-2026-56155 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="microsoft-july-2026-patch-tuesday-two-exploited-zero-days"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)</a></h3><p>Microsoft&#39;s July 2026 Patch Tuesday is its largest ever by CVE count and carries two zero-days Microsoft confirms were exploited before a fix existed, both added to CISA&#39;s Known Exploited Vulnerabilities catalog the same day (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-14</a>). <strong>CVE-2026-56155</strong> (CVSS 7.8, CWE-1220) is a local elevation-of-privilege in Active Directory Federation Services: an attacker who already holds a low-privileged authorized session on the AD FS host escalates to administrator (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). It is a post-foothold escalation rather than an initial-access vector, and Microsoft&#39;s advisory credits its own DART incident-response team in the acknowledgements — meaning it surfaced during a live intrusion, so an exposed AD FS host should be treated as a candidate for compromise assessment, not merely patched (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). <strong>CVE-2026-56164</strong> (CVSS 5.3, CWE-306) is the more exposed of the two: a missing-authentication flaw in on-prem SharePoint Server that lets an unauthenticated attacker elevate privileges over the network with no user interaction (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). Microsoft&#39;s mitigation guidance — enable AMSI on the SharePoint/IIS worker processes with Request Body Scan set to Full — indicates the trigger is a crafted HTTP POST body, the same class of exposure this pipeline tracked for the CVE-2026-45659 SharePoint deserialization RCE on 2026-07-02, so operators who already tuned AMSI for that flaw have partial coverage.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch both now; for AD FS the low CVSS understates the risk because the bug was caught in real-world incident response — treat internet- or partner-reachable AD FS servers as potentially targeted and pair the patch with a hunt of local process activity on those hosts. <strong>Triage:</strong> the AD FS escalation manifests in host-local process-execution and privilege-transition telemetry on the AD FS server itself (a low-privileged service account acquiring administrator context), not in network logs — normal AD FS operation does not spawn privilege transitions from its service account, so that lineage is the discriminator; the SharePoint escalation surfaces in IIS/SharePoint worker-process telemetry as an unauthenticated request preceding an unexpected privilege context, which AMSI full-body scanning is positioned to catch. No IOCs or exploiting cluster have been published for either.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.</p><p class="entry-cite__quote">Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.</p><figcaption class="entry-cite__attr"><a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener noreferrer">Krebs on Security</a></div></article>]]></content:encoded></item><item><title>19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland&#39;s Dec-2025 grid sabotage</title><link>https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</guid><pubDate>Mon, 13 Jul 2026 12:40:00 +0000</pubDate><dc:date>2026-07-13T12:40:00Z</dc:date><category>nation-state</category><category>espionage</category><category>actively-exploited</category><category>cisa-kev</category><category>wiper</category><category>law-enforcement</category><category>ot-ics</category><category>russia-nexus</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2018-0171</category><description><![CDATA[<p>A joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland&#39;s energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory" data-tags="nation-state espionage actively-exploited cisa-kev wiper law-enforcement ot-ics russia-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-13T12:40:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2018-0171/">CVE-2018-0171</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="fsb-centre-16-static-tundra-router-hijacking-advisory"><a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a></h3><p><strong>Background.</strong> The FSB Centre 16 network-device cluster is not new — it has a decade-plus public record under the vendor labels Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly and Ghost Blizzard, and Cisco Talos profiled it in August 2025 as &quot;Static Tundra,&quot; documenting long-term compromise of unpatched and end-of-life network gear for configuration theft and persistent collection (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). What is new is a same-day trio of actions on 2026-07-13: a much fuller TTP disclosure, a formal government attribution of a destructive attack, and the first coordinated EU/UK cyber-sanctions package.</p>
<p>A joint Cybersecurity Advisory carrying 19 authoring and co-sealing agencies across 13 countries — NSA, CISA, FBI and DC3 (US) alongside the cyber and intelligence authorities of Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden — describes FSB Centre 16 opportunistically compromising poorly configured routers across communications, defense industrial base, energy, financial services, government (especially state/local), and healthcare sectors (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA/CISA/FBI joint advisory, 2026-07-13</a>; <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). The advisory notes these TTPs overlap with Salt Typhoon activity, so the hardening below counters more than one actor.</p>
<p>The primary access vector is not a novel exploit but weak SNMP hygiene. The actors scan internet IP ranges for SNMP agents that accept common or default community strings, then issue spoofed-source SNMP Set-Requests carrying object identifiers that instruct the device to copy its running configuration to a file (commonly <code>config.bkp</code> or <code>output.txt</code>) and transfer it, usually over TFTP, to a leased VPS or a compromised FTP server (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). The advisory names the exact OIDs abused — <code>1.3.6.1.4.1.9.9.96.1.1</code> (Cisco Config Copy) and <code>1.3.6.1.4.1.9.9.96.1.1.1.1.5</code> (the destination address for the copied config). A stolen configuration frequently discloses further credentials and additional community strings, feeding lateral movement. Talos&#39;s profile records the actor guessing or reusing insecure read-write community strings such as <code>public</code> and <code>anonymous</code> (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). Secondarily — &quot;occasionally,&quot; per the advisory — the actors exploit known Cisco bugs and the Smart Install (SMI) feature, naming CVE-2018-0171 (the Smart Install pre-auth RCE, in CISA KEV since 2021) and CVE-2008-4128 (end-of-life devices only, no patch). Persistence has historically included the SYNful Knock IOS firmware implant.</p>
<p><strong>The Poland grid attribution.</strong> On the same day, the UK together with EU member states formally attributed the destructive 29 December 2025 attack on Poland&#39;s energy grid to FSB Centre 16 (<a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). CERT Polska&#39;s own incident report describes coordinated destructive activity against 30-plus wind and photovoltaic grid-connection substations — RTU, HMI and protection-relay firmware damaged or system files deleted — and a combined heat-and-power plant serving roughly half a million people, where wiper malware was blocked by the operator&#39;s EDR before detonation; CERT Polska tied the activity to the Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster via VPS, router and anonymizing-infrastructure overlap and called it &quot;the first publicly described destructive activity attributed to this activity cluster&quot; (<a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-01-30</a>). Note the attribution is contested at the cluster-label level: earlier ESET reporting attributed the same DynoWiper attack to the GRU&#39;s Sandworm (<a href="https://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-01-24</a>), and the EU Council statement names FSB Centre 16 as the parent controlling several groups including Turla — so treat &quot;FSB Centre 16&quot; as an umbrella unit rather than a single team.</p>
<p>The sanctions package is the policy layer: the EU designated 9 individuals and 4 entities and the UK designated 24, covering senior GRU figures, the front company IMPULS accused of recruiting hackers for GRU Unit 29155, Lumma Stealer operators, and the disinformation outlet Rybar LLC (<a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government, 2026-07-13</a>; <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-13</a>).</p>
<p><strong>Detection.</strong> The telemetry classes to prioritise on network gear: network-flow and firewall logs for inbound SNMP Set-Requests (especially with spoofed or unfamiliar source addresses) and for outbound TFTP sessions initiated from a router/switch management interface to non-management destinations; device syslog and AAA/TACACS+ logs for unexpected &quot;config copy&quot; events, new local-account creation, and unexplained drops in logging volume — Talos documents the actor tampering with TACACS+ configuration to blind logging and standing up GRE tunnels to redirect victim traffic (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>); and IDS rules keyed to inbound SNMP Set-Requests carrying the config-copy OIDs above, as the advisory recommends (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). Baseline NetFlow for the new GRE tunnel endpoints Talos describes.</p>
<p><strong>Defender takeaway.</strong> For a Swiss or European CI operator this is a router-hygiene mandate with a live destructive precedent next door. Disable Smart Install where it is not in active use, confirm CVE-2018-0171 is patched, migrate management SNMP to v3 with authPriv and disable SNMPv1/v2c (or, where legacy SNMP is unavoidable, replace every default/weak community string and enforce read-only), restrict all management protocols to known stations via out-of-band ACLs, use Cisco password hashing type 8 (never 0/4/7), and treat the device configuration held in your management system — not the device itself — as the source of truth so a tampered config is detectable.</p>
<p><strong>Triage:</strong> legitimate network-management stations poll SNMP on a predictable cadence from a known IP set, almost always read-only GET/GET-NEXT. The signal is a <em>write</em> (SNMP Set-Request) — particularly one carrying the config-copy OIDs — from a source outside the management range or with an inconsistent/spoofed source address, followed by an outbound TFTP transfer from the device; either alone is weak, the sequence config-write-then-TFTP-egress is the discriminator.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication</p><figcaption class="entry-cite__attr"><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The UK together with EU member states has also today formally attributed the December 2025 attack on Poland&#39;s energy grid to Russia&#39;s FSB Centre 16.</p><figcaption class="entry-cite__attr"><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is, however, the first publicly described destructive activity attributed to this activity cluster.</p><figcaption class="entry-cite__attr"><a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> <span class="entry-cite__date mono">2026-01-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.</p><figcaption class="entry-cite__attr"><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 12:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> · <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> · <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> · <a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Dutch NIS2 (Cyberbeveiligingswet) passed the Senate 7 July — entry into force fixed for 15 August 2026, ~8,000 organisations in scope</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</guid><pubDate>Sun, 12 Jul 2026 23:52:00 +0000</pubDate><dc:date>2026-07-12T23:52:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch First Chamber passed the Cyberbeveiligingswet (the NIS2 transposition) and the companion Wet weerbaarheid kritieke entiteiten (CER transposition) on 7 July 2026; both enter into force 15 August 2026. This closes the &#39;slipped past 1 July&#39; status prior weeklies tracked and fixes a hard date. The Cbw covers ~8,000 organisations across 18 sectors with a duty of care including supply-chain risk management, mandatory incident reporting to the CSIRT, entity-register registration, and board-level accountability. For Swiss-domiciled organisations with Dutch subsidiaries, NL critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is now the operative compliance clock.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-netherlands-nis2-in-force" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:52:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-netherlands-nis2-in-force"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a> <span class="mono muted">(2026-07-05)</span></p><p>the Dutch NIS2 transposition status this pipeline tracked as &quot;slipped past its 1 July target, Senate vote set for 7 July&quot; has resolved. On 7 July 2026 the Eerste Kamer (First Chamber) passed both the <strong>Cyberbeveiligingswet</strong> (Cbw, the NIS2 transposition) and the companion <strong>Wet weerbaarheid kritieke entiteiten</strong> (Wwke, the CER-directive transposition) — the Tweede Kamer had passed them on 15 April — and &quot;de wetten treden op 15 augustus 2026 in werking&quot; (&quot;the laws enter into force on 15 August 2026&quot;) (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The parliamentary vote record confirms broad cross-party support (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, 2026-07-07</a>). The Cbw covers roughly 8,000 organisations across 18 designated essential/important sectors and imposes a cybersecurity duty of care (including supply-chain risk management), mandatory registration in the NCSC entity register, significant-incident reporting to the relevant CSIRT, and board-level accountability with director training (<a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a>).</p>
<p><strong>Why this matters to the constituency:</strong> beyond direct applicability to any covered Dutch entity, this is a concrete datapoint for the deployment&#39;s standing EU NIS2-transposition watch — a member state moving from indefinite slip to a fixed enforcement date. For Swiss-domiciled organisations with Dutch subsidiaries, NL-incorporated critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is the operative clock, five weeks out from this brief. The next checkpoint is confirmation the NCSC-NL entity register is live and accepting registrations ahead of the date.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De wetten treden op 15 augustus 2026 in werking.</p><figcaption class="entry-cite__attr"><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal</a> · <a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a></div></article>]]></content:encoded></item><item><title>W28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/</guid><pubDate>Sun, 12 Jul 2026 23:34:00 +0000</pubDate><dc:date>2026-07-12T23:34:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>cloud</category><category>organized-crime</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>The week&#39;s confirmed incidents share a structural theme: the initial exposure sat in a cloud account, a third-party vendor, or a supplier platform rather than the victim&#39;s own perimeter. Accenture confirmed data theft after &#39;888&#39; advertised internal source code; Deutsche Bank disclosed a third-party vendor incident after &#39;Unsafe&#39; ransomware claims; KDDI named a third-party-software zero-day as the root cause of its 12M-record ISP email breach; Nayax (an EEA payment institution) disclosed a cloud-account incident claimed by &#39;The Syndicate&#39;; ShinyHunters&#39; Odido (NL telecom) breach drew Dutch-national-involvement attribution from police voice analysis; and Nextcloud GmbH&#39;s own hosting exposed 367K records via a misconfigured Elasticsearch. Supplier and cloud-account risk, not perimeter RCE, drove the week&#39;s disclosures.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-third-party-cloud-account-exposure" data-tags="data-breach supply-chain cloud organized-crime" data-regions="switzerland europe global" data-kind="incident" data-priority="notable" data-discovered="2026-07-12T23:34:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-third-party-cloud-account-exposure"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">This week&#39;s disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim</a></h3><p>Read as a set, the week&#39;s confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else&#39;s account, platform or supply chain.</p>
<p>The <strong>third-party / vendor</strong> strand: Accenture confirmed a data-theft incident after the handle &quot;888&quot; advertised roughly 35 GB of internal source code (<a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>); Deutsche Bank disclosed a third-party-vendor incident after the &quot;Unsafe&quot; ransomware group posted claims (<a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing, 2026-07-09</a>); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (<a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). The <strong>cloud-account</strong> strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by &quot;The Syndicate&quot;) in its own SEC Form 6-K (<a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax, 2026-07-09</a>); ShinyHunters&#39; Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (<a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie, 2026-07-08</a>); and Nextcloud GmbH&#39;s own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (<a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews, 2026-07-10</a>).</p>
<p><strong>Why the pattern matters for the constituency:</strong> several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor&#39;s zero-day, a supplier&#39;s compromised account, or a misconfigured datastore in your own cloud footprint.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat third-party and cloud-account exposure as first-class incident surface — maintain a supplier inventory with incident-notification clauses, apply the same internet-exposure and misconfiguration scanning to cloud-hosted datastores as to on-prem, and monitor cloud-account sign-in anomalies with the same rigour as endpoint alerts. <strong>Triage:</strong> a supplier-origin compromise typically first surfaces as anomalous data access via a legitimate integration or service account rather than a malware alert — the discriminator is access volume and pattern on that account against its baseline, and exfiltration to an unexpected destination class.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim/">2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/">2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/">2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">2026-07-09/nayax-cloud-account-incident-the-syndicate-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/">2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw/">2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw</a></p><div class="prov"><span>incident</span><span>12 Jul 23:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax Ltd. — SEC Form 6-K</a> · <a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie (Dutch National Police)</a> · <a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing (UK)</a> · <a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews</a></div></article>]]></content:encoded></item><item><title>Microsoft dissects GigaWiper — destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an &#39;OneDrive Update&#39; persistence tell</title><link>https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>wiper</category><category>ransomware</category><category>nation-state</category><category>infostealer</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented GigaWiper (2026-07-09), a Go destructive backdoor that combines a raw-disk wiper, a Crucio-derived encryptor whose keys are never saved, and a FlockWiper-derived secure-wipe module as on-demand commands, tasked over RabbitMQ/Redis with MinIO exfiltration. First seen October 2025; concrete low-noise hunt pivots exist. Relevant to any Windows critical-infrastructure estate as transferable destructive tradecraft.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper" data-tags="wiper ransomware nation-state infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="gigawiper-golang-destructive-backdoor-modular-wiper"><a href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant</a></h3><p>Microsoft Threat Intelligence first identified GigaWiper in October 2025 and has now published a code-level analysis of it: a Golang backdoor notable less for any single capability than for its construction — at least three previously separate destructive families folded into one implant as on-demand commands, so an operator can pick the mode of destruction at task time (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>). The raw-disk wiper command enumerates physical drives over WMI, identifies and spares the Windows installation drive, strips partition metadata from the other drives via <code>DeviceIoControl</code>/<code>IOCTL_DISK_CREATE_DISK</code>, overwrites disk content in 0xA00000-byte chunks (randomising only the first byte of each buffer to dodge naïve all-zero-wipe detections), then forces an immediate reboot. A second command reuses Crucio ransomware code to AES-encrypt files with per-run keys that are never saved and drops no ransom note — destruction wearing an extortion costume — while a third reimplements the C-based FlockWiper in Go for multi-pass secure wiping of the Windows drive. Microsoft ties the families together by code overlap and assesses that the same developer built GigaWiper and Crucio; it withholds actor attribution beyond that lineage. Google&#39;s Threat Intelligence Group and Binary Defense track the same activity as BLUERABBIT (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>; <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-07-10</a>).</p>
