{
  "schema_version": "1.0",
  "date": "2026-10-07",
  "generated_at": "2026-10-07T07:58:00-04:00",
  "built_at": "2026-10-07T11:35:37-04:00",
  "timezone": "America/New_York",
  "ai_note": "AI-assisted research, verified against primary sources.",
  "sections": {
    "kev_status": {
      "catalog_version": "2026.10.04",
      "catalog_released_at": "2026-10-04T14:52:56-04:00",
      "total": 1734,
      "new_today": [],
      "recent_window_days": 14,
      "recent_additions": [
        {
          "cve": "CVE-2026-88779",
          "vendor": "Citrix",
          "product": "NetScaler",
          "name": "Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
          "date_added": "2026-10-04",
          "due_date": "2026-10-07",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88779"
        },
        {
          "cve": "CVE-2026-102490",
          "vendor": "Zammad GmbH",
          "product": "Zammad",
          "name": "Zammad GmbH Zammad Improper Privilege Management Vulnerability",
          "date_added": "2026-10-02",
          "due_date": "2026-10-05",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102490"
        },
        {
          "cve": "CVE-2026-102489",
          "vendor": "Zammad GmbH",
          "product": "Zammad",
          "name": "Zammad GmbH Zammad Session Fixation Vulnerability",
          "date_added": "2026-10-02",
          "due_date": "2026-10-05",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102489"
        },
        {
          "cve": "CVE-2026-104286",
          "vendor": "Fortinet",
          "product": "FortiMail",
          "name": "Fortinet FortiMail Path Traversal Vulnerability",
          "date_added": "2026-10-01",
          "due_date": "2026-10-04",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286"
        },
        {
          "cve": "CVE-2026-76504",
          "vendor": "Cisco",
          "product": "Catalyst SD-WAN Manager",
          "name": "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability",
          "date_added": "2026-09-30",
          "due_date": "2026-10-03",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-76504"
        },
        {
          "cve": "CVE-2026-86950",
          "vendor": "Apple",
          "product": "Multiple Products",
          "name": "Apple Multiple Products Out-of-Bounds Write Vulnerability",
          "date_added": "2026-09-29",
          "due_date": "2026-10-02",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-86950"
        },
        {
          "cve": "CVE-2026-88772",
          "vendor": "Citrix",
          "product": "NetScaler",
          "name": "Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
          "date_added": "2026-09-27",
          "due_date": "2026-09-30",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88772"
        },
        {
          "cve": "CVE-2026-88771",
          "vendor": "Citrix",
          "product": "NetScaler",
          "name": "Citrix NetScaler Improper Input Validation Vulnerability",
          "date_added": "2026-09-27",
          "due_date": "2026-09-30",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88771"
        },
        {
          "cve": "CVE-2026-87902",
          "vendor": "WordPress",
          "product": "Core",
          "name": "WordPress Core Remote File Inclusion Vulnerability",
          "date_added": "2026-09-25",
          "due_date": "2026-09-28",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-87902"
        },
        {
          "cve": "CVE-2026-67279",
          "vendor": "MikroTik",
          "product": "RouterOS",
          "name": "Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability",
          "date_added": "2026-09-25",
          "due_date": "2026-09-28",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-67279"
        },
        {
          "cve": "CVE-2026-65660",
          "vendor": "Microsoft",
          "product": "SharePoint",
          "name": "Microsoft SharePoint Code Injection Vulnerability",
          "date_added": "2026-09-25",
          "due_date": "2026-09-28",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-65660"
        },
        {
          "cve": "CVE-2026-71362",
          "vendor": "Adobe",
          "product": "Commerce and Magento",
          "name": "Adobe Commerce and Magento Incorrect Authorization Vulnerability ",
          "date_added": "2026-09-24",
          "due_date": "2026-09-27",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-71362"
        },
        {
          "cve": "CVE-2026-5430",
          "vendor": "WSO2",
          "product": "Multiple Products",
          "name": "WSO2 Multiple Products Path Traversal Vulnerability ",
          "date_added": "2026-09-24",
          "due_date": "2026-09-27",
          "ransomware_use": "Unknown",
          "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-5430"
        }
      ],
      "source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    },
    "pressing": [
      {
        "id": "CVE-2026-88779",
