Last Updated On

CCTTII--22002266--00991111
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Your Firewall Manager Just Became a Qilin Beachhead

The box that manages your firewalls is handing out root, and CISA wants it closed by 2026-09-12. Cisco Talos documented live FMC intrusion sets that stole managed device credentials, planted Cyclops Blink, and in one case deployed Qilin, while CERT Polska and CISA put MikroTik MikroTrick on a 2026-09-13 clock against about 122500 SSH exposed routers already exploited from 82.192.72[.]4.

Commerce and build systems are in the same blast radius. StyleSmuggler is a CVSS 10.0 Magento GraphQL smash that drops Rust backdoors before the hotfix lands, Wiz watched Artifactory mint admin tokens in two HTTP calls, PaperCut telemetry ran through hundreds of organizations with education first in line, and GitLab's commits API is already being probed for unauthenticated file read one day after patch.

The strategic tell is GTG-20006. A Russia linked cluster used Claude to rebuild malware every time a product flagged it, then stole M365 tokens and hotel Wi Fi paths into government and defense networks. Hash lists are a speed bump. Hunt the ops account, the JSP in Tomcat, the PHP in pub/media, the minted jfrog-* admins, and device code sign ins before you call the change ticket done.

10

CVSS Score

90

IOC Count

18

Source Count

82

Confidence Score

CVEs

CVE-2026-67276, CVE-2026-67277, CVE-2026-86060, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-20079, CVE-2026-20316, CVE-2026-20131, CVE-2026-19490, CVE-2025-25249, CVE-2026-87491, CVE-2026-85706, CVE-2026-87719, CVE-2026-88765, CVE-2026-75650, CVE-2025-14733, CVE-2026-82583, CVE-2026-78224, CVE-2026-82578, CVE-2026-42018, CVE-2026-42016, CVE-2026-82329, CVE-2026-81578, CVE-2026-82078, CVE-2026-51990, CVE-2026-85046, CVE-2026-85880, CVE-2021-38003, CVE-2021-42278, CVE-2021-42287

Actors

GTG-20006, Midnight Blizzard, APT29, Cozy Bear, GTG-10007, UAT-12197, UAT-11823, Sandworm, UAT-11988, Qilin, UAT-10820, UNC3569, TA412, Violet Typhoon, APT31, JungleBamboo, TIDE CASTLE, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, JackPoterz

Sectors

Telecom, ISP, SMB, branch offices, federal civilian executive branch, government, defense, diplomatic, think tank, defense industrial base, hospitality, MSP, RMM, software development, DevOps, e commerce, retail, financial services, technology, critical infrastructure, healthcare, public health, education, aerospace, mining, commodities, manufacturing, energy, finance, consulting, cryptocurrency custody, real estate, IT, non profit, libraries

Regions

Global, Ukraine, Europe, Middle East, Asia, North Africa, United States, United Kingdom, France, Spain, Canada, Belgium, Portugal, Australia, Germany, Switzerland, Indonesia, Singapore, Vietnam, East Asia, Southeast Asia

Chapter 01 - Executive Overview

This window, stacked confirmed KEV exploitation on firewall managers and edge routers with an AI rebuilt espionage disclosure, a CVSS 10.0 commerce RCE already dropping Rust backdoors, in the wild Artifactory admin minting, an education heavy PaperCut wave, and commits API probing against GitLab one day after patch.

MikroTik MikroTrick. Critical. Network edge, all sectors.

[+] CISA added CVE-2026-67277 (missing authentication on the bandwidth test service) and CVE-2026-86060 (SSH argument injection, CVSS 9.2) to KEV on 2026-09-10 with a 2026-09-13 due date.

[+] Chained with CVE-2026-67276 (SSH authentication bypass via forged RSA key with exponent one, CVSS 9.2) the set yields complete unauthenticated takeover of any RouterOS device with SSH exposed.

[+] ShadowServer counted about 122500 exposed devices as of 2026-09-05. Exploitation from 82.192.72[.]4 is confirmed since at least 2026-09-02. The lead persistence tell is a privileged ops account.

[+] CISA flagged CVE-2026-86060 for forensic triage under BOD 26-04. This is compromise assessment, not routine patching. An in place upgrade does not evict an intruder.

Cisco Secure FMC root to ransomware. Critical. Enterprise, government, and any fleet managed from FMC.

[+] CVE-2026-20079 (CVSS 10.0) is an unauthenticated web interface authentication bypass caused by an improperly created boot time process. Crafted HTTP yields root on the underlying OS. No workaround exists. Hotfixes cover 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Federal due date 2026-09-12.

[+] CVE-2026-20316 (CVSS 5.3) is static low privilege credentials that Talos saw chained for privilege gain. CVSS 5.3 is not safe when chained.

[+] One intrusion set wrote a JSP web shell into the CSM Tomcat webroot, dropped cmd.jar, and queried users.auth_data.

[+] A second set replaced license.tmp as a Makeself payload executed through package_info.pl as root, opened a netcat shell, archived managed device configs, and installed a Cyclops Blink variant. Tooling overlap with Sandworm is Talos assessed at high confidence.

[+] A third set used the static credential path, enumerated AD and related maps, stood up SOCKS5 and reverse SSH, killed security tools, and deployed Qilin on selected systems.

[+] Compromising FMC is worse than compromising one firewall. It is the management plane for policy, logging, and updates across the fleet. Treat internet reachable FMC as likely compromised until triaged.

GTG-20006 and GTG-10007. High. Government, defense, diplomatic, drone supply chain.

[+] Anthropic disrupted GTG-20006, a Russian state linked cluster it assesses as consistent with Midnight Blizzard / APT29 / Cozy Bear reporting.

[+] Claude was used at every stage: implant build, phishing platform, admin console, and an evasion loop that watched whether security products flagged malware and then rebuilt it until it evaded.

[+] Operations hit more than 20 organizations across Ukraine, Europe, the Middle East, and Asia, including hotel Wi Fi DNS hijacking, WhatsApp companion device takeover, a North African government breach of more than 300000 identity records and more than 500000 company registry records, and M365 token theft from at least eight organizations via Embassy Kit.

[+] GTG-10007, assessed as Chinese speaking and likely Changsha based, ran automated vulnerability research against about 50 organizations and reportedly surfaced more than a dozen possible zero day findings in a month. That is a capability disclosure, not a named CVE event.

GitLab commits API. High. DevOps and software supply chain.

[+] CVE-2026-85706 is a max severity unauthenticated path traversal in the repository commits API. One POST to /api/v4/projects/{id}/repository/commits/ with a file.path parameter can read secrets, tokens, and gitlab-secrets.json.