<p>Operationally the implant is quieter than its payload. It persists as a scheduled task named <code>OneDrive Update</code> (configured to run roughly every minute and once at startup) and tracks its own execution count in a <code>HKCU\SOFTWARE\OneDrive\Environment</code> registry value, masquerading as Microsoft&#39;s sync client. For command-and-control it skips ordinary HTTP: tasking arrives over RabbitMQ/AMQP — a fanout exchange named <code>All</code> for broadcast to every infected client plus a topic exchange for targeted commands — status and output are polled back through a Redis server, and MinIO object storage carries exfiltration, alongside keylogging and screen-capture modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the persistence footprint and the C2 protocol mix are both high-value, low-false-positive hunt anchors — legitimate OneDrive never lives under that task name or registry path, and a standard workstation has no reason to speak AMQP, Redis and MinIO outbound. <strong>Triage:</strong> genuine OneDrive does run scheduled sync tasks, so the discriminator is the exact task name (<code>OneDrive Update</code>) and the <code>HKCU\SOFTWARE\OneDrive\Environment</code> key rather than the presence of a OneDrive-named task per se; pair that with outbound RabbitMQ/Redis/MinIO from a host with no such workload and the two together are the signal. Because the encryptor discards its keys, defence is recovery-first: this is a data-destruction threat, and the only meaningful mitigation for an exposed Windows estate is tested, offline backups.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction</p><p class="entry-cite__quote">The key and initialization vector (IV) that the malware uses to encrypt files are random and are not saved anywhere</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>ZDI details the HTTP.sys integer-overflow trigger — weaponisation bar drops for a pre-auth RCE reachable on any IIS/HTTPS listener</title><link>https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>poc-public</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-47291</category><description><![CDATA[<p>Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the HTTP.sys pre-auth kernel RCE patched in Microsoft&#39;s June 2026 cycle, documenting the exact integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the wild, but the mechanics — and a concrete network-detection heuristic — are now public, so anyone running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as newly weaponisable.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics" data-tags="vulnerabilities rce pre-auth poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47291/">CVE-2026-47291</a><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="cve-2026-47291-httpsys-zdi-exploitation-mechanics"><a href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut/">CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)</a> <span class="mono muted">(2026-06-10)</span></p><p>CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative&#39;s TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches <code>0xFFFB</code>, so the next increment wraps to <code>0x0000</code>; the subsequent reference addition then allocates a 40-byte buffer but <code>memmove</code>s roughly 524,256 bytes into it — a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS — HTTP/2 and HTTP/3 use a different parser and are unaffected (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The write-up also corrects the exposure picture the original advisory left fuzzy: the default <code>MaxRequestBytes</code> of 16,384 bytes caps a request at roughly 4,000 header lines — far short of the ~65,536 references needed — so only hosts that raised <code>MaxRequestBytes</code> to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE &quot;Exploitation More Likely&quot;; no in-the-wild exploitation is reported as of ZDI&#39;s publication (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-06-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the patch remains the only reliable fix, but the newly-public mechanics hand defenders a durable network signature — a single HTTP/1.x request bearing more than ~1,000 header lines (visible with TLS inspection), or an HTTPS connection emitting more than ~1,000 tiny TLS records over ~11 minutes (visible without decryption). <strong>Triage:</strong> ordinary browsers and proxies coalesce headers into a few records and never approach that line count, so a single long-lived HTTPS connection feeding one IIS/HTTP.sys request with hundreds-to-thousands of one-line TLS records is the discriminator; a kernel bugcheck on an internet-facing IIS box following such traffic warrants triage against this CVE.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="entry-cite__quote">If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><figcaption class="entry-cite__attr">Zero Day Initiative</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article>]]></content:encoded></item><item><title>NCSC-CH flags a Zimbra Classic Web Client flaw where opening a crafted email runs script in the webmail session — patch to ZCS 10.1.19</title><link>https://ctipilot.ch/entries/2026-07-10/zimbra-classic-web-client-code-exec-ncsc-ch/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/zimbra-classic-web-client-code-exec-ncsc-ch/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>vulnerabilities</category><category>patch-available</category><category>switzerland</category><category>europe</category><description><![CDATA[<p>Zimbra patched a Classic Web Client security issue in ZCS 10.1.19 (2026-07-07) where a specially crafted email runs malicious code when opened, exposing mailbox contents, session data and account settings; heise describes it as stored cross-site scripting. Switzerland&#39;s NCSC-CH surfaced it in its own advisory on 2026-07-10 with exploitation status &quot;unknown&quot; and no CVE assigned. Only the legacy Classic Web Client is affected — the Modern Web Client is not. Public-sector and telecom Zimbra operators across Europe should identify Classic Web Client use and upgrade.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/zimbra-classic-web-client-code-exec-ncsc-ch" data-tags="vulnerabilities patch-available" data-regions="switzerland europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="zimbra-classic-web-client-code-exec-ncsc-ch"><a href="https://ctipilot.ch/entries/2026-07-10/zimbra-classic-web-client-code-exec-ncsc-ch/">Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)</a></h3><p>Zimbra released ZCS 10.1.19 on 2026-07-07 to fix a Classic Web Client issue in which &quot;a specially crafted email could run malicious code when the email is opened,&quot; potentially granting access to mailbox information, session data or account settings (<a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/" target="_blank" rel="noopener noreferrer">Zimbra, 2026-07-07</a>); heise online covered it the same day as a stored cross-site-scripting flaw in the legacy webmail UI (<a href="https://www.heise.de/news/Zimbra-Collaboration-Suite-Kritische-Luecke-macht-Classic-Web-Client-angreifbar-11356522.html" target="_blank" rel="noopener noreferrer">heise online, 2026-07-07</a>). Switzerland&#39;s NCSC-CH added the item to its Cyber Security Hub on 2026-07-10, describing it as allowing unauthenticated remote attackers to reach session data, account settings and mailbox contents when a victim opens a malicious email, and explicitly recording the exploitation status as unknown (<a href="https://security-hub.ncsc.admin.ch/#/posts/12757" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch, 2026-07-10</a>). Only the Classic Web Client is affected; Zimbra and heise recommend switching users to the Modern Web Client as an interim mitigation.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the observable behavior is client-side script execution inside an authenticated webmail session triggered by message rendering — in webmail/application logs and browser telemetry, watch for anomalous outbound requests or session-token access originating from the webmail origin immediately after a message is opened, and for mailbox operations (rule creation, forwarding, bulk reads) that follow such a sequence. <strong>Triage:</strong> legitimate HTML mail renders inline content routinely, so a single rendered message is not the signal; the discriminator is script execution that reaches the session store or drives mailbox/account-setting changes rather than merely displaying content. The honest caveats are that no CVE has been assigned and no exploitation has been confirmed — the actionable reason to move now is that a national authority for the constituency chose to publish it and the affected surface is an unauthenticated, on-open path in a webmail platform still used across European public-sector and telecom environments.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.</p><figcaption class="entry-cite__attr"><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/" target="_blank" rel="noopener noreferrer">Zimbra</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Current exploitation status: UNKNOWN</p><figcaption class="entry-cite__attr"><a href="https://security-hub.ncsc.admin.ch/#/posts/12757" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/zimbra-classic-web-client-code-exec-ncsc-ch/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/" target="_blank" rel="noopener noreferrer">Zimbra</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12757" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch</a> · <a href="https://www.heise.de/news/Zimbra-Collaboration-Suite-Kritische-Luecke-macht-Classic-Web-Client-angreifbar-11356522.html" target="_blank" rel="noopener noreferrer">heise online</a></div></article>]]></content:encoded></item><item><title>ZeroBEC details Forg365 — a Telegram-sold M365 PhaaS that survives MFA and keeps operator access alive via a ForgCookie browser extension</title><link>https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>phishing</category><category>identity</category><category>cloud</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>ZeroBEC documented Forg365, a Telegram-distributed, subscription-priced Microsoft 365 phishing-as-a-service platform that pairs an OAuth device-code phishing path with an adversary-in-the-middle session-theft path, an in-panel AI lure generator, and a companion browser extension (ForgCookie) that silently refreshes the stolen Microsoft SSO cookie so access persists without the victim re-authenticating. Both paths yield a valid, MFA-satisfied token because the victim completes the real Microsoft login. It is a distinct kit and operator from the Railway/EvilTokens device-code campaign covered earlier — same primitive, productized.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie" data-tags="phishing identity cloud ai-abuse" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="forg365-m365-phaas-aitm-devicecode-forgcookie"><a href="https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/">Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence</a></h3><p>ZeroBEC&#39;s teardown, corroborated by BleepingComputer and a CSA Labs research note, describes Forg365 as a Telegram-distributed, subscription-priced (5-day trial, $400/month, $3,800/year) Microsoft 365 phishing-as-a-service platform that packages two independent credential-theft paths behind one operator console (<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC, 2026-07-09</a>; <a href="https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). The device-authorization branch presents a Microsoft-styled verification-code page and drives the legitimate Microsoft Authentication Broker flow; the adversary-in-the-middle branch classifies inbound traffic to decide whether to serve the phishing page or a benign decoy. Both converge on a valid, MFA-satisfied refresh token or session cookie because the victim completes the genuine Microsoft authentication — as CSA Labs puts it, &quot;multifactor authentication does not stop the attack because the victim, not the attacker, is the one completing the MFA challenge&quot; (<a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">CSA Labs, 2026-07-10</a>). Two capabilities stand out beyond the already-covered device-code primitive: an AI lure-drafting assistant embedded directly in the panel alongside SMTP rotation, OAuth-app configuration and token vaulting, and ForgCookie — a Chrome/Edge/Brave extension that silently triggers OAuth flows to refresh the stolen SSO cookie so operator access outlives its normal expiry (<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC, 2026-07-09</a>). ZeroBEC&#39;s Entra telemetry tied observed device-code activity to a residential ISP address, with a campaign-linked backend node later performing Microsoft Graph device-registration calls.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the durable, kit-independent detections are in Entra sign-in and audit telemetry, not on the lure — surface device-code authentication events (device-code client-id patterns in sign-in logs), OAuth app consent grants and mailbox-rule changes clustered immediately after a sign-in, and browser-extension installs on managed endpoints that programmatically refresh SSO cookies. Forg365 is a distinct product and operator from the Railway/EvilTokens device-code campaign, so it is a new entry rather than an update; the shared abused primitive (device-authorization-grant phishing) is already covered and not re-taught here. <strong>Triage:</strong> legitimate device-code sign-ins are real (CLI tools, smart-TV and headless-device apps) — the discriminator is a verification-code prompt reached via an unsolicited email lure or phone call rather than a user-initiated CLI/device flow, and a subsequent refresh-token or cookie reuse from an origin, ASN or device posture that does not match the user&#39;s baseline. Because the token is MFA-satisfied, revocation (<code>revokeSignInSessions</code>), not a password reset, is what actually evicts the operator.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Forg365 is a mature Microsoft 365-focused phishing-as-a-service platform that combines device-auth phishing, AiTM delivery, AntiBot evasion, campaign delivery, session persistence, AI-assisted lure creation, and post-compromise mailbox operations inside a commercial operator ecosystem.</p><p class="entry-cite__quote">ForgCookie, the browser extension associated with the platform, is designed for Microsoft SSO cookie refresh, browser-based access, and persistent session workflows after compromise.</p><figcaption class="entry-cite__attr"><a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">multifactor authentication does not stop the attack because the victim, not the attacker, is the one completing the MFA challenge</p><figcaption class="entry-cite__attr"><a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance (CSA Labs)</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns</a></p><div class="prov"><span>threat</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC</a> · <a href="https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance (CSA Labs)</a></div></article>]]></content:encoded></item><item><title>SANS ISC: a phishing page pads itself with ~430k repeated characters to dilute the payload below an AI classifier&#39;s threshold or exhaust an LLM&#39;s token budget</title><link>https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>phishing</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>A SANS Internet Storm Center diary analysed a phishing email whose HTML attachment was ~2.5 MB but whose functional credential-harvesting payload was only ~11 KB — the remainder a single HTML comment of ~430,000 repeated &quot;X&quot; characters placed after the payload. The analyst assesses the padding is aimed at AI/NLP-based email security: either diluting the malicious content&#39;s statistical weight until a probability classifier drops below its flag threshold, or inflating the token count until an LLM-based scanner exceeds its per-message time/size budget and cuts analysis short. The concept matters as AI content-scoring spreads across public-sector mail gateways; the defence is a non-AI fallback rule keyed on the anomalous oversized-single-character-run signature.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion" data-tags="phishing ai-abuse" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="comment-stuffing-html-phishing-ai-email-scanner-evasion"><a href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">&#39;Comment stuffing&#39; — HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners</a></h3><p>A SANS Internet Storm Center diary (2026-07-10, Jan Kopriva) dissects a phishing email that presented as a Microsoft Teams/SharePoint document notification and carried a <code>.xls.html</code> double-extension attachment weighing ~2.5 MB — anomalously large for a self-contained HTML page (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). Decoded from a <code>\uXXXX</code>-escaped <code>document.write()</code> wrapper, the file was ~431 KB, of which only the first ~11 KB was a working SharePoint-themed credential-harvesting page; the rest was a single HTML comment holding roughly 430,000 repeated &quot;X&quot; characters, placed <em>after</em> the functional payload, accounting for ~97% of the file.</p>
<p>The placement rules out the classic goal. Padding after the payload does nothing to conceal the malicious code, and at 2.5 MB the file falls well short of the tens-of-megabytes scan-size limits modern mail security uses, so this is not the MITRE &quot;Binary Padding&quot; scan-size-evasion play. The handler&#39;s assessment — explicitly flagged as informed speculation — is that the target is AI/NLP-based content scanning, which a growing number of gateways now run. Citing KnowBe4&#39;s earlier &quot;NLP obfuscation&quot; work, the diary notes that &quot;if a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence&quot;, and that &quot;the same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely&quot; (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). The author judges the token-budget-exhaustion goal the more likely of the two here, since a featureless block of one character works as well as crafted filler for that purpose. He is candid that against a well-tuned model the tactic is blunt — &quot;the padding is also about as low-entropy as any data can get, which means it wouldn&#39;t help the file blend in with benign content on a statistical level either&quot; — which is precisely why a simple non-AI signature catches it.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">as AI/NLP scoring becomes a load-bearing control in mail security, adversaries gain an incentive to attack the classifier&#39;s decision budget rather than hide from signatures — dilution below a confidence threshold, or token-count inflation past a per-message time budget that makes the gateway fail open. <strong>Triage:</strong> benign HTML mail and marketing content can be large, but a single repeated-character run or one HTML comment in the hundreds of kilobytes is not something legitimate senders produce — that oversized low-entropy block, and a large decompressed-vs-declared-size ratio, are the discriminators, and both are detectable without relying on the AI layer the padding is trying to defeat.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence.</p><p class="entry-cite__quote">The same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely.</p><p class="entry-cite__quote">The padding is also about as low-entropy as any data can get, which means it wouldn’t help the file blend in with benign content on a statistical level either</p><figcaption class="entry-cite__attr"><a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 12:53Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a></div></article>]]></content:encoded></item><item><title>Dutch police tie ShinyHunters&#39; Odido telecom breach to Dutch nationals via voice analysis — the vishing-to-spoofed-portal playbook now hits an EU telco</title><link>https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>data-breach</category><category>phishing</category><category>identity</category><category>organized-crime</category><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>Dutch National Police announced on 9 July 2026 that its investigation into the February 2026 ShinyHunters breach of telecom operator Odido (and its Ben brand) found strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded during the intrusion. The intrusion used the ShinyHunters playbook already tracked in this store: a vishing call impersonating IT staff persuaded a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-export 6.2M+ customer records before the account was blocked within an hour. The new signal is the EU-telco victim, the law-enforcement attribution, and two open Dutch DPA investigations; the underlying TTP is the ShinyHunters playbook already tracked in this store.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution" data-tags="data-breach phishing identity organized-crime law-enforcement" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="odido-shinyhunters-vishing-dutch-police-attribution"><a href="https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/">ShinyHunters&#39; Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco</a></h3><p>Dutch National Police (Team High Tech Crime) announced on 9 July that its investigation into the February 2026 breach of Dutch telecom operator Odido — and its Ben brand — has produced strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded at the time of the intrusion; police assess the caller as very likely a genuine human speaker (while not fully ruling out synthetic voice) and are publicly appealing for the caller to come forward before the recording is released (<a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie, 2026-07-09</a>; <a href="https://nos.nl/artikel/2622288-bellende-odido-hacker-vermoedelijk-nederlander-politie-dreigt-stem-openbaar-te-maken" target="_blank" rel="noopener noreferrer">NOS, 2026-07-09</a>).</p>
<p>This extends the ShinyHunters vishing-to-spoofed-portal playbook (registry: <code>actor:shinyhunters</code>) already covered in this store to a new victim class — an EU telecommunications operator. The mechanism, confirmed on-record by Odido CEO Tisha van Lammeren, is the same one documented previously: a caller impersonating Odido IT-department staff (<code>T1684.001</code>) used a voice-phishing pretext (<code>T1566.004</code>) to persuade a customer-service employee to log into a spoofed copy of the corporate work environment, harvesting that employee&#39;s real credentials (<code>T1078</code>) for the customer-contact system (<a href="https://nos.nl/artikel/2614128-odido-ontdekte-pas-na-bericht-van-hackers-dat-klantgegevens-waren-gestolen" target="_blank" rel="noopener noreferrer">NOS, 2026-05-12</a>). Odido blocked the account within an hour of noticing the intrusion (<a href="https://nos.nl/artikel/2614128-odido-ontdekte-pas-na-bericht-van-hackers-dat-klantgegevens-waren-gestolen" target="_blank" rel="noopener noreferrer">NOS, 2026-05-12</a>), but the operators had already bulk-exported 6.2 million customer records (name, address, contact details, customer number, bank account number, date of birth, and passport/driver&#39;s-licence numbers) (<a href="https://nos.nl/artikel/2602080-hack-bij-odido-gegevens-miljoenen-klanten-in-handen-van-criminelen" target="_blank" rel="noopener noreferrer">NOS, 2026-02-12</a>) — the CEO&#39;s Dutch quote via NOS: &quot;De hacker wist deze medewerker over te halen om in te loggen op een valse versie van de werkomgeving. Zo heeft hij de inloggegevens van die persoon gestolen&quot; (&quot;the hacker persuaded this employee to log into a fake version of the work environment, and so stole that person&#39;s login credentials&quot;) (<code>T1213</code>). The Dutch Data Protection Authority has two open investigations — into the adequacy of Odido&#39;s customer-system security and into whether it retained former-customer data longer than permitted.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">no software vulnerability was involved in this or the earlier tracked case — the single control that breaks the chain is out-of-band callback verification before any credential entry prompted by an inbound &quot;IT&quot; call, and the actor&#39;s speed (bulk export before same-day incident response detected the theft) means bulk-read alerting on customer/CRM repositories is the detection worth prioritising. <strong>Triage:</strong> a helpdesk agent logging into an internal portal is routine; the discriminator is a login into a portal reached via a link or address supplied during an inbound call, followed by an out-of-pattern bulk data read from a single session.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In het onderzoek heeft de politie sterke aanwijzingen gevonden dat Nederlandse criminelen betrokken zijn bij de Odido-hack.</p><figcaption class="entry-cite__attr"><a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie (Dutch National Police)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">De hacker wist deze medewerker over te halen om in te loggen op een valse versie van de werkomgeving. Zo heeft hij de inloggegevens van die persoon gestolen.</p><figcaption class="entry-cite__attr"><a href="https://nos.nl/artikel/2622288-bellende-odido-hacker-vermoedelijk-nederlander-politie-dreigt-stem-openbaar-te-maken" target="_blank" rel="noopener noreferrer">NOS (Dutch public broadcaster)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i/">2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i</a></p><div class="prov"><span>incident</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie (Dutch National Police)</a> · <a href="https://nos.nl/artikel/2622288-bellende-odido-hacker-vermoedelijk-nederlander-politie-dreigt-stem-openbaar-te-maken" target="_blank" rel="noopener noreferrer">NOS (Dutch public broadcaster)</a></div></article>]]></content:encoded></item><item><title>Huntress: device-code phishing and ROPC token-spray defeat M365 tenants by routing around the auth paths Conditional Access actually inspects</title><link>https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>identity</category><category>phishing</category><category>cloud</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>Huntress published a comparative root-cause analysis of two 2026 Microsoft 365 account-takeover campaigns that both bypassed Conditional Access policies requiring MFA — not by defeating MFA but by using auth flows CA rarely covers. &quot;Railway&quot; (March 2026, 344 orgs incl. Germany) used device-code phishing to harvest 90-day OAuth tokens; &quot;LSHIY&quot; (June 2026, 78 accounts across 64 orgs) ran 81M+ ROPC login attempts against Azure CLI through the /token endpoint. Of the 78 LSHIY-compromised accounts, 55 had active CA policies requiring MFA that failed because of scoping gaps. Every M365 tenant should block the device-code flow and ensure CA covers all cloud apps and all client app types including legacy auth.