        "title": "Citrix NetScaler ADC / Gateway SAML memory overflow",
        "cves": [
          "CVE-2026-88779"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190",
          "T1499.004"
        ],
        "log_sources": [
          "NetScaler system logs / syslog",
          "Appliance crash data",
          "Reboot / uptime history"
        ],
        "detection_hint": "Treat unexplained appliance reboots as a possible compromise signal. Preserve logs and crash data before upgrading, run Citrix's IOC script, and check its 'suspicious nobody process' hits by hand (they can be false positives).",
        "source_urls": [
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88779",
          "https://therecord.media/us-australia-warn-of-latest-citrix-vulnerability"
        ],
        "primary_source_urls": [
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88779"
        ],
        "primary_source_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88779",
        "product": "Citrix NetScaler ADC and Gateway",
        "status": "Exploited · CISA KEV due today · forensic triage required",
        "status_note": "CISA and Australia's ACSC have both issued warnings; no technical change since Oct 5.",
        "deadline": "2026-10-07",
        "deadline_state": "due_today",
        "kev": {
          "added": "2026-10-04",
          "due": "2026-10-07",
          "forensic_triage": "Yes",
          "ransomware_use": "Unknown",
          "cwes": [
            "CWE-119"
          ]
        },
        "action": "Re-patch to 14.1-73.41 / 13.1-64.28 (FIPS: 14.1-73.41 FIPS, 13.1-37.282 FIPS/NDcPP) and do forensic triage. Builds 14.1-73.37 and 13.1-64.23 are not enough.",
        "fixed_versions": [],
        "cvss": null,
        "one_line": "Beazley reports attackers use this DoS to force appliance reboots so the CVE-2026-88771 log injection fires."
      },
      {
        "id": "CVE-2026-102489/CVE-2026-102490",
        "title": "Zammad session fixation (RCE) chained with local privilege escalation",
        "cves": [
          "CVE-2026-102489",
          "CVE-2026-102490"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1068"
        ],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102489"
        ],
        "primary_source_urls": [
          "https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102489"
        ],
        "primary_source_url": "https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490",
        "product": "Zammad",
        "status": "Exploited · CISA KEV past due (Oct 5) · forensic triage required",
        "status_note": null,
        "deadline": "2026-10-05",
        "deadline_state": "past_due",
        "kev": {
          "added": "2026-10-02",
          "due": "2026-10-05",
          "forensic_triage": "Yes",
          "ransomware_use": "Unknown",
          "cwes": [
            "CWE-384"
          ]
        },
        "action": "Per Zammad's Oct 5 advisory, CVE-2026-102489 is exploitable only on 6.5 and older (end-of-life) and CVE-2026-102490 has no fix yet. Move off 6.5 now and restrict server access to trusted admins.",
        "fixed_versions": [],
        "cvss": null,
        "one_line": null
      },
      {
        "id": "CVE-2026-104286",
        "title": "Fortinet FortiMail IBE path traversal (unauthenticated file write)",
        "cves": [
          "CVE-2026-104286"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190",
          "T1574.006"
        ],
        "log_sources": [
          "FortiMail system and event logs",
          "Firewall / proxy logs (IOC IPs)"
        ],
        "detection_hint": "Hunt for Fortinet's published file hashes, /data/etc/ld.so.preload, unexpected remote 'archive account' entries, and connections to 79.141.169[.]187 or 45.129.0[.]192.",
        "source_urls": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286"
        ],
        "primary_source_urls": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286"
        ],
        "primary_source_url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
        "product": "Fortinet FortiMail",
        "status": "Exploited · CISA KEV past due (Oct 4) · forensic triage required",
        "status_note": null,
        "deadline": "2026-10-04",
        "deadline_state": "past_due",
        "kev": {
          "added": "2026-10-01",
          "due": "2026-10-04",
          "forensic_triage": "Yes",
          "ransomware_use": "Unknown",
          "cwes": [
            "CWE-22",
            "CWE-158"
          ]
        },
        "action": "Upgrade to 8.0.2, 7.6.7 or 7.4.9; on 7.2.x move to 7.4+. Until patched, turn IBE off or block internet access to webmail.",
        "fixed_versions": [
          "8.0.2",
          "7.6.7",
          "7.4.9",
          "7.2.x -> migrate to 7.4+"
        ],
        "cvss": {
          "score": 9.8,
          "version": "v3",
          "scored_by": "Fortinet",
          "raw": "v3 9.8 (Fortinet)"
        },
        "one_line": "Fortinet's Oct 5 solution update lists fixed builds."