[+] CVE-2026-87719 is an authenticated GraphQL Duo Chat deserialization flaw, CVSS 9.9. CVE-2026-88765 is an authenticated project import RCE.

[+] Fixed in CE/EE 19.3.2, 19.2.6, and 19.1.8. GitLab.com and Dedicated need no action. watchTowr observed probing within 24 hours. GitLab has not confirmed exploitation. Precedent: CISA has flagged four GitLab CVEs as exploited since 2021.

StyleSmuggler. Critical. E commerce and retail.

[+] CVE-2026-75650 (CVSS 10.0) smuggles PHP through GraphQL styles objects into Magento email templates, including Payment Transaction Failed Reminder.

[+] Consulted telemetry shows a PHP web shell at /pub/media/tmp/catalog_rules.php and a stripped Rust ELF at /tmp/.libaudit_systemd with crontab persistence and an NTP lookalike UDP beacon.

[+] Adobe hotfix VULN-39341 under APSB26-146. Patching does not evict implants planted before the bulletin.

Citrix, Fortinet, Chrome, WatchGuard. Critical to high. Edge and endpoint.

[+] CVE-2026-19490 (CVSS 9.3) NetScaler AAA or Gateway authentication bypass. Federal due date 2026-09-12. Honeypot attempts from 2026-09-03, with 36 recorded on 2026-09-08.

[+] CVE-2025-25249 Fortinet heap overflow, CISA KEV, due 2026-09-12. Secondary coverage describes shell to Node.js to PivotC2. Infection counts in that coverage are not independently confirmed here.

[+] CVE-2026-87491 Chromium V8 out of bounds write, CVSS 8.8, seventh Chrome zero day of 2026. Update to 153.0.8010.36 or later.

[+] CVE-2025-14733 WatchGuard Fireware OS out of bounds write in iked, CVSS 9.8, KEV since 2025-12-19, updated this window as known ransomware use. About 9000 devices still exposed per ShadowServer figures carried through consulted coverage. Disable IKEv2 if you cannot patch today.

Artifactory and PaperCut. Critical. Build systems and education.

[+] Wiz confirmed chaining CVE-2026-42018 plus CVE-2026-42016 to mint an anonymous JWT and raise it to admin, and standalone CVE-2026-82329 unauth registry join. Admin accounts appeared in under five minutes. Patching does not revoke minted tokens.

[+] PaperCut CVE-2026-81578 and CVE-2026-82078 campaign telemetry: 440 instances, 395 organizations, 48 countries, about half education, 280 credential harvests, 12 domain admin cases, peak of 11 organizations in 26 seconds. Actor unnamed. Install MR 26.0.5, 25.0.13, or 24.1.10 and hunt DCSync.

Client side, healthcare watch item, and adjacent activity.

[+] BlueMoon chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 into chrome.exe to cmd.exe to curl.exe to %TEMP%\msgbox.exe. Sets hit US NGO and mining, US aerospace with ShadowPad, Vietnamese manufacturing, and Indonesia and Singapore government and finance.

[+] Sogou IME CVE-2026-51990 plus n day V8 CVE-2021-38003 delivered GRAYRABBIT. Confirm Sogou 16.3.0.3498 or later and hunt 7z.dll under C:\Users\Public\Documents.

[+] Trezor, BitBox, and CoinTracking newsletter lists were phished after a 2026-09-09 Brevo incident. About 347000 Trezor addresses, subject Critical Security Alert: STM32 Entropy Vulnerability. Domain killed in 20 minutes. Seeds never go into an updater.

[+] Mirth Connect CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 are unexploited as of the CISA ICS medical advisory but sit in lab, radiology, and billing flows.

[+] A WebDAV ClickFix style chain delivering Amatera, ZigCryptoStealer, and NetSupport Manager was investigated at a Ukrainian government organization and tracked as UAT-10820. This item is early warning, not tied to FMC.

Bottom line for leadership:

[+] Three emergency change items sit inside 72 hours: internet facing FMC, MikroTik RouterOS with SSH or Winbox exposed, and self managed GitLab plus Artifactory.

[+] Patching is not remediation on FMC, RouterOS, Magento, or Artifactory. Hunt the ops account, JSP and JAR in Tomcat, PHP in pub/media, minted jfrog-* admins, and device code sign ins before you declare the ticket closed.

[+] Static hash blocking is structurally degrading against the GTG-20006 rebuild loop. Shift spend to behavioral detections, identity analytics, and management plane telemetry.

Chapter 02 - Threat & Exposure Analysis

MikroTik RouterOS takeover at internet scale.

[+] CERT Polska disclosed a six vulnerability RouterOS set on 2026-09-05. The critical chain is CVE-2026-67276 plus CVE-2026-86060, with CVE-2026-67277 as a parallel unauthenticated service.

[+] CVE-2026-67276 (CVSS 9.2) is an SSH authentication bypass from incomplete RSA key validation. An attacker who knows a valid username and the public RSA modulus forges a session without the private key by presenting a crafted key with exponent one.

[+] CVE-2026-86060 (CVSS 9.2, CWE-88) injects arguments through username parsing and alters the trusted RouterOS policy mask, escalating a forged or low privilege session to full admin.

[+] CVE-2026-67277 is missing authentication on the bandwidth test service.

[+] ShadowServer measured about 122500 SSH exposed devices on 2026-09-05. CERT Polska confirmed exploitation from 82.192.72[.]4 since at least 2026-09-02, creating a privileged ops user. Cyber Centre Canada warned on 2026-09-08 that the three lead CVEs were reportedly exploited. CISA added CVE-2026-67277 and CVE-2026-86060 to KEV on 2026-09-10 with a 2026-09-13 due date. Actor: unattributed.

Cisco FMC as a domain beachhead.

[+] CVE-2026-20079 (CVSS 10.0) is an authentication bypass in the Secure FMC web interface from an improperly created system process at boot. Crafted HTTP bypasses authentication, executes scripts, and yields root. Cisco confirmed exploitation in August 2026. KEV addition 2026-09-09 with a 2026-09-12 federal deadline. No workaround. Hotfix only.

[+] CVE-2026-20316 (CVSS 5.3) is static low privilege credentials. Talos observed it chained for privilege gain, including a path that ended in Qilin. A low base score is not a low operational score when the next step is root or domain.

[+] One operator set exploited CVE-2026-20079, wrote home.jsp into the CSM Tomcat webroot, decoded parameter F6C1F0E7, dropped cmd.jar, and ran OmniQuery against users.auth_data.

