Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Response

Incident response, containment, and blue-team work after an alert is in hand.

Huntress Expedited High alert showing SYSTEM running C:\\PerfLogs\\Temp\\svchost.exe with config.dll.
Figure: Huntress, Figure 1, EDR signal for post-compromise GOST svchost.exe loading config.dll, Oct 6, 2026 (fair use).

RESPONSE · NEW YORK

Huntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR Install

Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.

Noah Park, Response, New York

Read the story
Huntress Rapid Response branded graphic with an alert triangle on a console screen in a neon-lit server corridor.
Graphic: Huntress, Rapid Response header art for the Oct 8, 2026 AhsayCBS active-exploit post (fair use).

RESPONSE · NEW YORK

Huntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five Organizations

Huntress says attackers began chaining two AhsayCBS flaws on Oct. 7 to gain SYSTEM-level remote code execution, then planted JSP webshells, an XMRig miner disguised as Microsoft Edge, and an AI-assisted PowerShell script that hides mining when Task Manager is open. Four Sigma rules and IOCs are published for defenders.

Noah Park, Response, New York

Read the story
Cover of a TLP:CLEAR cybersecurity advisory numbered JCSA-20261006-01, co-authored by the FBI and the U.S. Secret Service, with both agency seals above the blue title FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts.
Document: FBI and U.S. Secret Service, cover of joint cybersecurity advisory JCSA-20261006-01, FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts, Oct 6, 2026 (fair use).

RESPONSE · NEW YORK

FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls

A joint FBI and Secret Service advisory says the credential theft campaign against internet-facing FortiGate firewalls is still scanning with stolen passwords, sometimes deletes or changes administrators' accounts so owners cannot log in, and has fed access to the INC/Lynx and Payload ransomware operations.

Noah Park, Response, New York

Read the story
StepSecurity graphic titled Tensorlake npm Package Compromised, A Worm With a Hostage Token That Wipes Your Machine If You Revoke It, beside an Attack profile card listing package tensorlake, behavior self-spreading worm, leverage hostage token, if revoked machine wiped, and the command npm i tensorlake marked critical and destructive.
Graphic: StepSecurity, summary of the tensorlake npm compromise, a self-spreading worm that holds a stolen GitHub token hostage and wipes the machine if the token is revoked, Oct 8, 2026 (fair use).

RESPONSE · NEW YORK

Poisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen Token

A malicious tensorlake 0.5.144, pushed to the AI sandbox company's own GitHub repository and published with valid npm provenance on October 8, steals cloud, GitHub and npm secrets, spreads through victims' packages and installs a monitor that deletes the home directory if the stolen GitHub token is revoked, so responders must remove it before rotating credentials.

Noah Park, Response, New York

Read the story
Citrix NetScaler graphic with a SAML service-unavailable card and the words Access Denied.
Image: The Hacker News, NetScaler SAML service-unavailable illustration (fair use).

RESPONSE · NEW YORK

Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 After Attacks Reboot Freshly Patched Appliances

Citrix shipped its second emergency NetScaler update in a week after attackers crashed SAML-enabled gateways that had already been patched for the PitScaler flaws, and incident responders say the forced reboots are being used to fire earlier log-injection payloads on appliances that missed the first fix.

Noah Park, Response, New York

Read the story
Eight-step diagram of a Zimbra SNMP command-injection attack chain from initial access through exfiltration.
Photo/figure: Microsoft Security Research / Microsoft Security Blog, Sep 30, 2026. Figure 1. CVE-2026-73570 attack chain (fair use).

RESPONSE · NEW YORK

Microsoft Tracks Unauthenticated Zimbra SNMP Command Injection Exploited as CVE-2026-73570

Microsoft Security Research published findings on September 30, 2026, tracking unauthenticated OS command injection in the Zimbra Collaboration Suite SNMP notification path as CVE-2026-73570, with post-exploitation webshells, privilege escalation, credential theft, and mailbox staging observed on internet-facing mail servers.

Noah Park, Response, New York

Read the story

RESPONSE · NEW YORK

Check Point VPN Flaw Is a Remote-Access Control-Plane Incident, Not Only a Gateway Patch

NEW YORK - For security operations teams, this is a VPN and remote-access control-plane incident, not only a gateway patch ticket, and it is distinct from the management-plane path traversal CVE-2026-93616 that Check Point disclosed in the same advisory wave. Priority work is inventory of gateways and Spark hosts still on vulnerable trains with certificate-based Site-to-Site or Remote Access VPN; installation of LivePatch Take 26 or the matching Jumbo or Spark build; and log review for anomalous certificate-based Mobile Access logins since September 12, without limiting the hunt to the three published subjects. Check Point also advises looking for second-stage internal port and service scanning from suspicious Mobile Access users. If patching is delayed, the vendor recommends disabling VPN implied rules and restricting Site-to-Site UDP/500 and UDP/4500 to peer IP addresses (and for Remote Access, the required UDP and TCP services), noting that those temporary mitigations do not apply to locally managed Spark firewalls. Confirmed or suspected compromise should trigger forensic triage before operators treat residual risk as closed on patch status alone.

Noah Park, Response, New York

Read the story

RESPONSE · WASHINGTON

CISA Flags TeamCity Flaw CVE-2026-63077 as Used in Ransomware Campaigns

WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.

Noah Park, Response, New York

Read the story

Did You Know

RESPONSE · WASHINGTON

Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail

WASHINGTON - When CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog and flags forensic triage, the agency's Binding Operational Directive 26-04 implementation guidance tells responders to collect evidence before they patch. Patching first can destroy the artifacts that show whether an adversary already used the hole.

September 25, 2026

Noah Park, Response, New York

Read the story