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns" data-tags="identity phishing cloud ai-abuse" data-regions="global" data-kind="research" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="m365-conditional-access-gaps-railway-lshiy-campaigns"><a href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA</a></h3><p>Huntress compared two structurally different but strategically identical 2026 Microsoft 365 account-takeover campaigns, both of which got through tenants whose Conditional Access (CA) policies required MFA — because each used an authentication path CA typically does not inspect (<a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>). The &quot;Railway&quot; campaign (March 2026) abused Microsoft&#39;s OAuth device-code flow: attackers generate a legitimate device-authorization code, embed it in a lure, and collect the resulting OAuth token (valid up to 90 days) when the victim enters the code at the real Microsoft endpoint — the victim may complete MFA, but the token is already gone, so the flow sidesteps MFA rather than defeating it (<code>T1528</code>). The operation ran from clean Railway.com PaaS IP ranges with trusted reputation (three IPs accounted for ~84% of traffic), used construction-RFP lure themes and in some chains triple-wrapped URLs through Cisco, Trend Micro and Microsoft SafeLinks in sequence, and reached 344 organisations across the US, Canada, Australia, New Zealand and Germany before Huntress published; it was attributed to a commercial phishing-as-a-service operation Huntress tracks as EvilTokens — a subscription platform with a storefront, a support team and AI-assisted lure generation (<a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The &quot;LSHIY&quot; campaign (active mid-June 2026) took the opposite approach: no phishing, just 81M+ login attempts from an IPv6 range against Azure CLI using the deprecated Resource Owner Password Credentials (ROPC) OAuth flow, which posts credentials straight to the <code>/token</code> endpoint and never touches the authorization endpoint where most CA policies are enforced (<code>T1110.003</code>, <code>T1078.004</code>, <a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-01</a>). It compromised at least 78 accounts across 64 organisations; the finding that matters for defenders is that 55 of those had active CA policies requiring MFA that failed for predictable scoping reasons (<code>T1556.006</code>): MFA scoped to specific apps such as Admin Portals but not &quot;All Cloud Apps&quot;, so Azure CLI slipped through; MFA scoped to specific user groups that omitted the compromised accounts; MFA required only from &quot;untrusted&quot; locations, bypassed by an attacker IP that geolocated inconsistently to the US; and two policies left in report-only mode. Huntress notes one tenant had a CA policy explicitly named &quot;Block Azure CLI&quot; that did not, in fact, block Azure CLI.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">MFA presence is not the control surface — CA policy <em>scope</em> is. Block the device-code flow tenant-wide (a victim who enters a code into the genuine Microsoft endpoint achieves nothing if the flow is disabled), and ensure MFA-requiring CA policies target all users, all cloud apps and all client app types including legacy/ROPC, backed by client-level strong-auth enforcement (<code>userStrongAuthClientAuthNRequired</code>) that blocks ROPC even with correct credentials. <strong>Triage:</strong> legitimate developer use of Azure CLI from a known device is the benign lookalike for the LSHIY pattern; the discriminators are volume (thousands of attempts), single-ASN concentration, and a successful legacy-auth/ROPC sign-in to a resource app with no interactive MFA event in the same session — and for device-code phishing, a device-code completion originating from something that is plainly not an input-constrained device.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Device code phishing is effective because it doesn&#39;t try to beat MFA. It sidesteps it.</p><p class="entry-cite__quote">Of the 78 compromised accounts, 55 had active Conditional Access policies requiring MFA.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">One glaring error here is that legacy protocols like ROPC can bypass some poorly-configured CAPs entirely since they don&#39;t go through the authorization endpoint where policies are enforced.</p><figcaption class="entry-cite__attr"><a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> <span class="entry-cite__date mono">2026-07-01</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Huntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware</title><link>https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>ransomware</category><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>lpe</category><category>identity</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2025-5777</category><description><![CDATA[<p>Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and — in the most progressed case — DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725" data-tags="ransomware vulnerabilities actively-exploited pre-auth lpe identity" data-regions="global" data-kind="threat" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-5777/">CVE-2025-5777</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="citrixbleed-2-dragonforce-iab-kill-chain-stac3725"><a href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)</a></h3><p>Across the first half of 2026 the Huntress Tactical Response unit worked at least six intrusions at unrelated organisations that reproduced the same seven-step kill chain so faithfully that analysts could predict the next artefact before pulling the log — the basis for their high-confidence assessment that an initial-access broker (IAB) has productised the path from an internet-facing Citrix box to domain-wide encryption, a cluster Sophos independently tracks as STAC3725 (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>; <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops, 2026-04-16</a>). Initial access is pre-auth exploitation of CitrixBleed 2 (<code>CVE-2025-5777</code>), a memory over-read in NetScaler ADC/Gateway configured as a Gateway or AAA virtual server: a POST to the login endpoint (<code>/p/u/doAuthentication.do</code> and equivalents) with the login form variable present but empty makes the appliance serialise roughly 127 bytes of adjacent process memory into the response, and sprayed at volume this yields live session tokens (<code>T1190</code>, <code>T1550.001</code>). In one reconstructed case a user authenticated normally over LDAP+MFA from a known-good IP at 13:07 UTC; twenty-one minutes later the same session was driven from the attacker&#39;s IP with no successful authentication from that IP anywhere in the logs — token replay, with MFA already satisfied and therefore irrelevant (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The privilege-escalation primitive is what makes the cluster unmistakable, because the hijacked session usually belongs to an unprivileged employee and the operator carries a portable, unsigned LPE tool (dropped to working paths such as <code>C:\temp</code> and renamed per victim — <code>eng.exe</code>, <code>legal.exe</code>, <code>as.exe</code> — often inside a password-protected archive pulled from <code>temp.sh</code>). The tool plants a <code>REG_LINK</code> <code>SymbolicLinkValue</code> under the RdpBus device-class key <code>{28d78fad-5a12-11d1-ae5b-0000f803a8c2}</code> that redirects into the Group Policy state hierarchy (<code>T1112</code>); running <code>gpupdate</code> forces the SYSTEM-context Group Policy engine to write through the planted link into a protected key, and <code>sc start AppMgmt</code> then makes the Service Control Manager relaunch the dropper as <code>NT AUTHORITY\SYSTEM</code>, which creates a backdoor administrator via <code>net user … /add</code> and <code>net localgroup Administrators … /add</code> (<code>T1068</code>, <code>T1136.001</code>, <code>T1098</code>). AppMgmt is chosen because it is always present, normally dormant, and plausibly related to policy processing. Before detonating, the tool snapshots the original key tree and restores it afterwards, leaving the registry indistinguishable from its pre-exploit state to erase the artefacts a responder would key on (<code>T1070</code>). Persistence then rides legitimate remote-management software — ScreenConnect and Zoho Assist, in one case Netbird plus Atera (<code>T1219</code>) — and in the most advanced case the operator used PsExec, Impacket and Mimikatz for lateral movement and credential access (<code>T1003</code>, <code>T1570</code>) before deploying DragonForce ransomware, contained to a single host (<code>T1486</code>). Huntress declines a firm DragonForce-affiliate-versus-IAB attribution given the tactic overlap, and ruled out an alternative NetScaler session-management race-condition flaw because the affected build and the required already-authenticated session to race against did not fit the evidence.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch NetScaler to the fixed builds and, critically, terminate every live session afterwards — harvested tokens survive the patch, which is the single most common post-patch reinfection path for this bug. On the appliance, the load-bearing detection is not the paired diagnostic breadcrumbs (&quot;Login request is not expected to be encrypted&quot;, &quot;X509 cert not found&quot;), which Huntress calls necessary but nowhere near sufficient, but the binary/unprintable data leaking through the ns.log AAA <code>LOGIN_FAILED</code> User field and — the cleanest signal — an authenticated session that has no corresponding successful login event. A default Citrix behaviour also fingerprints the operator: published-desktop sessions auto-create client printer mappings that embed the client workstation name (the same <code>WIN-</code> hostnames recurred case after case), correlatable by pivoting the <code>Microsoft-Windows-TerminalServices-LocalSessionManager/Operational</code> channel (source IP + session ID) against the <code>MetaFrameEvents</code> provider in the Application log (session ID + leaked client name). <strong>Triage:</strong> a NetScaler login flood looks like ordinary password spraying and is routinely dismissed as such — the discriminator is that the &quot;usernames&quot; are leaked heap memory (unprintable bytes, X.509/ASN.1 fragments, internal <code>Citrix-ns-orig-srcip</code> proxy headers), not guessed account names; and on the endpoint, a <code>gpupdate</code> → <code>AppMgmt</code> start → new-SYSTEM-process → local-admin-creation sequence within seconds is the signal, whereas legitimate Group Policy refreshes do not spawn a fresh SYSTEM binary that immediately creates an account.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><p class="entry-cite__quote">The cleanup serves to evade detection: by leaving the registry indistinguishable from its pre-exploit state, the tool removes the artifacts a responder would normally key on.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment.</p><figcaption class="entry-cite__attr"><a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> · <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops</a></div></article>]]></content:encoded></item><item><title>Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June</title><link>https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</guid><pubDate>Thu, 09 Jul 2026 20:38:00 +0000</pubDate><dc:date>2026-07-09T20:38:00Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>switzerland</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-50656</category><description><![CDATA[<p>NCSC-CH&#39;s Nightmare Eclipse tracker was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59) local privilege escalation in the Microsoft Malware Protection Engine behind Defender that lets a local attacker reach SYSTEM; Microsoft&#39;s MSRC record shows the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE sat in &quot;no fix&quot; for over three weeks. The engine auto-updates, so most estates are already current — but WSUS-gated, offline or OT-adjacent estates should explicitly verify the installed engine build.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50656/">CVE-2026-50656</a></div><h3 class="f-h" id="ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed"><a href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">CVE-2026-50656 — Microsoft Defender engine &#39;RoguePlanet&#39; local privilege escalation now patched; NCSC-CH tracks the ongoing &#39;Nightmare Eclipse&#39; zero-day series</a></h3><p>NCSC-CH&#39;s running tracker on the &quot;Nightmare Eclipse&quot; (aka Chaotic Eclipse) researcher&#39;s 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to <strong>RoguePlanet</strong>: <strong>CVE-2026-50656</strong>, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / &quot;link following&quot;) in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker &quot;execute arbitrary code or spawn a command shell with SYSTEM-level privileges&quot; (<code>T1068</code>), at which point NCSC-CH logged its status as &quot;Proof of Concept Available, no patch available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). Microsoft&#39;s own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, <code>AV:L/AC:L/PR:L/UI:N</code>, rated &quot;Exploitation More Likely&quot;, exploitation status &quot;No&quot;) and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it — last vulnerable Malware Protection Engine build <strong>1.1.26050.11</strong>, first fixed build <strong>1.1.26060.3008</strong> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>).</p>
<p>Because the Malware Protection Engine (<code>mpengine.dll</code>) auto-updates multiple times a day by default, most estates will already carry the fixed build — Microsoft&#39;s guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. <strong>Triage:</strong> the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, <code>MsMpEng.exe</code> (the engine&#39;s scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence — the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656.</p><p class="entry-cite__quote">Improper link resolution before file access (&#39;link following&#39;) in Microsoft Defender allows an authorized attacker to elevate privileges locally.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch Cyber Security Hub</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a></div></article>]]></content:encoded></item><item><title>KDDI pins its multi-ISP email-platform breach on a zero-day in an unnamed third-party component the vendor had not recognised</title><link>https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/</guid><pubDate>Thu, 09 Jul 2026 12:38:00 +0000</pubDate><dc:date>2026-07-09T12:38:00Z</dc:date><category>data-breach</category><category>zero-day</category><category>supply-chain</category><category>apac</category><description><![CDATA[<p>KDDI&#39;s 6 July update on the shared email platform serving STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE discloses the root cause — a zero-day in an unnamed third-party software component, unrecognised by the vendor at KDDI&#39;s 17 June discovery date — and confirms final scale of 12,233,087 exposed email addresses and 7,616,173 exposed passwords. The transferable lesson: a genuine vendor-unknown zero-day that no patch-management process alone would have caught, underscoring behavioural/EDR detection on infra hosting third-party components.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update" data-tags="data-breach zero-day supply-chain" data-regions="apac" data-kind="incident" data-priority="routine" data-discovered="2026-07-09T12:38:00Z"><div class="badges"><span class="b ">ROUTINE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="kddi-isp-email-breach-zero-day-root-cause-update"><a href="https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/">KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m/">KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs</a> <span class="mono muted">(2026-06-29)</span></p><p>KDDI&#39;s 6 July update — reported by BleepingComputer on 8 July — discloses the confirmed root cause and exact scale of the breach of the shared email platform serving STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. The platform was compromised on 16 May 2026 via a zero-day vulnerability in an (still unnamed) third-party software component — a flaw that, per KDDI, &quot;was not recognized by the software vendor&quot; as of KDDI&#39;s 17 June confirmation date and which the vendor is now reporting to public authorities (<a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). KDDI confirmed final counts of 12,233,087 exposed email addresses and 7,616,173 exposed passwords — down from the earlier &quot;up to 14.22 million&quot; estimate (<a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-28</a>) — deployed EDR post-incident, completed a forensic audit on 23 June confirming the flaw was patched with no other issues remaining, and notified Japan&#39;s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.</p>
<p>Neither report names the exploited third-party product; KDDI has stated only &quot;third-party software&quot;, and that ambiguity is in the source, not omitted here.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the delta of interest for telco and any multi-tenant-platform operator is the disclosure timeline — a multi-tenant email platform serving several ISPs was compromised via a genuine zero-day the software vendor itself had not identified, a scenario no patch-management process alone would have caught, which is the concrete argument for behavioural/EDR detection and egress monitoring on infrastructure hosting third-party components and for rapid regulator notification once exploitation is confirmed.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">&quot;As a result of our investigation, as of June 17, 2026, the date of our confirmation, this vulnerability was not recognized by the software vendor,&quot; KDDI said.</p><figcaption class="entry-cite__attr">KDDI (via BleepingComputer)</figcaption></figure></div><div class="prov"><span>incident</span><span>09 Jul 12:38Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Two Golang DDoS botnets, Apex2 and c2c/meow, flood exposed Telnet/SSH Linux and IoT with fake-systemd persistence and passwordless-sudo escalation</title><link>https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</guid><pubDate>Thu, 09 Jul 2026 12:33:00 +0000</pubDate><dc:date>2026-07-09T12:33:00Z</dc:date><category>botnet</category><category>ddos</category><category>ot-ics</category><category>global</category><description><![CDATA[<p>Nozomi Networks Labs details two Golang DDoS botnet families caught via honeypots this spring: Apex2 (Telnet brute-force, Linux+Windows builds, a Cloudflare-bypass HTTP flood plus UDP/TLS floods) and c2c/meow (SSH-delivered, escalates via passwordless sudo, persists as a fake systemd &#39;cpufreqd&#39; service). Neither is sophisticated, but the point for defenders is the pace: exposed Telnet/SSH management interfaces on IoT and embedded-Linux keep getting repurposed for DDoS faster than before — directly relevant to OT-adjacent estates in energy, water and transport.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets" data-tags="botnet ddos ot-ics" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-09T12:33:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets"><a href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Nozomi documents two new Golang IoT/Linux DDoS botnets (Apex2, c2c/meow) built for speed and reuse over sophistication</a></h3><p>Nozomi Networks Labs&#39; AI-assisted honeypot triage flagged two Golang-based DDoS botnet samples this spring that stand out from the routine volume of Mirai-derived variants: Apex2 and c2c (distributed under the filename &quot;meow&quot;) (<a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs, 2026-07-06</a>). Apex2 is a direct structural evolution of the earlier Apex botnet: infection begins with Telnet connections and credential brute-forcing, followed by download-and-execute of the Golang payload, which registers with its C2 over a plaintext protocol (host OS/architecture) and ships builds for Linux (arm, arm64, mipsle, ppc64) and Windows (386, amd64). Its named flood commands include <code>cf</code> (an HTTP(S) flood specifically tuned to bypass Cloudflare via randomized User-Agent lists and long keep-alive timeouts), <code>udp</code>/<code>pps</code>, <code>discord</code>/<code>game</code> UDP floods, and three TLS-flood variants (<code>tls</code>, <code>tlsplus</code>, <code>tlsplusbypass</code>). c2c/meow is architecturally simpler — a Golang flooder with no built-in propagation (a separate SSH scanner handles brute-forcing and delivery) that authenticates to a hardcoded C2 over plaintext JSON-over-TCP, checks for passwordless sudo (<code>sudo -n true</code>) to self-escalate, then persists by copying itself to <code>/usr/local/bin/cpufreqd</code> and registering a fake systemd unit masquerading as a &quot;CPU Frequency Daemon&quot; — supporting ten flood-module types (icmp, dnsudp, udp, http, directhttp, fasthttp, betterhttp, tcp, tcphandshake, dnstcp).</p>
