Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Huntress Expedited High alert showing SYSTEM running C:\PerfLogs\Temp\svchost.exe with config.dll.

Figure: Huntress, Figure 1, EDR signal for post-compromise GOST svchost.exe loading config.dll, Oct 6, 2026 (fair use).

RESPONSE · NEW YORK

Huntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR Install

Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.

October 11, 2026

Noah Park, Response, New York

Latest

Full desk
Huntress Expedited High alert showing SYSTEM running C:\\PerfLogs\\Temp\\svchost.exe with config.dll.
Figure: Huntress, Figure 1, EDR signal for post-compromise GOST svchost.exe loading config.dll, Oct 6, 2026 (fair use).

RESPONSE · NEW YORK

Huntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR Install

Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.

Noah Park, Response, New York

Read the story
CrowdStrike diagram summarizing nine MITRE ATT&CK-aligned offensive categories where the decompose-recompose pipeline produced working exploit code.
Figure: CrowdStrike, Figure 4, full pipeline nine offensive security use cases, Oct 6, 2026 (fair use).

DETECTION · LONDON

CrowdStrike Shows Attackers Bypass LLM Safety Classifiers by Splitting Harmful Goals Into Benign Subtasks

CrowdStrike says a frontier-model safety classifier blocked about 515 direct bypass attempts, but adversaries can still extract building blocks through genuinely benign subtasks and reassemble working offensive code with an unclassified local model.

Ava Okello, Detection, London

Read the story
Cisco Talos Threat Spotlight branded graphic for the UAT-11985 AI-assisted phishing report.
Graphic: Cisco Talos, Threat Spotlight header art for the Oct 8, 2026 UAT-11985 post (fair use).

THREAT INTEL · SINGAPORE

Cisco Talos Tracks UAT-11985 Phishing Taiwan Researchers With AI-Assisted Invites and Real-Time Google Login Relays

Cisco Talos says the campaign reused real public event details, likely AI-assisted invitation templates, and an adversary-in-the-middle kit that relays Google authentication including MFA challenges over HTTP and WebSocket. ClamAV and Snort coverage plus IOCs are published.

Priya Shah, Threat Intel, Singapore

Read the story
Huntress Rapid Response branded graphic with an alert triangle on a console screen in a neon-lit server corridor.
Graphic: Huntress, Rapid Response header art for the Oct 8, 2026 AhsayCBS active-exploit post (fair use).

RESPONSE · NEW YORK

Huntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five Organizations

Huntress says attackers began chaining two AhsayCBS flaws on Oct. 7 to gain SYSTEM-level remote code execution, then planted JSP webshells, an XMRig miner disguised as Microsoft Edge, and an AI-assisted PowerShell script that hides mining when Task Manager is open. Four Sigma rules and IOCs are published for defenders.

Noah Park, Response, New York

Read the story
Abstract Cisco Talos CAIRN research header graphic for a technical blog on malware that embeds instructions aimed at AI analysis tools.
Graphic: Cisco Talos, CAIRN header art for the Oct 8, 2026 post on AI-analysis evasion in malware (fair use).

DETECTION · LONDON

Malware Now Embeds Instructions Meant to Steer AI Analysis Tools, Cisco Talos Finds Across 84 Samples

Cisco Talos says four malware families now plant plain-language notes inside samples to influence AI triage tools, a class it calls A3. Across 84 samples the cheapest "ignore this file" comments steered model verdicts most often, while more elaborate template tricks often backfired, and defenders can hunt the same plaintext as a detection signal.

Ava Okello, Detection, London

Read the story
A small Windows application window titled Dairy with the heading DailyPlanner, a date picker reading Wednesday, April 22, 2026, two text boxes each labeled Today containing keyboard gibberish, and a large photo of an orange tabby kitten with its mouth wide open.
Screenshot: ESET Research, the fake daily planner window, titled Dairy, that late 2025 MATCHBOIL samples display when opened directly, from MATCHBOIL: New tricks, same old evil intentions, Oct 8, 2026 (fair use).

