Last Updated On

The Box That Admits Devices Now Hands Out Root
Tomorrow morning federal operators have to prove they did more than patch Cisco ISE. CVE-2026-76460 is a CVSS 10.0 unauthenticated API bypass with root on the box that decides who joins the network, and the KEV clock ends 2026-09-19. Sitting beside it are a crafted mail root RCE on Secure Email Gateway, three intrusion sets on FMC including a Qilin affiliate and Cyclops Blink, two Windows AppContainer to SYSTEM zero days, a zero click Pixel modem bug, and an Acronis hosting plugin that turns a tenant into the host.
Settra is the noise that still encrypts. Ninety three claimed victims, MeshAgent at 45.13.122[.]7 and 193.5.65[.]114, gdrv.sys to kill EDR, then reagentc, diskpart, and cipher before .locked_wip and a Tox chat. Hunt the remote tool and the driver, not the ransom note.
The rest of the window is the same class of failure on different products. GitLab commits API file read hit KEV inside a day. MikroTik SSH and Orkes INLINE workflows stay exploitable after a lazy upgrade if persistence is left behind. Check Point is critical but not observed in the wild. Gyazo spilled tens of millions of records. PhantomRaven is stealing developer secrets from npm. ShinyHunters posted Kimberly-Clark without proof. Patch the KEV set tonight. Reimage anything that already answered an unauthenticated admin call.
10
CVSS Score
14
IOC Count
32
Source Count
84
Confidence Score
CVE-2026-76460, CVE-2026-76461, CVE-2026-87886, CVE-2026-58704, CVE-2026-81963, CVE-2026-85880, CVE-2026-41870, CVE-2026-41871, CVE-2026-41869, CVE-2026-91843, CVE-2026-67276, CVE-2026-86060, CVE-2026-67279, CVE-2026-58138, CVE-2026-84869, CVE-2026-20079, CVE-2026-20316, CVE-2026-85706, CVE-2026-20329, CVE-2026-20330, CVE-2026-20331, CVE-2026-20332, CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336, CVE-2026-20324, CVE-2026-20341, CVE-2026-76420, CVE-2026-20323
Settra, Sandworm, Qilin, UAT-11823, UAT-11988, UAT-12197, Storm-2945, Midnight Blizzard, JPD, ShinyHunters
Government, Critical Infrastructure, Technology, Telecom, Manufacturing, Professional Services, Retail, Hospitality, Financial Services, Healthcare, Education, MSP, Software Development, Web Hosting, Consumer Goods
Global, United States, Europe, APAC, India, Latin America, Japan, Poland
Chapter 01 - Executive Overview
The window is a management plane problem first and a ransomware problem second. The product that decides who joins the network, the product that reads every inbound message, and the product that orchestrates firewall policy all sat on unauthenticated or weakly authenticated paths at the same time.
[+] Cisco ISE and ISE-PIC CVE-2026-76460, Critical, Government Enterprise MSP: Unauthenticated API authentication bypass, CVSS 10.0, CWE-648. Cisco confirmed exploitation after a TAC case. CISA KEV on 2026-09-16 with forensic triage required and a 2026-09-19 federal date. Success can yield web management access and root command execution. Attackers can wipe on box logs. No workaround. First fixed trains are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. ISE 3.0 is end of maintenance and must be migrated. MSP and managed NAC operators create third party risk. Demand per node patch attestation, log hunting, and egress review.
[+] Cisco Secure Email Gateway CVE-2026-76461, Critical, Enterprise Government Email Security: Pre authentication SQL injection in AsyncOS parsing. A crafted message yields SQL and then root on the appliance. CVSS 9.8. KEV on 2026-09-14. Exploited before disclosure. Cisco contacted cloud customers after detected activity. Affected AsyncOS 15.5 before 15.5.5-014, 16.0 before 16.0.4-302, 16.5 before 16.5.0-780. No workaround.
[+] Cisco FMC CVE-2026-20079 and CVE-2026-20316, Critical, Network Security Operators: Authentication bypass plus a hard coded low privilege static credential. Talos tracks three intrusion sets on the same access: UAT-12197 (JSP web shell, cmd.jar, credential harvest), UAT-11823 (Sandworm tooling overlap, upgraded 64 bit Cyclops Blink), UAT-11988 (Qilin affiliate, disable AV, ransomware). The 2026-09-16 hardening cycle added a large sibling CVE set on the same family. Treat unpatched on premises FMC as a live incident until proven otherwise.
[+] Microsoft September 2026 Patch Tuesday, High, All Windows Estates: Record 966 flaws in the primary consult, 113 Critical. Two exploited zero days. CVE-2026-81963 Windows Update Stack link following elevation of privilege, CVSS 7.8, first in the wild for that component. CVE-2026-85880 ALPC heap buffer overflow, CVSS 7.8, second ALPC zero day since CVE-2023-21674. Both move a low privilege AppContainer process to SYSTEM. Same day KEV. Prioritize tier 0, PAW, VDI, and internet facing hosts.