[+] A second set used CVE-2026-20079 and or static credentials, replaced /var/tmp/license.tmp as a Makeself archive executed through package_info.pl as root, opened a netcat FIFO shell, archived managed device configs, and installed Cyclops Blink with persistence under /etc/init.d/, DoH, file admin, credential harvest, and sniffing. Talos assesses APT with high confidence tooling overlap with Sandworm.

[+] A third set logged in via CVE-2026-20316, mapped AD, ADFS, Exchange, files, and databases, exfiltrated staged files over HTTP GET, tunneled LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM, then used Impacket, Invoke-TheHash, custom AV killers, and Qilin on selected systems.

[+] Companion KEV adds the same day, CVE-2026-19490 (Citrix NetScaler, 9.3) and CVE-2025-25249 (Fortinet heap overflow), reinforce that edge management planes are the dominant exploitation surface this week.

GTG-20006 AI rebuild loop and GTG-10007 exploit foundry.

[+] Anthropic describes an actor that used Claude to build two Windows implants with keylogging, screenshots, and Chrome credential extraction via SECOMS64, a mobile kit, a browser password store stealer, a phishing platform, and an admin console.

[+] AI agents monitored whether deployed malware was detected and autonomously modified and rebuilt it until it evaded. Delivery ran through phishing, ClickFix, and DNS hijacking of at least three hospitality vendors hotel guest Wi Fi.

[+] Windows payloads named in coverage: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc. Android: GiftDrop, a rebrand of GiftsExpress. iOS: DarkSword. Activity overlaps the CaptiveCrunch campaign tracked by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

[+] Escalation included WhatsApp companion device hijacking with bulk conversation export and read receipt suppression, camera stream token harvest, a North African government intrusion (more than 300000 national identity records and more than 500000 company registry records), and Embassy Kit device code phishing stealing M365 tokens from at least eight organizations.

[+] GTG-10007 ran agent swarms against about 50 education, retail, energy, finance, and manufacturing organizations and reportedly produced more than a dozen possible zero day findings in a month against network appliance firmware. No product name or CVE was published.

GitLab unauthenticated file read against the software factory.

[+] CVE-2026-85706 is improper path confinement plus missing authentication on the repository commits API. An unauthenticated POST carrying file.path traverses outside the repository root. Discovery credited to researcher s3ntago via HackerOne.

[+] CVE-2026-87719 is insecure deserialization in the GraphQL subscription serializer for authenticated Duo Chat users. CVE-2026-88765 is an authenticated Unicode buffer overflow RCE on crafted project import.

[+] watchTowr published hunt logic within 24 hours of patch. Indiscriminate exploitation is assessed likely imminent given the historical GitLab timeline. GitLab has not confirmed exploitation.

StyleSmuggler pre auth template execution.

[+] CVE-2026-75650 (CWE-94) hits Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9.

[+] Unauthenticated GraphQL mutations poison styles objects. When Magento renders transactional email templates the parser executes smuggled PHP as www-data.

[+] Post exploitation: PHP web shell at /pub/media/tmp/catalog_rules.php, compiled Rust ELF at /tmp/.libaudit_systemd, crontab /etc/cron.d/php_session_cleaner, and a UDP beacon that mimics NTP with nine 48 byte datagrams about every 60 seconds.

Artifactory admin in two HTTP calls.

[+] POST /access/api/v1/aws/token/ (trailing slash) returns an anonymous JWT even with anonymous access off (CVE-2026-42018). POST /access/api/v1/tokens upgrades scope (CVE-2026-42016). Logs show token:anonymous.

[+] CVE-2026-82329: unauthenticated POST /access/api/v1/registry/join returns HTTP 201 plus an admin token on default config. Join key theft enables cluster join. Groovy plugin execute is RCE as the Artifactory service user.

[+] Wiz saw sub five minute admin creation, droppers in /dev/shm, /tmp, /var/tmp, and a custom Rust C2. Exposure at disclosure was 67 to 69 percent of Wiz visible orgs. Cloud Artifactory needs no action per JFrog. Tokens survive upgrades.

PaperCut mass compromise, education heavy.

[+] From 2026-08-31 an unnamed operator used 45.142.193[.]132, a Codex harness, DeepSeek, and Netlas targeting against CVE-2026-81578 (auth bypass) and CVE-2026-82078 (unsafe class load RCE).

[+] Outcomes in consulted telemetry: 440 instances, 395 organizations, 48 countries, about 204 of 440 in education, 280 credential harvests, 12 domain admin cases, 11 organizations in 26 seconds at peak. Secret theft counts differ across outlets (147 versus 137) and are flagged as conflicting.

[+] Follow on: LSASS and registry dumps, pass the hash, NoPac (CVE-2021-42278 and CVE-2021-42287 in secondary coverage), Domain Admins add when PaperCut ran as SYSTEM or on a DC, then DCSync. Tools named: Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, custom Rust collectors.

WatchGuard, Mirth Connect, client kits, and adjacent delivery.

[+] CVE-2025-14733 is an out of bounds write in the WatchGuard iked process on Mobile User VPN with IKEv2 and Branch Office VPN with a dynamic gateway peer. CISA now states ransomware groups use it. About 115000 devices were exposed in December 2025 and about 9000 remained open in this window.

[+] Mirth Connect 4.7.1 and earlier: authenticated SQLi via the Database Connector API and XXE. CISA reports no public exploitation as of 2026-09-10. Blast radius is clinical data flow, not confirmed intrusion.

[+] BlueMoon uses a Chromium patch gap on CVE-2026-85046 (V8 type confusion, commit 2026-08-07, stable 2026-09-03) plus CVE-2026-87491 and CVE-2026-85880. Default payload is curl to %TEMP%\msgbox.exe. Sets include TA412 against US NGO and mining with a fake Gemini extension, aerospace with ShadowPad, Vietnamese manufacturing from compromised SEA government mail, and Indonesia and Singapore government and finance.

[+] Sogou IME CVE-2026-51990 abuses the sgbiz: handler and unsandboxed CEF 80, chained with CVE-2021-38003, 7z.dll sideload, and GRAYRABBIT C2 at mail.uaiubifas[.]top:443. Tencent shipped 16.3.0.3498 on 2026-04-21. User prompt requirement is disputed between vendors.

[+] Trezor via Brevo: 120 accounts per Trezor versus 138 in crypto press (conflicting), 347000 newsletter addresses, 2500 clicks, domain killed in 20 minutes. BitBox and CoinTracking also abused. No other Trezor systems touched per Trezor.

[+] WebDAV chain at a Ukrainian government organization delivered Amatera with ZigCryptoStealer and NetSupport Manager secondary payloads, fake CAPTCHA ClickFix, rundll32 ordinal calls, in memory payload, and a vulnerable driver used to terminate EDR. Talos tracks the actor as UAT-10820 and assesses opportunistic theft rather than a tightly targeted campaign. BNB Smart Chain infrastructure was abused for hosting. This item is not linked to FMC.