THREAT INTEL · SINGAPORE

Russia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy Firms

ESET says UAC-0099, a group it describes as able to act as an initial access broker for Sandworm, planted its rebuilt MATCHBOIL downloader at Ukrainian transportation, manufacturing and energy companies, adding fake planner screens, sandbox checks and a new DLL variant while leaving a trail of file paths, scheduled tasks and HTTP headers defenders can hunt.

Priya Shah, Threat Intel, Singapore

Read the story
Cover of a TLP:CLEAR cybersecurity advisory numbered JCSA-20261006-01, co-authored by the FBI and the U.S. Secret Service, with both agency seals above the blue title FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts.
Document: FBI and U.S. Secret Service, cover of joint cybersecurity advisory JCSA-20261006-01, FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts, Oct 6, 2026 (fair use).

RESPONSE · NEW YORK

FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls

A joint FBI and Secret Service advisory says the credential theft campaign against internet-facing FortiGate firewalls is still scanning with stolen passwords, sometimes deletes or changes administrators' accounts so owners cannot log in, and has fed access to the INC/Lynx and Payload ransomware operations.

Noah Park, Response, New York

Read the story
Dark login page with a shield icon and the name KMON_NOC above a single password field and a log-in button, with Russian-language labels for access password and log in and a line noting that authorization is required for all endpoints.
Screenshot: Datadog Security Labs, the login page of the KMON_NOC credential harvesting platform, which asks for an access password, Oct 6, 2026 (fair use).

DETECTION · LONDON

Attackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can Spot

Datadog Security Labs says a credential harvesting platform called KMON_NOC and two Python scripts check stolen AWS keys for access to Amazon Bedrock AI models with a short, repeatable run of API calls, a sequence it has seen in 12 organizations in the past 30 days and that detection teams can hunt for.

Ava Okello, Detection, London

Read the story
StepSecurity graphic titled Tensorlake npm Package Compromised, A Worm With a Hostage Token That Wipes Your Machine If You Revoke It, beside an Attack profile card listing package tensorlake, behavior self-spreading worm, leverage hostage token, if revoked machine wiped, and the command npm i tensorlake marked critical and destructive.
Graphic: StepSecurity, summary of the tensorlake npm compromise, a self-spreading worm that holds a stolen GitHub token hostage and wipes the machine if the token is revoked, Oct 8, 2026 (fair use).

RESPONSE · NEW YORK

Poisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen Token

A malicious tensorlake 0.5.144, pushed to the AI sandbox company's own GitHub repository and published with valid npm provenance on October 8, steals cloud, GitHub and npm secrets, spreads through victims' packages and installs a monitor that deletes the home directory if the stolen GitHub token is revoked, so responders must remove it before rotating credentials.

Noah Park, Response, New York

Read the story
FBI screenshot of a Chinese-language web dashboard titled E-commerce Order Management, served from 127.0.0.1:8080, showing counts of 694 low, 160 medium and 1,138 high threats, 649 completed scans and 21,851 total reports, a redacted list of the five most vulnerable hosts and a top-five plugin list led by sensitive information collection.
Screenshot: FBI, via joint Cybersecurity Advisory AA26-281A, a MicroScan account dashboard showing detected vulnerabilities, recovered in FBI investigations of Integrity Technology Group, Oct 8, 2026 (fair use).

THREAT INTEL · SINGAPORE

FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email

The FBI and nine partner agencies said on October 8 that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, stole email from government, law enforcement, healthcare and religious organizations in Southeast Asia, as the Justice Department seized domains behind the company's Microscan scanner and FishHub phishing tool.

Priya Shah, Threat Intel, Singapore

Read the story
Black Lotus Labs diagram titled The Canto Incognito Campaign, April to Sept 2026: an actor server in Italy, an infected router serving malware on port 81 and C2 on port 9999, a PoeLLM botnet of LiteLLM, Ollama, Gotenberg and Gitea servers that find the C2 from a poem on GitHub, and arrows to a Kryptex mining pool, scanning and brute force.
Graphic: Black Lotus Labs (Lumen Technologies), overview of the Canto Incognito campaign, in which PoeLLM-infected LiteLLM, Ollama, Gotenberg and Gitea servers find their command server from a poem on GitHub, mine cryptocurrency and scan for new victims, Oct 7, 2026 (fair use).