<p>Nozomi&#39;s stated point for defenders is that neither family is sophisticated — both lean on commodity Golang tooling, weak/default credentials and exposed Telnet/SSH interfaces rather than novel exploitation — and that the lack of sophistication does not reduce the risk at scale, because the build-and-deploy cycle for such botnets is getting faster. ATT&amp;CK mapping: <code>T1110 Brute Force</code> (Telnet/SSH), <code>T1105 Ingress Tool Transfer</code>, <code>T1548.003 Abuse Elevation Control Mechanism: Sudo</code> (c2c&#39;s passwordless-sudo self-escalation), <code>T1543.002 Create or Modify System Process: Systemd Service</code> with <code>T1036.005 Masquerading</code> (the fake cpufreqd unit), and <code>T1498 Network Denial of Service</code> for the flood modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is not a novel threat but a concrete hunt package for the OT-adjacent and embedded-Linux estates in the constituency&#39;s energy, water and transport remit — the fake-systemd-service naming, the <code>sudo -n true</code> escalation probe, and plaintext-JSON C2 are all cheap, durable detections, and the durable fix is the unglamorous one of removing internet-exposed Telnet/SSH and default credentials on IoT and embedded devices.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It checks whether passwordless sudo is available by running sudo -n true and evaluating the return value. If successful, it relaunches itself with increased privileges, copies to /usr/local/bin/cpufreqd, and creates a fake systemd service named &quot;CPU Frequency Daemon&quot;</p><p class="entry-cite__quote">In both cases, the emphasis is not on sophistication, but on speed, reuse and scalability.</p><figcaption class="entry-cite__attr"><a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> <span class="entry-cite__date mono">2026-07-06</span></figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 12:33Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> · <a href="https://industrialcyber.co/ransomware/nozomi-identifies-apex2-and-c2c-golang-malware-driving-faster-iot-botnet-attacks-raising-risks-for-ot-environments/" target="_blank" rel="noopener noreferrer">Industrial Cyber</a></div></article>]]></content:encoded></item><item><title>Sygnia IR: an AI-assisted AWS intrusion ran four parallel workstreams per stolen key and used four accounts&#39; keys in one second</title><link>https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>cloud</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>Sygnia&#39;s incident response into a financially-motivated AWS intrusion found no novel malware or zero-day — every technique maps to a known MITRE ATT&amp;CK ID — but the tempo and parallelism point to AI-assisted/agentic tooling: initial access to broad compromise in ~72h, and four access keys from four separate accounts used from one source IP and user-agent within a single observed second. The detection signal is the orchestration, not the individual actions. Defenders should pre-build minutes-not-hours containment and alert on one source authenticating with multiple distinct keys in a tight window.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h" data-tags="ai-abuse cloud organized-crime" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="sygnia-ai-orchestrated-aws-cloud-intrusion-72h"><a href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours — four keys from four accounts used from one source in the same second</a></h3><p>Sygnia&#39;s incident-response investigation of a financially-motivated AWS cloud intrusion found no novel malware or zero-day — every individual technique maps to a long-tracked MITRE ATT&amp;CK ID — but the operationalisation was materially faster than typical manual intrusions, which Sygnia attributes to AI-assisted or agentic tooling (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>). After obtaining an initial access key via a weakness in an internet-facing application, the actor ran four workstreams in parallel — secrets theft (ECS/EC2 environment variables, GitHub/Bitbucket CI/CD runner env vars, S3 plaintext secrets, Secrets Manager, SSM Parameter Store); persistence (new IAM users, EC2/ECS reverse shells, modified deployment files); RDS exfiltration via several hundred distinct SQL queries across dozens of databases; and reversible impact (S3 access denial, ECS scaled to zero, SQS purges) used purely as extortion leverage — and repeated the full playbook on every newly obtained credential rather than progressing linearly. The most striking artefact: four different AWS access keys from four separate accounts were used from the same source IP and user-agent within a single observed second, which Sygnia assesses is very hard to explain as manual operation (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>).</p>
<p>Scripts, structured reporting output, and commit messages/branch names framing the activity as an authorized &quot;pentest&quot;/&quot;red team&quot; with a fabricated CEO sign-off are consistent with LLM-generated tooling — possibly including prompt-framing meant to reduce refusal from AI assistants being abused by the operator. Sygnia maps the case onto the same tactic distribution (Execution, Discovery, Credential Access, Collection, Defense Evasion) that Anthropic&#39;s June 2026 LLM ATT&amp;CK research found concentrated in banned AI-abuse accounts. Relevant IDs per Sygnia include <code>T1651 Cloud Administration Command</code>, <code>T1552/T1528</code> (credential/token harvesting), <code>T1087/T1580/T1619</code> (account/cloud-infra/storage discovery re-run per key), <code>T1578</code> (modify cloud compute infra) and <code>T1078 Valid Accounts</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector estate mid-cloud-migration running AWS with GitHub/Bitbucket CI/CD, the lesson is tempo. The ATT&amp;CK-mappable individual actions are not the alarm — the orchestration is: one source authenticating with multiple distinct keys/accounts in seconds, and the same secrets-harvesting sequence re-firing on each new credential. Because manual response cannot keep pace, containment (network isolation, credential rotation, session revocation) has to be pre-built to run in minutes, and every exposed credential must be assumed used instantly and at scale.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In one observed second, four different access keys belonging to four separate accounts were used from the same source IP address and the same user-agent</p><p class="entry-cite__quote">The intrusion progressed from initial access to broad cloud compromise within approximately 72 hours.</p><p class="entry-cite__quote">multiple attacker-created artifacts were framed as part of a &#39;pentest&#39; or a &#39;red team&#39;. This framing appeared in branch names, commit messages, and other artifacts, including references suggesting the activity was approved by a non-existent CEO.</p><figcaption class="entry-cite__attr"><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a></div></article>]]></content:encoded></item><item><title>Mandiant recovers a live ADFS signing key from Machine DPAPI — a Golden SAML variant that sidesteps the WID/DKM path and LSASS-watching detection</title><link>https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>identity</category><category>espionage</category><category>cloud</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Mandiant documented an ADFS Golden SAML variant: when AutoCertificateRollover is disabled and certificates are rotated manually, the WID configuration database drifts to a stale &quot;ghost&quot; certificate while the active token-signing key sits in the machine CAPI store protected by Machine DPAPI. A SYSTEM-level attacker recovers it with SharpDPAPI /machine — without touching the WID/DKM path or LSASS — and forges a Global Administrator SAML assertion that Entra ID accepts, bypassing MFA and conditional access. The drift is observable via ADFS Event ID 385; treat ADFS as Tier 0.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery" data-tags="identity espionage cloud" data-regions="global europe switzerland" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="mandiant-adfs-machine-dpapi-golden-saml-key-recovery"><a href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Mandiant &quot;Ghost in the Database&quot;: recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails</a></h3><p><strong>Background.</strong> Golden SAML — forging SAML assertions by stealing an identity provider&#39;s token-signing key — has been public tradecraft since CyberArk&#39;s 2017 disclosure (<a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" target="_blank" rel="noopener noreferrer">CyberArk, 2017</a>), and Mandiant previously documented network-based extraction of ADFS secrets during the UNC2452/SolarWinds intrusions (<a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network" target="_blank" rel="noopener noreferrer">Mandiant</a>). The standard extraction path pulls the encrypted signing key from the ADFS Windows Internal Database (WID) and decrypts it with Distributed Key Manager (DKM) material stored in Active Directory. This new Mandiant write-up documents a variant that defeats that assumption when ADFS configuration has drifted.</p>
<p>During a red-team engagement, Mandiant found that ADFS deployments with <code>AutoCertificateRollover</code> disabled (<code>Get-AdfsProperties</code> → <code>AutoCertificateRollover: False</code>) and certificates rotated manually can leave the WID configuration database holding only a stale &quot;ghost&quot; certificate record, while the ADFS service actually signs tokens with a newer certificate whose private key lives in the machine CAPI store (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). In that state the classic path still &quot;works&quot; mechanically — the WID blob decrypts via DKM — but Entra ID rejects the resulting token with <strong>AADSTS500172</strong> because the key is no longer the one in use.</p>
<p><strong>The key&#39;s real location and protection.</strong> The active private key sits under <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code>, with the certificate enrolled in the <code>LocalMachine\My</code> store. It is protected by <strong>Machine DPAPI</strong> (not user-bound DPAPI): the <code>DPAPI_SYSTEM</code> LSA secret plus machine masterkeys under the <code>S-1-5-18</code> (SYSTEM) context at <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>. Machine-scoping is deliberate — it keeps the key usable across service-account password changes, gMSA rotations and reboots — but it also means a SYSTEM-level actor can recover the key entirely from the host. Mandiant confirmed recovery with <code>SharpDPAPI /machine</code>, which enumerated the active key material under that path (the CNG <code>Crypto\Keys</code> store was not in use in the assessed environment) — no interaction with the live ADFS process or LSASS is required, reducing visibility for defenses that watch only credential-dumping/process-memory access (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Kill chain (ATT&amp;CK).</strong> SYSTEM-level foothold on the ADFS host → recover Machine-DPAPI-protected masterkeys and the CAPI signing key (<code>T1552 Unsecured Credentials</code>, via <code>SharpDPAPI /machine</code>) → forge a SAML assertion impersonating a Global Administrator (<code>T1606.002 Forge Web Credentials: SAML Tokens</code>) → Entra ID accepts it as a valid federated authentication assertion, yielding Global Administrator access to the Microsoft 365 tenant with MFA and conditional access fully bypassed (<code>T1078.004 Valid Accounts: Cloud Accounts</code>). Because the forged assertion is honoured for <strong>all SAML relying-party trusts</strong>, the blast radius extends to every SaaS platform federated through the same ADFS, not just Microsoft services.</p>
<p><strong>Hunt and detection.</strong> The drift condition itself is observable: <strong>ADFS Event ID 385</strong> fires when the WID record and the actively-used signing certificate diverge, and self-resolves only once <code>AutoCertificateRollover</code> is re-enabled and a rollover runs. For key-theft detection, Mandiant recommends SACL-based object-access auditing (Security <strong>Event ID 4663</strong>) on <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code> and <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>, treated as correlation evidence rather than a standalone signal. The strongest analytic is cross-source: correlate ADFS token-issuance/claims events (Event IDs 299 and the 1200-series, version-dependent) against Entra ID sign-in logs to surface federated sign-ins with no matching upstream authentication context, baselining claim sets, IP ranges and user-agents per relying-party trust for privileged accounts — neither log source alone is sufficient (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Hardening.</strong> Migrate token-signing certificates to an HSM to eliminate the software-accessible key and thus the Machine DPAPI extraction path entirely; run ADFS under gMSA to reduce manual-rotation drift; govern ADFS servers as <strong>Tier 0</strong> (restricted admin paths, dedicated PAWs, separation from general server administration). When <code>AutoCertificateRollover</code> is disabled, a manual rotation must include <code>Set-AdfsCertificate</code> — installing the certificate alone is insufficient — and be validated with <code>Get-AdfsCertificate</code>; a subsequent Event ID 385 signals lingering inconsistency. Organisations migrating to native OIDC federation remove this attack path altogether (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). ADFS remains widely deployed for on-prem/hybrid identity across Swiss and EU public-sector estates mid-migration to Entra ID, making this a direct Tier 0 hardening item for the constituency.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication</p><p class="entry-cite__quote">The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion</p><p class="entry-cite__quote">Configure object access auditing via SACLs on C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\ and C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\. When configured correctly, this generates Security Event ID 4663 for file access attempts.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> · <a href="https://itbrief.co.uk/story/mandiant-finds-way-to-recover-active-adfs-signing-keys" target="_blank" rel="noopener noreferrer">itbrief.co.uk</a></div></article>]]></content:encoded></item><item><title>Research: signature malleability lets anyone forge a second &quot;Verified&quot; GitHub commit under a new hash, bypassing SHA-based supply-chain controls</title><link>https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>supply-chain</category><category>poc-public</category><category>no-patch</category><category>global</category><description><![CDATA[<p>Jacob Ginesin (CMU / Cure53) showed that Git/GitHub&#39;s &quot;Verified&quot; commit badge is not a unique identifier: given any signed commit, an attacker without the signing key can mint a second, distinct commit with the same tree, author and date and a still-valid signature — differing only in its hash. The cause is signature malleability (ECDSA (r,s)→(r,n−s); ignorable OpenPGP subpackets; S/MIME encoding), not a hash collision. Hash-based incident-response blocklists and push-protection rules can be trivially bypassed. A public PoC tool exists; no CVE and no Git/GitHub fix as of disclosure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin" data-tags="supply-chain poc-public no-patch" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="git-signature-malleability-github-verified-commit-ghost-twin"><a href="https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/">Git commit-signature malleability mints a second &quot;Verified&quot; GitHub commit with a different hash — defeating hash-based blocklists</a></h3><p>Jacob Ginesin (Carnegie Mellon PhD student, Cure53 auditor) published research on 2 July, amplified by The Hacker News on 8 July, showing that Git/GitHub&#39;s <strong>&quot;Verified&quot; commit badge is not a unique identifier</strong>: given any signed commit, an attacker without the signing key can mint a second, distinct commit with an identical tree, identical author/date metadata, and a valid signature that still shows &quot;Verified&quot; — differing only in its resulting hash (<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-08</a>; <a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noopener noreferrer">Ginesin, arXiv, 2026-07-02</a>). The root cause is <strong>signature malleability</strong>, not a hash collision. A commit&#39;s SHA is computed over everything inside it, including the raw signature bytes in its header, and many signatures can be rewritten into a different-but-valid form.</p>
<p>Three malleation routes are demonstrated: (1) for ECDSA, the classical algebraic symmetry that turns a valid pair <code>(r,s)</code> into <code>(r, n−s)</code> using only public curve parameters, producing a second equally-valid signature over the same payload with different bytes and therefore a different commit hash; (2) for RSA and EdDSA under OpenPGP, appending an ignorable experimental subpacket in the unhashed subpacket region defined in RFC 4880 §5.2.3; (3) an analogous X.509/S-MIME path. GitHub does not normalize or canonicalize a signature before verifying it — no strict encoding enforcement on S/MIME, no stripping of the manipulable OpenPGP fields, and non-canonical ECDSA values accepted as-is (<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-08</a>). A public exploitation tool implementing all three attacks, plus demo repos where the malleated commits still show &quot;Verified&quot;, is released (<a href="https://github.com/JakeGinesin/git-chain-malleator" target="_blank" rel="noopener noreferrer">Ginesin, git-chain-malleator</a>). Ginesin reported to GNU/Git in January and GitHub in March 2026; neither had shipped a fix at publication, and no CVE is assigned. Maps to <code>T1195.002 Compromise Software Supply Chain</code> as a control-bypass primitive.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any organisation — including government CI/CD pipelines — that keys incident-response or push-protection controls off a specific commit SHA should treat those controls as bypassable. After taking down a known-malicious commit, an operator can re-push a content-identical &quot;ghost twin&quot; under a fresh, equally-&quot;Verified&quot; hash that is not on the blocklist. Move integrity decisions to tree hash + author + content diff, allowlist content rather than commit identity, and read &quot;Verified&quot; as provenance rather than uniqueness until Git/GitHub canonicalize signatures.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps &#39;Verified.&#39;</p><p class="entry-cite__quote">GitHub does not normalize a signature before checking it. No strict encoding on S/MIME, no stripping of those OpenPGP fields, and non-canonical ECDSA values accepted as-is.</p><figcaption class="entry-cite__attr">The Hacker News, summarising Jacob Ginesin&#39;s research</figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noopener noreferrer">Jacob Ginesin (CMU / Cure53) — arXiv preprint</a> · <a href="https://github.com/JakeGinesin/git-chain-malleator" target="_blank" rel="noopener noreferrer">Jacob Ginesin — public PoC tool (git-chain-malleator)</a></div></article>]]></content:encoded></item><item><title>Wiz &quot;GhostApproval&quot;: malicious repos escape the workspace sandbox of six AI coding assistants via symlink + fake confirmation dialog</title><link>https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>vulnerabilities</category><category>supply-chain</category><category>ai-abuse</category><category>rce</category><category>poc-public</category><category>patch-available</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-12958</category><category>CVE-2026-50549</category><description><![CDATA[<p>Wiz Research disclosed GhostApproval, a pattern combining symlink-following (CWE-61) with confirmation-dialog UI misrepresentation (CWE-451) across Amazon Q Developer, Cursor, Google Antigravity, Augment, Windsurf and Anthropic Claude Code. A malicious repository plants an in-workspace symlink resolving to a sensitive path (e.g. ~/.ssh/authorized_keys); the agent writes to the true target while the approval dialog shows the harmless in-workspace name — enabling host compromise. AWS (CVE-2026-12958) and Cursor (CVE-2026-50549) shipped fixes; Augment and Windsurf were unpatched at disclosure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary" data-tags="vulnerabilities supply-chain ai-abuse rce poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12958/">CVE-2026-12958 +1</a></div><h3 class="f-h" id="ghostapproval-ai-coding-assistant-symlink-trust-boundary"><a href="https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/">GhostApproval (CVE-2026-12958, CVE-2026-50549) — symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants&#39; workspace sandbox</a></h3><p>Wiz Research published <strong>GhostApproval</strong> on 8 July, a systematic vulnerability pattern combining <code>CWE-61</code> (symbolic-link following) with <code>CWE-451</code> (UI misrepresentation of critical information) found, in varying severity, across six AI coding assistants: Amazon Q Developer, Cursor, Google Antigravity, Augment, Cognition Labs&#39; Windsurf and Anthropic&#39;s Claude Code (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). A malicious repository plants a symlink inside the workspace that resolves to a sensitive path outside it — e.g. a file named <code>project_settings.json</code> that is actually a link to <code>~/.ssh/authorized_keys</code> — then a README or prompt instructs the agent to &quot;update&quot; the file. In several tools the agent&#39;s own reasoning identifies the true target, yet the confirmation dialog still shows the harmless in-workspace name, so the user rubber-stamps a write to the real target, enabling persistent passwordless SSH access or other host compromise. Windsurf exhibited a <strong>pre-authorization write</strong> — the file was modified on disk before the Accept/Reject buttons even rendered, making the prompt an &quot;undo&quot; button rather than a gate.</p>
<p>AWS assigned <strong>CVE-2026-12958</strong> (missing symlink validation in Language Servers for AWS, CVSS 8.5, fixed in language-servers 1.69.0 / <code>@aws/lsp-codewhisperer</code> 0.0.117) and Cursor assigned <strong>CVE-2026-50549</strong> (sandbox escape via symlink + failed path canonicalization, fixed in Cursor 3.0), both confirming arbitrary out-of-workspace file write as the impact (<a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GHSA-6v3r-4p5c-mrp5, 2026-06-23</a>; <a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GHSA-3v8f-48vw-3mjx, 2026-06-05</a>). Google fixed Antigravity (CVE pending at publication). Augment and Windsurf acknowledged the report but were still testable-vulnerable at disclosure (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). Anthropic assessed the report as outside its threat model for Claude Code — its stated rationale is that a user who starts a session in a directory has already extended trust to it — while noting it had shipped a symlink warning in the Edit/Write permission dialog in v2.1.32 (5 Feb 2026) as unrelated proactive hardening (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). Mapped to <code>T1195.002 Compromise Software Supply Chain</code>, <code>T1222 File and Directory Permissions Modification</code> (via symlink) and <code>T1552.004 Unsecured Credentials</code> (authorized_keys write).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any public-sector or enterprise engineering team running these assistants against externally-sourced repositories is exposed regardless of the tool&#39;s own confirmation-dialog behaviour. Beyond patching, the durable control is to treat every AI-coding-assistant file write to credential/dotfile paths as high-severity and to canonicalize symlink targets before trusting an &quot;Accept&quot; prompt — the confirmation must be a gate, not an undo.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The user approves what they believe is a harmless local edit; the agent writes to a sensitive file outside of the project workspace.</p><figcaption class="entry-cite__attr"><a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary.</p><figcaption class="entry-cite__attr"><a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GitHub Security Advisory (GHSA-6v3r-4p5c-mrp5)</a> <span class="entry-cite__date mono">2026-06-23</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">A malicious agent could write arbitrary files outside the workspace under the user&#39;s privileges. This enables non-sandboxed Remote Code Execution.</p><figcaption class="entry-cite__attr"><a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GitHub Security Advisory (GHSA-3v8f-48vw-3mjx)</a> <span class="entry-cite__date mono">2026-06-05</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research</a> · <a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GitHub Security Advisory (GHSA-6v3r-4p5c-mrp5)</a> · <a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GitHub Security Advisory (GHSA-3v8f-48vw-3mjx)</a></div></article>]]></content:encoded></item><item><title>ESET Threat Report H1 2026: PromptSpy runs Gemini in its own execution flow, ClickFix 2x, QR-phishing at record levels, 100+ EDR-killers catalogued</title><link>https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>phishing</category><category>mobile</category><category>ransomware</category><category>infostealer</category><category>global</category><category>europe</category><description><![CDATA[<p>ESET&#39;s semi-annual threat report (Dec 2025–May 2026 telemetry) flags four items for a Tier 2/3 team: PromptSpy, described as the first Android malware to use generative AI (Google Gemini) at runtime to interpret UI and adapt behaviour; ClickFix detections more than doubling H2 2025→H1 2026 and expanding beyond fake CAPTCHA into AI-help-page and cloud-auth lures; QR-code phishing at record levels (~11% of detected phishing emails); and 100+ distinct EDR-killer tools now catalogued in the wild.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/eset-threat-report-h1-2026" data-tags="ai-abuse phishing mobile ransomware infostealer" data-regions="global europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="eset-threat-report-h1-2026"><a href="https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/">ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers</a></h3><p>ESET&#39;s semi-annual threat-landscape report (telemetry December 2025–May 2026) flags four developments a Tier 2/3 team should track (<a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity, 2026-07-08</a>; <a href="https://www.globenewswire.com/news-release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html" target="_blank" rel="noopener noreferrer">ESET press release, 2026-07-08</a>).</p>