Intelligence gaps.

[+] No MikroTrick actor name. No public GTG domains or hashes. No vendor confirmed GitLab exploitation. Fortinet PivotC2 victim counts and PaperCut actor language rest on secondary coverage. WatchGuard ransomware family unnamed. Trezor lure FQDN unpublished.

Chapter 03 - Operational Response

MikroTik. Emergency patch and compromise assessment, 72 hour sprint.

[+] Within 24 hours inventory every RouterOS device including branch, third party managed, cloud, and colocation estates.

[+] Upgrade to RouterOS 6.49.21, 7.23.4, 7.24.2, or 7.25beta3. Validate the running version after upgrade, not the change ticket.

[+] Disable or ACL SSH (22), Winbox (8291), and the bandwidth test service from untrusted networks. Restrict administration to a dedicated management network or WireGuard VPN.

[+] Hunt the privileged ops account, unexpected users, scripts, scheduler jobs, tunnels, proxy and DNS changes, and firewall rule modifications. Check logs and Flagged state. Any hit starts incident response. Preserve evidence. Rotate all device secrets.

[+] Block 82.192.72[.]4 at the perimeter. Retro search flow and auth logs since 2026-09-02. A clean vendor Flagged state is not a clean bill of health.

Cisco Secure FMC. Hotfix by 2026-09-12. No workaround.

[+] Apply Cisco hotfixes for 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 immediately. Treat FMC as tier 0. Do not wait for the hardening bundle due the week of 2026-09-14 (one Talos paragraph also says the week of 2026-09-16; treat as next week).

[+] Confirm FMC web interfaces are not internet reachable. Enforce management plane ACLs.

[+] Because exploitation dates to August 2026, review FMC web access logs and OS integrity back to 2026-08-01: unexpected processes, scripts, accounts, home.jsp, cmd.jar, /var/tmp/license.tmp, package_info.pl execution, nc listeners, socks5.py, reverse SSH, Impacket, and Qilin.

[+] Enable Snort SIDs 66075 through 66080, 66883, 66960, and 66961. Snapshot before patch if the UI was WAN reachable.

Citrix, Fortinet, WatchGuard.

[+] NetScaler: upgrade to 14.1-73.32 or 13.1-63.21 or matching FIPS builds. Hunt AAA and nslog for tokens issued without SAML assertions and for alternate path URIs.

[+] FortiOS: patch CVE-2025-25249. Hunt Node.js reverse shells and TLS C2 consistent with PivotC2 descriptions. Treat infection counts as unverified.

[+] Firebox: patch to 12.5.15, 12.11.6, or 2025.1.4 or later. If you cannot patch today, disable IKEv2 Mobile User and Branch Office VPN. Review logs since 2025-12-19. Actor and family are unpublished, so do not wait on IOC feeds.

StyleSmuggler and Artifactory.

[+] Apply Adobe hotfix VULN-39341 (APSB26-146). If Composer lags, WAF block unescaped template operators and raw styles injections to /graphql.

[+] Sweep /pub/media/, /pub/media/tmp/, /tmp/, /var/tmp/, /dev/shm/, and /etc/cron.d/ for PHP and ELF implants. Rotate app/etc/env.php encryption keys, database passwords, payment tokens, and admin credentials if any hit lands.

[+] Artifactory self hosted: upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 per branch. 7.146 and 7.161 still need the 82329 fix. Rotate join keys. Revoke tokens minted since 2026-08-15. Delete unexpected admins including token:anonymous activity and jfrog-* lookalikes. Restrict /access/api/* to build networks.

GitLab, PaperCut, identity, and AI rebuild.

[+] Upgrade self managed GitLab to 19.3.2, 19.2.6, or current 19.1 patch. Run the commits API hunt against reverse proxy and Workhorse logs. If the instance was internet exposed, rotate CI/CD secrets, deploy tokens, and credentials in reachable files.

[+] PaperCut: install MR 26.0.5, 25.0.13, or 24.1.10. Assume RCE if unpatched after 2026-08-31. Hunt LSASS dumps, NoPac, new DA accounts, DCSync, Ligolo-ng, and 45.142.193[.]132. Rotate domain secrets if PaperCut ran as SYSTEM or DA. Education SOCs should treat this as a likely victim population.

[+] Stop relying on hash blocking as the primary control against GTG-20006. Audit M365 sign in logs for device code flow from anomalous geographies or ASNs and review Entra ID consent grants. Alert on WhatsApp companion device linking for high risk personnel. Treat hotel Wi Fi as hostile for diplomatic and defense travelers.

[+] Chrome, Edge, Brave, Vivaldi: force 153.0.8010.36 or later. Hunt chrome.exe to cmd.exe to curl.exe to msgbox.exe, GemStone path C:\Users\Public\stomp_ext, and tasks EdgeCore_AutoUpdate and GeForceService.

[+] Sogou: confirm 16.3.0.3498 or later. Hunt C:\Users\Public\Documents\7z.dll and non TLS TCP/443 to mail.uaiubifas[.]top.

[+] Trezor, BitBox, CoinTracking users: treat newsletter addresses as burned. Never enter a seed into an STM32 updater.

[+] Mirth Connect: inventory versions at or below 4.7.1, restrict Database Connector API and admin access, isolate from general business networks, monitor for unexpected admin access and SQL or XML parse failures.

[+] WebDAV Amatera: hunt WebDAV activity followed by rundll32.exe launching DLL exports by ordinal after a fake verification prompt.

[+] 2025-12-19: CVE-2025-14733 disclosed and added to CISA KEV.

[+] December 2025 through August 2026: Anthropic observes and disrupts GTG-20006 and GTG-10007.

[+] 2026-04-21: Tencent ships Sogou 16.3.0.3498. Public UNC3569 research lands only this week.

[+] July 2026: CVE-2026-20316 exploited and KEV listed late month. Earliest Fortinet CVE-2025-25249 exploit evidence in secondary coverage.

[+] 2026-07-27 / 2026-08-12 / 2026-08-28: Artifactory 42016, 42018, and 82329 disclosed. 67 to 69 percent of Wiz visible orgs vulnerable.

[+] August 2026: Cisco becomes aware of CVE-2026-20079 exploitation.

[+] 2026-08-07 / 2026-09-03: Chromium commit versus Chrome stable for CVE-2026-85046 patch gap.

[+] 2026-08-15 through 2026-09-08: Wiz observes Artifactory token chain and Rust backdoor.