[+] Google Pixel CVE-2026-58704, High, Mobile Fleets: Zero click baseband logic flaw. Crafted cellular signals escalate privilege with no tap and no app install. CVSS 8.0. Google describes limited targeted use. KEV on 2026-09-16, federal date 2026-09-19. Fix is security patch level 2026-09-05 or later. There is no network control that replaces the modem patch.
[+] Acronis Backup CVE-2026-87886, High, Hosting and MSP: Incorrect default permissions on cPanel WHM plugin and Plesk extension, with DirectAdmin builds also named in consults. Local low privilege to host privilege on shared infrastructure. KEV on 2026-09-16, federal date 2026-09-19. Fixed builds include cPanel plugin 1.9.3.1021 / 1.9.4.1022 and Plesk 1.8.11.638.
[+] Settra ransomware, High, Multi Sector Opportunistic: 93 claimed victims since Jun 2026. Double extortion, four plus confirmed leaks. Path is compromised VPN credentials, MeshAgent (mvtcs.exe or default), gdrv.sys BYOVD, log clear, reagentc /disable, diskpart recovery wipe, cipher /w, then [domain]_win64.exe to .locked or .locked_wip and RESTORE_FILES.txt over Tox. Best detection is before encryption.
[+] Adjacent pressure in the same window: Check Point CVE-2026-91843 CVSS 9.8 login stack overflow with no observed exploitation and LivePatch sk1000155. MikroTik MikroTrick CVE-2026-67276 plus CVE-2026-86060 exploited from 2026-09-02, persistence can survive the upgrade. Orkes Conductor CVE-2026-58138 unauthenticated INLINE RCE exploited from 2026-08-21. GitLab CVE-2026-85706 CVSS 10.0 commits API path traversal exploited within 24 hours of disclosure. ScreenConnect CVE-2026-84869 remains a post deadline worm like file push risk. Gyazo disclosed about 23.62 million user records and about 490 million image metadata records after a 2026-09-11 upload server intrusion. PhantomRaven npm stealer tied to JPD publishers. ShinyHunters posted Kimberly-Clark on a leak site without independent breach confirmation. Apache Nutch CVE-2026-41870 family is disclosed only, fixed by removing the Nutch Server component in 1.23.
[+] Leadership take: patch and triage ISE, Secure Email, FMC, Windows, Pixel, Acronis, GitLab, RouterOS, and Conductor on emergency change. Hunt MeshAgent and gdrv.sys before ransom notes appear. Do not treat a closed patch ticket as forensic closure on any KEV item that requires triage.
Chapter 02 - Threat & Exposure Analysis
Unauthenticated administrative planes and opportunistic ransomware ran in parallel. The same week that ISE and Secure Email Gateway went to KEV, operators also faced FMC multi actor abuse, a GitLab file read that landed in exploits inside a day, and a ransomware crew that kills recovery before it encrypts.
[+] Cisco ISE CVE-2026-76460: Insufficient authentication on a privileged API endpoint (CWE-648) in ISE and ISE-PIC, independent of device configuration. An unauthenticated attacker on the management or control plane sends a crafted request and bypasses the web management interface. Cisco PSIRT learned of live use during a TAC case and published cisco-sa-ISE-ABP-VNSW7Tn5 on 2026-09-16. CISA listed it the same day with forensic triage = Yes, known ransomware use = Unknown, and a 2026-09-19 federal date. Consulted trackers state root command execution is achievable when chained. Root on ISE means log wiping, certificate and admin tampering, RADIUS TACACS+ pxGrid policy edits, and a pivot through every NAD that trusts that node. Exact endpoint and request shape remain unpublished. ISE 3.0 is end of maintenance.
[+] Cisco Secure Email Gateway CVE-2026-76461: AsyncOS email parsing fails to sanitize input. A crafted message carrying SQL statements executes arbitrary SQL and escalates to root on the appliance OS with no user action. CVSS 9.8. Advisory 2026-09-15, KEV 2026-09-14, Rapid7 and related consults treat it as zero day because attacks predated disclosure. Cisco contacted Secure Email Cloud customers after detecting malicious activity. Trains: AsyncOS 15.5 before 15.5.5-014, 16.0 before 16.0.4-302, 16.5 before 16.5.0-780. No reliable workaround.
[+] Cisco FMC CVE-2026-20079 and CVE-2026-20316: CVE-2026-20079 is an authentication bypass from an improper system process created at FMC boot. If no legitimate user claims the session, an unauthenticated remote attacker hijacks it and runs scripts as root through crafted HTTP to the FMC web interface. CVE-2026-20316 is a hard coded low privilege static credential used as a chain by at least one set. Talos describes three intrusion sets. UAT-12197 drops a JSP web shell and cmd.jar into the CSM Tomcat webroot, then runs OmniQuery.pl against the internal mdb to pull auth_data. UAT-11823 overlaps previously attributed Sandworm tooling, rewrites license.tmp to trigger a reverse shell, and installs an upgraded 64 bit Cyclops Blink implant with packet sniffing and DNS over HTTPS. UAT-11988 is a Qilin affiliate path that uses the static credential for reconnaissance, disables antivirus, and deploys ransomware. The 2026-09-16 hardening cycle grouped 29 related FMC FTD ASA flaws including CVE-2026-20324 sftunnel arbitrary file write to root and CVE-2026-20341 sftunnel deserialization to root. Those siblings are not reported as exploited in consulted sources.
