CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 October 2026)

Published: Loading…

At a Glance

  • Atlassian Data Center flaw CVE-2026-21589, rated 9.3, is under exploitation within hours of a public proof of concept, exposing files across eight products.
  • FortiBleed credential-stuffing attacks against FortiGate firewalls and SSL VPN gateways have compromised 86,644 devices and are locking administrators out, according to an FBI and Secret Service advisory.
  • Attackers compromised the .gh, .sl and .as country-code registries, altered DNS records and obtained unauthorised HTTPS certificates for several Google domains.
  • SonicWall patched CVE-2026-102255, a CVSS 10.0 pre-authentication SSRF flaw, alongside three other vulnerabilities in SMA1000 series appliances.
  • Arizona's court system breach exposed personal information of more than one million people, while a rogue ASOS app notification claimed a Snowflake compromise.
  • The PoeLLM malware has infected more than 3,000 exposed AI servers to mine cryptocurrency, using an adversarial poem to evade guardrails.

Editorial Analysis

Atlassian's CVE-2026-21589 moved from advisory to active exploitation in roughly two days. Atlassian published the flaw on 5 October, watchTowr released a technical write-up with a proof of concept the following day, and honeypot operators reported attempts within hours. The advisory describes limited impact because an attacker must know an exact file name and path and cannot list directories. watchTowr's chain shows why that understates the risk: in Jira, a leaked crowd.properties file exposes plaintext Crowd application credentials, which can be used to create a user and add it to the jira-administrators group. The impact therefore depends on what sits in the web root, while Crowd's IP allow-listing may constrain the final step. Atlassian's caveat about sensitive files in some configurations turned out to be central to the exploitation path.

The FortiBleed advisory and the ccTLD registry hijacks concern trust placed in infrastructure that organisations do not fully control. The FBI and Secret Service say FortiBleed uses reused or leaked credentials and legacy SHA-256 password storage against FortiGate firewalls and SSL VPN gateways, with SOCRadar verifying 86,644 compromised devices across 194 countries. Attackers have moved beyond credential theft, creating new accounts and in some cases deleting or changing existing ones, locking administrators out of their own devices. The registry hijacks operate at a different layer: attackers compromised the operators of the .gh, .sl and .as ccTLDs, altered authoritative DNS records and obtained HTTPS certificates for several Google domains and other organisations. Google says its systems were not breached and does not believe the certificate authorities made an error, meaning the certificates were validly issued against hijacked DNS. Chrome could block them through CRLSets, but Google notes that this protection does not extend to other clients.

AI tooling features in two of the day's reports, in different roles. CrowdStrike's analysis of a campaign against South Korean financial organisations found the operator using ARTEX, an agentic penetration-testing tool, with several language models behind it. Exposed directories contained Claude Code session histories and memory files, providing a record of the operator's activity, including prompts asking where Korean breach data is sold. PoeLLM, reported by Lumen's Black Lotus Labs, targets exposed AI and LLM infrastructure instead: more than 3,000 servers have been infected for cryptomining and botnet growth, with an adversarial poem used as a jailbreak.

Highlights of the Day

Atlassian File Read Flaw Enables Jira Admin Access Amid Exploitation

CVE-2026-21589 is a 9.3-rated flaw that lets unauthenticated attackers read files from the web root of eight Atlassian Data Center products. watchTowr Labs showed that a leaked Jira crowd.properties file exposes Crowd credentials, enough to create an administrator account. Related reporting says exploitation attempts began within hours of public details and a proof of concept appearing.

FBI and Secret Service Warn of FortiBleed Campaign Hitting FortiGate Devices

The FBI and US Secret Service issued a joint advisory on FortiBleed, an active global campaign targeting internet-facing FortiGate firewalls and SSL VPN gateways. SOCRadar has verified more than 86,644 compromised devices across 194 countries. The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, allowing attackers to harvest and crack authentication data at scale, with lockouts reported.