      },
      {
        "id": "CVE-2026-76504",
        "title": "Cisco Catalyst SD-WAN Manager authentication bypass",
        "cves": [
          "CVE-2026-76504"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190"
        ],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-76504",
          "https://www.vulncheck.com/blog"
        ],
        "primary_source_urls": [
          "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-76504",
          "https://www.vulncheck.com/blog"
        ],
        "primary_source_url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU",
        "product": "Cisco Catalyst SD-WAN Manager",
        "status": "Exploited · CISA KEV past due (Oct 3) · forensic triage required",
        "status_note": null,
        "deadline": "2026-10-03",
        "deadline_state": "past_due",
        "kev": {
          "added": "2026-09-30",
          "due": "2026-10-03",
          "forensic_triage": "Yes",
          "ransomware_use": "Unknown",
          "cwes": [
            "CWE-177"
          ]
        },
        "action": "Apply the fixed releases in Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU. VulnCheck published a full exploitation walkthrough on Oct 1 (one unauthenticated request gives admin over the SD-WAN fabric), so expect wider use.",
        "fixed_versions": [],
        "cvss": null,
        "one_line": null
      },
      {
        "id": "CVE-2026-94504/CVE-2026-93836",
        "title": "Exploited stored XSS in Ninja Forms (<=3.15.3) and WPC Product Bundles (<=8.6.6) -> fake 'WP Smart Thumbnails' plugin, hidden admin, magic login URL, unauth file manager",
        "cves": [
          "CVE-2026-94504",
          "CVE-2026-93836"
        ],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/",
          "https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/"
        ],
        "primary_source_urls": [
          "https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/"
        ],
        "primary_source_url": "https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/",
        "product": null,
        "status": "Exploitation reported · not in CISA KEV",
        "status_note": null,
        "deadline": null,
        "deadline_state": "not_in_kev",
        "kev": null,
        "action": null,
        "fixed_versions": [
          "Ninja Forms 3.15.4",
          "WPC Product Bundles 8.6.7"
        ],
        "cvss": {
          "score": 7.2,
          "version": "v3",
          "scored_by": "Wordfence, CVE-2026-94504",
          "raw": "v3 7.2 (Wordfence, CVE-2026-94504)"
        },
        "one_line": null
      }
    ],
    "critical_cves": [
      {
        "id": "CVE-2026-104286",
        "item_id": "CVE-2026-104286",
        "cves": [
          "CVE-2026-104286"
        ],
        "product": "Fortinet FortiMail",
        "summary": "Path traversal in IBE lets an unauthenticated attacker write arbitrary files.",
        "cvss": 9.8,
        "cvss_version": "v3",
        "cvss_scored_by": "Fortinet",
        "fixed_versions": [
          "8.0.2",
          "7.6.7",
          "7.4.9",
          "7.2.x -> migrate to 7.4+"
        ],
        "exploited": true,
        "in_kev": true,
        "exploitation_note": null,
        "notes": null,
        "source_url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
        "source_urls": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286"
        ],
        "primary_source_urls": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190",
          "T1574.006"
        ],
        "log_sources": [
          "FortiMail system and event logs",
          "Firewall / proxy logs (IOC IPs)"
        ],
        "detection_hint": "Hunt for Fortinet's published file hashes, /data/etc/ld.so.preload, unexpected remote 'archive account' entries, and connections to 79.141.169[.]187 or 45.129.0[.]192."
