Last Updated On

CCTTII--22002266--00990044
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

SonicWall Root Access Chrome V8 and 153 Million Stolen Licenses

VPN concentrators, artifact registries, and office browsers all failed in public this window. SonicWall SMA 1000 CVE-2026-83548 and CVE-2026-83549 chain to root with no workaround, JFrog CVE-2026-82329 mints administrator tokens from one unauthenticated POST, Google says Chrome V8 CVE-2026-85046 is already exploited, and Switchvox CVE-2026-9586 still turns /pa into a shell.

The same cycle added Kestra, LiteLLM, Starlette, and Elementor to the emergency patch list while BREEZE COMET pushed fraudulent Pix, STR, and Boleto traffic and a Teams fake helpdesk walk dropped Node.js implants plus WinRM into domain controllers.

More than 153 million licenses tied to IDScan.net workflows hit a dark web shop now under FBI review, and Mirage Kitten began handing aviation and fintech developers NodeRabbit through fake coding challenges. Patch, relaunch Chrome, revoke tokens, and treat identity vendors as an incident, not a footnote.

10

CVSS Score

200

IOC Count

30

Source Count

86

Confidence Score

CVEs

CVE-2026-83548, CVE-2026-83549, CVE-2026-82329, CVE-2026-85046, CVE-2026-9586, CVE-2026-49869, CVE-2026-59822, CVE-2026-42271, CVE-2026-48710, CVE-2026-32475, CVE-2026-58613, CVE-2026-33824

Actors

BREEZE COMET, Mirage Kitten, Teams Impersonation Operators, Qilin, Nexus Service Operators, UAT-10147, Unattributed Opportunistic Exploit Operators

Sectors

Technology and Software Supply Chain, Financial Services and Banking, Government and Public Sector, Telecommunications and VoIP, Critical Manufacturing and OT, Aviation and Aerospace, Retail and Ecommerce, Healthcare, Fintech, Managed Service Providers

Regions

North America, Europe, Asia Pacific, Brazil and Latin America, Middle East and Africa, Global internet facing assets

Chapter 01 - Executive Overview

Edge gateways, developer platforms, browser fleets, voice appliances, payment switches, and identity proofing vendors were hit in the same reporting window. The combined picture is not one actor. It is several live exploit chains plus two financially motivated campaigns, one espionage recruiting set, and a mass identity warehouse now under federal inquiry.

[+] SonicWall SMA 1000 zero day chain: CISA and international authorities confirm in the wild use of CVE-2026-83548 (pre auth SSRF, CVSS 10.0) chained with CVE-2026-83549 (AMC command injection, CVSS 7.8). An unauthenticated caller hits an alternate Workplace path, forces an internal request to the local management console, and runs commands as root on appliances that terminate corporate VPN sessions. Hotfixes 12.4.3-03526 and 12.5.0-02952 are mandatory. Consulted sources record no viable configuration workaround. FCEB remediation under BOD 26-04 is due 2026-09-05.

[+] JFrog Artifactory identity bypass: CVE-2026-82329 (CVSS 9.8) lets unauthenticated callers talk to /access/api/v1/registry/join/router and mint platform administrator JWTs. Self hosted artifact repositories then surrender private builds, upstream dependencies, and persistence inside the software supply chain. Mass scanning accelerated on 2026-09-03. Upgrade the listed 7.x branches and revoke tokens minted since 2026-08-28.

[+] Chrome V8 in the wild exploit: Google released Stable 152.0.7977.82 and 152.0.7977.83 to fix 12 issues including high severity type confusion CVE-2026-85046. Google states an exploit exists in the wild and withholds chain, delivery, actor, and post exploitation detail. Treat this as an emergency fleet patch with mandatory relaunch. Do not invent renderer escape, ransomware, or nation state claims the vendor did not make.

[+] Switchvox SQL to shell carry over: CVE-2026-9586 (CVSS 9.3) is unauthenticated SQL injection on /pa that becomes OS command execution as PostgreSQL. Honeypots saw COPY TO PROGRAM and netcat to shell. Current reporting still calls exploitation live and KEV listed. Patch to 8.4.0.2 or later or isolate the PBX. About 4000 internet exposed /pa endpoints were visible in exposure scans.