DETECTION · LONDON

Malware That Reads Its Orders From a Poem on GitHub Has Hit More Than 3,400 Exposed AI and Developer Servers

Lumen's Black Lotus Labs said on October 7 that PoeLLM, a cryptomining botnet it ties to an Italian-speaking actor, breaks into exposed LiteLLM, Ollama, Gotenberg and Gitea servers and finds its command server by decoding four words in a poem the operator edits on GitHub.

Ava Okello, Detection, London

Read the story
Login screen headed Dubai Airports Careers Login, with User Name and Password fields, a yellow LOGIN button and a laptop illustration on the left.
Screenshot: Unit 42 (Palo Alto Networks), the fake Dubai Airports careers portal the attackers had the target install before sending a trojanized coding test, Oct 6, 2026 (fair use).

THREAT INTEL · SINGAPORE

Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test

Unit 42 researchers said on October 6 that an Iranian state-aligned group it tracks as CL-STA-1178 sent an Iraq-based engineer a fake coding assessment that ran malware as soon as Visual Studio opened the project, then took its orders through GitHub repositories and issue comments.

Priya Shah, Threat Intel, Singapore

Read the story
Chrome window on gemini-beta-invites.com showing a second, fake Chrome window inside the page with a lock icon, an accounts.google.com address bar and a Google Sign in form.
Screenshot: Island, clicking Connect on a spoofed Gemini Ads page opens a fake Google sign-in window drawn inside the page while the real address bar still shows gemini-beta-invites.com, Oct 6, 2026 (fair use).

THREAT INTEL · SINGAPORE

Fake ChatGPT and Gemini Ad Portals Use Browser-in-the-Browser Pop-Ups to Steal Logins and MFA Codes

Island researchers said on October 6 that a human-operated phishing platform posing as AI advertising products for Gemini, ChatGPT, Claude, Perplexity and a fake Muse Ads draws a counterfeit Google sign-in window inside the page, then lets a live operator choose which MFA prompt the victim sees next.

Priya Shah, Threat Intel, Singapore

Read the story
Fake Cloudflare verification box with Win+R, Ctrl+V and Enter steps above a Windows Run dialog, with the cmd for /r command that searches the Firefox profile for f_ files of 33433 bytes.
Screenshot: Microsoft Threat Intelligence, a fake Cloudflare check telling the visitor to paste a command into Windows Run that copies a cached file to t.vbs and runs it, Oct 3, 2026 (fair use).

DETECTION · LONDON

Microsoft Warns ClickFix Lures Now Hide Their Payload in the Browser Cache

Microsoft Threat Intelligence said on October 3 that compromised websites are pre-fetching a VBScript payload into visitors' browser caches disguised as a PNG file, so the ClickFix command a victim pastes into Windows Run only has to find and launch it. Huntress, separately, described killing ClickFix chains on the endpoint before its SOC saw the alert.

Ava Okello, Detection, London

Read the story
Wireshark capture of STUN packets with the transaction ID annotated as command, method, target IP, port and duration.
Screenshot: Nozomi Networks Labs packet capture of a spoofed STUN reply carrying a flood command in its transaction ID, Oct 1, 2026 (fair use).

THREAT INTEL · SINGAPORE

ClingSTUN Backdoor Turns Unpatched IoT Devices Into Proxies Hidden in Public STUN Traffic

FortiGuard Labs said on October 5 that ClingSTUN, a Linux backdoor spread through 24 known flaws in routers, cameras and other edge devices, uses legitimate public STUN servers so its traffic blends with VoIP and WebRTC. Nozomi Networks, tracking the same malware as Cling, found operator commands hidden in STUN transaction IDs.

Priya Shah, Threat Intel, Singapore

Read the story
Sequence diagram of forged signatures leading SConnect's native host to load an unsigned DLL.
Figure: Bay Area Labs / Am I Being Pwned?, SConnect drive-by RCE attack flow, Oct 2, 2026 (fair use).