      },
      {
        "_sec": "critical_cves",
        "_first": "2026-10-05",
        "id": "CVE-2026-105207",
        "item_id": "CVE-2026-105207",
        "cves": [
          "CVE-2026-105207"
        ],
        "product": "ZITADEL (identity provider)",
        "summary": "Unauthenticated account takeover through external-IdP linking, by an attacker who knows a user's login name.",
        "cvss": 9.8,
        "cvss_version": "v3",
        "cvss_scored_by": "VulnCheck/GHSA",
        "fixed_versions": [
          "4.17.3"
        ],
        "exploited": false,
        "in_kev": false,
        "notes": "3.x is end-of-life with no fix. Disabling external-IdP linking is only a partial mitigation (the API path stays open).",
        "source_url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4",
        "source_urls": [
          "https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4"
        ],
        "primary_source_urls": [
          "https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false
      },
      {
        "_sec": "critical_cves",
        "_first": "2026-10-05",
        "id": "CVE-2026-105209",
        "item_id": "CVE-2026-105209",
        "cves": [
          "CVE-2026-105209"
        ],
        "product": "ZITADEL (identity provider)",
        "summary": "Cross-organization account takeover through passkey enrollment.",
        "cvss": 9.6,
        "cvss_version": "v3",
        "fixed_versions": [
          "3.4.15",
          "4.17.1"
        ],
        "exploited": false,
        "in_kev": false,
        "source_url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-pq2q-2c6r-75c4",
        "source_urls": [
          "https://github.com/zitadel/zitadel/security/advisories/GHSA-pq2q-2c6r-75c4"
        ],
        "primary_source_urls": [
          "https://github.com/zitadel/zitadel/security/advisories/GHSA-pq2q-2c6r-75c4"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false
      },
      {
        "id": "CVE-2025-64393",
        "item_id": "CVE-2025-64393",
        "cves": [
          "CVE-2025-64393"
        ],
        "product": "Veeam Backup & Replication: Backup Viewer role -> code exec as SYSTEM on backup server",
        "summary": "Veeam Backup & Replication: Backup Viewer role -> code exec as SYSTEM on backup server",
        "cvss": 9.4,
        "cvss_version": "v4",
        "cvss_scored_by": "HackerOne CNA",
        "fixed_versions": [],
        "exploited": false,
        "in_kev": false,
        "exploitation_note": null,
        "notes": "fixed version not confirmed in this run",
        "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64393",
        "source_urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2025-64393"
        ],
        "primary_source_urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2025-64393"
        ],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null
      },
      {
        "id": "CVE-2026-21589",
        "item_id": "CVE-2026-21589",
        "cves": [
          "CVE-2026-21589"
        ],
        "product": "Atlassian Data Center (8 products incl. Confluence, Jira Software, JSM, Bitbucket)",
        "summary": "Unauthenticated read of known files in the web root.",
        "cvss": 9.3,
        "cvss_version": "v4",
        "cvss_scored_by": "Atlassian",
        "fixed_versions": [],
        "exploited": false,
        "in_kev": false,
        "exploitation_note": null,
        "notes": "Server editions have no fix listed. Crowd 7.1 fix version differs between sources (7.1.7 in the ticket, 7.1.1 in the CVE record). Until patched: take internet-facing Data Center instances off the public internet or add Atlassian's WAF / RewriteValve rule.",
        "source_url": "https://jira.atlassian.com/browse/CONFSERVER-104488",
        "source_urls": [
          "https://jira.atlassian.com/browse/CONFSERVER-104488",
          "https://jira.atlassian.com/browse/JSDSERVER-16809",
          "https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html"
        ],
        "primary_source_urls": [
          "https://jira.atlassian.com/browse/CONFSERVER-104488",
          "https://jira.atlassian.com/browse/JSDSERVER-16809"
        ],
        "first_seen": "2026-10-06",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190"
        ],
        "log_sources": [
          "Reverse proxy / web server access logs",
          "Tomcat access logs"
        ],
        "detection_hint": "URL-decode access logs twice, then hunt for '..' next to '/', '\\' or '::'."