[+] Microsoft CVE-2026-81963 and CVE-2026-85880: September 2026 Patch Tuesday closed 966 CVEs with 113 Critical. CVE-2026-81963 is improper link following in the Windows Update Stack (CWE-59). A local low privilege attacker escapes AppContainer to SYSTEM. It is the first in the wild zero day for that component. CVE-2026-85880 is a heap buffer overflow in Windows ALPC. Same impact, second ALPC zero day since CVE-2023-21674. Both listed in KEV the day they shipped. Actor unnamed.
[+] Google Pixel CVE-2026-58704: Logic error in cellular modem firmware allows a permission check bypass over an adjacent radio path. No tap, no link, no app. CVSS 8.0. Google says limited targeted exploitation. Fixed in the September 2026 Pixel update at patch level 2026-09-05 or later. All supported Pixel devices in that bulletin are in scope. CISA KEV 2026-09-16. Actor unnamed. Victimology unpublished.
[+] Acronis CVE-2026-87886: Incorrect default permissions (CWE-732) in the Backup plugin for cPanel and WHM, the Plesk extension, and DirectAdmin builds named in consults. A low privilege tenant can escalate to host privilege on shared backup infrastructure. KEV 2026-09-16, federal date 2026-09-19. Targeted exploitation reported against cPanel WHM deployments. Plesk exploitation not independently confirmed. Vendor portal text was thin in this window.
[+] Settra: Active since Jun 2026, 93 claimed victims, four plus data leaks, no RaaS panel evidence in consulted MOXFIVE notes. Initial access through compromised VPN credentials or unpatched software. Post compromise deploys open source MeshAgent, renamed mvtcs.exe in Jul and default named in Sep, calling 45.13.122[.]7 then 193.5.65[.]114. Sep incidents load Gigabyte gdrv.sys to punch EDR at kernel level. Anti forensics include wevtutil log clear, ipconfig /flushdns, reagentc /disable, diskpart against recovery partitions, and cipher /w overwrites. Payloads use [victim domain]_win64.exe from C:\Perflogs or user Documents. Extensions moved from .locked to .locked_wip. Note is RESTORE_FILES.txt. Talks move to Tox. Targeting is sector agnostic.
[+] Check Point CVE-2026-91843: Pre authentication stack overflow in the login process of Security Management Server, Multi Domain Security Management Server, Log Server, and Multi Domain Log Server. Censys style reproduction uses an extremely long username. CVSS 9.8. Check Point and CISA recorded no exploitation as of 2026-09-17. Fix is LivePatch sk1000155. Detection string: Administrator failed to log in: Username too long.
[+] MikroTik MikroTrick CVE-2026-67276 plus CVE-2026-86060, with Bishop Fox variant CVE-2026-67279: Stage one bypasses SSH authentication through incomplete RSA public key verification. Stage two feeds a crafted username such as -2 to a legacy login helper and receives full administrative rights. Exploitation against internet exposed SSH observed from 2026-09-02. Post compromise artifacts include extra full privilege accounts, scripts, and schedulers that recreate a privileged account. Suspicious objects may show owner="0" instead of owner="admin". RouterOS login history is memory resident and dies on reboot. Patching does not remove persistence. Fixed: RouterOS 6.49.21, 7.23.4, 7.24.2.
[+] Orkes Conductor CVE-2026-58138: INLINE, LAMBDA, DO_WHILE, and SWITCH tasks evaluate attacker JavaScript or Python on GraalVM with HostAccess.ALL, which disables the sandbox. Default open source server has no authentication. One unauthenticated POST registers a hostile INLINE workflow and starts it as the Conductor process, often root. Patched in 3.30.2 in Jun. In the wild from 2026-08-21. Fortinet blocked about 1300 attempts on 2026-09-08 through 2026-09-09.
[+] GitLab CVE-2026-85706: Improper path confinement plus missing authentication on /api/v4/projects/{id}/repository/commits/. Workhorse regex checks bypass via trailing slash, .json suffix, or percent encoding such as %63ommits. A POST with file.path containing ../ returns files readable by the GitLab process, including .env, gitlab.yml, SSH keys, and CI/CD variables, often echoed in Rack errors such as invalid %-encoding. CVSS 10.0. Exploited within 24 hours of the 2026-09-11 patch. KEV 2026-09-14. Affected CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2.
[+] Gyazo / Helpfeel: On 2026-09-11 a third party abused an image upload server vulnerability, ran arbitrary commands, and reached the database. Access routes were blocked by early 2026-09-12. Disclosure 2026-09-16: about 23.62 million user records including emails and password hashes, plus about 490 million image metadata records. Unique image IDs can reconstruct image URLs.