[+] Additional KEV class product flaws: Kestra CVE-2026-49869 (CVSS 10.0) with Docker socket abuse, LiteLLM CVE-2026-59822 and CVE-2026-42271 with key harvest and a Qilin association in one dataset, Starlette CVE-2026-48710 smuggling used in those chains, and Elementor Pro CVE-2026-32475 webshells. Windows IKEE CVE-2026-33824 remains an overdue KEV control from 2026-04. NCSC separately warned that internet exposed OT and edge devices are under increased targeting with limited real world disruption so far.

[+] BREEZE COMET payment fraud: operators tracked as UNC5669 evolved from vishing and retail fraud into manipulation of Pix, STR, and Boleto rails using Rust, Nim, Go, Java, and Node families plus AI generated operational scripts. Compromised .gov[.]br and other municipal domains stage tools. Consulted sources describe at least one heist moving tens of thousands of USD inside 24 to 48 hours.

[+] Teams helpdesk impersonation: an external tenant poses as IT support, steers the victim into Quick Assist or Teams control, then runs PowerShell, a silent MSI, portable Node.js from LocalAppData, screen capture, ADSI discovery, and WinRM to domain controllers and certificate authorities. Azure Blob hosts stage the MSI. Recovered implants included a dormant Ethereum contract C2 fallback.

[+] IDScan.net and Nexus identity warehouse: more than 153 million US and Canadian driver licenses, plus millions of ID cards, travel documents, medical cards, and CAC records, were advertised through the Nexus service and tied to IDScan.net scanning workflows used by Hertz, Target, FedEx, Jack Henry, Caesars, and dispensary check in. FBI New Orleans opened an inquiry on 2026-09-02. The shop went offline after disclosure.

[+] Mirage Kitten developer lures: the set also tracked as UNC1549 now delivers cross platform NodeRabbit and PollCat through fake LinkedIn coding challenges hosted on S3, with short deadlines and an AI tool ban. Persistence includes fake VS Code extensions and Git hooks marked #shepherd-persist. Targeting concentrates on aviation and fintech developers in Egypt, Ethiopia, and Afghanistan, with detections in Germany, Türkiye, Israel, India, and Ireland.

[+] Executive decision now: patch SMA 1000 and the 2026-09-05 KEV set today, force Chrome relaunch to 152.0.7977.82 or later, isolate unpatched Switchvox and JFrog management planes, restrict Teams external access, rotate AI gateway and artifact tokens, inventory internet exposed OT, and treat IDScan.net customer relationships as a legal and communications event rather than only a vulnerability ticket.

Chapter 02 - Threat & Exposure Analysis

Adversaries spent this window attacking the devices and services that sit in front of everything else: VPN concentrators, artifact registries, browsers, PBX ports, AI gateways, and the human helpdesk channel. Parallel to that product exploitation, financially motivated operators manipulated payment rails, an identity warehouse reached the dark web, and an espionage set refreshed its developer lure kit.

[+] SonicWall confused deputy to root: CVE-2026-83548 is unauthenticated SSRF in the Workplace portal. A request to an unintended alternate access path skips session checks and makes the appliance send an authenticated call to its own AMC listener. CVE-2026-83549 then injects shell metacharacters into AMC parameters and reaches root through a system() wrapper. Perimeter ACLs never see the second hop because it is born on 127[.]0[.]0[.]1:8443.

[+] JFrog Access token minting: CVE-2026-82329 lives in the node join key exchange. A crafted JSON POST to /access/api/v1/registry/join/router with an empty or default kid tricks Access into signing a JWT with platform administrator rights. One HTTP 201 is enough to pull private builds, rewrite dependencies, and leave a durable API identity.

[+] Chrome V8 type confusion: CVE-2026-85046 is a High severity bug in the JavaScript and WebAssembly engine. Google confirms an exploit exists in the wild and is withholding mechanics while 152.0.7977.82 and 152.0.7977.83 roll out. Absence of a public chain is not absence of risk. It only means detection beyond patch compliance and generic browser telemetry is speculation.

[+] Switchvox SQL to OS: CVE-2026-9586 parses PhoneIP from a PolycomIPPhone XML body on /pa and concatenates it into an unparameterized PostgreSQL statement. COPY TO PROGRAM becomes process execution as the database service account. Honeypots logged nc to sh, curl, bash, and follow on process listing. This is confirmed exploit behavior, not a named actor playbook.