      },
      {
        "_sec": "critical_cves",
        "_first": "2026-10-05",
        "id": "CVE-2026-86345",
        "item_id": "CVE-2026-86345",
        "cves": [
          "CVE-2026-86345"
        ],
        "product": "389 Directory Server (389-ds-base)",
        "summary": "StartTLS injection can make a failed LDAP bind look successful to the client.",
        "cvss": 9.0,
        "cvss_version": "v3",
        "cvss_scored_by": "Red Hat",
        "exploited": false,
        "in_kev": false,
        "notes": "Fixed versions: see the Red Hat advisory.",
        "source_url": "https://access.redhat.com/security/cve/CVE-2026-86345",
        "source_urls": [
          "https://access.redhat.com/security/cve/CVE-2026-86345"
        ],
        "primary_source_urls": [
          "https://access.redhat.com/security/cve/CVE-2026-86345"
        ],
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false
      }
    ],
    "developments": [
      {
        "id": "CVE-2026-102255",
        "title": "SonicWall SMA1000 pre-auth SSRF in Appliance Work Place (unintended proxy path); plus 3 post-auth bugs CVE-2026-102256/-102257/-102258",
        "cves": [
          "CVE-2026-102255",
          "CVE-2026-102256"
        ],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017",
          "https://labs.beazley.security/advisories/BSL-A1223",
          "https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/"
        ],
        "primary_source_urls": [
          "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017",
          "https://labs.beazley.security/advisories/BSL-A1223"
        ],
        "primary_source_url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017",
        "type": "advisory",
        "date": "2026-10-07",
        "one_line": null
      },
      {
        "id": "CCTLD-HIJACK-GH-SL-AS-2026-10",
        "title": "Attackers hijacked .gh, .sl and .as ccTLD operators, changed authoritative DNS and obtained unauthorized HTTPS certs for Google and other large brands; Chrome blocked via CRLSets",
        "cves": [],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/",
          "https://www.helpnetsecurity.com/2026/10/07/google-unauthorized-https-certificates-cctld-hijacks/",
          "https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/"
        ],
        "primary_source_urls": [
          "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/"
        ],
        "primary_source_url": "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/",
        "type": "campaign",
        "date": "2026-10-07",
        "one_line": null
      },
      {
        "id": "CHROME-155-2026-10",
        "title": "Chrome 155.0.8059.39 fixes 247 bugs incl. 4 Critical UAFs (CVE-2026-106382, -106197, -106358, -106347) and 53 High",
        "cves": [
          "CVE-2026-106382"
        ],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2026-106197",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-106382",
          "https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/"
        ],
        "primary_source_urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2026-106197",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-106382"
        ],
        "primary_source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106197",
        "type": "advisory",
        "date": "2026-10-07",
        "one_line": null
      },
      {
        "id": "UAC-0277-LUNEX-UPDATE",
        "title": "CERT-UA UAC-0277 detail: MSI via ClickFix; Mode 2 shows lure only to Windows users from search, max 2x/12h; variant uses vulnerable AMD PDFWKRNL.sys to blind EDR; LUNARAXE extension + NAIVEMESS PowerShell native-messaging host",
        "cves": [],
        "first_seen": "2026-10-07",
        "is_new": true,
        "updated": false,
        "attack_ids": [],
        "log_sources": [],
        "detection_hint": null,
        "source_urls": [
          "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv",
          "https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html"
        ],
        "primary_source_urls": [
          "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv"
        ],
        "primary_source_url": "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv",
        "type": "campaign",
        "date": "2026-10-07",
        "one_line": null
      },
      {
        "id": "UAC-0277-LUNEX-2026-10",
        "title": "CERT-UA: UAC-0277 mass ClickFix campaign delivers LunexStealer",
        "cves": [],
        "first_seen": "2026-10-06",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1189",
          "T1204.004",
          "T1059.001",
          "T1068",
          "T1176",
          "T1102.001"
        ],
        "log_sources": [
          "Windows process creation (4688 / Sysmon 1)",
          "Registry: Explorer\\RunMRU",
          "PowerShell script block logging (4104)",
          "Driver load events (Sysmon 6)",
          "Browser extension inventory"
        ],
        "detection_hint": "Alert when explorer.exe / RunMRU launches PowerShell or mshta, disable the Run dialog for standard users via GPO, enforce Microsoft's vulnerable-driver blocklist, and allow-list browser extensions.",
        "source_urls": [
          "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv",
          "https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/",
          "https://dev.ua/en/news/hackers-steal-data-through-fake-im-not-a-robot-verification-cert-ua-detects-large-scale-cyberattack"
        ],
        "primary_source_urls": [
          "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv",
          "https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/"
        ],
        "primary_source_url": "https://cip.gov.ua/ua/news/ya-ne-robot-cert-ua-fiksuye-masove-poshirennya-shkidlivogo-programnogo-zabezpechennya-z-ponad-100-zlamanikh-vebsaitiv",
        "i18n": {
          "uk": {
            "title": "CERT-UA: масова кампанія ClickFix групи UAC-0277 доставляє LunexStealer",
            "one_line": "У вересні група впровадила JavaScript на понад 100 зламаних легітимних сайтах із фейковою перевіркою Cloudflare «Я не робот», яка спонукає жертву вставити команду у Win+R або PowerShell. Корисне навантаження LunexStealer (malware-as-a-service) містить крок із вразливим драйвером (BYOVD) і підроблене розширення браузера «Microsoft Office Word Editor» для крадіжки облікових даних і віддаленого доступу; конфігурація розміщується в Polygon / Ethereum."