[+] CaptiveCrunch Storm-2945: Microsoft describes a Midnight Blizzard subcluster manipulating DNS and HTTP on hospitality networks, dropping travelers into device code phishing on a legitimate Microsoft sign in page or into fake updates that steal credentials, session tokens, security configuration, and remote access history. Single vendor in this window.
[+] PhantomRaven: CrowdStrike describes an LLM flavored JavaScript stealer in typosquatted npm packages transform-jsbi-to-bigint and sort-imports-es6-autofix, publishers jpdhellonpm1, jpd15, jpd12, jpd13, npmhell, jpdhackerone11. Collects mail addresses, fingerprints, and CI/CD variables. Actor JPD claims bug bounty work and has been active since 2022-11.
[+] ShinyHunters / Kimberly-Clark: Leak site post on 2026-09-13 with a 2026-09-16 deadline and language about digital problems. No independent confirmation of intrusion or theft appeared by window close. Historical ShinyHunters tradecraft (vishing, Okta hijack, Salesforce and Snowflake theft) is context, not proof of this incident.
[+] Apache Nutch CVE-2026-41870, CVE-2026-41871, CVE-2026-41869: Unauthenticated JEXL RCE, missing auth plus unsafe reflection job execution, and missing auth plus improper shutdown denial of service on Nutch Server in 1.10 through 1.22. Fixed in 1.23 by removing the component. No KEV, no known exploitation, no public proof of concept in consulted sources.
[+] ScreenConnect CVE-2026-84869 remains a post deadline context item. Unpatched clients that accept TransferFiles style push and execute through live sessions should be treated as suspect.
Chapter 03 - Operational Response
Work the KEV clock first, then hunt persistence that survives a patch.
[+] Cisco ISE CVE-2026-76460 P0: Inventory every ISE and ISE-PIC node including MSP, managed NAC, SASE, and campus vendor nodes. Record exact release plus patch against 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Migrate ISE 3.0. Restrict management with iACLs during the window. Pull ise-kong/access.log and ./ise/logs/apigateway/access.log on every node, not only the primary. Hunt odd usernames including dummyuser as a non exhaustive example. Compare firewall, NetFlow, and proxy telemetry for ISE originated egress. Root can wipe local logs, so off box telemetry is the record. If compromise is plausible, reimage, restore from a clean config backup, and revalidate admins, certificates, authorization policies, pxGrid trusts, and RADIUS TACACS+ secrets. Demand vendor attestation per node by 2026-09-19.
[+] Cisco Secure Email Gateway CVE-2026-76461 P0: Inventory AsyncOS appliances. Upgrade to 15.5.5-014, 16.0.4-302, 16.5.0-780 or later. Review mail_logs for SQL error leakage and system_logs for unexpected command execution. Check for new admin accounts and config drift. Cloud customers should confirm whether Cisco already flagged their tenant.
[+] Cisco FMC CVE-2026-20079 P0: Confirm patch state against the already passed federal date. Hunt license.tmp staging, cmd.jar and JSP in Tomcat webroot, OmniQuery.pl against mdb, unexpected sftunnel use, and Cyclops Blink style outbound DNS over HTTPS. Treat Qilin affiliate behavior as ransomware prep. Rebuild rather than tidy any FMC that shows web shell artifacts.
[+] Windows CVE-2026-81963 and CVE-2026-85880 P0: Deploy September 2026 Patch Tuesday everywhere. Lead with domain controllers, PAW, jump hosts, VDI, and internet facing servers. Watch wuauclt.exe and Update related svchost.exe spawning shells as SYSTEM. Watch lsass.exe ALPC oddities from low integrity parents. Event 4672 plus an AppContainer parent is the correlation to keep.
[+] Pixel CVE-2026-58704 P1: Enforce patch level 2026-09-05 or later through MDM. Block unmanaged or unpatched Pixels from corporate resources. High risk users can reduce radio time, but that is not a fix.
[+] Acronis CVE-2026-87886 P1: Upgrade cPanel WHM plugin to 1.9.3.1021 or 1.9.4.1022, Plesk extension to 1.8.11.638 or later, DirectAdmin plugin to 1.2.3.238 or later. Audit tenant isolation and auth logs for sudo or su from hosting users into Acronis paths.
[+] Settra P1: Hunt MeshAgent and mvtcs.exe, outbound 45.13.122[.]7 and 193.5.65[.]114, certificate CN matches on those addresses, Sysmon 6 loads of gdrv.sys, reagentc /disable, diskpart recovery edits, cipher /w, wevtutil cl, Event 1102. Quarantine hits, revoke VPN credentials, unload the driver, restore from offline immutable backups. Do not pay. Tox negotiation is criminal contact.
[+] Check Point CVE-2026-91843 P1: Apply LivePatch sk1000155. Alert on Username too long in admin login logs and on usernames longer than 512 bytes.