[+] AI and CMS follow through: Kestra CVE-2026-49869 accepts command injection that consulted telemetry ties to reverse shells, miners, and Docker socket abuse. LiteLLM CVE-2026-59822 and CVE-2026-42271 skip auth on management and Model Context Protocol paths, then leak API keys and open SSH persistence. Starlette CVE-2026-48710 smuggles requests into that stack. Elementor Pro CVE-2026-32475 is being used to drop webshells on WordPress estates. One vendor dataset associates some LiteLLM abuse with Qilin staging.

[+] BREEZE COMET payment switch work: the set moved from password spraying and vishing in 2024, through compromised municipal sites and XWORM, into custom REALBREEZE LDAP brute tools, COBALTSPIN Rust SOCKS5 and WebSocket tunnels, LIGHTPAINT SoftEther, MILDFROST Java DNS tunnels, KICKPLATE Nim loaders, and BOATBEAM Go fake IIS listeners. AI generated recon and credential scripts show unrolled code and verbose comments. Objectives are mTLS certificates, CI secrets, and fraudulent Pix, STR, and Boleto traffic.

[+] Teams impersonation: operators join from an external tenant as IT support, talk the user into Quick Assist or remote control, then run PowerShell, a silent MSI from Azure Blob, portable Node.js under LocalAppData with non standard extensions, encrypted JavaScript tasking, Base64 screen capture, ADSI enumeration, rundll32 with tokens, and WinRM to directory and certificate servers. A dormant Ethereum contract string was reserved as C2 fallback.

[+] Identity resale: Nexus advertised more than 153 million licenses and companion document types whose IR and UV characteristics and timestamps matched IDScan.net customer workflows, including Hertz rentals and dispensary check ins. Collection ran for more than a year at hundreds of thousands of new records per day before the shop vanished after public reporting.

[+] Mirage Kitten lure refresh: fake LinkedIn recruiters send an S3 coding challenge with a one to three hour deadline and a ban on AI assistants. NodeRabbit installs as a Node.js RAT with a fake VS Code extension and Git hook persistence. PollCat is OTP gated and sweeps the host after the victim "submits" work. Azure and Cloudflare front the C2 to look like ordinary developer traffic.

[+] OT and overdue Windows: NCSC describes increased targeting of internet exposed industrial systems with limited disruption so far, which is a warning about exposure rather than a claim of widespread outages. CVE-2026-33824 on Windows IKEE remains a listed KEV from 2026-04. CVE-2026-58613 is patched and not confirmed exploited in this window.

Chapter 03 - Operational Response

Work the live exploit surfaces first, then the human channels, then the breach communications problem. There is no configuration workaround for the SMA 1000 chain.

[+] SonicWall SMA 1000: upgrade models 6210, 7210, and 8200v to 12.4.3-03526, 12.5.0-02952, or later now. If the hotfix cannot land inside the current cycle, remove the appliance from public routing and place the Workplace portal behind a deny first control. Inspect the file system for unexpected shells, cron entries, and modified configuration.

[+] JFrog Artifactory: upgrade self hosted instances to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20, or later. Disable anonymous join. Restrict Access APIs to administrative bastion ranges. Query token logs for administrator keys created since 2026-08-28 and revoke anything that is not a scheduled node enrollment.

[+] Chrome fleet: force Stable 152.0.7977.82 or 152.0.7977.83 on Windows and macOS and 152.0.7977.82 on Linux. A downloaded update is not a fix until the browser relaunches. Inventory unmanaged, BYOD, VDI, kiosk, and admin workstations that have not checked in. Hunt crashes, odd child processes, and browser originated egress as generic triage only.

[+] Switchvox: find every instance and whether /pa is reachable from untrusted networks. Restrict at the firewall or reverse proxy. Upgrade to 8.4.0.2 or later. Preserve /var/log/switchvox/db-quirks.log, web and proxy logs, PostgreSQL logs, process accounting, and egress before rebuild. Hunt COPY TO PROGRAM, nc, curl, bash, /tmp/, and base64 decode strings. Treat 176[.]65[.]148[.]184:39323 as a pivot, not a verdict.