[+] 2026-08-19: Citrix initial advisory for CVE-2026-19490.

[+] 2026-08-27 to 2026-08-28: PaperCut emergency patches for CVE-2026-81578 and CVE-2026-82078.

[+] 2026-08-28: TA412 first BlueMoon use.

[+] 2026-08-31: PaperCut AI agent campaign start from 45.142.193[.]132.

[+] 2026-09-01 through 2026-09-08: Artifactory CVE-2026-82329 exploitation. Fastly attempt spike 2026-09-02.

[+] 2026-09-02: MikroTrick exploitation from 82.192.72[.]4 confirmed as active. CISA KEV for CVE-2026-82329 due 2026-09-05.

[+] 2026-09-02 to 2026-09-03: UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket BlueMoon activity.

[+] 2026-09-03: NetScaler reconnaissance and honeypot attempts begin. 56 attempts through 2026-09-08, 36 on 2026-09-08.

[+] 2026-09-04: Sansec detects StyleSmuggler exploitation against live Magento instances.

[+] 2026-09-05: CERT Polska discloses MikroTrick. ShadowServer measures 122500 exposed devices. Sansec public StyleSmuggler alert.

[+] 2026-09-07: Adobe APSB26-146 and hotfix VULN-39341 for CVE-2026-75650.

[+] 2026-09-08: Cyber Centre Canada AL26-020 on RouterOS. CISA KEV add for CVE-2026-75650.

[+] 2026-09-09: CISA KEV adds CVE-2026-20079, CVE-2026-19490, CVE-2025-25249, CVE-2026-87491. FCEB due 2026-09-12. Talos FMC cluster publication. Google Chrome 153.0.8010.36. Brevo incident and Trezor phishing. CISA updates CVE-2025-14733 for ransomware use.

[+] 2026-09-10: CISA KEV adds CVE-2026-67277 and CVE-2026-86060, due 2026-09-13, BOD 26-04 forensic triage on CVE-2026-86060. GitLab 19.3.2 / 19.2.6 / 19.1.8. Anthropic GTG disclosure. CISA ICSMA-26-253-01 for Mirth Connect. PaperCut MR builds ship 2026-09-11 in follow on coverage.

[+] 2026-09-11: watchTowr GitLab probing. Broader GTG, Artifactory, PaperCut, Sogou, and Trezor reporting. This record published 21:45 IST.

[+] Next checkpoints: 2026-09-12 Cisco, Citrix, Fortinet FCEB deadline. 2026-09-13 MikroTik FCEB deadline. Watch for CVE-2026-85706 KEV addition.

Chapter 04 - Detection Intelligence

MikroTrick chain mechanism.

[+] CVE-2026-67276 fails closed RSA verification. Exponent one makes a forged signature verify trivially once the username and public modulus are known from reconnaissance.

[+] CVE-2026-86060 sits on the same SSH login path. Crafted username input changes the trusted policy mask. Combined result is unauthenticated full admin.

[+] CVE-2026-67277 is a separate unauthenticated remote surface on the bandwidth test service.

[+] Post exploitation confirmed by CERT Polska is creation of a highly privileged ops user that survives reboot and reentry after an in place patch if the account is not removed. Root cause class: input validation failure across authentication, authorization, and an exposed auxiliary service.

FMC boot process, static session, and license.tmp.

[+] CVE-2026-20079 is CWE-288 class. An improperly created boot time process leaves a reusable session identifier. Crafted HTTP to the web UI executes scripts as root.

[+] CVE-2026-20316 is a static credential login to a low privilege account. Operators chained it with the appliance upgrade readiness mechanism.

[+] UAT-11823 and UAT-11988 abused legitimate package_info.pl /var/tmp/license.tmp --lsm so a malicious Makeself archive ran as root. Detection must treat package_info.pl plus unexpected license.tmp as exploitation, not patching.

[+] UAT-12197 planted home.jsp, used parameter F6C1F0E7, and launched cmd.jar to query OmniQuery.pl against mdb user tables.

StyleSmuggler template parser.

[+] The vector lives in Magento\Framework\Filter\Template. GraphQL bodies carrying nested styles with {{template config_path=...}} plus PHP file_put_contents or base64_decode execute when Payment Transaction Failed Reminder or similar templates render.

[+] Resulting implant profile: 485 byte class PHP shells in pub/media, symbol stripped Rust ELF about 1.9 MB posing as .libaudit_systemd, and a tight 48 byte UDP/123 burst of nine datagrams each minute.

Artifactory token algebra.

[+] Trailing slash on /access/api/v1/aws/token/ is load bearing. The handler returns an internal anonymous JWT. Token exchange does not enforce scope. Registry join on default config returns admin.

[+] Persistence blends in as jfrog-distribution, jfrog-insight, repo-service, backup-service, migration-tool, ldap_admin. PoC noise names Nxploited_, 0xTerror, labadmin_ also appeared.

GitLab commits API.

[+] Missing auth plus missing path confinement on /api/v4/projects/{id}/repository/commits/. file.path is the exploit parameter. One unauthenticated HTTP request can return SSH keys, gitlab-secrets.json, database credentials, and CI variables under certain conditions.

PaperCut, Sogou, and BlueMoon mechanics.

[+] PaperCut: authentication bypass then unsafe dynamic class loading under SYSTEM. Domain joined print servers yield LSASS and NTDS. Speed figures (4 hours to first RCE, plus 2 hours to DA, 7 minutes DA on one US high school) are GreyNoise operational telemetry via consulted coverage, not independently remeasured here.

[+] Sogou: sgbiz:sg_process?module=sgmyinput.exe&param=-page=skincenter -url= launches CEF 80 with no_sandbox=TRUE and disable-web-security. Payload uses CVE-2021-38003, a 921 byte downloader, 7-Zip sideload, process count at least 50 anti sandbox, ADS self delete, GRAYRABBIT CoreClientInstall, command IDs 0 through 9, RC4 frames of 0x1000 bytes, key m5b1u3.

[+] BlueMoon: TurboFan/Maglev Array.prototype.sort plus fill() type confusion yields addrof/fakeobj and Float64Array read write (CVE-2026-85046). Wasm body overwrite (CVE-2026-87491) loads recon DLL p1 then LPE DLL p2 then injector pp into the Chrome broker, which runs curl -sS -o %TEMP%\msgbox.exe.

GTG-20006 toolchain.

[+] Modular cross platform kit plus AI verified AV evasion before staging on disposable hosting. Hotel Wi Fi path: stolen hospitality vendor admin credentials, DNS record change, guest fingerprinting, device tailored payload. WhatsApp path: headless browser companion device linking. North Africa path: VPN appliance credential reuse against a central account server.