<p>First, ESET analysed roughly 900,000 &quot;AI skills&quot; — small functional components used by AI agents — and found tens of thousands suspicious and thousands outright malicious, an expanding attack surface in the emerging agentic-AI ecosystem. Second, it identified <strong>PromptSpy</strong>, described as the first known Android malware to use generative AI (specifically Google&#39;s Gemini) inside its own execution flow to interpret UI elements and adapt behaviour across devices at runtime rather than relying on hardcoded logic — following the first AI-powered ransomware disclosed in 2025 (<a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET, 2026-07-08</a>). Third, <strong>ClickFix</strong> (the fake-error social-engineering technique) has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions and cloud-authentication scenarios, with ESET detections more than doubling between H2 2025 and H1 2026. Fourth, <strong>QR-code phishing</strong> (&quot;quishing&quot;) reached record levels, with roughly 11% of all ESET-detected phishing emails in H1 2026 using QR codes to move victim interaction onto mobile devices and evade cursory inspection. Ransomware activity continued unabated with over <strong>100 distinct EDR-killer tools</strong> now catalogued by ESET, though a declining share of victims are reportedly paying.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is a single reference entry for ESET&#39;s semi-annual H1/H2 report cadence (predecessor: ESET Threat Report H2 2025). The operational reads for the constituency: the volume of EDR-killer tooling argues for prioritising driver/process-tampering and protected-process telemetry over ransomware-binary signatures; QR codes in email bodies deserve the same handling as embedded URLs; and ClickFix awareness material must now cover AI-help-page and browser-extension-install variants, not just the fake-CAPTCHA lure. PromptSpy and the malicious-&quot;AI-skills&quot; finding are early indicators that runtime GenAI is moving into the malware execution path itself, worth tracking as a developing class rather than an immediate control change.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow</p><p class="entry-cite__quote">ESET detections of this vector more than doubled between H2 2025 and H1 2026</p><p class="entry-cite__quote">ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly</p><figcaption class="entry-cite__attr"><a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>annual-report</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity</a> · <a href="https://www.globenewswire.com/news-release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html" target="_blank" rel="noopener noreferrer">GlobeNewswire (ESET press release)</a></div></article>]]></content:encoded></item><item><title>Januscape (CVE-2026-53359): 16-year-old KVM shadow-MMU UAF gives a guest root a host escape on both Intel and AMD</title><link>https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-53359</category><description><![CDATA[<p>Januscape (CVE-2026-53359) is a use-after-free in the KVM/x86 shadow-MMU emulation (arch/x86/kvm/mmu/mmu.c) that lay dormant in the Linux kernel for ~16 years and lets a root user inside any KVM guest escape to the host on both Intel and AMD. A public PoC panics the host kernel (DoS against every co-tenant); a working host-RCE exploit exists but is withheld. Fixed upstream 2026-06-16 — patch KVM host kernels to the fixed trains now; there is no guest-side mitigation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-53359/">CVE-2026-53359</a></div><h3 class="f-h" id="cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape"><a href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">CVE-2026-53359 — Linux KVM/x86 &quot;Januscape&quot;: shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD</a></h3><p>Researcher Hyunwoo Kim (V4bel) disclosed <strong>Januscape (CVE-2026-53359)</strong>, a use-after-free in the shadow-MMU emulation of KVM/x86 (<code>arch/x86/kvm/mmu/mmu.c</code>) whose root cause traces to a 2010 commit — roughly 16 years dormant before the fix landed upstream on 16 June 2026 (<a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-07</a>). The bug fires when <code>kvm_mmu_get_child_sp()</code> reuses a shadow page without comparing its role, producing a mismatched direct/indirect flag and an incorrect GFN computation; orphaned rmap entries survive memslot deletion and are later dereferenced after the backing memory is freed (<a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>). The upstream fix is commit <code>81ccda30b4e8</code> (16 June 2026); the researcher gives the vulnerable range as commit <code>2032a93d66fa</code> (2010-08-01) through that fix (<a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e8" target="_blank" rel="noopener noreferrer">kernel.org, 2026-06-16</a>; <a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>).</p>
<p>This is a genuine <strong>guest-to-host escape</strong>: a root user inside a KVM guest can trigger the UAF from purely guest-side actions, on both Intel and AMD hosts — the researcher calls it &quot;the first guest-to-host exploit research triggerable on both&quot; vendors (<a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>). Januscape was submitted as a live 0-day against Google&#39;s kvmCTF program. A public PoC that panics the host kernel — a denial of service against every co-tenant on the same physical host — is released; a full working host-compromise/RCE exploit exists but the researcher is deliberately withholding it (<a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-07</a>). Mapped to <code>T1611 Escape to Host</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any Swiss/EU public-sector or critical-infrastructure estate running KVM-backed private cloud or renting KVM capacity is in scope — a single hostile tenant (or a tenant whose guest root is compromised) can take down or take over the physical host. Prioritise the host-kernel patch above (guest patching does not help), and until every KVM host is on a fixed train, watch for host kernel-panic/oops events correlated with one tenant&#39;s VM as the DoS signature; not-yet-public RCE would surface as unexpected host-level process execution or new host accounts with no corresponding admin action.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">With guest-side actions alone, an attacker can compromise the host that runs their VM. For example, an attacker who has rented just a single instance on a public cloud could panic the host kernel to take down every other tenant VM on the same physical machine (DoS), or run code with root privilege on the host to take over the host and all the guests on it (RCE).</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is the first guest-to-host exploit research triggerable on both Intel and AMD</p><figcaption class="entry-cite__attr"><a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">Hyunwoo Kim (V4bel) — researcher write-up + PoC</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">Hyunwoo Kim (V4bel) — researcher write-up + PoC</a> · <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e8" target="_blank" rel="noopener noreferrer">Linux kernel upstream fix commit</a></div></article>]]></content:encoded></item><item><title>CCB Belgium flags Plesk XML-API flaw (CVE-2026-48614): any authenticated panel user can reach root</title><link>https://ctipilot.ch/entries/2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>vulnerabilities</category><category>priv-esc</category><category>patch-available</category><category>europe</category><category>switzerland</category><category>patch-available</category><category>CVE-2026-48614</category><description><![CDATA[<p>CVE-2026-48614 is a code-injection flaw (CWE-94) in Plesk&#39;s XML API that lets an authenticated, low-privilege panel user inject configuration directives and achieve an arbitrary file write as root — full local privilege escalation to the hosting server (CVSS 9.9). CCB Belgium issued a &quot;patch immediately&quot; advisory; on multi-tenant shared hosting the authenticated prerequisite is met by any customer, collapsing tenant isolation. Affected &lt; 18.0.30; fixed 18.0.30 through 18.0.78.4 (18.0.79+ unaffected). No confirmed in-the-wild exploitation reported.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe" data-tags="vulnerabilities priv-esc patch-available" data-regions="europe switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-48614/">CVE-2026-48614</a></div><h3 class="f-h" id="cve-2026-48614-plesk-xml-api-code-injection-root-lpe"><a href="https://ctipilot.ch/entries/2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe/">CVE-2026-48614 — Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)</a></h3><p>The Centre for Cybersecurity Belgium (CCB) published a standalone &quot;patch immediately&quot; advisory on 8 July for <strong>CVE-2026-48614</strong>, a <code>CWE-94</code> (improper control of code generation / code injection) flaw in Plesk&#39;s XML API (<a href="https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately" target="_blank" rel="noopener noreferrer">CCB, 2026-07-08</a>). An authenticated, low-privilege panel user can send a crafted XML-API request that bypasses the intended authorization boundary and injects arbitrary configuration directives into upstream config generation; because input neutralisation is broken, this yields an arbitrary file write performed as <strong>root</strong>, i.e. local privilege escalation from any authenticated panel account to full root on the hosting server. CCB scores it CVSS 3.1 9.9 (<code>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</code>) (<a href="https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately" target="_blank" rel="noopener noreferrer">CCB, 2026-07-08</a>). Plesk&#39;s own advisory confirms the CVE and the LPE impact, thanks independent researcher Georgii Shutiaev for the disclosure, and lists affected versions below 18.0.30, patched in 18.0.30 through 18.0.78.4, with 18.0.79 and later unaffected (<a href="https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-CVE-2026-48614-in-Plesk-XML-API" target="_blank" rel="noopener noreferrer">Plesk, 2026-07-03</a>). Neither CCB nor Plesk reports in-the-wild exploitation at publication. Mapped to <code>T1068 Exploitation for Privilege Escalation</code>.</p>
<p>The prerequisite is only a valid low-privilege authenticated session — and that is the point for defenders: on multi-tenant shared-hosting Plesk installs, every hosting customer already holds such an account, so the flaw collapses tenant isolation and turns any customer into a path to root on the shared server and thus to every co-tenant&#39;s sites and data. Plesk is broadly deployed across Swiss and EU web-hosting providers and public-sector/SME web infrastructure, which is why CCB — a national authority (Admiralty A) — escalated it rather than leaving it to routine patching.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat this as beyond the normal patch cadence wherever a Plesk panel grants any untrusted party authenticated access. Patch to a fixed line now; where that must wait, disable or tightly access-restrict the XML API. Hunt Plesk XML-API access logs (e.g. the <code>sw-cp-server</code> access log / <code>/usr/local/psa/admin</code> RPC endpoint, version-dependent) for authenticated accounts making out-of-pattern XML-API calls, and correlate with unexpected root-owned writes under Plesk&#39;s config directories.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives.</p><p class="entry-cite__quote">The exploitation of this flaw can result in an arbitrary file write as the root user, leading to local privilege escalation (LPE).</p><figcaption class="entry-cite__attr"><a href="https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately" target="_blank" rel="noopener noreferrer">Centre for Cybersecurity Belgium (CCB)</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately" target="_blank" rel="noopener noreferrer">Centre for Cybersecurity Belgium (CCB)</a> · <a href="https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-CVE-2026-48614-in-Plesk-XML-API" target="_blank" rel="noopener noreferrer">Plesk (vendor PSIRT)</a></div></article>]]></content:encoded></item><item><title>Cavern Manticore&#39;s C2 splits across IL, Mixed-Mode and NativeAOT binaries to break RE toolchains — pushed through SysAid&#39;s legitimate deployment feature</title><link>https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>espionage</category><category>nation-state</category><category>iran-nexus</category><category>global</category><category>middle-east</category><description><![CDATA[<p>Check Point Research documented Cavern Manticore, an Iran MOIS-linked APT (overlaps with MuddyWater and OilRig&#39;s Lyceum) targeting Israeli government and IT-sector orgs. Its modular .NET C2 &quot;Cavern&quot; is deliberately compiled across three binary formats (IL-only, Mixed-Mode C++/CLI, .NET 8 NativeAOT), each needing a different reverse-engineering toolchain; NativeAOT hides sensitive P/Invoke calls from import-based triage. Delivery abused SysAid&#39;s legitimate software-deployment feature (no SysAid vuln) to sideload a trojanized uxtheme.dll. Transferable hunt: uxtheme.dll outside System32 and RMM push actions staging binaries to non-standard paths.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis" data-tags="espionage nation-state iran-nexus" data-regions="global middle-east" data-kind="threat" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="cavern-manticore-iran-mois-modular-net-c2-anti-analysis"><a href="https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/">Check Point: Iran MOIS-linked &quot;Cavern Manticore&quot; ships a modular .NET C2 that uses three compilation formats as an anti-analysis layer, delivered via SysAid RMM abuse</a></h3><p>Check Point Research documented <strong>Cavern Manticore</strong>, an Iran MOIS-linked APT it assesses shares technical and infrastructure overlap with MuddyWater and OilRig&#39;s Lyceum subgroup, targeting Israeli government and IT-sector organisations (<a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-07-06</a>). Its namesake framework, <strong>Cavern</strong>, is a modular post-exploitation .NET C2 whose components are deliberately compiled into three different binary formats: pure IL-only .NET (the <code>mhm.dll</code> file-ops/DPAPI-decrypt module, <code>db.dll</code> SQL browser, <code>ode.dll</code> LDAP/AD-recon module), Mixed-Mode C++/CLI IL+native (the <code>uxtheme.dll</code> Cavern Agent core), and .NET 8 NativeAOT native-only (<code>n-HTCommp.dll</code> HTTPS/WebSocket transport, <code>n-ten.dll</code> network recon/SMB brute-force, <code>n-sws.dll</code> SOCKS5/WSS tunnel). The compilation-format diversity is itself the anti-analysis layer: each format demands a different reverse-engineering toolchain, and NativeAOT strips framework symbols and resolves security-sensitive P/Invoke calls (<code>WNetAddConnection2</code>, <code>NetShareEnum</code>, <code>NetLocalGroupGetMembers</code>) through runtime descriptor tables rather than the PE import table, hiding capability from import-based triage (<a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-07-06</a>).</p>
<p>Delivery is the transferable part: the actor abused SysAid&#39;s legitimate software-update/deployment feature — not a SysAid vulnerability — to push a WinDirStat DLL-sideloading package that loads the trojanized <code>uxtheme.dll</code> as the Cavern Agent, which exports 83 functions mimicking the real Windows theming library (82 empty stubs; the one live export, <code>EnableThemeDialogTexture</code>, is the C2 entry point) — a sandbox trap for automated analysis that only invokes default exports. Each loaded module is isolated in its own .NET AppDomain via a <code>MarshalByRefObject</code> proxy so modules can be unloaded cleanly after use, leaving minimal forensic residue; most samples score zero or near-zero on VirusTotal. ATT&amp;CK: <code>T1574.002 DLL Side-Loading</code>, <code>T1027 Obfuscated Files or Information</code> (via compilation-format diversity), <code>T1620 Reflective Code Loading</code> (AppDomain-isolated modules), <code>T1219 Remote Access Software</code> (SysAid deployment abuse).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the primary targeting is Israeli government, but Iran MOIS clusters (MuddyWater/OilRig lineage) also target European public-sector and critical-infrastructure networks, and the two techniques here transfer regardless of victim: hunt <code>uxtheme.dll</code> loaded outside System32 by anomalous parents, and treat RMM/deployment-tool (SysAid and equivalents) push actions that stage binaries to non-standard <code>ProgramData</code> paths as suspicious — abuse of a legitimate deployment feature leaves no CVE to patch, so the control is behavioural. Reversers triaging suspected NativeAOT payloads need dedicated metadata-recovery tooling, since import-table inspection will under-report the sample&#39;s real capability.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig subgroup named Lyceum</p><p class="entry-cite__quote">the compilation format itself becomes the anti-analysis layer, since each of the three formats has to be reversed with a different toolchain</p><p class="entry-cite__quote">SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature</p><figcaption class="entry-cite__attr"><a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research</a> <span class="entry-cite__date mono">2026-07-06</span></figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research</a></div></article>]]></content:encoded></item><item><title>NCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more</title><link>https://ctipilot.ch/entries/2026-07-08/ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-08/ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection/</guid><pubDate>Wed, 08 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-08T20:35:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>patch-available</category><category>auth-bypass</category><category>path-traversal</category><category>sqli</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-50746</category><category>CVE-2026-50747</category><category>CVE-2026-50748</category><category>CVE-2026-54402</category><category>CVE-2026-54403</category><category>CVE-2026-55115</category><description><![CDATA[<p>NCSC-NL advisory NCSC-2026-0221 covers Ubiquiti&#39;s Security Advisory Bulletin 066 — 25 vulnerabilities across UniFi Connect, Talk, Access, Network, Protect and UniFi OS. The headline flaw CVE-2026-50746 (CVSS 10.0) is unauthenticated command injection in UniFi Connect; a chainable path-traversal auth-bypass (CVE-2026-54403) removes the privilege prerequisite for others. No exploitation yet; upgrade-only, no interim mitigations.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-08/ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection" data-tags="vulnerabilities rce pre-auth patch-available auth-bypass path-traversal sqli" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-08T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50746/">CVE-2026-50746 +5</a></div><h3 class="f-h" id="ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection"><a href="https://ctipilot.ch/entries/2026-07-08/ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection/">Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)</a></h3><p>NCSC-NL published advisory NCSC-2026-0221 on 7 July 2026 covering Ubiquiti&#39;s Security Advisory Bulletin 066 (vendor-published 2026-07-02): 25 vulnerabilities spanning the UniFi Connect, Talk, Access, Network and Protect applications plus the UniFi OS platform itself across the Dream Machine / Cloud Gateway / Cloud Key / Network-Video-Recorder / Enterprise-Fortress-Gateway hardware families (<a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0221" target="_blank" rel="noopener noreferrer">NCSC-NL, 2026-07-07</a>). This is a distinct, larger disclosure from the CVE-2026-34908/-34909/-34910 UniFi OS chain covered on 2026-06-24 — different CVEs, broader scope. The most severe, CVE-2026-50746 (CVSS 10.0), is an improper-access-control flaw in UniFi Connect (&lt; 3.4.20) letting a network-adjacent unauthenticated attacker execute OS command injection on the host device; CVE-2026-50747 (CVSS 9.9, authenticated SQLi in Talk), CVE-2026-50748 (CVSS 9.9, command injection in Access), CVE-2026-54402 (CVSS 9.9, command injection in UniFi OS) and CVE-2026-55115 (CVSS 9.9, SSRF in Protect) round out the critical set, and CVE-2026-54403 (CVSS 8.6, path traversal in UniFi OS) bypasses authentication outright and is explicitly flagged by Ubiquiti as chainable to drop the low-privilege prerequisite of the others. SOCRadar confirms no functional public PoC and no confirmed in-the-wild exploitation as of 2026-07-08 (<a href="https://socradar.io/blog/ubiquiti-cve-2026-50746-unifi-connect/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-07-08</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">UniFi gear is dense across DACH/EU schools, municipal government and SME networks, and the June UniFi disclosure showed the platform is actively targeted once exposed; there is no interim mitigation for any of the 25 flaws, so the operational move is to patch the affected applications/OS and, independent of patch state, pull every UniFi management interface off internet/WAN exposure and watch UniFi Protect hosts for SSRF-style outbound probing of internal service endpoints.</div></aside><div class="prov"><span>vulnerability</span><span>08 Jul 20:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-08/ubiquiti-unifi-sab-066-cve-2026-50746-cmd-injection/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0221" target="_blank" rel="noopener noreferrer">NCSC Netherlands</a> · <a href="https://socradar.io/blog/ubiquiti-cve-2026-50746-unifi-connect/" target="_blank" rel="noopener noreferrer">SOCRadar</a></div></article>]]></content:encoded></item><item><title>Talos: China-nexus UAT-7810 builds ORB relay networks from unpatched Ruckus/ASUS routers for secondary APTs</title><link>https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/</guid><pubDate>Wed, 08 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-08T20:35:00Z</dc:date><category>nation-state</category><category>espionage</category><category>botnet</category><category>china-nexus</category><category>global</category><category>apac</category><description><![CDATA[<p>Cisco Talos profiled UAT-7810, a China-nexus actor it assesses builds Operational Relay Box (ORB) networks from compromised Ruckus and ASUS routers for secondary China-nexus APTs (e.g. UAT-5918, documented against Taiwanese critical infrastructure). Initial access is known, unpatched router CVEs; the malware suite now adds LONGLEASH, DOGLEASH and JARLEASH. Detection is network-telemetry-based, on the CPE itself.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash" data-tags="nation-state espionage botnet china-nexus" data-regions="global apac" data-kind="threat" data-priority="notable" data-discovered="2026-07-08T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="talos-uat-7810-china-nexus-orb-network-longleash"><a href="https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/">Cisco Talos: China-nexus UAT-7810 expands its ORB network with LONGLEASH/DOGLEASH/JARLEASH via unpatched Ruckus and ASUS routers</a></h3><p>Cisco Talos profiled UAT-7810, a China-nexus actor Talos assesses with high confidence is tasked with building and maintaining Operational Relay Box (ORB) networks — relay/proxy infrastructure built from compromised networking gear that secondary China-nexus APTs use to launder the origin of operations against high-value targets (<a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2026-07-07</a>). Talos names UAT-5918 — previously documented targeting Taiwanese critical infrastructure — as one such downstream consumer. Initial access is exploitation of known, unpatched vulnerabilities in Ruckus wireless routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492), a tactic UAT-7810 has used since 2025 rather than a fresh zero-day (<code>T1190</code>). The malware suite, internally &quot;ff-agent&quot;, now includes LONGLEASH — an enhanced successor to the SHORTLEASH backdoor adding reverse-shell and HTTP/DNS/SOCKS/TCP/ICMP/UDP multi-protocol proxying (<code>T1090.003</code>) — plus DOGLEASH, a passive C-based Linux backdoor, and JARLEASH, a Java-based admin tool for file management and FTP/SFTP access; it is built with Boost.Asio, custom protobuf encoding and MbedTLS TLS proxying, compiled for MIPS/ARM/x64, and self-deletes if tampering or a suspicious connection is detected (<code>T1070</code>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the relevance here is the <em>actor and infrastructure model</em>, not a specific victim — a China-nexus ORB builder feeding critical-infrastructure-targeting APTs is exactly the same-actor read that matters for Swiss/European CI and government defenders, whose exposure is twofold: their own edge/CPE being conscripted into the relay mesh, and adversary traffic arriving <em>from</em> residential/SOHO ranges that IP-reputation alone will not flag. Detection is network-telemetry-based since the implants live on embedded CPE, not managed endpoints.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918.</p><p class="entry-cite__quote">Talos has observed UAT-7810 primarily exploit known vulnerabilities in unpatched Ruckus wireless routers, a tactic UAT-7810 has used since 2025.</p><figcaption class="entry-cite__attr"><a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>threat</span><span>08 Jul 20:35Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer">Cisco Talos</a></div></article>]]></content:encoded></item><item><title>Netherlands NIS2 (Cyberbeveiligingswet) slips — Senate vote 7 July, entry into force now 15 August 2026</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</guid><pubDate>Sun, 05 Jul 2026 23:42:00 +0000</pubDate><dc:date>2026-07-05T23:42:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch NIS2 transposition (Cyberbeveiligingswet) missed the 1 July 2026 entry-into-force target reported in prior coverage. The Eerste Kamer (Senate) tabled its response to the second committee report on 29 June — the last written step before debate — and its bill-tracking page now sets the floor vote for 7 July, with the government&#39;s revised entry-into-force target 15 August 2026. Substantive scope is unchanged (NCSC-NL supervisor, 24h/72h/1-month notification, fines to EUR 10M/2%, board liability, ~1,000→~8,000 in-scope entities).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-netherlands-nis2-slip" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-05T23:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="weekly-w27-netherlands-nis2-slip"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a> <span class="mono muted">(2026-06-29)</span></p><p>the Dutch NIS2 transposition — the Cyberbeveiligingswet (Cbw) plus the companion Wet weerbaarheid kritieke entiteiten — has missed the 1 July 2026 entry-into-force target the prior weekly reported as the government&#39;s goal.</p>