[+] AI and workflow gateways: patch Kestra, LiteLLM, and Starlette on the KEV clock. Rotate every API key and model provider secret. Audit Model Context Protocol endpoints. Remove Docker socket mounts from workflow engines. Isolate these services from the public internet.

[+] Elementor Pro and WordPress: update immediately and hunt webshells in upload and cache paths.

[+] Teams channel: allow external tenants only from an approved domain list. Enable ASR rules that block executable mail content, script interpreters, and MSI files from user writable paths. Block update1n*.blob[.]core[.]windows[.]net plus synctimes[.]australiaeast[.]cloudapp[.]azure[.]com, webwether[.]eastus[.]cloudapp[.]azure[.]com, and dssdfvsdfvsdfvsdgbfbdvdzv[.]org. Restrict WinRM 5985 to management jump hosts and alert on user context WinRM.

[+] BREEZE COMET: deploy the published family YARA, monitor WebSocket and SOCKS5 toward payment API ranges, lock down 802.1X at retail and branch ports, decrypt egress where lawful, and search for mTLS material tied to boleto, cnab, remessa, and Pix webhooks. Rotate any identity that touched those hosts.

[+] Mirage Kitten: hunt #shepherd-persist in developer Git hooks, require VS Code Workspace Trust, and treat unexpected S3 coding challenge zips that bundle node_modules as hostile.

[+] Identity warehouse: treat IDScan.net and similar proofing vendors as a supplier incident. Start legal, privacy, and customer notification review against GDPR, CCPA, and LGPD clocks that began 2026-09-02. Do not wait for a CVE.

[+] OT: build a definitive inventory of internet reachable PLCs, HMIs, and engineering hosts. Remove default credentials, stop remote programming from untrusted networks, and follow the NCSC hardening list.

[+] 2024 through 2025: BREEZE COMET progresses from spraying and vishing to municipal domain staging, rogue retail hardware, and custom multi language backdoors.

[+] 2025-06 onward: identity warehouse timestamps indicate continuous collection that later appears in Nexus listings.

[+] 2026-04: Windows IKEE CVE-2026-33824 is patched and listed for accelerated KEV remediation. Many estates still show it as overdue.

[+] 2026-06-01: Talos reports CVE-2026-58613 to Microsoft. Late 2026-06 Microsoft and Wiz telemetry begin to see LiteLLM and Kestra abuse.

[+] 2026-07-14: Microsoft ships the Cloud Files Mini Filter fix. Mirage Kitten NightLedger activity is visible in the same month.

[+] 2026-08-04: Chrome CVE-2026-85046 is reported to Google by Salvatore Gulizia (Serotav).

[+] 2026-08-26 to 2026-08-28: SonicWall discloses the SMA 1000 pair. JFrog privately discloses CVE-2026-82329 and ships patched 7.x branches. NCSC publishes the OT exposure advisory on 2026-08-27.

[+] 2026-08-30: Switchvox honeypots record a valid CVE-2026-9586 exploitation attempt.

[+] 2026-08-31: Nexus advertises the license corpus on a criminal forum.

[+] 2026-09-01: SonicWall confirms in the wild SMA 1000 attacks in SNWLID-2026-0016. Horizon3 publishes Switchvox internals. Google GTIG and Mandiant publish BREEZE COMET. Kaspersky publishes NodeRabbit and PollCat. Public reporting on Nexus and IDScan.net begins.

[+] 2026-09-02: CISA adds the seven product CVEs to KEV with 2026-09-05 and 2026-09-16 clocks. Microsoft publishes the Teams impersonation chain. FBI New Orleans opens the identity inquiry. Nexus goes offline.

[+] 2026-09-03: Google ships Chrome Stable containing the V8 fix. Fastly and honeypots record a surge on JFrog join endpoints. Talos publishes Cloud Files detail. Operational newsrooms restate KEV and Switchvox exploitation.

[+] 2026-09-04: CSA Singapore releases AL-2026-114 on SMA 1000 exploitation. Public exploit reproductions for the edge chain circulate.

Chapter 04 - Detection Intelligence

[+] SMA 1000 request path bug: the Workplace proxy fails to enforce session state on an alternate handler. An external unauthenticated POST under /workplace/ or /dana-na/ can include amc, localhost, or 127[.]0[.]0[.]1 in the query. The proxy then issues an internal POST to hxxp://127[.]0[.]0[.]1:8443/amc/api/v1/system/exec. User controlled bytes land inside a shell wrapper without sanitization, so metacharacters such as ; | ` and $( become root commands.