MikroTrick.

[+] IPv4 82.192.72[.]4 : exploitation origin since 2026-09-02. Malicious.

[+] Account artifact ops : privileged RouterOS user. Compromise indicator.

[+] Service exposure TCP/22, TCP/8291, bandwidth test service internet reachable : attack surface.

Cisco Talos FMC.

[+] SHA256 b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d : home.jsp.

[+] SHA256 db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e : cmd.jar.

[+] SHA256 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 : Cyclops Blink sample.

[+] IPv4 89.34.96[.]56, 208.123.119[.]215, 91.214.78[.]118 : nc / Cyclops C2.

[+] IPv4 104.218.165[.]253 : scanner.

[+] IPv4 43.204.2[.]142 : Qilin cluster associated.

[+] Filenames home.jsp, cmd.jar, license.tmp, socks5.py. Path /var/sf/bin/OmniQuery.pl.

[+] Snort 66075 through 66080, 66883, 66960, 66961.

StyleSmuggler.

[+] IPv4 45.154.255[.]89, 185.196.220[.]44, 194.38.20[.]112, 104.238.169[.]114, 193.142.146[.]211, 89.208.103[.]144 : scanner, staging, C2.

[+] SHA256 e7b99c06d84a1e948f219194ec89420db20775a6f23c7c4f420cb058e578c77e : ELF 64 bit Rust backdoor.

[+] SHA256 4c88cf736fdf5a7db0124ad72eb0fbb9e6ff17482dcfa82e8549306b3a2a694a : PHP web shell.

[+] SHA256 87f6368d184cf4e2f94bf6529813b1a2083510e1189d2d0b57e7a83d73f1d8f1 : stager.

[+] Paths /pub/media/tmp/catalog_rules.php, /tmp/.libaudit_systemd, /etc/cron.d/php_session_cleaner.

[+] URL hxxp://185.196.220[.]44/bins/x86_64_daemon and hxxp://45.154.255[.]89/assets/img/style.css.php.

Artifactory.

[+] IPv4 93.104.155[.]133, 149.102.229[.]150, 186.247.79[.]240, 182.62.201[.]69 (42018/42016).

[+] IPv4 146.19.216[.]120, 185.190.58[.]172, 45.61.176[.]88, 223.144.227[.]110, 129.121.56[.]234, 16.54.250[.]190, 105.188.75[.]16, 103.124.165[.]42, 176.88.121[.]152, 155.254.120[.]23, 220.246.124[.]92, 15.157.64[.]113, 104.28.251[.]139, 137.184.111[.]69 (82329).

[+] URL hxxp://log.gitclone[.]org:45678/smtp and hxxp://3.88.162[.]79:36789/smtp and 64.207.232[.]6:8443.

[+] SHA1 513a907b69edffc3cb77a494da395178d21ef9bd : /tmp/.z.

[+] Accounts Nxploited_[a-zA-Z0-9]{3}, labadmin_, svc_, 0xterror, jfrog-distribution, jfrog-insight, jfrog-mission-control, jfrog-pipeline, repo-service, backup-service, migration-tool, ldap_admin, ldap_administrator, token:anonymous.

PaperCut, Sogou, BlueMoon, GitLab, Trezor.

[+] IPv4 45.142.193[.]132 : PaperCut orchestration.

[+] SHA256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 : 7z.dll.

[+] SHA256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e : p downloader.

[+] SHA256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a : GRAYRABBIT core.dll.

[+] Hosts mail.uaiubifas[.]top:443, noht1ng[.]top, 8.218.50[.]207, path C:\Users\Public\Documents.

[+] BlueMoon process tree chrome.exe to cmd.exe to curl.exe to msgbox.exe. Tasks EdgeCore_AutoUpdate, GeForceService. Path C:\Users\Public\stomp_ext. C2 ms.checrity[.]com / 79.133.56[.]90. Delivery secboxes[.]com, msbenefit[.]com, attcdn[.]com, airproducts[.]ink, precipart[.]ink, rocketlabusa[.]ink, joinmacket[.]com, brianwilli[.]com, fracons[.]com.

[+] URI pattern POST /api/v4/projects//repository/commits/ with file.path : GitLab CVE-2026-85706 probe.

[+] Sender help@trezor[.]io spoofed via Brevo. Lure FQDN unpublished after 20 minute takedown.

Named implant pivots, not blocklist objects.

[+] PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc, GiftDrop, DarkSword, SECOMS64, Embassy Kit, CaptiveCrunch overlap, Cyclops Blink, Qilin, Amatera, ZigCryptoStealer, NetSupport Manager, GRAYRABBIT, GemStone, ShadowPad.

Infrastructure notes.

[+] GTG-20006 stages on disposable hosting only after AI agents confirm AV evasion. Expect short infrastructure half life. Domain lists were not published.

[+] StyleSmuggler beacon profile reported to 99.84.67[.]186 as NTP lookalike in one technical writeup. Confirm before estate wide blocking.

[+] FMC and Firebox often lack EDR. Artifactory may not retain /access/api logs by default. PaperCut AI speed means a 24 hour IR window can miss the intrusion.

[+] No file hashes or C2 domains were published for GTG-20006, WatchGuard ransomware use, or Mirth Connect in this window.

SIGMA. MikroTik privileged account creation.


SIGMA. GitLab CVE-2026-85706 commits API traversal.


SIGMA. StyleSmuggler GraphQL plus web shell drop.


SIGMA. FMC package_info.pl executing license.tmp.


SIGMA. Artifactory anonymous token chain.


SIGMA. BlueMoon default loader.


SIGMA. WatchGuard anomalous IKEv2 volume. Heuristic only. Not verified against a public PoC.


SIGMA. Mirth Connect Database Connector hunt. No confirmed exploitation.


YARA. ClickFix lure HTML scaffold for GTG-20006 pattern. No published samples. Validate before blocking.


YARA. StyleSmuggler Rust backdoor and PHP shell.


YARA. FMC cmd.jar / home.jsp and GRAYRABBIT.

rule UAT12197_FMC_cmd_jar {
  meta:
    hash = "db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e"
  strings:
    $omni = "OmniQuery.pl" ascii
    $auth = "SELECT name, auth_data FROM users" ascii
    $sh = "/bin/sh -c" ascii
  condition:
    filesize < 2MB and 2 of them
}

rule UAT12197_home_jsp {
  strings:
    $p = "F6C1F0E7" ascii
    $b64 = "Base64" ascii
  condition:
    filename matches /home\.

SIEM and EDR field logic.