[+] MikroTik P1: Capture config, accounts, scripts, schedulers, proxies, and tunnels before reboot or reset. Upgrade to 6.49.21, 7.23.4, or 7.24.2. Hunt owner="0" and usernames matching ^-[0-9]+$. Rotate secrets on any exposed box. Patching alone leaves persistence.
[+] Orkes P1: Upgrade to 3.30.2 or later. Authenticate and firewall the workflow API. Review INLINE and LAMBDA submissions since 2026-08-21.
[+] GitLab CVE-2026-85706 P0 for self managed: Upgrade to 19.1.8, 19.2.6, or 19.3.2. Hunt unauthenticated POST to /api/v4/projects//repository/commits with file.path and ../. Rotate SSH keys, deploy tokens, database secrets, and CI/CD variables. Audit users, projects, and webhooks created after 2026-09-11.
[+] Gyazo users P2: Force password resets, revoke sessions, expect phishing that weaponizes reconstructed image URLs.
[+] PhantomRaven P2: Remove transform-jsbi-to-bigint and sort-imports-es6-autofix. Block the JPD publisher handles. Rotate developer and CI secrets. Prefer a private registry and signed packages.
[+] CaptiveCrunch P2 for hospitality: Constrain device code flow in Conditional Access. Brief front of house networks on captive portal tampering.
[+] ShinyHunters claim P2: Monitor the leak site. Do not treat the post as confirmed compromise. Verify backups and watch Okta impossible travel only as general hygiene.
[+] Apache Nutch P2: Upgrade to 1.23 so the vulnerable Nutch Server component is gone.
[+] ScreenConnect P1 if still unpatched: Isolate, assume file push abuse, rotate access.
Time IST | Event |
|---|---|
2022-11 | JPD publisher activity that later maps to PhantomRaven |
2026-06 | Settra campaign start in consulted victimology |
2026-08-21 | Orkes Conductor exploitation identified |
2026-09-02 | MikroTrick exploitation observed on exposed RouterOS SSH |
2026-09-05 | CERT Polska discloses six RouterOS flaws |
2026-09-08 to 2026-09-09 | Fortinet blocks about 1300 Orkes attempts |
2026-09-09 | Talos public on CVE-2026-20079 exploitation |
2026-09-11 | GitLab patches CVE-2026-85706. Gyazo upload intrusion. Acronis fixed plugin builds. ScreenConnect KEV context |
2026-09-12 | Gyazo access routes blocked. GitLab public detail expands |
2026-09-13 | ShinyHunters posts Kimberly-Clark |
2026-09-14 | Cisco discloses CVE-2026-76461. CISA KEV for CVE-2026-76461 and CVE-2026-85706. GitLab exploitation reported inside 24 hours of disclosure |
2026-09-15 | Pixel bulletin fixes CVE-2026-58704. CrowdStrike PhantomRaven analysis |
2026-09-16 | Cisco ISE advisory and KEV for CVE-2026-76460, CVE-2026-87886, CVE-2026-58704. Microsoft Patch Tuesday with two exploited zero days. Gyazo disclosure. Check Point sk1000155. FMC hardening cycle siblings published |
2026-09-17 | Trade press ISE analyses. Huntress Settra detail. SEG KEV date passes. Check Point exploitation recorded as none |
2026-09-18 | CSA Singapore, JPCERT/CC, AhnLab Secure Email alerts. Pixel targeted use restated. Settra coverage expands. Window close 19:10 IST |
2026-09-19 | Federal date for CVE-2026-76460, CVE-2026-87886, CVE-2026-58704 |
2026-09-28 | Single consult states CISA weekly vulnerability bulletin ends. Treat as unconfirmed |
Chapter 04 - Detection Intelligence
[+] CVE-2026-76460: CWE-648 privileged API misuse in the Kong gateway layer of ISE and ISE-PIC 3.1.0 through 3.5.0. Authentication is not enforced before a privileged endpoint runs. One crafted unauthenticated HTTP request bypasses web management. ISE is a hardened Linux appliance, so post bypass admin actions are device wide. First fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.
[+] CVE-2026-76461: Pre authentication SQL injection in AsyncOS parsing. Injected SQL in headers, body, or attachments rides the normal mail path to root OS command execution.
[+] CVE-2026-20079: Boot time system process creates a session that can be claimed by an unauthenticated HTTP client if a legitimate user never binds it. Combined with CVE-2026-20316 static credential, operators get script execution as root and a path into Tomcat webroot.
[+] CVE-2026-81963: Link following in Windows Update Stack lets a low integrity or AppContainer process plant a path that Update processing follows into SYSTEM.
[+] CVE-2026-85880: ALPC heap overflow from a low privilege client to a SYSTEM service, token escape out of the sandbox.
[+] CVE-2026-58704: CWE-284 style permission check failure in Pixel modem firmware. Adjacent radio input escalates inside the modem context and can reach host data. Host EDR cannot see the first hop.