          }
        },
        "type": "campaign",
        "date": "2026-10-06",
        "one_line": "In September the group injected JavaScript into 100+ compromised legitimate sites to show a fake Cloudflare 'I'm not a robot' check that tells the victim to paste a command into Win+R or PowerShell. The payload, LunexStealer (malware-as-a-service), comes with a vulnerable-driver (BYOVD) step and a fake 'Microsoft Office Word Editor' browser extension for credential theft and remote access; config is staged on Polygon / Ethereum."
      },
      {
        "_sec": "developments",
        "_first": "2026-10-06",
        "id": "ATB-CONFIRMED-2026-10",
        "title": "ATB (Ukraine) confirms cyberattack; DataSuckers data-theft claims unverified",
        "first_seen": "2026-10-06",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190",
          "T1486"
        ],
        "log_sources": [
          "Web / WAF access logs",
          "CMS change and deploy logs",
          "Identity provider sign-in logs"
        ],
        "detection_hint": "Monitor public-facing web properties for unauthorized defacement or ransom pages; rotate exposed credentials if any web apps were compromised.",
        "source_urls": [
          "https://internetua.com/atb-lokalizuvala-masshtabnu-kiberataku-iz-zastosuvannyam-shtucsnogo-intelektu-kriticsnih-naslidkiv-ne-dopusxeno",
          "https://unn.ua/en/news/no-personal-data-is-stored-on-the-resources-atb-commented-on-the-hacker-attack-on-the-website",
          "https://therecord.media/atb-ukraine-cyberattack-ransomware"
        ],
        "primary_source_urls": [
          "https://internetua.com/atb-lokalizuvala-masshtabnu-kiberataku-iz-zastosuvannyam-shtucsnogo-intelektu-kriticsnih-naslidkiv-ne-dopusxeno",
          "https://unn.ua/en/news/no-personal-data-is-stored-on-the-resources-atb-commented-on-the-hacker-attack-on-the-website"
        ],
        "primary_source_url": "https://internetua.com/atb-lokalizuvala-masshtabnu-kiberataku-iz-zastosuvannyam-shtucsnogo-intelektu-kriticsnih-naslidkiv-ne-dopusxeno",
        "i18n": {
          "uk": {
            "title": "АТБ підтверджує кібератаку; заяви DataSuckers про викрадення даних не перевірені",
            "one_line": "5 жовтня найбільша мережа супермаркетів України підтвердила цільову атаку на окремі системи та цифрові сервіси. АТБ повідомляє, що атаку локалізовано, критичного впливу на основні системи чи роботу мережі немає, а персональні дані клієнтів не скомпрометовані, бо не зберігаються на уражених ресурсах. Російськомовна фінансово мотивована група DataSuckers заявила про 7,9 млн записів клієнтів і викуп $400 тис. після публікації на сайті АТБ; ці цифри — неперевірені заяви зловмисників."
          }
        },
        "type": "breach",
        "date": "2026-10-06",
        "one_line": "On Oct 5, Ukraine's largest grocery chain confirmed a targeted attack on some systems and digital services. ATB says the attack was contained, with no critical impact on core systems or operations, and that customer personal data was not compromised because it is not stored on the affected resources. The Russian-speaking, financially motivated group DataSuckers claimed 7.9M customer records and a $400k ransom after posting on ATB's site; those volume figures are unverified adversary claims."