[+] JFrog Access join bug: the join protocol accepts a JSON body and a kid header. When kid is empty or set to e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 the service falls back to a static verifier and signs an administrator JWT. HTTP 201 from an untrusted source is the minting artifact.

[+] Chrome V8: type confusion inside the engine. No public PoC, HTML lure, hash, or renderer escape evidence is in consulted sources. The only confirmed control is a patched and relaunched binary. Version compares must use normalized semantic versions, not raw string sorts.

[+] Switchvox /pa bug: PhoneIP from PolycomIPPhone XML is concatenated into SQL. COPY TO PROGRAM hands the database engine a shell. Parent processes to watch are postgres, postmaster, httpd, apache2, and perl. Children to watch are sh, bash, nc, ncat, curl, wget, and base64. Evidence often survives in /var/log/switchvox/db-quirks.log.

[+] Kestra and LiteLLM: command injection and auth bypass on workflow and LLM gateway endpoints, including Model Context Protocol listeners. Post exploitation in consulted telemetry includes XMRig, SSH key inserts, PostgreSQL recon, and Docker socket calls that turn the engine into a host admin.

[+] Teams implant internals: PowerShell Invoke-WebRequest retrieves an MSI from update1n*.blob[.]core[.]windows[.]net. msiexec /qn unpacks a portable Node.js under LocalAppData using extensions such as .tmp, .ini, .dat, .bin, or .cfg. wscript launches node.exe. The implant long polls HTTPS, sleeps with jitter, captures the screen through CopyFromScreen and ToBase64String, enumerates AD with ADSI, and reaches TCP 5985. Persistence uses HKCU Run EdgeUpdate and Startup shortcuts.

[+] BREEZE COMET internals: REALBREEZE brute forces LDAP with Portuguese UI strings. COBALTSPIN speaks SOCKS5 then upgrades to WebSocket. MILDFROST uses Java DNS tunnel verbs such as shell:, exec:, upload, and dl|. BOATBEAM pretends to be IIS on 443. LIGHTPAINT plants SoftEther and firewall rules. KICKPLATE masquerades as WinUpdate and schedules itself.

[+] Mirage Kitten internals: the challenge zip runs npm install or node challenge.js. NodeRabbit drops a fake VS Code extension and writes #shepherd-persist into post-merge and post-checkout hooks so later git operations relaunch the RAT. PollCat stays quiet until an OTP arrives from the fake recruiter.

Defanged values below are hunt material. Chrome still has no vendor IOC. The Switchvox address is a pivot.

# Network scan and callback nodes
194[.]38[.]20[.]14
185[.]196[.]220[.]89
91[.]240[.]118[.]172
45[.]154[.]255[.]67
176[.]65[.]148[.]184:39323

# JFrog Access and SonicWall Workplace paths
/access/api/v1/registry/join
/access/api/v1/registry/join/router
/access/api/v1/registry/join/router?override=true
/dana-na/auth/url_default/welcome.cgi?redir=/amc/
/workplace/portal/alternate_handler.do
hxxp://127[.]0[.]0[.]1:8443/amc/api/v1/system/exec

# Switchvox markers
/pa
/var/log/switchvox/db-quirks.log
PolycomIPPhone
PhoneIP
COPY TO PROGRAM

# JWT kid
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

# SMA dropped artifacts
/tmp/.amc_session.sh
/var/tmp/sonic_daemon_rev.elf

# Teams MSI SHA-256
4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d
a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676
cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5

# Teams DLL SHA-256
0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3
69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23
a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87

# Teams staging and C2 (defanged)
hxxps://update1n5[.]blob[.]core[.]windows[.]net
hxxps://update1n6[.]blob[.]core[.]windows[.]net
hxxps://update1n7[.]blob[.]core[.]windows[.]net
hxxps://update1n9[.]blob[.]core[.]windows[.]net
hxxps://updatetmp[.]blob[.]core[.]windows[.]net
synctimes[.]australiaeast[.]cloudapp[.]azure[.]com
webwether[.]eastus[.]cloudapp[.]azure[.]com
dssdfvsdfvsdfvsdgbfbdvdzv[.]