DETECTION · LONDON

Thales SConnect Flaw Opened Drive-By Code Execution on PCs Used for SWIFT 3SKey Sign-In

Bay Area Labs disclosed on October 2, 2026, how a hand-rolled RSA check in Thales SConnect, the browser middleware long used with SWIFT 3SKey tokens, let a malicious web page or iframe load an unsigned DLL in about six to 10 seconds. Thales published the flaw as CVE-2026-18397, rated 9.4 critical, on October 1.

Ava Okello, Detection, London

Read the story
Citrix NetScaler graphic with a SAML service-unavailable card and the words Access Denied.
Image: The Hacker News, NetScaler SAML service-unavailable illustration (fair use).

RESPONSE · NEW YORK

Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 After Attacks Reboot Freshly Patched Appliances

Citrix shipped its second emergency NetScaler update in a week after attackers crashed SAML-enabled gateways that had already been patched for the PitScaler flaws, and incident responders say the forced reboots are being used to fire earlier log-injection payloads on appliances that missed the first fix.

Noah Park, Response, New York

Read the story
Rapid7 Labs investigation title card over a dark field.
Photo/figure: Rapid7 Labs research art, Sleeper Cells in the Telecom Backbone hero (fair use).

THREAT INTEL · SINGAPORE

Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways

Rapid7 Intelligence published its first research drop on October 2, 2026, documenting Linux implants that impersonate South Korean SpamSniper and Taiwanese ShareTech mail-security appliances, with BPFDoor, Rekoobe, and a modular tool Rapid7 tracks as AVERAT blending command-and-control into SMTP traffic on the network edge.

Priya Shah, Threat Intel, Singapore

Read the story
Eight-step diagram of a Zimbra SNMP command-injection attack chain from initial access through exfiltration.
Photo/figure: Microsoft Security Research / Microsoft Security Blog, Sep 30, 2026. Figure 1. CVE-2026-73570 attack chain (fair use).

RESPONSE · NEW YORK

Microsoft Tracks Unauthenticated Zimbra SNMP Command Injection Exploited as CVE-2026-73570

Microsoft Security Research published findings on September 30, 2026, tracking unauthenticated OS command injection in the Zimbra Collaboration Suite SNMP notification path as CVE-2026-73570, with post-exploitation webshells, privilege escalation, credential theft, and mailbox staging observed on internet-facing mail servers.

Noah Park, Response, New York

Read the story
Splunk Enterprise Security product screen with an investigation summary and an isolate-host approve or decline control.
Photo: Splunk. Enterprise Security 8.7 product UI showing the AI SOC Analyst moving from investigation context to a governed response action with Approve or Decline.

OPINION · LONDON

SOC Autonomy Without Governance Recreates the Same Failure Modes AI Was Meant to Fix

Splunk Enterprise Security 8.7 frames the Agentic SOC as a move from AI-assisted investigation to governed autonomous response, where permitted actions, approval gates, evidence, policy, and auditability matter more than buying a stronger model.

Elena Vos, Opinion, London

Read the story
Microsoft Security Blog featured image for Unmasking EvilTokens, an operations room with a video wall.
Photo: Microsoft. Official Security Blog featured image for Unmasking EvilTokens.

DETECTION · LONDON

Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft

Microsoft Threat Intelligence says EvilTokens, sold as phishing-as-a-service and tracked to Storm-2992, abused device code authentication to steal tokens and fuel BEC campaigns that compromised more than 12,000 inboxes worldwide.

Ava Okello, Detection, London

Read the story

RESPONSE · NEW YORK

Check Point VPN Flaw Is a Remote-Access Control-Plane Incident, Not Only a Gateway Patch

NEW YORK - For security operations teams, this is a VPN and remote-access control-plane incident, not only a gateway patch ticket, and it is distinct from the management-plane path traversal CVE-2026-93616 that Check Point disclosed in the same advisory wave. Priority work is inventory of gateways and Spark hosts still on vulnerable trains with certificate-based Site-to-Site or Remote Access VPN; installation of LivePatch Take 26 or the matching Jumbo or Spark build; and log review for anomalous certificate-based Mobile Access logins since September 12, without limiting the hunt to the three published subjects. Check Point also advises looking for second-stage internal port and service scanning from suspicious Mobile Access users. If patching is delayed, the vendor recommends disabling VPN implied rules and restricting Site-to-Site UDP/500 and UDP/4500 to peer IP addresses (and for Remote Access, the required UDP and TCP services), noting that those temporary mitigations do not apply to locally managed Spark firewalls. Confirmed or suspected compromise should trigger forensic triage before operators treat residual risk as closed on patch status alone.