      },
      {
        "_sec": "developments",
        "_first": "2026-10-05",
        "id": "DK-CPR-2026-10",
        "title": "Denmark's CPR register accessed: about 8.8M people's records",
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1078",
          "T1213"
        ],
        "log_sources": [
          "API gateway / query logs",
          "Partner access audit logs"
        ],
        "detection_hint": "For partner and API data access: per-partner query quotas, alerts on bulk enumeration and volume anomalies, and regular review of delegated access.",
        "source_urls": [
          "https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/",
          "https://techcrunch.com/2026/10/05/hackers-steal-8-million-citizens-records-from-danish-government-database/"
        ],
        "primary_source_urls": [
          "https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/"
        ],
        "primary_source_url": "https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/",
        "type": "breach",
        "date": "2026-10-05",
        "one_line": "Attackers abused a private company's lawful search access during September to pull names, addresses and CPR numbers; detected Oct 2, access cut off, no attribution. Expect phishing that uses the data."
      },
      {
        "_sec": "developments",
        "_first": "2026-10-05",
        "id": "WARLOCK-LONGLEGS-2026-10",
        "title": "Warlock ransomware (Storm-2603) still entering through unpatched on-prem SharePoint",
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1190",
          "T1562.001",
          "T1570",
          "T1572",
          "T1486"
        ],
        "log_sources": [
          "Windows process creation (4688 / Sysmon 1)",
          "File creation on domain controllers (SYSVOL)",
          "SharePoint / IIS logs",
          "EDR tamper alerts"
        ],
        "detection_hint": "Alert on executables written to SYSVOL\\...\\scripts, detect 'code tunnel service install', enforce Microsoft's vulnerable-driver blocklist / WDAC, and rotate SharePoint ASP.NET machine keys after patching.",
        "source_urls": [
          "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
        ],
        "primary_source_urls": [
          "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
        ],
        "primary_source_url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure",
        "type": "campaign",
        "date": "2026-10-05",
        "one_line": "Symantec counts at least 4 victims in two months (water utility, telecom, regional government body, university). In one intrusion an AV/EDR killer hit 40+ hosts in about 2 hours before Warlock ran on 33+ hosts staged from SYSVOL. Also seen: the K7RKScan vulnerable driver (CVE-2025-1055) and VS Code tunnels."
      },
      {
        "_sec": "developments",
        "_first": "2026-10-05",
        "id": "TRANSLUCE-AGENTS-GOV-2026-09",
        "title": "AI agents generating attack-like traffic against government sites",
        "first_seen": "2026-10-05",
        "is_new": false,
        "updated": false,
        "attack_ids": [
          "T1595"
        ],
        "log_sources": [
          "WAF / CDN logs",
          "Web server access logs"
        ],
        "detection_hint": "Add an 'autonomous agent' category to traffic triage and attribution, and watch for agents relaying requests through archive and scanner services.",
        "source_urls": [
          "https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites",
          "https://transluce.org/us-canada-gov"
        ],
        "primary_source_urls": [
          "https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites",
          "https://transluce.org/us-canada-gov"
        ],
        "primary_source_url": "https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites",
        "type": "ai",
        "date": "2026-10-05",
        "one_line": "Transluce documented agents sending 200k+ requests to a US Department of Education site on Sep 30, including a SQL injection probe, plus crude probes against Library and Archives Canada. No access to non-public data was found; Canada's Cyber Centre reports no sign of compromise."