<p>The Eerste Kamer (Senate) tabled its government response to the second committee report (&quot;nota naar aanleiding van het tweede verslag&quot;) on 29 June 2026 — the last written-preparation step before plenary debate — and the Senate&#39;s own bill-tracking page now states the floor vote will take place on <strong>7 July 2026</strong>, noting the bill was adopted by the Tweede Kamer on 15 April 2026 (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>). iBestuur reports the government&#39;s revised entry-into-force target is now <strong>15 August 2026</strong>, roughly six weeks later than previously communicated (<a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur, 2026-07-01</a>).</p>
<p>The substantive scope is unchanged from prior coverage: NCSC-NL as designated supervisor, a three-step 24h/72h/one-month incident-notification protocol, essential-entity fines up to EUR 10M or 2% of global turnover, personal board liability for security-measure oversight, and an expansion of in-scope Dutch entities from roughly 1,000 to roughly 8,000. This is the fourth documented slip in the Dutch NIS2 timetable (originally targeted Q3 2025).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the only action for a Swiss/EU reader is administrative — re-anchor readiness milestones and contractual compliance-date references onto 15 August 2026 for any Dutch group entities, hosting, or counterparties. No technical control change follows from the date shift itself.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De stemming in de Eerste Kamer vindt plaats op 7 juli 2026.</p><p class="entry-cite__quote">Het voorstel (EK, A) is op 15 april 2026 aangenomen door de Tweede Kamer.</p><figcaption class="entry-cite__attr"><a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>05 Jul 23:42Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a> · <a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur</a></div></article>]]></content:encoded></item><item><title>Kemp LoadMaster CVE-2026-8037 — exploitation attempts confirmed the day the PoC dropped</title><link>https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/</guid><pubDate>Thu, 02 Jul 2026 04:55:25 +0000</pubDate><dc:date>2026-07-02T04:55:25Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>poc-public</category><category>patch-available</category><category>global</category><category>exploited</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-8037</category><description><![CDATA[<p>Kemp LoadMaster exploitation now confirmed. eSentire reports in-the-wild exploitation attempts against the pre-auth command-injection CVE-2026-8037 began 29 June — the same day a public PoC dropped — though observed attempts failed (eSentire TRU).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme" data-tags="vulnerabilities actively-exploited rce pre-auth poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-02T04:55:25Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-8037/">CVE-2026-8037</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme"><a href="https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/">Kemp LoadMaster CVE-2026-8037 — exploitation attempts confirmed the day the PoC dropped</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/">CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API</a> <span class="mono muted">(2026-06-30)</span></p><p>eSentire&#39;s Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037 — the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the <code>/accessv2</code> API endpoint (CVSS 9.6–9.8) — began 2026-06-29, the same day a public proof-of-concept was released, confirming the compressed PoC-to-exploitation timeline (<a href="https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037" target="_blank" rel="noopener noreferrer">eSentire TRU, 2026-06-30</a>).</p>
<p>The observed attempts were unsuccessful, with no post-compromise activity, but eSentire assesses that public PoC availability plus detailed technical write-ups will drive continued and likely more successful attacks near-term (<a href="https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-01</a>). Affected versions remain LoadMaster 7.2.63.1 and earlier (GA) and 7.2.54.17 and earlier (LTSF); Progress shipped patched firmware in early June 2026. Patch remains the primary mitigation; disabling the LoadMaster API where not required removes the <code>/accessv2</code> attack surface entirely. Hunt <code>/accessv2</code> traffic for malformed/oversized parameters and repeated probing from related sources in a short window (T1190 → T1059).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-30): eSentire&#39;s Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037 — the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the /accessv2 API endpoint (CVSS 9.6–9.8) — began 2026-06-29, the same day …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>02 Jul 04:55Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037" target="_blank" rel="noopener noreferrer">eSentire TRU</a> · <a href="https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API</title><link>https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/</guid><pubDate>Tue, 30 Jun 2026 05:10:38 +0000</pubDate><dc:date>2026-06-30T05:10:38Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>patch-available</category><category>CVE-2026-8037</category><description><![CDATA[<p>Progress Kemp LoadMaster pre-auth RCE (CVE-2026-8037, CVSS 9.8) — uninitialized-malloc heap corruption in the /accessv2 API reaches code execution as root. watchTowr published the full mechanics; Progress reports no known exploitation; patch is in v7.2.63.2.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-30T05:10:38Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-8037/">CVE-2026-8037</a></div><h3 class="f-h" id="cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin"><a href="https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/">CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API</a></h3><p>CVE-2026-8037 (CVSS 9.8) is a pre-authentication RCE in Progress Kemp LoadMaster, an edge load balancer (<a href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/" target="_blank" rel="noopener noreferrer">watchTowr Labs, 2026-06-29</a> · <a href="https://www.zerodayinitiative.com/advisories/ZDI-26-342/" target="_blank" rel="noopener noreferrer">Trend Micro ZDI, 2026-06-09</a>). The <code>escape_quotes()</code> function in the <code>access</code> executable allocates buffers via uninitialized <code>malloc()</code> without null-terminating escaped strings; a sprayed JSON payload to <code>/accessv2</code> (four single-quotes expanding to 16 bytes) overwrites heap metadata in adjacent freed chunks, and the subsequent <code>__sprintf_chk()</code> reads out-of-bounds into attacker-controlled data, reaching code execution as root with no authentication. watchTowr published the full mechanics. Affected: GA ≤ 7.2.63.1 and LTSF ≤ 7.2.54.17; fixed in v7.2.63.2 (which switches to <code>calloc()</code> with proper null termination). A second bulletin CVE, CVE-2026-33691, bypasses file-upload extension checks via OWASP CRS whitespace padding. Progress reports no known active exploitation. Hardening: patch to v7.2.63.2 and restrict the management interface to a dedicated admin VLAN; perimeter anomaly detection for unusual character sequences in JSON POSTs to <code>/accessv2</code>.</p><div class="prov"><span>vulnerability</span><span>30 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a> · <a href="https://www.zerodayinitiative.com/advisories/ZDI-26-342/" target="_blank" rel="noopener noreferrer">Trend Micro Zero Day Initiative</a></div></article>]]></content:encoded></item><item><title>KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs</title><link>https://ctipilot.ch/entries/2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m/</guid><pubDate>Mon, 29 Jun 2026 04:47:13 +0000</pubDate><dc:date>2026-06-29T04:47:13Z</dc:date><category>data-breach</category><category>supply-chain</category><category>phishing</category><category>apac</category><category>global</category><description><![CDATA[<p>KDDI discloses a third-party email-platform breach exposing up to 14.22 million subscriber credentials across six Japanese ISPs. Attackers exploited a vulnerability in a shared ISP email-management platform (detected ~2026-06-17); email addresses and passwords for STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe and one further KDDI ISP are in scope. No CH/EU nexus, but the leaked credential pairs feed directly into credential-stuffing and phishing-as-initial-access against European targets (BleepingComputer, 2026-06-28).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m" data-tags="data-breach supply-chain phishing" data-regions="apac global" data-kind="incident" data-priority="high" data-discovered="2026-06-29T04:47:13Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="kddi-third-party-email-platform-breach-exposes-up-to-14-22-m"><a href="https://ctipilot.ch/entries/2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m/">KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs</a></h3><p>Japanese carrier KDDI disclosed that a threat actor exploited a vulnerability in third-party software integrated into its centralised ISP email-management platform, with unauthorised access detected on approximately 2026-06-17 (<a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-28</a>). The breach potentially exposed email addresses and passwords for up to 14.22 million subscriber accounts across six ISPs running on the shared platform — STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe and a further KDDI ISP; KDDI states some passwords were stored hashed or encrypted and that 14.22 million is a worst-case figure pending forensic completion (<a href="https://securityaffairs.com/194387/data-breach/kddi-data-breach-impacts-up-to-14-2-million-email-accounts-at-six-isps.html" target="_blank" rel="noopener noreferrer">SecurityAffairs, 2026-06-28</a>; <a href="https://infosecurity-magazine.com/news/kddi-breach-japanese-telcos/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-06-24</a>). No CVE for the third-party software flaw and no threat actor have been named; KDDI notified Japan&#39;s Personal Information Protection Commission and advised affected users to change passwords and enable MFA.</p>
<p><strong>Why it matters to us:</strong> The structural lesson, not the jurisdiction, is the signal — a single vulnerable dependency in a shared multi-tenant email-management plane produced a six-ISP blast radius, the same exposure model any European telco or managed-ISP operator carries when subscriber-mail administration is consolidated onto one vendor platform. The immediate downstream risk for Swiss/EU defenders is credential-stuffing: 14.22 million leaked email/password pairs will surface in combolists and feed phishing-as-initial-access. Hunt for anomalous authentication against external-facing services from Japanese-ISP email address spaces, and treat any reused-password exposure on those domains as a stuffing precursor. Inventory third-party vendor access to your own subscriber/identity-management platforms and enforce MFA on the administration plane itself.</p><div class="prov"><span>incident</span><span>29 Jun 04:47Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/kddi-third-party-email-platform-breach-exposes-up-to-14-22-m/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://securityaffairs.com/194387/data-breach/kddi-data-breach-impacts-up-to-14-2-million-email-accounts-at-six-isps.html" target="_blank" rel="noopener noreferrer">SecurityAffairs</a> · <a href="https://infosecurity-magazine.com/news/kddi-breach-japanese-telcos/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>FortiBleed</title><link>https://ctipilot.ch/entries/2026-06-29/fortibleed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/fortibleed/</guid><pubDate>Mon, 29 Jun 2026 00:21:19 +0000</pubDate><dc:date>2026-06-29T00:21:19Z</dc:date><category>actively-exploited</category><category>data-breach</category><category>identity</category><category>russia-nexus</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>FortiBleed escalates from credential exposure to confirmed AD domain takeover at a NATO-aligned defence contractor — patch level is irrelevant; rotate any FortiGate credential active May–June and hunt AD persistence. (daily 06-24, CISA)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/fortibleed" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:19Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="fortibleed"><a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a></h3><p>The W25 top story continued without a scale revision — the device count holds at the 86,644 figure the dailies reported — but the in-window development is the clearest state-interest signal yet: CISA <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">updated its hardening alert on 06-22</a> to link Fortinet&#39;s revised guidance, and reporting now confirms that on in mid-June the Russian-speaking operator completed offline Kerberos-hash cracking from captured FortiGate configs and immediately exfiltrated DFS backup data from a NATO-aligned defence contractor — a full AD domain takeover (<a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>). Outstanding for defenders: treat any FortiGate admin/VPN credential active May–June 2026 as compromised, rotate, then hunt AD for pass-the-hash, DCSync and DFS-backup exfiltration (Kerberos ticket anomalies, LSASS access, <code>ntdsutil</code>/impacket artefacts). Patch level is irrelevant — this is credential reuse, not a new CVE.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">CISA alert</a> · <a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a></div></article>]]></content:encoded></item><item><title>CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Mandiant reconstructs the full zero-day chain</title><link>https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/</guid><pubDate>Mon, 29 Jun 2026 00:20:59 +0000</pubDate><dc:date>2026-06-29T00:20:59Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>priv-esc</category><category>rce</category><category>patch-available</category><category>global</category><category>switzerland</category><category>exploited</category><category>patch-available</category><category>CVE-2026-20245</category><description><![CDATA[<p>Mandiant (GTIG) published the first complete TTP chain on 06-24 for the Catalyst SD-WAN Manager zero-day activity, observed at a service provider: a peering/authentication bypass (CVE-2026-20127, CVE-2026-20182) leading to credential manipulation, then local privilege escalation to root via a malicious CSV upload …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons" data-tags="vulnerabilities actively-exploited priv-esc rce patch-available" data-regions="global switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:20:59Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20245/">CVE-2026-20245</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/">CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Mandiant reconstructs the full zero-day chain</a></h3><p>Mandiant (GTIG) <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">published the first complete TTP chain</a> on 06-24 for the Catalyst SD-WAN Manager zero-day activity, observed at a service provider: a peering/authentication bypass (CVE-2026-20127, CVE-2026-20182) leading to credential manipulation, then local privilege escalation to root via a malicious CSV upload (CVE-2026-20245) to plant a root backdoor. NCSC-CH <a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">posted on it</a>, giving it direct Swiss relevance. Telco and public-sector SD-WAN operators should hunt for unexpected file writes under the web-UI service account and root-owned artefacts post-dating the patch.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Mandiant (GTIG) published the first complete TTP chain on 06-24 for the Catalyst SD-WAN Manager zero-day activity, observed at a service provider: a peering/authentication bypass (CVE-2026-20127, CVE-2026-20182) leading to credential manipulation, then local privilege escalation to root via a …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Google Mandiant (GTIG)</a> · <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a></div></article>]]></content:encoded></item><item><title>Mandiant documents the full Cisco Catalyst SD-WAN exploitation chain — CSV-injection to a root backdoor</title><link>https://ctipilot.ch/entries/2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati/</guid><pubDate>Sat, 27 Jun 2026 05:17:48 +0000</pubDate><dc:date>2026-06-27T05:17:48Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>auth-bypass</category><category>priv-esc</category><category>global</category><category>switzerland</category><category>exploited</category><category>patch-available</category><category>CVE-2026-20127</category><category>CVE-2026-20182</category><category>CVE-2026-20245</category><description><![CDATA[<p>UPDATE (originally covered 2026-06-26): Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 (Google Mandiant, 2026-06-24).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati" data-tags="vulnerabilities actively-exploited auth-bypass priv-esc" data-regions="global switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-27T05:17:48Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20127/">CVE-2026-20127 +2</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati"><a href="https://ctipilot.ch/entries/2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati/">Mandiant documents the full Cisco Catalyst SD-WAN exploitation chain — CSV-injection to a root backdoor</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco/">Mandiant publishes the forensic reconstruction behind Cisco SD-WAN Manager CVE-2026-20245</a> <span class="mono muted">(2026-06-26)</span></p><p>Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 (<a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Google Mandiant, 2026-06-24</a>). NCSC-CH amended its Security Hub post to add the report on 2026-06-25 (<a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12579</a>).</p>
<p>The chain: authentication bypass via <code>CVE-2026-20182</code>/<code>CVE-2026-20127</code> (rogue peering connection), then privilege escalation via <code>CVE-2026-20245</code> — a malicious <code>evil_tenant.csv</code> uploaded through the <code>request tenant-upload</code> CLI carries unsanitised shell commands that append a <code>troot</code> root user to <code>/etc/passwd</code> and <code>/etc/shadow</code>, after which the actor reverts configuration changes and deletes the file for anti-forensics. This gives defenders concrete hunts the earlier advisory could not: search SD-WAN Manager instances for unexpected <code>/etc/passwd</code> additions, <code>evil_tenant.csv</code> artefacts, and <code>request tenant-upload</code> execution in CLI logs.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-26): Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 (Google Mandiant, 2026-06-24).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>27 Jun 05:17Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Google Mandiant (GTIG)</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12579</a></div></article>]]></content:encoded></item><item><title>Cisco Catalyst SD-WAN Manager CVE-2026-20245</title><link>https://ctipilot.ch/entries/2026-06-26/cisco-catalyst-sd-wan-manager-cve-2026-20245/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-26/cisco-catalyst-sd-wan-manager-cve-2026-20245/</guid><pubDate>Fri, 26 Jun 2026 04:54:43 +0000</pubDate><dc:date>2026-06-26T04:54:43Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>priv-esc</category><category>rce</category><category>patch-available</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2026-20245</category><description><![CDATA[<p>Mandiant&#39;s Google Threat Intelligence Group published a forensic reconstruction of an intrusion in which Cisco Catalyst SD-WAN Manager (formerly vManage) was compromised through CVE-2026-20245 as a zero-day — exploited at a communications service provider from late 2025 through March 2026, months before Cisco&#39;s …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-26/cisco-catalyst-sd-wan-manager-cve-2026-20245" data-tags="vulnerabilities actively-exploited priv-esc rce patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-26T04:54:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20245/">CVE-2026-20245</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cisco-catalyst-sd-wan-manager-cve-2026-20245"><a href="https://ctipilot.ch/entries/2026-06-26/cisco-catalyst-sd-wan-manager-cve-2026-20245/">Cisco Catalyst SD-WAN Manager CVE-2026-20245</a></h3><p>Mandiant&#39;s Google Threat Intelligence Group published a forensic reconstruction of an intrusion in which Cisco Catalyst SD-WAN Manager (formerly vManage) was compromised through CVE-2026-20245 as a zero-day — exploited at a communications service provider from late 2025 through March 2026, months before Cisco&#39;s advisory (<a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Mandiant/GTIG, 2026-06-24</a>). Mandiant attributes the activity to no named actor. The reason this matters beyond one victim: SD-WAN Manager is the control plane for an entire WAN fabric — root on the controller is push-access to every managed edge device — so it warrants the same monitoring tier as a VPN concentrator or firewall, and it is now one of several Cisco SD-WAN flaws confirmed exploited during 2026.</p>