Chrome Blocks Unauthorised Certificates After Ghana, Sierra Leone and Samoa Domain Hijacks

Attackers compromised the .gh, .sl and .as country-code registries, modified authoritative DNS records and obtained unauthorised HTTPS certificates covering several Google domains and other organisations. Google blocked the certificates in Chrome through CRLSets and worked with the issuing certificate authorities to revoke them. Certificate Transparency log data later revealed additional affected organisations, whose certificates Chrome also blocked.

Source: Google

ASOS Customers Receive Extortion Message Through Retailer's Own App

ASOS app users received a push notification on 6 October 2026 claiming a Snowflake compromise and threatening a data leak. ASOS confirmed unauthorised activity on third-party customer communication platforms, with names and contact details possibly accessed. Snowflake said it found no compromise of its platform.

Source: Vectra AI

SonicWall Patches Four SMA1000 Flaws, Including Maximum-Severity SSRF

SonicWall disclosed four vulnerabilities in SMA1000 series appliances, led by CVE-2026-102255, a pre-authentication server-side request forgery rated 10.0 on CVSS. The remaining flaws are post-authentication, covering OS command injection, a Zip Slip archive extraction issue and stored cross-site scripting. Models 6210, 7210 and 8200v are affected, SonicWall reports no in-the-wild exploitation, and SSL-VPN on SonicWall firewalls is unaffected.

Source: SonicWall

MALFEX npm Campaign Delivers RAT and Stealer to Windows Developers

Checkmarx tracked MALFEX, an npm campaign run by a single operator since August 2023, which published eight malicious packages delivering three separate Windows payloads. These include a loader for the Overlord remote access trojan, a Node.js stealer called movinlike targeting Discord, browsers, Telegram and crypto wallets, and a long-running downloader in function-flag. The packages recorded 40,767 downloads, and three remained installable on 29 September 2026.

Source: Checkmarx

PhantomPolia ClickFix Campaign Uses Ethereum Contract to Deliver Remus Stealer

LevelBlue observed compromised websites loading PhantomPolia, a JavaScript loader that retrieves an encrypted command-and-control domain from an Ethereum Sepolia smart contract. Victims are then shown a ClickFix prompt that runs a PowerShell command, which downloads an AutoIt installer that executes Donut-packed shellcode in memory. The final payload, Remus Stealer, collects credentials, browser data, password manager contents and cryptocurrency wallets, then sends them encrypted to attacker servers.

Source: LevelBlue

GhostAction Returns, Injecting Secret-Stealing Workflows into 772 GitHub Repositories

GitGuardian reported a new GhostAction wave between 31 August and 30 September 2026, pushing a malicious workflow to 772 public repositories belonging to 373 GitHub users and organisations. The workflow sends hardcoded repository secrets in a single request to a bare IP address, targeting 2,577 secrets including SSH keys, Azure credentials and container registry logins. Only 124 repositories had been cleaned in public history by 5 October 2026.

Unknown Actor Uses AI Pentesting Tool ARTEX Against South Korean Banks

CrowdStrike identified a campaign against South Korean financial organisations from late September to early October 2026, in which the threat actor used ARTEX, an open-source Chinese agentic penetration testing tool, alongside large language models. Exposed open directories held Claude Code session histories, ARTEX configuration files and Claude memory files. The actor is assessed with moderate confidence to be Chinese-speaking and financially motivated, and has not been attributed to a named adversary.

Daily Coverage

Developments
Atlassian ExploitationFortibleed LockoutsCctld Registry HijacksSonicwall Sma1000 Ssrf
Vulnerabilities
CVE-2026-21589Bamboo Data Center All Other Versions (Critical)CVE-2026-102255Sma1000 12.4.3-03526 (Platform-Hotfix) And Older VersionsCVE-2026-93524CVE-2026-93536CVE-2026-102489Zammad 6.3.0 (Critical)CVE-2026-48388Adobe Photoshop Installer (High)CVE-2026-59346Vmware Workstation 25H2 (Critical)CVE-2026-59347Vmware Workstation 25H2 (High)CVE-2026-107181Telegram Desktop (High)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.HAFNIUMHAFNIUM is a likely statesponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.