Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (10 October 2026)
Published: Loading…
At a Glance
- Attackers are exploiting SonicWall SMA1000 flaw CVE-2026-102255, a maximum-severity pre-authentication SSRF, three days after it was patched.
- The FBI seized seven domains tied to the MicroScan and FishHub tools used by Flax Typhoon, and CISA added five exploited flaws to KEV.
- Citrix patched CVE-2026-107406, a CVSS 9.5 memory overflow in NetScaler ADC and Gateway SAML configurations that may allow remote code execution.
- Unpatched AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 are being exploited to deploy web shells and XMRig cryptocurrency miners.
- A new GhostAction workflow mines full git histories for credentials, with an 8 October sweep through two compromised maintainer accounts hitting 345 repositories.
- Germany arrested a Russian national suspected of being a core Qilin ransomware member after his extradition from Japan.
Editorial Analysis
SonicWall's CVE-2026-102255 went from patch to exploitation in three days. On 6 October, SonicWall released fixes for four SMA1000 flaws, rating the pre-authentication SSRF at 10.0 and reporting no evidence of exploitation. Attackers are now exploiting it. The flaw allows the Work Place interface to make requests on an attacker's behalf and reach internal functionality without authentication, making it more immediately dangerous than the three authenticated vulnerabilities. AhsayCBS faces a more direct exposure: CVE-2026-105133 and CVE-2026-105134 are being exploited to deploy web shells and XMRig miners while patches remain unavailable. Citrix's CVE-2026-107406, patched this week with a 9.5 rating, is the third NetScaler SAML memory overflow in under two weeks. Citrix reports no known unmitigated exploits, but earlier flaws were exploited.
The Flax Typhoon disruption and the Qilin arrest illustrate different limits of enforcement. The FBI seized seven domains linked to MicroScan and FishHub, tools used to scan and, in some cases, breach critical infrastructure. CISA also added five exploited vulnerabilities to KEV, including ProFTPD CVE-2015-3306, which has a CVSS score of 10.0. Several flaws in the advisory are years old, so removing the group's infrastructure does not secure the systems it targeted. The Qilin case instead depended on cross-border police cooperation: after Germany obtained a warrant, the suspect travelled to Japan, where police detained him under a provisional arrest warrant pending handover. The latest ShinyHunters arrest and reports that the group is leaving Telegram add further pressure on individuals and platforms, but neither arrests nor account closures automatically eliminate established intrusion methods.
GhostAction and PAYLOAD demonstrate how attackers can exploit administrative systems without relying on conventional malware. GhostAction's malicious security-audit.yml workflow runs under compromised maintainer identities, searches working trees and full Git histories for credentials, then sends results over HTTP to a raw IP address. Commits carry legitimate maintainer names, and the search can recover secrets deleted years earlier. A StepSecurity run log for uber/athenadriver shows the collector acknowledging receipt four seconds after the workflow began. PAYLOAD, investigated by Kaspersky, uses a malicious Active Directory Group Policy Object to display a ransom note, lock screens and disable local administrator accounts without encrypting files. In both incidents, existing administrative mechanisms provide the means to act across an environment. Kaspersky's observation that attackers are encrypting less often in 2026 suggests that disruption and coercion can be effective even when files remain intact.
Highlights of the Day
Citrix Patches Critical NetScaler Memory Overflow Enabling Remote Code Execution
Citrix published a bulletin for CVE-2026-107406, a critical memory overflow in NetScaler ADC and NetScaler Gateway that may lead to remote code execution or denial of service. The flaw is rated 9.5 on CVSS 4.0 and affects appliances configured as a SAML service provider or identity provider. Citrix says it is not aware of any unmitigated exploits, and Citrix-managed cloud services are not affected.
FBI Announces Another ShinyHunters Arrest After Jobs Site Breach
FBI Director Kash Patel said agents arrested another suspected ShinyHunters co-conspirator this week, with the New York Times reporting the arrest took place in Pennsylvania and involved a Canadian national. At least two other suspected members have been detained over the past two weeks following the breach of the FBIjobs.gov domain. The FBI has taken down much of the group's infrastructure, and ShinyHunters says it will leave Telegram.
GhostAction Campaign Adds History-Scanning Workflow and Lookalike GitHub Domain
OpenSourceMalware and StepSecurity reported a new GhostAction variant, security-audit.yml, that scans repository contents and full git history for credential patterns before posting results over HTTP to 193[.]32[.]204[.]199. An 8 October sweep through two compromised maintainer accounts hit 345 repositories, and a run log from uber/athenadriver confirmed the collector acknowledged the exfiltration. A newly registered domain, my-github.com, resolves to the same address, though operator attribution remains unresolved.
Germany Arrests Suspected Qilin Ransomware Leader After Japanese Detention
Germany announced the arrest of a Russian national believed to have led the Qilin ransomware group, which has attacked organisations worldwide. Japan's National Police Agency said Japanese police detained the suspect under a provisional arrest warrant after he travelled to Japan. He was then handed over to Germany under extradition procedures, with support from Japan's Ministry of Justice and the Tokyo High Public Prosecutors Office.
PAYLOAD Extortion Campaign Hijacks Active Directory Instead of Encrypting Data
Kaspersky investigated the PAYLOAD campaign, in which attackers seized control of an Active Directory environment and created a malicious group policy object instead of deploying ransomware. The policy pushed a ransom note, changed wallpapers, locked screens, displayed a login banner and disabled local administrator accounts. Kaspersky's incident response team linked the approach to a wider decline in data encryption for ransom during 2026.
Daily Coverage