<p><strong>The vulnerability.</strong> CVE-2026-20245 (CVSS 7.8, no workaround) is a command-injection weakness in the SD-WAN Manager CLI tenant-upload handler: the feature that ingests a tenant-list CSV fails to sanitise file content before it reaches a shell context, so an authenticated operator can embed OS commands inside a crafted CSV and have them execute as root on the underlying Linux host (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT, cisco-sa-sdwan-privesc-4uxFrdzx</a>). The injected commands appended a new UID-0 account (<code>troot</code>) to the host&#39;s local account databases, giving the actor a persistent root login independent of the vManage application&#39;s own user model.</p>
<p><strong>Kill chain (as Mandiant documents it):</strong></p>
<ul><li><strong>Initial access</strong> — the actor reached an authenticated position by abusing peering-authentication-bypass flaws CVE-2026-20127 / CVE-2026-20182 to enrol unauthorised peering and obtain SSH as the <code>vmanage-admin</code> account, or alternatively by using certificate material stolen in a previous compromise (<a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>, <a href="https://attack.mitre.org/techniques/T1078/004/" target="_blank" rel="noopener noreferrer">T1078.004</a>).</li><li><strong>Privilege escalation</strong> — exploitation of CVE-2026-20245 via the crafted tenant CSV, executing as root (<a href="https://attack.mitre.org/techniques/T1068/" target="_blank" rel="noopener noreferrer">T1068</a>).</li><li><strong>Persistence</strong> — creation of the <code>troot</code> UID-0 account in the host account databases, reachable via <code>su</code> (<a href="https://attack.mitre.org/techniques/T1136/001/" target="_blank" rel="noopener noreferrer">T1136.001</a>).</li><li><strong>Defense evasion / anti-forensics</strong> — the actor changed the legitimate <code>admin</code> password and then reverted it to its original value to reduce detection probability, and deleted command history, syslog entries, and the uploaded files after use (<a href="https://attack.mitre.org/techniques/T1070/003/" target="_blank" rel="noopener noreferrer">T1070.003</a>).</li></ul>
<p><strong>Hunt and detection concepts.</strong> The decisive gap is that vManage&#39;s own health dashboards do not surface OS-level account creation — detection has to happen on the underlying host. Baseline and monitor <code>/etc/passwd</code> and <code>/etc/shadow</code> for accounts added since a known-good snapshot (a UID-0 account other than <code>root</code> is the high-fidelity signal here). Review SD-WAN Manager audit logs for tenant-upload CLI/API invocations and correlate them with subsequent privileged shell activity; alert on child processes spawned by the tenant-upload service, and on shell-history truncation or gaps on the controller host. Because the actor reverted the admin password, an unexplained password-change-then-revert pair in admin account auditing is itself worth investigating.</p>
<p><strong>Hardening.</strong> Upgrade to a fixed train — 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2 — as there is no workaround. Restrict which operators hold privileged CLI roles, place the management/northbound interfaces behind a source-IP ACL rather than exposing them broadly, enforce MFA on all administrator accounts, and rotate SD-WAN admin credentials (including the default <code>vmanage-admin</code>) on any controller that may have been exposed before patching. Cisco&#39;s Catalyst SD-WAN Hardening Guide carries the vendor&#39;s own configuration baseline.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Mandiant&#39;s Google Threat Intelligence Group published a forensic reconstruction of an intrusion in which Cisco Catalyst SD-WAN Manager (formerly vManage) was compromised through CVE-2026-20245 as a zero-day — exploited at a communications service provider from late 2025 through March 2026, months …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>26 Jun 04:54Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-26/cisco-catalyst-sd-wan-manager-cve-2026-20245/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Mandiant/GTIG</a> · <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a></div></article>]]></content:encoded></item><item><title>Mandiant publishes the forensic reconstruction behind Cisco SD-WAN Manager CVE-2026-20245</title><link>https://ctipilot.ch/entries/2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco/</guid><pubDate>Fri, 26 Jun 2026 04:54:42 +0000</pubDate><dc:date>2026-06-26T04:54:42Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>priv-esc</category><category>rce</category><category>patch-available</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2026-20245</category><description><![CDATA[<p>Mandiant reconstructs a months-long zero-day compromise of Cisco Catalyst SD-WAN Manager (CVE-2026-20245) — updating our 6 June coverage, GTIG details an authenticated request tenant-upload CLI command-injection path that planted a troot UID-0 account on the controller, reached after a peering-auth-bypass foothold and exploited at a service provider from late 2025 through March 2026, well before the patch (Mandiant/GTIG, 2026-06-24). Today&#39;s deep dive (§5). Patch to the fixed trains immediately and audit vManage hosts for OS-level account creation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco" data-tags="vulnerabilities actively-exploited priv-esc rce patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-26T04:54:42Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20245/">CVE-2026-20245</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="mandiant-publishes-the-forensic-reconstruction-behind-cisco"><a href="https://ctipilot.ch/entries/2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco/">Mandiant publishes the forensic reconstruction behind Cisco SD-WAN Manager CVE-2026-20245</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-06/cve-2026-20245-cisco-catalyst-sd-wan-manager-actively-exploi/">CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)</a> <span class="mono muted">(2026-06-06)</span></p><p>When we first noted CVE-2026-20245 it was a fresh Cisco advisory for a command-injection-to-root flaw in Catalyst SD-WAN Manager with confirmed exploitation but little public detail. Mandiant/GTIG has now published the forensic reconstruction, confirming the flaw was used as a <strong>zero-day at a communications service provider from late 2025 through March 2026 — months before the patch</strong> (<a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Mandiant/GTIG, 2026-06-24</a>).</p>
<p>The new substance is the kill chain: a peering-authentication-bypass foothold (CVE-2026-20127 / CVE-2026-20182) into SSH as <code>vmanage-admin</code>, then a crafted tenant CSV through the <code>request tenant-upload</code> CLI handler injecting commands that planted a backdoor <code>troot</code> UID-0 account, with anti-forensic clean-up (admin-password change-then-revert, history/syslog deletion). Mandiant names no threat actor. Full mechanics, ATT&amp;CK mapping and host-level detection are in §5.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-06): When we first noted CVE-2026-20245 it was a fresh Cisco advisory for a command-injection-to-root flaw in Catalyst SD-WAN Manager with confirmed exploitation but little public detail.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>26 Jun 04:54Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Mandiant/GTIG</a> · <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a></div></article>]]></content:encoded></item><item><title>8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing</title><link>https://ctipilot.ch/entries/2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8/</guid><pubDate>Wed, 24 Jun 2026 05:11:56 +0000</pubDate><dc:date>2026-06-24T05:11:56Z</dc:date><category>data-breach</category><category>organized-crime</category><category>identity</category><category>cloud</category><category>us</category><category>global</category><description><![CDATA[<p>UPDATE (originally covered 2026-06-19; campaign delta 2026-06-23): US cloud-communications provider 8x8 (NASDAQ: EGHT) filed a Form 8-K Item 1.05 on 2026-06-23 disclosing that an unauthorised party accessed its Salesforce environment on 2026-06-11/12 via a third-party integration — the Klue …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8" data-tags="data-breach organized-crime identity cloud" data-regions="us global" data-kind="incident" data-priority="notable" data-discovered="2026-06-24T05:11:56Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span></div><h3 class="f-h" id="8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8"><a href="https://ctipilot.ch/entries/2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8/">8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai/">Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed</a> <span class="mono muted">(2026-06-21)</span></p><p>US cloud-communications provider 8x8 (NASDAQ: EGHT) filed a Form 8-K Item 1.05 on 2026-06-23 disclosing that an unauthorised party accessed its Salesforce environment on 2026-06-11/12 via a <strong>third-party integration — the Klue competitive-intelligence platform</strong> — the OAuth-integration vector behind the Icarus extortion campaign already tracked in prior briefs (<a href="https://www.sec.gov/Archives/edgar/data/0001023731/000102373126000084/eght-20260617.htm" target="_blank" rel="noopener noreferrer">SEC EDGAR — 8x8 Form 8-K, 2026-06-23</a>).</p>
<p>The filing states the accessed data is limited to contract information, internal sales notes and business contact data (names, business emails, phone numbers, mailing addresses). As a publicly-listed company&#39;s mandatory material-incident disclosure, it is the formal confirmation that 8x8 is a named Klue-integration victim, extending the campaign&#39;s confirmed-victim list.</p>
<p>Defender takeaway for anyone running SaaS-to-Salesforce OAuth integrations (including EU public-sector users of competitive-intel tooling): audit Connected Apps in Salesforce Setup → App Manager for unexpected or stale OAuth grants, scope connected-app permissions to least privilege, and monitor <code>EventType=OAuthToken</code> in Salesforce Event Monitoring for anomalous token use (<code>T1078.004</code> Valid Accounts: Cloud, <code>T1550.001</code> token abuse).</p><div class="prov"><span>incident</span><span>24 Jun 05:11Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/0001023731/000102373126000084/eght-20260617.htm" target="_blank" rel="noopener noreferrer">SEC EDGAR — 8x8 Inc Form 8-K Item 1.05</a></div></article>]]></content:encoded></item><item><title>FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE</title><link>https://ctipilot.ch/entries/2026-06-23/fortibleed-first-full-tool-chain-disclosure-fortigatesniffer/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-23/fortibleed-first-full-tool-chain-disclosure-fortigatesniffer/</guid><pubDate>Tue, 23 Jun 2026 04:52:50 +0000</pubDate><dc:date>2026-06-23T04:52:50Z</dc:date><category>actively-exploited</category><category>data-breach</category><category>russia-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>The FortiBleed credential-harvesting campaign got its first full tool-chain disclosure: a Golang &quot;FortigateSniffer&quot; that abuses FortiOS&#39;s native diagnose sniffer packet to capture auth traffic, a PCAP converter, and a 36-GPU offline-cracking cluster — with Fortinet confirming no new CVE, only credential reuse and brute force. The detection opportunity is the sniffer&#39;s own footprint (BleepingComputer, 2026-06-22).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-23/fortibleed-first-full-tool-chain-disclosure-fortigatesniffer" data-tags="actively-exploited data-breach russia-nexus" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-23T04:52:50Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="fortibleed-first-full-tool-chain-disclosure-fortigatesniffer"><a href="https://ctipilot.ch/entries/2026-06-23/fortibleed-first-full-tool-chain-disclosure-fortigatesniffer/">FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-18/fortibleed-73-932-internet-facing-fortigate-devices-exposed/">FortiBleed — 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory</a> <span class="mono muted">(2026-06-18)</span></p><p>New analysis published 2026-06-22 gives the first complete tool-chain picture of the FortiBleed credential-harvesting campaign. The operators deploy a purpose-built Golang tool, <strong>FortigateSniffer</strong>, that abuses FortiOS&#39;s native <code>diagnose sniffer packet</code> diagnostic command to capture authentication traffic on a compromised FortiGate; a second tool, <strong>SNIFTRAN</strong>, converts the captured traffic to PCAP, which a Python toolkit then parses for cleartext credentials, NTLM hashes, Kerberos tickets and LDAP/SQL auth material across ~24 protocols (<a href="https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-22</a>; <a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-06-16</a>).</p>
<p>Fortinet&#39;s PSIRT response confirms the campaign uses <strong>no new vulnerability</strong> — it reuses credentials from the previously-disclosed CVE-2026-24858, CVE-2025-59718 and CVE-2025-59719 plus brute force against devices lacking strong passwords and MFA (<a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT, 2026-06-19</a>; <a href="https://www.securityweek.com/fortinet-responds-to-fortibleed-campaign/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-22</a>). Reported tradecraft includes a distributed 36-GPU cluster — rented from a generative-AI provider, per BleepingComputer — for offline cracking of the harvested hashes; SOCRadar characterises the operators as Russian-speaking (<a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-06-16</a>).</p>
<p>The delta for defenders is a concrete detection surface that earlier coverage lacked: FortiOS audit-logs <code>diagnose sniffer packet</code> execution, so hunt for unexpected CLI sniffer invocations and stray PCAP files on the appliance, and — because harvested AD credentials are the downstream prize — treat all domain credentials on any FortiBleed-corpus device as compromised and force a domain-wide rotation, watching for anomalous Kerberos service-ticket requests (event 4769) and new-source Logon Type 3 events (4624) against privileged accounts. Upgrade to firmware with PBKDF2 password hashing to make offline cracking expensive, terminate active sessions, enable MFA and disable external management access.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Threat actors deployed a Golang-based tool called &#39;FortigateSniffer&#39; that abused FortiOS&#39;s built-in diagnose sniffer packet functionality to harvest authentication credentials from network traffic</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Fortinet states the attack does not exploit new vulnerabilities, but rather reuses credentials from prior incidents ... combined with brute-force techniques against systems lacking strong passwords and MFA</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/fortinet-responds-to-fortibleed-campaign/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>23 Jun 04:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-23/fortibleed-first-full-tool-chain-disclosure-fortigatesniffer/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT</a> · <a href="https://www.securityweek.com/fortinet-responds-to-fortibleed-campaign/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank" rel="noopener noreferrer">SOCRadar</a></div></article>]]></content:encoded></item><item><title>&quot;Squidbleed&quot; — a 29-year-old heap over-read in Squid&#39;s FTP gateway leaks other users&#39; cleartext HTTP credentials (CVE-2026-47729)</title><link>https://ctipilot.ch/entries/2026-06-23/squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-23/squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew/</guid><pubDate>Tue, 23 Jun 2026 04:52:48 +0000</pubDate><dc:date>2026-06-23T04:52:48Z</dc:date><category>vulnerabilities</category><category>info-disclosure</category><category>no-patch</category><category>ai-abuse</category><category>global</category><category>europe</category><category>no-patch</category><category>CVE-2026-47729</category><description><![CDATA[<p>A 29-year-old heap over-read in Squid&#39;s FTP gateway (&quot;Squidbleed&quot;, CVE-2026-47729) lets an attacker-controlled FTP server leak other proxy users&#39; cleartext HTTP credentials and cookies; the upstream fix version is disputed (the maintainer cited 7.6 then 7.7, while SecurityWeek and Debian indicate the commit is already in 7.6, released 8 June). Shared school/university/government proxies are the exposure class (Calif.io, 2026-06-18).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-23/squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew" data-tags="vulnerabilities info-disclosure no-patch ai-abuse" data-regions="global europe" data-kind="research" data-priority="high" data-discovered="2026-06-23T04:52:48Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47729/">CVE-2026-47729</a></div><h3 class="f-h" id="squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew"><a href="https://ctipilot.ch/entries/2026-06-23/squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew/">&quot;Squidbleed&quot; — a 29-year-old heap over-read in Squid&#39;s FTP gateway leaks other users&#39; cleartext HTTP credentials (CVE-2026-47729)</a></h3><p>Researchers at Calif.io disclosed CVE-2026-47729, nicknamed Squidbleed: a heap buffer over-read in the Squid proxy&#39;s FTP-over-HTTP gateway (<code>src/FtpGateway.cc</code>) introduced by a 1997 code commit (<a href="https://blog.calif.io/p/squidbleed-cve-2026-47729" target="_blank" rel="noopener noreferrer">Calif.io, 2026-06-18</a>; <a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-22</a>). The root cause is a whitespace-skipping loop that calls <code>strchr(w_space, *copyFrom)</code> without first checking for the string terminator: <code>strchr</code> returns a non-NULL pointer when the search character is the embedded <code>\0</code>, so the parser walks past the end of the FTP directory-listing buffer into adjacent heap memory containing other users&#39; cached HTTP requests. An attacker who controls an FTP server and can induce the proxy to fetch from it (FTP support and TCP/21 are in Squid&#39;s default <code>Safe_ports</code> ACL) can leak <code>Authorization</code> headers, session cookies, API keys and other cleartext request content from concurrent users sharing the same proxy worker (<a href="https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-22</a>). HTTPS relayed via <code>CONNECT</code> tunnels is not exposed; only cleartext HTTP and TLS-terminating proxy setups are. SUSE rates it moderate (CVSS 6.5) and there is no confirmed in-the-wild exploitation. The <strong>fixed-version picture is disputed upstream</strong>: the patch was merged in spring 2026, but the Squid maintainer first attributed the fix to 7.6 (released 8 June 2026) then corrected that to 7.7, while Debian&#39;s assessment is that the referenced commit is already present in 7.6, and SecurityWeek reports the fix shipped in 7.6 (<a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-22</a>; <a href="https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-22</a>). The safe reading for defenders is to treat the fixed version as uncertain and verify against your own build rather than assuming a single release line is clean Calif.io credits an AI model (Anthropic&#39;s &quot;Claude Mythos&quot;) with surfacing the <code>strchr</code> edge case during AI-assisted fuzzing — another data point in the AI-assisted-vulnerability-discovery pattern the W25 weekly tracked.</p>
<p><strong>Why it matters to us:</strong> Squid is widely deployed as a forward / caching / web-filtering proxy across EU public-sector networks, university perimeters and ISP infrastructure — exactly the multi-user environments where the cross-user leak has impact. Interim mitigation that does not depend on resolving the fixed-version dispute: disable FTP proxying (<code>acl ftp proto FTP</code> + <code>http_access deny ftp</code>, or drop FTP from <code>Safe_ports</code>) where it is not needed, and restrict who can reach the proxy from untrusted/multi-tenant segments. Confirm the fix is present in your actual build (RHEL/Debian/Ubuntu ship 4.x–6.x — check for a backport) rather than trusting a version number. Detection: monitor Squid <code>access.log</code> for <code>ftp://</code>-scheme requests from unusual clients and for worker heap-corruption / crash signals (<code>T1190</code> Exploit Public-Facing Application; effective outcome resembles <code>T1040</code> Network Sniffing).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A heap over-read in the Squid web proxy can leak another user&#39;s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy</p><figcaption class="entry-cite__attr"><a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">while (strchr(w_space, *copyFrom)) — without checking for string termination first, causing the pointer to advance beyond the buffer boundary</p><figcaption class="entry-cite__attr"><a href="https://blog.calif.io/p/squidbleed-cve-2026-47729" target="_blank" rel="noopener noreferrer">Calif.io</a></figcaption></figure></div><div class="prov"><span>research</span><span>23 Jun 04:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-23/squidbleed-a-29-year-old-heap-over-read-in-squid-s-ftp-gatew/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.calif.io/p/squidbleed-cve-2026-47729" target="_blank" rel="noopener noreferrer">Calif.io</a> · <a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS</title><link>https://ctipilot.ch/entries/2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of/</guid><pubDate>Mon, 22 Jun 2026 04:52:29 +0000</pubDate><dc:date>2026-06-22T04:52:29Z</dc:date><category>botnet</category><category>actively-exploited</category><category>rce</category><category>ot-ics</category><category>global</category><category>europe</category><category>nordics</category><category>no-patch</category><category>exploited</category><category>patch-available</category><category>CVE-2013-3307</category><category>CVE-2016-5681</category><category>CVE-2025-11837</category><description><![CDATA[<p>A previously-undocumented botnet, AryStinger, has conscripted 4,300+ end-of-life D-Link routers (DIR-850L, DIR-818LW) and QNAP NAS devices into a distributed reconnaissance-and-proxy network — and Sweden is its third-largest victim pool at 6.4%. Initial access is three public CVEs (two decade-old D-Link RCEs plus a 2025 QNAP code-injection), after which each node gets a Dropbear SSH backdoor and is tasked with distributed DNS brute-forcing and traffic tunnelling that launders the operator&#39;s attack traffic (QiAnXin XLab, 2026-06-17). EoL D-Link models have no patch path — replacement is the only fix.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of" data-tags="botnet actively-exploited rce ot-ics" data-regions="global europe nordics" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-22T04:52:29Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2013-3307/">CVE-2013-3307 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of"><a href="https://ctipilot.ch/entries/2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of/">AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS</a></h3><p>QiAnXin XLab disclosed AryStinger, a previously-undocumented botnet its telemetry first observed on 2026-03-12, with English-language follow-up reporting on 2026-06-21 (<a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank" rel="noopener noreferrer">QiAnXin XLab, 2026-06-17</a>; <a href="https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-21</a>). Unlike the DDoS- and cryptomining-oriented router botnets that dominate this device class, AryStinger&#39;s design centre is <strong>pre-intrusion reconnaissance and traffic laundering</strong>: infected nodes are enrolled as &quot;Executors&quot; and handed distributed scanning and DNS-brute-force tasks by a C2 controller, and they relay the operator&#39;s attack traffic so its true origin is hidden. XLab counts at least 4,300 infected nodes and rising, distributed South Korea 48.5%, China 31.8%, <strong>Sweden 6.4%</strong>, Malaysia 3.5%, Singapore 2.5%; detection rate on public multi-engine scanning was zero at disclosure.</p>