[+] Handling: correlate JFrog 201s with unknown source IPs, SMA Workplace posts with immediate root child shells, Switchvox /pa posts with COPY TO PROGRAM and egress to 176[.]65[.]148[.]184, Teams external chats with MSI writes and node.exe from LocalAppData, and developer hosts with the Git hook marker. Do not declare compromise from a single defanged address.

Deploy the product rules first, then the campaign chains. Rules below are experimental and need field normalization on the target SIEM. They detect published behaviors. They do not by themselves prove a named actor.

[+] SIGMA SonicWall SMA 1000 pre auth SSRF to AMC injection:


[+] SIGMA JFrog Access rogue join token:


[+] SIGMA Switchvox SQL to command artifacts:


[+] SIGMA Teams external contact to MSI to Node to WinRM (pseudocode):

title: Suspicious Teams External Contact Followed by MSI Execution
id: inferlume-teams-imper-msi-chain
status: experimental
logsource:
  product: windows
  service: sysmon
detection:
  selection_teams:
    EventID: 1
    Image: '*\\Teams.exe'
    CommandLine|contains: 'external'
  selection_msi_download:
    EventID: 1
    Image: '*\\powershell.exe'
    CommandLine|contains:
      - 'Invoke-WebRequest'
      - 'DownloadFile'
    TargetFilename|endswith: '.msi'
    TargetFilename|contains:
      - '\\Downloads\\'
      - '\\AppData\\'
      - '\\Temp\\'
  selection_silent_msiexec:
    EventID: 1
    Image: '*\\msiexec.exe'
    CommandLine|contains: '/qn'
  selection_nodejs_localappdata:
    EventID: 1
    Image: '*\\node.exe'
    CommandLine|contains: '\\AppData\\Local\\'
    CommandLine|not|contains: '.js'
  selection_wscript_nodejs:
    EventID: 1
    Image: '*\\wscript.exe'
    CommandLine|contains|all:
      - '\\AppData\\Local\\'
      - 'node.exe'
      - '.js'
  selection_screen_capture:
    EventID: 1
    Image|in: ['*\\powershell.exe', '*\\cmd.exe']
    CommandLine|contains|all:
      - 'CopyFromScreen'
      - 'ToBase64String'
      - 'System.Drawing.Bitmap'
      - 'WriteAllText'
  selection_winrm_lateral:
    EventID: 3
    DestinationPort: 5985
    Image: '*\\

[+] YARA SMA dropper and mixed artifacts:


[+] YARA Switchvox log triage only, not a general malware signature:

rule Inferlume_Switchvox_CVE_2026_9586_Exploit_Artifacts
{
    meta:
        description = "Triage match for published Switchvox SQL to shell artifacts"
        author = "Inferlume CTI"
        date = "2026-09-04"
    strings:
        $sql_copy_program = "COPY (SELECT" ascii nocase
        $to_program       = "TO PROGRAM" ascii nocase
        $polycom          = "<PolycomIPPhone>

[+] YARA BREEZE COMET families from consulted research (representative):

rule M_Utility_REALBREEZE_2 {
    meta:
        author = "Consulted GTIG research"
        description = "BREEZE COMET LDAP brute force utility"
    strings:
        $s1 = "IP/REDE" wide
        $s2 = "SENHA" wide
        $s3 = "U\\x00S\\x00U\\x00\\xc1\\x00R\\x00I\\x00O\\x00:" wide
        $s4 = "Arquivo de Texto (*.txt)|*

[+] SIEM correlation SMA web request then root child shell:


[+] SIEM Switchvox request to process to egress:

FROM web_proxy OR firewall OR Switchvox_http_logs
WHERE destination_asset.role = "Switchvox"
  AND http.request_path = "/pa"
  AND http.method IN ("POST", "PUT")
  AND (
       http.request_body CONTAINS "<PolycomIPPhone>"
       OR http.request_body CONTAINS "PhoneIP"
       OR http.request_body MATCHES "(?i)(copy\\s*\\(|to\\

[+] Chrome fleet gap query. Compare normalized versions, not raw strings:


[+] Extra hunts: node.exe from LocalAppData with a non .js argument, Git hooks containing #shepherd-persist, JFrog administrator tokens created after 2026-08-28, LiteLLM or Kestra hosts spawning XMRig, and WinRM 5985 from a non admin PowerShell process.