[+] CVE-2026-87886: World accessible or mis-permissioned files under Acronis plugin paths on cPanel, Plesk, and DirectAdmin allow local privilege escalation to host root.
[+] CVE-2026-91843: Stack buffer overflow in a pre authentication login handler triggered by an oversized username.
[+] MikroTrick: Incomplete RSA public key verification opens SSH without the private key. A crafted username is then parsed as an instruction by a legacy helper, which applies an attacker chosen identity and policy mask.
[+] CVE-2026-58138: GraalVM HostAccess.ALL on INLINE class tasks turns user expressions into Java Runtime or ProcessBuilder calls.
[+] CVE-2026-85706: file.path is not confined to the repository root and Workhorse auth regex is bypassed by slash, .json, or percent encoding. Rails opens the traversal target and leaks content through error pages.
[+] Settra chain: VPN credential reuse, MeshAgent C2, gdrv.sys kernel callbacks, then a recovery destruction sequence before [domain]_win64.exe encrypts and drops RESTORE_FILES.txt.
[+] Nutch 1.10 to 1.22: JEXL injection and unsafe reflection on an unauthenticated REST job API. 1.23 deletes the component.
[+] Gyazo: command execution on the image upload server to database access. Image IDs are enough to rebuild public URLs.
[+] Network high confidence: 45.13.122[.]7 MeshAgent C2 Jul Settra. 193.5.65[.]114 MeshAgent C2 Sep Settra, certificate CN match.
[+] Network low confidence do not operationalize alone: 208.123.119[.]215, 89.34.96[.]x reported as Cyclops Blink C2 by a single consult.
[+] Host files: mvtcs.exe renamed MeshAgent. [domain]_win64.exe Settra payload pattern. license.tmp FMC staging. cmd.jar FMC Tomcat executor. RESTORE_FILES.txt Settra note. JSP web shell in CSM Tomcat webroot, filename unpublished.
[+] Driver: gdrv.sys Gigabyte BYOVD, historical CVE-2018-19320 pairing, SHA256 insufficient.
[+] Extensions: .locked Jul Settra. .locked_wip Sep Settra.
[+] Names: WIN-LIVFRVQFMKO workstation. dummyuser ISE hunt example, non exhaustive.
[+] Paths: ise-kong/access.log. ./ise/logs/apigateway/access.log from support bundles. C:\Perflogs Jul launch. %USERPROFILE%\Documents Sep launch. /usr/local/cpanel/base/3rdparty/acronis/ and Plesk Acronis paths for permission audit.
[+] Log signatures: Check Point Administrator failed to log in: Username too long. GitLab Rack invalid %-encoding with ../. RouterOS usernames matching ^-[0-9]+$. ISE API success with empty or odd user from outside approved admin networks.
[+] Packages: transform-jsbi-to-bigint, sort-imports-es6-autofix. Publishers jpdhellonpm1, jpd15, jpd12, jpd13, npmhell, jpdhackerone11.
[+] Workflow objects: Orkes taskType INLINE with java.lang.Runtime, ProcessBuilder, /bin/sh, or cmd.exe. RouterOS objects with owner="0" and schedulers that recreate privileged users.
Coverage is strong where hosts emit process, driver, and API logs. It is weak on the Pixel modem and on appliances that can wipe their own disks after root.
[+] Coverage snapshot:
Item | SIGMA or equivalent | EDR behavior | Network | Log hunt | Coverage |
|---|---|---|---|---|---|
Cisco ISE | Yes | Process tree, file, egress | ISE originated flows | ise-kong/access.log | High |
Secure Email Gateway | Yes | Limited on appliance | Limited | mail_logs, system_logs | Moderate |
Windows zero days | Yes | AppContainer to SYSTEM | Weak | Events 4672, 4688 | High |
Pixel modem | No host view | No | Specialized radio | No | Low, patch only |
Acronis | Weak | Auth and sudo | No | auth.log, plugin paths | Low to moderate |
Settra | Yes | Driver, process, file | MeshAgent C2 | Events 1102, 4688 | High |
FMC clusters | Behavioral | Tomcat webroot, license.tmp | DoH, reverse shell | FMC audit | Moderate |
GitLab | Yes | Weak | Unauth POST | Rack errors | High |
Check Point | Yes | Weak | Weak | Username too long | Moderate |
MikroTik | On box CLI | Weak | SSH anomalies | owner="0", crafted user | Moderate |
Orkes | YARA on workflows | Interpreter spawn | Workflow API | API bodies | Moderate |
Nutch | REST anomalies | Java child process | Job API | Access logs | Moderate |
PhantomRaven | Package install | Outbound from npm | Unknown C2 | npm audit | Moderate |
[+] Detection gaps: Pixel baseband has no useful endpoint sensor. Acronis vendor text in this window was too thin for a precise signature. Secure Email and ISE can lose local evidence after root. Attribution gaps mean there is no actor specific C2 list for the vulnerability clusters.
[+] ISE SIEM idea: successful API or admin events without a prior RADIUS or login from the same source in five minutes, plus any ISE node not on the fixed patch matrix.