      }
    ],
    "ransomware_stats": {
      "label": "Leak-site claims (unverified)",
      "window_end": "2026-10-07T07:58:00-04:00",
      "latest_post_seen": "2026-10-07T01:51:42-04:00",
      "posts_24h": 23,
      "posts_7d": 194,
      "groups_active_7d": 45,
      "top_groups_7d": [
        {
          "group": "qilin",
          "posts": 19,
          "source_url": "https://www.ransomware.live/group/qilin"
        },
        {
          "group": "lamashtu",
          "posts": 14,
          "source_url": "https://www.ransomware.live/group/lamashtu"
        },
        {
          "group": "safepay",
          "posts": 13,
          "source_url": "https://www.ransomware.live/group/safepay"
        },
        {
          "group": "incransom",
          "posts": 10,
          "source_url": "https://www.ransomware.live/group/incransom"
        },
        {
          "group": "akira",
          "posts": 9,
          "source_url": "https://www.ransomware.live/group/akira"
        },
        {
          "group": "krybit",
          "posts": 9,
          "source_url": "https://www.ransomware.live/group/krybit"
        },
        {
          "group": "thegentlemen",
          "posts": 9,
          "source_url": "https://www.ransomware.live/group/thegentlemen"
        },
        {
          "group": "settra",
          "posts": 8,
          "source_url": "https://www.ransomware.live/group/settra"
        },
        {
          "group": "Booba Project",
          "posts": 7,
          "source_url": "https://www.ransomware.live/group/Booba%20Project"
        },
        {
          "group": "N0n",
          "posts": 6,
          "source_url": "https://www.ransomware.live/group/N0n"
        }
      ],
      "top_groups_24h": [
        {
          "group": "everest",
          "posts": 5,
          "source_url": "https://www.ransomware.live/group/everest"
        },
        {
          "group": "incransom",
          "posts": 4,
          "source_url": "https://www.ransomware.live/group/incransom"
        },
        {
          "group": "qilin",
          "posts": 3,
          "source_url": "https://www.ransomware.live/group/qilin"
        },
        {
          "group": "akira",
          "posts": 2,
          "source_url": "https://www.ransomware.live/group/akira"
        },
        {
          "group": "Panzer",
          "posts": 2,
          "source_url": "https://www.ransomware.live/group/Panzer"
        }
      ],
      "note": "Counts of new posts on ransomware / extortion leak sites, by discovery time, as indexed by ransomware.live. These are criminal claims, often exaggerated or recycled, and are not confirmed by the organisations listed. Victim names are not published.",
      "source": "ransomware.live",
      "source_url": "https://www.ransomware.live/"
    },
    "best_practices": [
      {
        "text": "WordPress: update Ninja Forms to 3.15.4+ and WPC Product Bundles to 8.6.7+, then hunt for the wp-smart-thumbnails plugin, unexpected mu-plugins and hidden admin accounts; patching does not remove an existing backdoor.",
        "related": [
          "CVE-2026-94504/CVE-2026-93836"
        ],
        "source_urls": [
          "https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/"
        ]
      },
      {
        "text": "Certificates: monitor Certificate Transparency for every domain you own and publish restrictive CAA records (with accounturi where your CA supports it) so a DNS hijack can't quietly mint certificates.",
        "related": [
          "CCTLD-HIJACK-GH-SL-AS-2026-10"
        ],
        "source_urls": [
          "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/"
        ]
      },
      {
        "text": "Remote-access and NAC appliances: keep SMA1000, ClearPass and switch management interfaces off the internet and on a dedicated management VLAN; patch on the vendor's first hotfix, not after exploitation starts.",
        "related": [
          "CVE-2026-102255"
        ],
        "source_urls": [
          "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017"
        ]
      }
    ]
  },
  "methodology": "Threat Watch is compiled each morning by Starbound's AI-assisted research pipeline. Each item is checked against primary sources (the CISA KEV catalog, vendor and CNA advisories, CERTs and government notices, and original research) before publication. Items backed only by secondary reporting are held until a primary source is available. \"Pressing\" lists vulnerabilities with evidence of exploitation, including CISA KEV entries and their remediation deadlines. The CVE table lists vulnerabilities scored CVSS 9.0 or higher, as published by the named vendor or CNA (or, where noted, the reporting source). Ransomware figures count new posts on extortion leak sites as indexed by ransomware.live; they are criminals' claims, not confirmed incidents, and victim names are generally not published. A named organization may appear only when that organization has publicly confirmed the incident; adversary volume and ransom claims remain labeled unverified. ATT&CK technique IDs are Starbound analyst mappings of behavior described in the cited sources. Times are US Eastern.",
  "disclaimer": "Provided for awareness, as-is and without warranty. Confirm affected and fixed versions in the linked vendor advisory before acting; this is not a substitute for your own risk assessment."
}