[+] Initial Access T1190 D3-INP Inbound Traffic Filtering: unauthenticated HTTP to Workplace, Access join, /pa, Kestra, LiteLLM, Starlette, Elementor, and IKEE. Behavioral evidence is external POST traffic to those routes.

[+] Initial Access T1566.003 and T1566.002: Teams external IT impersonation and LinkedIn coding challenge links.

[+] Execution T1059.004 D3-PSA Process Spawn Analysis: AMC subshells, Switchvox COPY TO PROGRAM, Kestra injection.

[+] Execution T1059.001 T1059.007 T1218.007 T1218.011: PowerShell, Node.js, silent msiexec, rundll32 token loads.

[+] Credential Access T1556 D3-URA User Rights Revocation: JFrog Access signing a rogue administrator JWT. LiteLLM key harvest is the cloud analog.

[+] Defense Evasion T1090.002 D3-EAM Encrypted Traffic Analysis: Workplace proxy relaying loopback requests to AMC on port 8443.

[+] Persistence T1505.003 D3-FSA File Integrity Monitoring: shells in /tmp/ and /var/tmp/, Elementor webshells, Git hooks marked #shepherd-persist, HKCU Run EdgeUpdate.

[+] Lateral Movement T1021.006: WinRM TCP 5985 from user context PowerShell toward domain controllers and certificate authorities.

[+] Command and Control T1071.001 T1572: HTTPS long poll, COBALTSPIN SOCKS5 and WebSocket, MILDFROST DNS tunnel verbs, Azure Blob staging.

[+] Collection T1113 T1005: Base64 screen capture and theft of mTLS or CI secrets.

[+] Impact: fraudulent payment API use and identity resale sit outside a single technique ID and should be hunted as business logic abuse plus data leakage.

[+] Chrome mapping status: no source mapped ATT&CK ID. Inferred client execution only. Do not publish a fake drive by chain.

Chapter 05 - Governance, Risk & Compliance

[+] CISA BOD 26-04: FCEB agencies must remediate CVE-2026-83548, CVE-2026-83549, CVE-2026-9586, CVE-2026-82329, and CVE-2026-49869 by 2026-09-05, and the remaining LiteLLM and Starlette pair by 2026-09-16. CVE-2026-33824 is already overdue from the 2026-04 cycle.

[+] NIST SP 800-53: unmitigated internet facing SMA, Switchvox, and Artifactory exposure fails AC-3 Access Enforcement and SI-2 Flaw Remediation.

[+] ISO/IEC 27001:2022: A.8.8 technical vulnerability management is incomplete while KEV clocks are open. A.5.15 supplier security fails on the IDScan.net warehouse because a proofing vendor held raw license images.

[+] EU NIS2 and NCSC CAF: supply chain and OT boundary duties apply. NCSC wants a definitive OT asset inventory, no internet exposed PLCs or HMIs, MFA instead of default credentials, hardened gateways, secure protocol migration, logging, no untrusted remote programming, segmentation, and tested backups.

[+] PCI DSS 4.0 Req 6.5.6: injection and auth bypass on Switchvox and JFrog are direct control failures for any cardholder adjacent estate.

[+] Privacy statutes: GDPR, CCPA, and LGPD notification clocks for the identity warehouse started 2026-09-02. Public companies that used IDScan.net may have SEC 8-K materiality questions. CAC records pull in transport security review. Brazilian BACEN incident reporting applies where Pix, STR, or Boleto rails were touched.

[+] Executive threshold: an unpatched internet facing SMA 1000 is a routing removal event, not a weekly change ticket. Chrome compliance must be reported as installed, relaunched, unmanaged, and unseen for seven days. Each PBX and AI gateway needs a named owner, exposure state, and tested recovery path.

[+] Residual risk acceptance: unsupported OS and browser pairs, and OT devices that cannot patch, require a written owner signature rather than silence.

Chapter 06 - Adversary Emulation

Run these only on authorized lab assets. Do not replay live exploits against production VPN, PBX, payment, or identity systems. Do not attempt to reconstruct the unpublished Chrome exploit.

[+] JFrog non destructive join probe:

#!/usr/bin/env bash
# Title: Detection validation probe for CVE-2026-82329 join behavior
# Authorized assessment only. No token abuse beyond a lab target.