[+] SEG CLI hunt: grep SQL syntax and command words in /var/log/mail_logs/current and /var/log/system_logs/current.
[+] RouterOS hunt: /user print detail, /system script print, /system scheduler print, /system logging print, and alert on usernames matching ^-[0-9]+$.
[+] MeshAgent hunt: process name mvtcs.exe or MeshAgent, outbound 45.13.122[.]7 or 193.5.65[.]114.
Technique to detection pairing. All inferred mappings carry a behavioral basis. No vendor published a full official ATT&CK annex in this window.
Technique | Basis | Detection object |
|---|---|---|
T1190 | ISE API, SEG mail SQLi, FMC HTTP, GitLab commits API, Check Point login, Orkes API, MikroTik SSH | ISE, SEG, GitLab, Check Point rules above |
T1210 | ISE and FMC root after bypass | ISE egress and FMC webroot hunt |
T1068 | Windows zero days, Pixel modem, Acronis permissions, gdrv.sys | EoP token rule, MDM patch, auth logs, driver load rule |
T1211 | gdrv.sys used to kill agents | Driver load rule |
T1505.003 | FMC JSP, possible ISE or Nutch web shell | Tomcat webroot, Java child processes |
T1059.003 | Settra cmd, diskpart, cipher, wevtutil | Anti recovery rule |
T1059.004 | Root shells on Linux appliances | Appliance process and egress |
T1105 | MeshAgent, Cyclops Blink | IOC addresses and license.tmp |
T1070.001 T1070.004 T1490 | Settra log clear and recovery wipe | Anti recovery rule, Event 1102 |
T1486 | Settra and Qilin affiliate | .locked, .locked_wip, RESTORE_FILES.txt |
T1136 T1053 | RouterOS extra accounts and schedulers | owner="0" CLI hunt |
T1552 T1552.001 | FMC auth_data, GitLab file read | OmniQuery.pl, Rack errors |
T1528 | CaptiveCrunch device code tokens | Conditional Access anomalies |
T1195.002 T1036.005 | PhantomRaven packages | npm publisher and package rules |
T1040 T1071.004 | Cyclops Blink sniff and DoH | FMC outbound DoH |
T1546.012 | Nutch reflection jobs | REST job API anomalies |
T1562.001 | Qilin affiliate disables AV | Security tool stop events |
[+] D3FEND: D3-PLA inventory of ISE, SEG, FMC, Pixel, Windows, Acronis, GitLab, RouterOS, Conductor. D3-NM restrict management planes and watch ISE egress plus MeshAgent C2. D3-HLA block gdrv.sys. D3-SBR reimage compromised ISE or FMC. D3-PM Sysmon driver and process creation. D3-LLA centralize ise-kong/access.log, Windows Security, GitLab access, RouterOS config.
Chapter 05 - Governance, Risk & Compliance
KEV dates turn several of these from patch backlog into audit findings.
[+] Cisco ISE CVE-2026-76460: BOD 26-04 requires forensic triage by 2026-09-19 for FCEB, not a patch ticket alone. MSP operated ISE is third party risk. A compromised vendor node is a compromised admission fabric. Demand written per node attestation. NIS2, CIRCIA, and UK NIS notification clocks can start if identity or essential service impact is found. Insurers may exclude unpatched KEV after the date. Keep the triage file.
[+] Cisco Secure Email Gateway CVE-2026-76461: Same KEV logic, date already passed on 2026-09-17. Mail gateway compromise exposes inbound and outbound content, attachments, and privilege. GDPR Art. 33/34, CCPA, and HIPAA clocks start on discovery. MSPs that host mail inherit contractual notice duties.
[+] Cisco FMC CVE-2026-20079: Federal date already passed. Multi actor use including a ransomware affiliate makes this a board level control failure on the firewall brain, not a routine advisory.
[+] Windows zero days: 966 CVEs and two exploited elevations create enterprise wide evidence needs for PCI DSS 6.5.6, SOX, and HIPAA Security Rule patch tracking. Tier 0 and PAW miss here is a reportable control gap.
[+] Pixel CVE-2026-58704: Conditional access must enforce patch level 2026-09-05 or later. Zero click bypasses awareness training. NIST 800-124 and ISO 27001 Annex A.6.2.1 are the mobile control references. Targeted use implies executive protection briefing.
[+] Acronis CVE-2026-87886: Shared hosting tenant isolation failure is a GDPR, SOC 2, and ISO 27001 event if cross tenant access occurred. Federal date 2026-09-19.
[+] GitLab CVE-2026-85706: Source and CI/CD secret exposure can be material under SEC disclosure, SOC 2 confidentiality, and GDPR if personal data sat in those files. Rotate secrets even when logs look clean.
[+] Settra: Double extortion plus confirmed leaks starts 72 hour notice clocks. Anti forensics can delay timelines. Document impairment. OFAC and insurer rules weigh against payment. Law enforcement contact is the defensible path.