[+] RouterOS edge: (dst_port == 22 OR dst_port == 8291 OR bandwidth test service) AND dst_asset.type == mikrotik_routeros AND (src_ip == 82.192.72[.]4 OR conn.duration > baseline_p95 OR bytes_out > 10MB) → mikrotrick_edge_anomaly. Retro hunt timestamp >= 2026-09-02T00:00:00Z.

[+] FMC management egress: src_ip IN fmc_inventory AND dest_ip NOT IN approved_update_servers over 24h buckets. Also process_name=package_info.pl AND command CONTAINS license.tmp. Outbound dest_port in (3090) or reverse SSH with forwarded 88/389/445/636/5985.

[+] Magento: event=file_write AND path STARTSWITH pub/media AND ext=php. Pair Payment Transaction Failed Reminder renders with php-fpm child creation within 60s.

[+] NTP masquerade: proto=UDP AND dest_port=123 AND avg_packet_size≈48 AND flows_per_minute≈9 AND interval≈60s FROM web_tier_hosts.

[+] Entra ID device code: authenticationProtocol == deviceCodeFlow AND (geoDistance_from_baseline > 1500km OR asn NOT IN org_baseline_asns) AND newly_consented_app == true → m365_devicecode_anomaly.

[+] Artifactory: uri=/access/api/v1/aws/token/ status 401 then 200 from same src_ip in under 2 minutes. user=token:anonymous AND uri CONTAINS /tokens OR /plugins OR /users.

[+] PaperCut: unauth POSTs to admin UI then Java classload errors. LSASS access from the PaperCut service account. Replication (DCSync) from print server computer accounts.

[+] Sogou: biz_helper.exe to SGMyInput.exe with -url= then 7z.exe from Public\Documents and non TLS TCP/443 to mail.uaiubifas[.]top.

[+] Static detection degradation monitor for GTG-20006: if AV or EDR flags an artifact and a functionally similar new hash appears within N days, classify as AI rebuild candidate and escalate to behavior rules. Do not only add the hash.

[+] Detection context: RouterOS, FMC, and Firebox sit where EDR is often absent. Network auth logs, NetFlow, and config snapshots are the viable sensors.

[+] T1190 Exploit Public Facing Application. Initial Access. Source mapped: MikroTik SSH chain, FMC web UI, GitLab commits API, Magento GraphQL, NetScaler Gateway, FortiOS HTTP, Firebox IKEv2, Artifactory /access/api, PaperCut UI.

[+] T1068 Exploitation for Privilege Escalation. Source mapped: CVE-2026-86060, CVE-2026-20079 root, BlueMoon ALPC/WNF LPE.

[+] T1136.001 Create Account Local Account. Source mapped: RouterOS ops user.

[+] T1505.003 Web Shell. Source mapped: home.jsp in Tomcat, catalog_rules.php in pub/media.

[+] T1078 Valid Accounts. Source mapped: FMC static credentials, Artifactory minted tokens, NetScaler AAA sessions, WhatsApp takeover.

[+] T1133 External Remote Services. Source mapped and inferred: exposed RouterOS SSH, FMC management plane, VPN reuse against the North African appliance.

[+] T1566 and T1566.002 Phishing. Source mapped: GTG-20006 platform, BlueMoon lures, Trezor STM32 lure.

[+] T1204.002 User Execution Malicious File. Inferred from ClickFix paste and run.

[+] T1555.003 Credentials from Web Browsers. Source mapped: SECOMS64 and browser password store theft.

[+] T1528 Steal Application Access Token. Source mapped: Embassy Kit and camera tokens.

[+] T1557 Adversary in the Middle. Inferred from hotel Wi Fi DNS changes.

[+] T1059.004 Unix Shell and T1059.001 PowerShell. Source mapped: netcat FIFO, cmd.jar, Invoke-TheHash.

[+] T1053.003 Cron and T1053.005 Scheduled Task. Source mapped: php_session_cleaner, EdgeCore_AutoUpdate, GeForceService.

[+] T1027 Obfuscated Files. Source mapped and inferred: base64 PHP, stripped Rust, AI rebuilt binaries.

[+] T1105 Ingress Tool Transfer. Source mapped: JAR after JSP, Rust daemons, 7z.dll.

[+] T1046 Network Service Discovery. Source mapped: Cyclops Blink scanning.

[+] T1003 and T1550.002. Source mapped on FMC DB dump. Inferred on PaperCut LSASS, NTDS, DCSync.

[+] T1021.002 SMB, T1021.006 WinRM, T1090 Proxy. Source mapped on the Qilin tunnel path.

[+] T1562.001 Impair Defenses. Source mapped: AV killers before Qilin and EDR killer driver on the WebDAV chain.

[+] T1486 Data Encrypted for Impact. Source mapped: Qilin after FMC. CISA ransomware flag on CVE-2025-14733.

[+] T1176 Browser Extensions. Source mapped: GemStone.

[+] T1574.002 DLL Side Loading. Source mapped: 7z.dll and BlueMoon pairs.

[+] T1070.004 File Deletion. Inferred: Sogou ADS self delete.

[+] T1567 Exfiltration Over Web Service. Inferred: WhatsApp and mail bulk export.

[+] T1095 Non Application Layer Protocol. Inferred: netcat and UDP NTP lookalike beacon.

[+] T1036.005 Match Legitimate Name or Location. Inferred: kworker, fc-cache, chronyd, .libaudit_systemd.

[+] D3FEND control families inferred, not source mapped as IDs: D3-NTA network traffic analysis on edge and FMC egress, D3-PSA process spawn analysis on package_info.pl and chrome to curl, D3-UBA on device code flow, D3-FA and D3-FIM on pub/media and Tomcat webroot, D3-WAF on GraphQL styles and /access/api, D3-FH file hashing explicitly degraded against the GTG rebuild loop.

Chapter 05 - Governance, Risk & Compliance

[+] Regulatory clocks are immediate. BOD 22-01 and BOD 26-04 give FCEB agencies until 2026-09-12 for Cisco FMC CVE-2026-20079, Citrix CVE-2026-19490, and Fortinet CVE-2025-25249, and until 2026-09-13 for MikroTik CVE-2026-67277 and CVE-2026-86060. Missed deadlines are reportable compliance failures.

[+] CVE-2026-86060 carries a forensic triage designation. Agencies must evidence compromise assessment, not just patching. The same pre patch compromise check posture should be applied to internet facing FMC, Magento, Artifactory, and PaperCut even outside federal scope.

[+] NIS2 and related EU duties: early warning within 24 hours and detailed reporting within 72 hours can apply to digital service providers when Citrix gateways, Magento stores, or Artifactory build systems are confirmed compromised.