TARGET_HOST="https://artifactory.internal.lab:8082"
PROBE_ENDPOINT="/access/api/v1/registry/join/router"

echo "[*] Initiating Non Destructive Probe for Detection Engineering..."

HTTP_RESPONSE=$(curl -k -s -o /dev/null -w "%{http_code}" -X POST "${TARGET_HOST}${PROBE_ENDPOINT}" \
  -H "Content-Type: application/json" \
  -H "User-Agent: Inferlume-Detection-Test/1.0" \
  -d '{"test_mode": true, "kid": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"}')

echo "[*] Server Response Code: ${HTTP_RESPONSE}"

if [ "${HTTP_RESPONSE}" -eq 201 ]; then
    echo "[!] ALERT: Vulnerable Endpoint Detected (HTTP 201 Created). Patch Required!"
elif [ "${HTTP_RESPONSE}" -eq 401 ] || [ "${HTTP_RESPONSE}" -eq 403 ]; then
    echo "[+] SUCCESS: Access Denied. Endpoint is either patched or access controlled."
elif [ "${HTTP_RESPONSE}" -eq 404 ]; then
    echo "[+] INFO: Endpoint not found or path restricted."
else
    echo "[?]

[+] Chrome safe validation: measure time to list endpoints below 152.0.7977.82, deploy a known safe telemetry test that launches a controlled child after a simulated browser event, and confirm EDR records process lineage, download provenance, crash telemetry, and outbound metadata. No malicious HTML and no PoC.

[+] Switchvox purple team on an isolated non production instance: send a benign /pa XML body with a unique inert PhoneIP marker, confirm proxy logs capture it, write the literal text COPY TO PROGRAM into a test log rather than executing it, generate a representative parent child process event, and open an approved callback to a lab listener rather than 176[.]65[.]148[.]184. The rule must fire only when request, host, and egress line up.

[+] SMA detection test: replay only the path and query shape against a lab appliance or a fixture log. Do not deliver a live system() payload on a production concentrator.

[+] Teams chain rehearsal: start from a lab external tenant, drop a benign MSI to a user writable path, launch a lab node.exe from LocalAppData, emit a fake CopyFromScreen command line, and open WinRM to a lab endpoint. Validate CloudAppEvents, DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents correlation.

[+] BREEZE COMET rehearsal: password spray against a lab AD, stage a lab SOCKS5 or WebSocket tunnel toward a fake payment API range, and test WDAC or fapolicyd blocks on user writable execution. Search lab stores for inert strings such as boleto and Pix webhook names. Do not touch live payment switches.

[+] Mirage Kitten rehearsal: place a harmless #shepherd-persist marker in a lab repository hook, disable Workspace Trust on a lab VS Code profile, and confirm outbound to a lab Azure styled hostname alerts. Do not phish real developers.

Intelligence Confidence86%

Factor

Judgment

Effect on 86 / 100

National and vendor confirmation

CISA KEV, SonicWall PSIRT, CSA Singapore, Google Chrome Releases, Microsoft Defender XDR, JFrog advisories

Strong upward. Core product exploitation is verified.

Multi source edge telemetry

Fastly, honeypots, Rapid7, Qualys, Horizon3, Defused Cyber

Strong upward for SMA, JFrog, and Switchvox scanning and exploit attempts.

Chrome exploit detail

In the wild confirmed. Chain, IOC, actor, and victims withheld

Neutral to slight downward. Urgency is high. Forensic specificity is low.

Switchvox KEV wording

Operational coverage states KEV listing. One research pass did not retrieve the individual catalog row

Slight downward. Exploitation itself is still well evidenced.

BREEZE COMET and Teams

Multi year GTIG or Mandiant tracking and full Microsoft chain reconstruction

Strong upward for those campaigns.

Mirage Kitten sponsor label

Detailed malware and lure research with thinner independent echo in this window

Downward for the Iran nexus claim, not for the Node.js lure behavior.

Qilin and UAT-10147

Single stream linkages

Downward. Kept as watch items.

Identity warehouse

FBI inquiry, vendor investigation, record volume, shop takedown after disclosure

Strong upward for the breach event. Operator name stays unassigned.

Attribution overall

Opportunistic KEV use remains under attribution by design

Prevents any score near 95.