[+] Gyazo: 23.62 million user records and 490 million metadata records create downstream notice questions for EU and UK processors. Action not confirmed per jurisdiction in consulted sources.
[+] MikroTik and Orkes: Internet reachable admin planes without authentication or with broken SSH checks are a measurable hygiene class. Inventory is the control.
[+] ShinyHunters claim: No confirmed regulatory threshold met because the breach itself is unverified. Do not notify solely on a leak site post.
[+] Vodafone España €400000 GDPR fine reported 2026-09-17 after a service provider ransomware event is the reminder on third party oversight. Single consult item, used as context only.
[+] CISA weekly bulletin retirement on 2026-09-28 is a single consult claim. Plan as if KEV and live exploitation evidence remain the prioritization spine.
Chapter 06 - Adversary Emulation
Lab and owned assets only. Do not fire withheld ISE payloads or public exploit code at production.
[+] ISE API bypass: On a lab 3.4 Patch 6 node, generate unauthenticated management API calls from a non admin network. Validate the ISE API anomaly rule, ise-kong/access.log source oddity, and NetFlow egress. Blue team applies iACLs, hunts, reimages, and restores config. Do not attempt root post exploitation on a live cluster.
[+] ISE as pivot: On an isolated lab with a downstream NAD, show how a hostile authorization profile or pxGrid trust would look. Validate RADIUS and pxGrid change alerts.
[+] Secure Email SQLi: On lab AsyncOS 16.0.3 send a mail with SQL tokens in header or body. Expect log leakage or parser faults. Confirm the SEG rule and system_logs process spawn.
[+] Windows EoP: On pre patch Windows 11 24H2, use a low integrity AppContainer parent and watch for Event 4672 plus SYSTEM token. Public proof of concept was not in consulted sources. Stop at detection validation.
[+] Settra MeshAgent: Launch renamed mvtcs.exe against a mock MeshCentral. Confirm process creation and C2 address match.
[+] Settra BYOVD: Load gdrv.sys via a lab service. Confirm Sysmon 6 and kernel callback visibility. Unload and delete after.
[+] Settra anti recovery: reagentc /disable, diskpart recovery, cipher /w, wevtutil cl. Confirm the anti recovery rule and Event 1102.
[+] Settra encrypt simulation: harmless canary files to .locked_wip plus RESTORE_FILES.txt. Confirm file monitors.
[+] Check Point long username: scripted logins over 512 bytes against a patched build. Alert must fire. No code execution expected.
[+] MikroTrick: On lab RouterOS below 7.24.2 with lab SSH only, show extra accounts and owner="0" schedulers after the chain. Confirm hunting commands.
[+] Orkes INLINE: Unauthenticated POST of an INLINE task that runs a benign marker, not a destructive command, on Conductor below 3.30.2. YARA must match the stored workflow.
[+] GitLab traversal: POST file.path=../../../../etc/passwd style against a disposable self managed instance below 19.1.8. Confirm the GitLab rule and Rack error leak. Rotate lab secrets after.
[+] CaptiveCrunch purple: Simulated device code phishing and fake update lure. Measure helpdesk report rate and Conditional Access blocks.
[+] PhantomRaven purple: Install known bad package names in an isolated runner. Confirm SCA and npm audit alerts.
[+] Safety: no production ISE bypass attempts, no rogue base station against staff Pixels, no real ransomware encryptors, no contact with Tox negotiation channels.
Score 84/100.
Factor | Direction | Effect |
|---|---|---|
Cisco ISE vendor plus KEV plus multiple independent consults | Positive | Strong |
Cisco Secure Email vendor plus KEV plus CERT alerts | Positive | Strong |
Microsoft official Patch Tuesday plus same day KEV | Positive | Strong |
Google Pixel bulletin plus KEV plus targeted use statement | Positive | Strong |
GitLab advisory plus KEV plus 24 hour exploitation reporting | Positive | Strong |
Huntress Settra TTPs plus corroborating consults | Positive | Strong |
Talos FMC three cluster narrative | Positive | Moderate. Second major house thin |
Acronis KEV listing | Positive | Moderate. Vendor text thin here |
MikroTik CERT Polska plus Bishop Fox persistence | Positive | Moderate |
Orkes Empirical plus Fortinet numbers | Positive | Moderate. Some relayed through trade press |
Check Point as exploited | Negative | Not observed |
Apache Nutch exploitation | Negative | None known |
CaptiveCrunch Midnight Blizzard link | Negative | Single vendor |
Cyclops Blink IP fragments | Negative | Single consult |
ShinyHunters Kimberly-Clark theft | Negative | Claim only |
Withheld ISE request shape and missing hashes | Negative | Limits detection precision |
Attribution gaps on most exploit clusters | Negative | Caps score under 90 |
[+] Net: exploitation status is solid for the KEV set and for Settra tradecraft. Actor names and atomic IOC depth are not. Keep the score in the mid 80s until Cisco, CISA, or Talos publish indicators or a second house restates the Sandworm overlap.