[+] PCI DSS 4.0: StyleSmuggler on Adobe Commerce threatens Requirement 6.3 and 6.4.3. Scripts in /pub/media/ can touch PAN and SAD and force PFI scoped work.

[+] HIPAA and ICS medical context: Mirth Connect sits in lab, radiology, and billing flows. CISA ICSMA-26-253-01 is constructive notice even without confirmed exploitation.

[+] Education and student data: PaperCut DCSync on school domains can trigger student record notification rules. Confirm locally.

[+] Third party and TPRM: MikroTik often sits in ISP CPE, branch offices, and cages outside inventory. GTG-20006 used hospitality vendors against target personnel. AdaptHealth style privileged vendor access remains the lesson for contractor offboarding and session recording.

[+] Software supply chain: CVE-2026-85706 and the Artifactory token chain threaten build integrity for more than half of the Fortune 100 GitLab installed base and for any org still exposing self hosted Artifactory. Classify both as critical infrastructure in asset tiers. Validate SBOM and artifact signing for the exposure window.

[+] Insurance and disclosure: confirmed MikroTik, FMC, Magento, or Artifactory compromise found in forensics can open cyber insurance notification windows. Preserve /var/tmp, Tomcat webroot, Artifactory access logs from 2026-08-15, PaperCut logs from 2026-08-31, and GitLab production_json or api_json from 2026-09-10 before remediation wipes them.

[+] Board line: unauthenticated flaws on firewall managers and artifact servers are being used for ransomware and backdoors. The US KEV clock for the Cisco, Citrix, and Fortinet set expires 2026-09-12. Mean time from fix availability to deployment on internet facing assets belongs on the board metric list. The FMC flaw was fixed in March and exploited in August.

[+] Emergency change authority should pre authorize out of cycle windows for KEV listed internet facing assets. Normal CAB queues will not survive 24 to 72 hour clocks.

[+] A Japan Digital Agency breach item dated 2026-09-11 was excluded from full incident treatment because consulted registry outlets did not carry it in this window. Revisit next cycle.

Chapter 06 - Adversary Emulation

Run only in a dedicated lab. Never against production security appliances. Do not replay Qilin, Cyclops Blink, or GRAYRABBIT payloads on live networks.

FMC validation.

[+] From an attacker VLAN send crafted HTTP against a patched versus unpatched lab FMC. Success: unpatched returns script exec as root. Patched returns 401 or 403. Confirm management plane HTTP telemetry exists at all.

[+] Wrap a benign id in a Makeself license.tmp and invoke package_info.pl. Detection Intelligence must fire. This proves the LOTL path, not an implant.

[+] Plant a canary JSP that writes a timestamp in the lab Tomcat webroot. Measure file write detection time.

[+] Launch a contained netcat listener from the lab FMC and a port sweep of the lab management subnet. Egress and scanning from security infrastructure must alert, not be trusted source noise.

MikroTrick validation.

[+] Attempt SSH with a partial match RSA key and crafted username payloads against a lab RouterOS build. Login failure logging must reach SIEM.

[+] Create a test privileged local account. Account creation Sigma and a nightly /user print plus /system scheduler print diff must both catch it.

[+] Place controlled persistence then apply the vendor update. Demonstrate to stakeholders that a clean Flagged state is not a clean bill of health.

StyleSmuggler and GitLab validation.

[+] On an isolated Magento 2.4.8 without VULN-39341, POST a GraphQL mutation with a canary comment inside styles. WAF must block {{template directives. Write a benign PHP canary to /pub/media/tmp/ and confirm auditd or EDR.

[+] From a lab web host send nine 48 byte UDP datagrams to port 123 every 60 seconds. NTP masquerade flow analytics must fire.

[+] Replay a safe commits API request with file.path pointed at a canary file against patched GitLab 19.3.2. Request must fail closed and the commits API Sigma must still alert.

Artifactory, PaperCut, identity, and client side.

[+] POST /access/api/v1/aws/token/ with and without the trailing slash. Confirm the 401 then 200 signature is gone after upgrade. POST /access/api/v1/registry/join must not return 201 admin.

[+] After PaperCut MR upgrade, unauth configuration change to classload must fail closed.

[+] Simulate device code flow from a non baseline ASN against a test tenant. Identity detections, not email gateways, must fire.

[+] Generate chrome.exe to cmd.exe to curl.exe writing %TEMP%\msgbox.exe without the exploit itself. EDR must fire.

[+] ClickFix drill: training tenant lure requiring paste to run. Measure execution layer alerting rather than URL blocking.

[+] AI rebuild simulation: take a benign flagged artifact, repack it to a new hash, redeploy. Behavioral detection must still fire. If it does not, the control gap matches GTG-20006.

Success criteria.

[+] Every step produces an alert with an owner, a triage path, and a measured detection time. Any step with no telemetry is a coverage gap to close in the same cycle as KEV patching.

Intelligence Confidence82%

Item

Score

Why it holds

Why it is capped

Cisco FMC

88

Cisco Talos primary cluster writeup plus CISA KEV and hotfix detail

Public IOC set incomplete versus the full private Talos list; hardening date wording conflicts across paragraphs

MikroTrick

92

CISA KEV, Cyber Centre Canada AL26-020, CERT Polska disclosure, ShadowServer count

No actor name; exposure snapshot dated 2026-09-05

StyleSmuggler

90

Adobe bulletin, CISA KEV, Sansec technical chain, published hashes and paths

Beacon destination confirmed in one technical writeup only

Artifactory

88

Wiz in the wild chain plus vendor patch branches

Scanner versus operator mix on IPs; Fastly attempt counts are not compromises

GitLab

62

Vendor CVEs and watchTowr probing

Exploitation versus probe not settled; GitLab has not confirmed in the wild use

GTG-20006 / GTG-10007

70

Primary vendor victimology and CaptiveCrunch overlap named across multiple vendors

Hedged consistent with attribution; zero public IOCs

PaperCut

68

Multi outlet telemetry, MR builds shipped

Actor unnamed; secret theft counts conflict; CVSS recap figures unconfirmed

WatchGuard ransomware flag

85

CISA KEV update is authoritative

No family, no victims, no IOCs; remaining exposure is an estimate

Citrix / Fortinet / Chrome

84

CISA KEV plus vendor patches

Fortinet victim counts and PivotC2 detail are secondary only

BlueMoon / Sogou / Trezor / Mirth / WebDAV

55 to 65

Vendor or CISA technical facts exist

Client kits rest on research disclosures; Mirth unexploited; WebDAV is single source; Trezor FQDN unpublished

Record rollup

82

No conclusion rests on a single weak outlet

Thin items were kept for defender action but not allowed to lift the score