<p><strong>Initial access — three public CVEs across two device classes.</strong> The router variant spreads through <code>CVE-2013-3307</code> (command injection in Linksys/D-Link models built on the Realtek RTL819X SoC family) and <code>CVE-2016-5681</code> (a stack-based buffer overflow in the D-Link DIR-850L HTTP service) — both unauthenticated RCE on devices manufactured 2012–2015. From 2026-04-26 a second, NAS-targeting variant began exploiting <code>CVE-2025-11837</code>, a code-injection flaw in QNAP&#39;s Malware Remover utility (fixed in build <code>6.6.8.20251023</code>; QNAP&#39;s advisory scopes the affected product to the 6.6.x line — update to the latest build). Mapped to <code>T1190</code> Exploit Public-Facing Application (<a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>). The most infected models — D-Link DIR-850L (75% of nodes) and DIR-818LW (13%) — are <strong>end-of-life with no firmware fix</strong> (D-Link support bulletin SAP10503), so for the router population there is no patch and replacement is the only remediation.</p>
<p><strong>Post-exploitation and persistence.</strong> After exploitation a downloader pulls the current payload from C2, the bot authenticates with a unique Executor ID, and a <strong>Dropbear SSH server is deployed on a fixed non-standard port</strong> with an <code>iptables</code> rule added to allow inbound C2 traffic — establishing persistent, system-level remote access (<a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank" rel="noopener noreferrer">QiAnXin XLab, 2026-06-17</a>). This combines <code>T1133</code> External Remote Services (<a href="https://attack.mitre.org/techniques/T1133/" target="_blank" rel="noopener noreferrer">T1133</a>) for the SSH backdoor with <code>T1562.004</code> Impair Defenses: Disable or Modify System Firewall (<a href="https://attack.mitre.org/techniques/T1562/004/" target="_blank" rel="noopener noreferrer">T1562.004</a>) for the firewall change. The router binary masquerades under a system-daemon-like process name (<code>T1036</code> Masquerading, <a href="https://attack.mitre.org/techniques/T1036/" target="_blank" rel="noopener noreferrer">T1036</a>).</p>
<p><strong>Two malware variants, different capability tiers.</strong> The constrained RTL819X C variant carries <code>massdns</code>-style distributed DNS reconnaissance and a NAT-traversal tunnelling module (<code>T1572</code> Protocol Tunneling, <a href="https://attack.mitre.org/techniques/T1572/" target="_blank" rel="noopener noreferrer">T1572</a>; <code>T1090.002</code> external proxy, <a href="https://attack.mitre.org/techniques/T1090/002/" target="_blank" rel="noopener noreferrer">T1090.002</a>). The Go &quot;Standard&quot; variant for more-capable hosts (NAS) bundles off-the-shelf offensive tooling — <code>fscan</code>, <code>ksubdomain</code>, <code>httpx</code>, <code>tlsx</code> — for network-service discovery and subdomain enumeration (<code>T1046</code> Network Service Discovery, <a href="https://attack.mitre.org/techniques/T1046/" target="_blank" rel="noopener noreferrer">T1046</a>; <code>T1595</code> Active Scanning, <a href="https://attack.mitre.org/techniques/T1595/" target="_blank" rel="noopener noreferrer">T1595</a>), plus remote command execution and source-level payload execution in Go/Java/Python. C2 is HTTP/HTTPS with Protobuf message bodies under XOR obfuscation; a hardcoded key string embeds a 2024 marker, suggesting the operation predates the 2026 first-sighting.</p>
<p><strong>Why this matters to a Swiss/EU public-sector SOC.</strong> The direct exposure is indirect but real: EoL D-Link SOHO routers persist in branch offices, municipal sites, and home-office setups, and QNAP NAS appliances are widely used as departmental file shares — both populations sit on the audience&#39;s attack surface, and Sweden&#39;s 6.4% share shows European devices are already being conscripted. A node&#39;s job is to <em>scan and proxy</em>, so a compromised device inside or adjacent to an organisation&#39;s network becomes a launch point for credential brute-forcing and lateral reconnaissance that looks like it originates from trusted infrastructure.</p>
<p><strong>Hunt and detection concepts (no IOCs).</strong> On Linux/MIPS network appliances, hunt for an unexpected Dropbear (or any) SSH daemon listening on a non-standard port and for <code>iptables</code> rules added outside change management. On QNAP and other Linux NAS, alert on <code>curl</code>/<code>python</code> (or other interpreters) spawned from the security-utility process tree (<code>T1059.006</code>, <a href="https://attack.mitre.org/techniques/T1059/006/" target="_blank" rel="noopener noreferrer">T1059.006</a>) and on file writes into <code>/tmp/bin/</code> by a service account that should not be writing executables. Network-side, watch for bursts of outbound DNS queries consistent with mass subdomain brute-forcing from edge/IoT VLAN segments, and for long-lived outbound SSH from device-management ranges. Inventory edge devices for the affected D-Link models and for QNAP Malware Remover build numbers.</p>
<p><strong>Hardening.</strong> Replace EoL D-Link DIR-850L / DIR-818LW (and same-era RTL819X models) — there is no firmware path. Patch QNAP Malware Remover to <code>6.6.8.20251023</code> or later. Restrict inbound SSH on management VLANs to known jump hosts, and apply egress filtering so SOHO/IoT segments cannot freely initiate outbound SSH or high-volume DNS. Attribution: XLab claims none; the brief reports the activity as XLab characterises it, not as a named actor.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">QiAnXin XLab disclosed AryStinger, a previously-undocumented botnet its telemetry first observed on 2026-03-12, with English-language follow-up reporting on 2026-06-21 (QiAnXin XLab, 2026-06-17; BleepingComputer, 2026-06-21).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 04:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank" rel="noopener noreferrer">QiAnXin XLab</a> · <a href="https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Brazil&#39;s national Cell Broadcast alert platform hijacked to push fake &quot;Extreme Alert&quot; messages to ~30M phones</title><link>https://ctipilot.ch/entries/2026-06-22/brazil-s-national-cell-broadcast-alert-platform-hijacked-to/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/brazil-s-national-cell-broadcast-alert-platform-hijacked-to/</guid><pubDate>Mon, 22 Jun 2026 04:52:27 +0000</pubDate><dc:date>2026-06-22T04:52:27Z</dc:date><category>data-breach</category><category>disinformation</category><category>latam</category><category>europe</category><description><![CDATA[<p>Brazil&#39;s national Cell Broadcast emergency-alert platform was hijacked overnight 19–20 June to push fake &quot;Extreme Alert&quot; notifications to ~30M phones across seven states, forcing the system offline. Cell Broadcast deliberately bypasses opt-outs and silent mode, so an administrative-plane compromise is a high-impact leverage point — the same EU-mandated technology underpins Switzerland&#39;s ALERTSWISS (The Next Web, 2026-06-20).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/brazil-s-national-cell-broadcast-alert-platform-hijacked-to" data-tags="data-breach disinformation" data-regions="latam europe" data-kind="incident" data-priority="high" data-discovered="2026-06-22T04:52:27Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="brazil-s-national-cell-broadcast-alert-platform-hijacked-to"><a href="https://ctipilot.ch/entries/2026-06-22/brazil-s-national-cell-broadcast-alert-platform-hijacked-to/">Brazil&#39;s national Cell Broadcast alert platform hijacked to push fake &quot;Extreme Alert&quot; messages to ~30M phones</a></h3><p>An unidentified actor gained unauthorised access to Brazil&#39;s national Cell Broadcast emergency-alert platform overnight 19–20 June 2026 and sent at least ten unauthorised &quot;Extreme Alert&quot; notifications — the highest-severity tier, reserved for imminent-danger events — to roughly 30 million phones across seven states (<a href="https://thenextweb.com/news/brazil-civil-defense-alert-hack-misanthropy-cell-broadcast" target="_blank" rel="noopener noreferrer">The Next Web, 2026-06-20</a>). The Ministry of Integration and Regional Development took the platform offline at 01:30 on 20 June after confirming the intrusion; Brazil&#39;s Federal Police opened an investigation and no actor has been formally attributed (a person who claimed responsibility on X had their posts removed, but police have not confirmed the claim). The specific access vector — compromised administrative credential, API key, or platform vulnerability — has not been disclosed. Cell Broadcast is architecturally designed to bypass user opt-outs and to activate devices that are on silent, which is exactly what makes administrative-plane control of it so consequential. <code>[SINGLE-SOURCE]</code> on the primary technical detail</p>
<p><strong>Why it matters to us:</strong> This is a demonstrator for a risk class, not a Brazil-specific story. The EU Electronic Communications Code (Directive 2018/1972) mandates Cell Broadcast-based public-warning systems across member states, and Switzerland&#39;s Federal Office for Civil Protection (BABS) runs the same technology as ALERTSWISS. The incident points at the administration interface — privileged access to the broadcast console — rather than radio-side spoofing, so operators should prioritise MFA and PAM on alert-platform admin accounts, least-privilege on broadcast-issuing roles, and anomaly detection on outbound broadcast commands (volume, severity tier, off-hours issuance). A false high-severity alert is both a public-safety and a public-trust event.</p><div class="prov"><span>incident</span><span>22 Jun 04:52Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/brazil-s-national-cell-broadcast-alert-platform-hijacked-to/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thenextweb.com/news/brazil-civil-defense-alert-hack-misanthropy-cell-broadcast" target="_blank" rel="noopener noreferrer">The Next Web</a></div></article>]]></content:encoded></item><item><title>CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use</title><link>https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/</guid><pubDate>Mon, 22 Jun 2026 00:14:43 +0000</pubDate><dc:date>2026-06-22T00:14:43Z</dc:date><category>vulnerabilities</category><category>auth-bypass</category><category>poc-public</category><category>europe</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-50751</category><description><![CDATA[<p>Status update on the W24 § 1 item: NCSC-NL updated its advisory on 2026-06-16 to note public proof-of-concept code is now available for the IKEv1 VPN authentication bypass, which a Qilin ransomware affiliate has used for initial access (Help Net Security; NCSC-NL NCSC-2026-0179; daily 06-17).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen" data-tags="vulnerabilities auth-bypass poc-public" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50751/">CVE-2026-50751</a></div><h3 class="f-h" id="cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use</a></h3><p>Status update on the W24 § 1 item: NCSC-NL updated its advisory on 2026-06-16 to note public proof-of-concept code is now available for the IKEv1 VPN authentication bypass, which a Qilin ransomware affiliate has used for initial access (<a href="https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/" target="_blank" rel="noopener noreferrer">Help Net Security</a>; <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179" target="_blank" rel="noopener noreferrer">NCSC-NL NCSC-2026-0179</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). A Remote Access VPN gateway still running the deprecated IKEv1 path is an active ransomware entry point. Apply the Check Point hotfix and disable IKEv1 where IKEv2 can replace it.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179" target="_blank" rel="noopener noreferrer">NCSC-NL advisory NCSC-2026-0179</a></div></article>]]></content:encoded></item><item><title>CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root, exploited as a zero-day (CISA KEV)</title><link>https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/</guid><pubDate>Mon, 22 Jun 2026 00:14:38 +0000</pubDate><dc:date>2026-06-22T00:14:38Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>path-traversal</category><category>cisa-kev</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-20262</category><description><![CDATA[<p>A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) lets an authenticated remote attacker create or overwrite any file on the underlying OS and escalate to root code execution; Cisco patched it after zero-day exploitation and CISA added it to KEV (Cisco PSIRT; daily 06-16).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a" data-tags="vulnerabilities actively-exploited rce path-traversal cisa-kev" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:38Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20262/">CVE-2026-20262</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/">CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root, exploited as a zero-day (CISA KEV)</a></h3><p>A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) lets an authenticated remote attacker create or overwrite any file on the underlying OS and escalate to root code execution; Cisco patched it after zero-day exploitation and CISA added it to KEV (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>). SD-WAN Manager is the centralised control plane for an entire SD-WAN fabric, so a rooted controller is a fabric-wide compromise. Patch on emergency cadence and restrict management-plane access to a dedicated administrative network.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) lets an authenticated remote attacker create or overwrite any file on the underlying OS and escalate to root code execution; Cisco patched it after zero-day exploitation and CISA added it to KEV (Cisco …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a> · <a href="https://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916" target="_blank" rel="noopener noreferrer">The Register</a></div></article>]]></content:encoded></item><item><title>FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory</title><link>https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/</guid><pubDate>Mon, 22 Jun 2026 00:14:31 +0000</pubDate><dc:date>2026-06-22T00:14:31Z</dc:date><category>actively-exploited</category><category>data-breach</category><category>identity</category><category>russia-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>FortiBleed is the Monday-morning escalation — 86,644 FortiGate credentials validated and a Russian-speaking operator pivoting into Active Directory; CISA issued emergency hardening. Treat any exposed FortiGate&#39;s secrets as compromised regardless of patch level. (daily 06-20, SecurityWeek)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:31Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="fortibleed-russian-speaking-operator-cracking-86-644-fortiga"><a href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory</a></h3><p><strong>If you did nothing this week:</strong> any internet-facing FortiGate whose admin or SSL VPN credentials are in the &quot;FortiBleed&quot; corpus is a live initial-access foothold right now — patch level is irrelevant, because the leaked credential is the weapon, and the operator is already pivoting from validated VPN logins into internal Active Directory.</p>
<p>The FortiBleed dataset surfaced on 2026-06-17 as 73,932 unique FortiGate management URLs (~75,000 devices across 194 countries) paired with valid VPN and administrative credentials (<a href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-17</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). By 2026-06-19 the verified count had grown to 86,644 confirmed working credentials and CISA had issued an emergency hardening advisory (<a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). Fortinet&#39;s PSIRT confirmed the campaign ties to previously disclosed incidents (FG-IR-26-060 / FG-IR-25-647) and that the credentials originated from exported device configurations — its position is that this is <strong>not a new CVE</strong>, the corpus being a reshare of prior-incident data combined with large-scale brute-forcing (<a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT, 2026-06-19</a>) — but that distinction is cold comfort operationally: the credentials validate. The methodology that emerged this week is the load-bearing detail. A Russian-speaking actor intercepts SSL VPN authentication, cracks the captured hashes on a 45-GPU Hashtopolis cluster, and then uses the recovered service and admin accounts to move laterally into internal Active Directory (<code>T1078</code> valid accounts following <code>T1110</code> credential cracking).</p>
<p>The escalation that makes this § 1 rather than a routine credential-leak note is the AD pivot plus CISA&#39;s mandated response: terminate all SSL VPN sessions, reset every credential, migrate admin-hash storage from the older MD5-crypt scheme to PBKDF2, and enforce phishing-resistant MFA on all remote access. FortiGate is ubiquitous on Swiss and EU public-sector and telco perimeters, so treat any exposed device&#39;s local admin and VPN secrets as potentially in the corpus regardless of firmware version. Hunt for sequential VPN authentication failures from rotating residential IP ranges followed by a success and immediate internal RDP/SMB/LDAP reconnaissance, and cross-reference SSL VPN session logs against the Shadowserver notification feed.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries</p><p class="entry-cite__quote">They intercept SSL VPN authentication, crack hashes on a 45-GPU cluster managed via Hashtopolis, and pivot into internal Active Directory environments</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT</a> · <a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer — first coverage</a></div></article>]]></content:encoded></item><item><title>FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance</title><link>https://ctipilot.ch/entries/2026-06-20/fortibleed-reaches-86-644-compromised-fortigate-devices-cisa/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-20/fortibleed-reaches-86-644-compromised-fortigate-devices-cisa/</guid><pubDate>Sat, 20 Jun 2026 05:12:18 +0000</pubDate><dc:date>2026-06-20T05:12:18Z</dc:date><category>actively-exploited</category><category>data-breach</category><category>identity</category><category>russia-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>FortiBleed escalates to 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance. Up from 73,932 (covered 2026-06-18); attackers are cracking SSL VPN password hashes and pivoting into Active Directory (§ 4).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-20/fortibleed-reaches-86-644-compromised-fortigate-devices-cisa" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe" data-kind="incident" data-priority="high" data-discovered="2026-06-20T05:12:18Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="fortibleed-reaches-86-644-compromised-fortigate-devices-cisa"><a href="https://ctipilot.ch/entries/2026-06-20/fortibleed-reaches-86-644-compromised-fortigate-devices-cisa/">FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-18/fortibleed-73-932-internet-facing-fortigate-devices-exposed/">FortiBleed — 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory</a> <span class="mono muted">(2026-06-18)</span></p><p>The FortiBleed SSL VPN credential-harvesting campaign has grown from the 73,932 internet-facing FortiGate devices reported on 2026-06-18 to 86,644 confirmed compromised credentials across 194 countries, and CISA has published an emergency hardening advisory (<a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-19</a>; <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure" target="_blank" rel="noopener noreferrer">CISA, 2026-06-18</a>).</p>
<p>The new detail is methodology and impact: a Russian-speaking actor cracked SSL VPN password hashes with a 45-GPU Hashtopolis cluster, after which the actors pivot into internal Active Directory using harvested service and admin accounts (<a href="https://www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-19</a>). CISA&#39;s guidance mandates immediate SSL VPN session termination, full credential resets, enforcement of PBKDF2 (replacing the older MD5-crypt admin-hash scheme), and phishing-resistant MFA on all remote access. Defenders should cross-reference SSL VPN session logs against the Shadowserver notification feed and hunt for sequential VPN authentication failures from rotating residential IP ranges followed by a success and immediate internal RDP/SMB/LDAP reconnaissance.</p><div class="prov"><span>incident</span><span>20 Jun 05:12Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-20/fortibleed-reaches-86-644-compromised-fortigate-devices-cisa/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure" target="_blank" rel="noopener noreferrer">CISA alert</a> · <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>CVE-2026-42530 / CVE-2026-42055 — NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches</title><link>https://ctipilot.ch/entries/2026-06-19/cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-19/cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr/</guid><pubDate>Fri, 19 Jun 2026 05:20:56 +0000</pubDate><dc:date>2026-06-19T05:20:56Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-42530</category><category>CVE-2026-42055</category><description><![CDATA[<p>F5 shipped out-of-band patches on 2026-06-17 for two critical NGINX flaws (NGINX, 2026-06-17; SecurityWeek, 2026-06-18).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-19/cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-19T05:20:56Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-42530/">CVE-2026-42530 +1</a></div><h3 class="f-h" id="cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr"><a href="https://ctipilot.ch/entries/2026-06-19/cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr/">CVE-2026-42530 / CVE-2026-42055 — NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches</a></h3><p>F5 shipped out-of-band patches on 2026-06-17 for two critical NGINX flaws (<a href="https://nginx.org/en/security_advisories.html" target="_blank" rel="noopener noreferrer">NGINX, 2026-06-17</a>; <a href="https://www.securityweek.com/f5-patches-critical-high-severity-nginx-vulnerabilities/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-18</a>). CVE-2026-42530 (use-after-free, CWE-416, CVSS v4 9.2): a remote unauthenticated attacker sends a crafted HTTP/3 session that reopens a QPACK encoder stream in <code>ngx_http_v3_module</code>, corrupting worker-process memory — a crash by default, code execution where ASLR is disabled or bypassed; affects Open Source 1.31.0–1.31.1. CVE-2026-42055 (heap-based buffer overflow, CWE-122, CVSS v4 9.2): in <code>ngx_http_proxy_v2_module</code>/<code>ngx_http_grpc_module</code>, but only under a non-default configuration triple — <code>proxy_http_version 2</code> or <code>grpc_pass</code>, <code>ignore_invalid_headers off</code>, and <code>large_client_header_buffers</code> above 2 MB. Fixed in Open Source 1.31.2 (and 1.30.3 stable), NGINX Plus R36 P6 / 37.0.2.1, and Gateway Fabric 2.6.4. Interim mitigation for CVE-2026-42530 is to remove <code>quic</code> from all <code>listen</code> directives (disabling HTTP/3); for CVE-2026-42055, keep <code>ignore_invalid_headers</code> at its default <code>on</code>. Note the scoring split: nginx.org&#39;s own advisory rates CVE-2026-42530 &quot;major&quot; and CVE-2026-42055 &quot;medium&quot; (reflecting the latter&#39;s non-default-config gating), while SecurityWeek scores both at CVSS v4 9.2; the brief carries the higher third-party score with the vendor&#39;s qualifier noted. F5 reports no in-the-wild exploitation.</p><div class="prov"><span>vulnerability</span><span>19 Jun 05:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-19/cve-2026-42530-cve-2026-42055-nginx-http-3-quic-use-after-fr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://nginx.org/en/security_advisories.html" target="_blank" rel="noopener noreferrer">NGINX security advisories</a> · <a href="https://www.securityweek.com/f5-patches-critical-high-severity-nginx-vulnerabilities/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item></channel></rss>