Noah Park, Response, New York

Read the story

RESPONSE · WASHINGTON

CISA Flags TeamCity Flaw CVE-2026-63077 as Used in Ransomware Campaigns

WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.

Noah Park, Response, New York

Read the story

Did You Know

RESPONSE · WASHINGTON

Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail

WASHINGTON - When CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog and flags forensic triage, the agency's Binding Operational Directive 26-04 implementation guidance tells responders to collect evidence before they patch. Patching first can destroy the artifacts that show whether an adversary already used the hole.

September 25, 2026

Noah Park, Response, New York

Read the story

THREAT INTEL · SINGAPORE

Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.

Priya Shah, Threat Intel, Singapore

Read the story
A technician at monitors in a data-center monitoring room. Not a photograph of an Arista or VeloCloud incident.
Photo: Derrick Coetzee

THREAT INTEL · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

Priya Shah, Threat Intel, Singapore

Read the story

TOOLS · REDMOND

Microsoft folds SIEM and threat protection into Defender as ISOC enters preview

REDMOND - Microsoft on September 23, 2026, announced Integrated Security Operations Center, or ISOC, in Microsoft Defender, a preview foundation that puts security information and event management and native threat protection on one shared platform so analysts and agents can investigate and act without stitching separate stacks.

Ava Okello, Detection, London

Read the story

TOOLS · WASHINGTON

CISA Scales Free SIEM-as-a-Service to Shorten Federal Response Windows

WASHINGTON - The Cybersecurity and Infrastructure Security Agency is expanding its security information and event management as a service offering for federal civilian agencies, aiming to give agency and CISA hunters shared SIEM telemetry at no cost to participating departments while cutting the time needed to start an investigation.

September 25, 2026

James Whitford, Tools, Austin

Read the story

TOOLS · MOUNTAIN VIEW

SentinelOne Extends Wayfinder Threat Hunting to AWS, Azure, and Google Cloud

MOUNTAIN VIEW - SentinelOne on September 24, 2026, said it has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud. In a Business Wire announcement that day, the company said the service pairs Singularity Platform telemetry with human-led hunting, and that it uses threat intelligence and intrusion findings from SentinelOne and Google Threat Intelligence in one workflow. SentinelOne said the cloud step follows earlier Wayfinder coverage of endpoints and of identity hunting for Okta and Microsoft Entra ID.

September 25, 2026

James Whitford, Tools, Austin

Read the story

Photo: SentinelOne

OPINION · LONDON

Alert Fatigue Is a Detection Pipeline Failure, Not an Analyst Character Flaw

LONDON - SOCs still treat missed alerts as a people problem. Detection engineering evidence says most alert fatigue is manufactured upstream in the detection pipeline. Future of SecOps (Aug 2026, Marta K.) described a review that blamed an analyst after a shift queue of more than 800 alerts, including EDR and identity duplicates of one medium-severity credential anomaly. Alert fatigue is volume, noise, duplication, and weak prioritization exceeding review capacity. Intezer (THN Sep 12, 2026): ~16.9M SOC alerts Feb-Jun 2026; ~73k AI-related (0.43%), up 685%; of AI-related, 94.1% benign tool use, 5.8% unsafe/policy, 0.02% confirmed attacks; no confirmed org-agent takeovers. ISACA 2025 via FoS: 55% understaffed; 38% need 3-6 months to fill entry-level. Fix: measure FP/duplicate/backlog/TTA by rule; tune defaults; correlate; severity contracts; rule owners; triage feedback. AI triage helps enrichment but cannot retire orphan rules.

Elena Vos, Opinion, London

Read the story

Did You Know

DETECTION · LONDON

Untuned Alerts Can Hide Active Intrusions From the SOC

LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.

Ava Okello, Detection, London

Read the explainer