11 min read
Cyber Threat Intelligence Report
This week, for Cybersecurity Awareness Month, we briefed our clients on the basics. While it may seem trivial, fundamentals will thwart most...
This week, for Cybersecurity Awareness Month, we briefed our clients on the basics. While it may seem trivial, fundamentals will thwart most cyberattacks.
KEY TAKEAWAYS
Cybersecurity Awareness Month Part 1 – The Basics. Review of passwords, MFA, patching, logging, auditing, backups, and configurations.
Critical and high-severity vulnerabilities Citrix, Check Point, F5, Cisco, Fortinet, TeamViewer, Dell, and Kiteworks, plus updates to CISA KEV, patch now!
October is Cybersecurity Awareness Month, and in this week's report, we will touch on some key cybersecurity fundamentals that are often overlooked. While these topics may seem trivial, these basic fundamentals will go a long way toward thwarting most cyberattacks, including ransomware. The rise of AI usage in cyberattacks makes these fundamentals even more important, as these systems will commonly abuse them if they are not implemented or configured correctly.
Passwords
It's almost the end of 2026, and some of the most common passwords used today are still "Password!", "123456", and "Fall2026". Poor passwords, combined with a lack of multi-factor authentication (MFA), make it trivially easy for adversaries to brute-force or simply guess the correct password of their target, even on administrator accounts.
Making a Strong Password
There are two simple methods for creating and storing secure passwords. One is to use a password manager. These tools have random password generators built in, making it just a single click to generate a strong random password. These passwords can be extremely random and complex, as the user does not need to actually remember them; they will be stored in the password vault. Most modern password managers have web browser extensions that work seamlessly with web authentication pages. Do NOT store passwords in the web browser itself, use a password manager.
An alternative method is to make long, secure passwords that are memorable. This can be done with passphrases. Here's an example of how to build one:
With these short, simple steps, we have taken a regular phrase and turned it into a virtually uncrackable password that is easy to remember.
How Often Should Passwords be Changed
Traditionally, accepted practice was to rotate passwords at regular intervals (every 30-90 days). With this method however, it has been shown that even with complexity requirements such as upper and lower case, numbers, and special characters, changing passwords this frequently forced users to make increasingly simpler and easier to guess passwords over time, actually making password strengths weaker.
NIST guidelines now suggest having users set strong, secure passwords once, and only rotate them if there is evidence of a compromise.
Multi-factor Authentication
Multi-factor authentication (MFA) is one of the most effective ways to protect against unauthorized access of accounts. Regardless of how secure a password is, eventually they get leaked in data breaches. If threat actors are able to obtain these credentials, and the target account does not have MFA, the threat actor can trivially authenticate to the target account and gain initial access to the target environment. MFA should be enabled across ALL accounts for at least every account and application that is internet facing. While MFA is not a silver bullet, it greatly increases the amount of effort required for a threat actor to gain access to an account.
Patching
Remote exploitation of unpatched vulnerabilities continues to be one of the most effective ways for threat actors to gain an initial foothold in a target environment. Most cybercriminals, especially modern ransomware groups, tend to abuse known vulnerabilities to gain initial access. With advances in AI accelerating vulnerability discovery and exploit development, patching is more critical now than it has ever been before.
When planning your patch management program, ensure that ALL internet-exposed devices and services are patched regularly. This includes security devices themselves. Firewalls, load balancers, proxies and gateways, have all had critical remote code execution vulnerabilities in recent years. For these types of critical vulnerabilities, having an emergency patch management system in place is crucial, as threat actors historically abuse and exploit vulnerabilities of these devices within 24 hours of vulnerability disclosure. Ensuring that all internet-facing devices and services are fully patched at all times will greatly reduce your organization's attack surface.
Logging
Most organizations do not have the budget or manpower to maintain a central logging system. This means that logs are stored locally on each device. In last November's Threat Intel Report article "Where the Wild Logs Are (Revisited)", it posed a hypothetical scenario where your organization faces a ransomware outbreak, and the IR team requests logs from various devices such as firewalls, virtual machines, and various servers. Without central logging, how do you get those logs? What is the retention policy for logs on each device? What types of events are being logged on each device? What are the commands to run on each device to export the logs?
If the answers to these questions are not known ahead of time, days can be wasted figuring out the answer, and in the context of an IR, this can be devastating. By the time a solution is figured out of how to export logs from your firewall, the data that is needed may have already rolled over, and the data is gone forever. Understand where your logs are and how long they live in your environment. Document the findings and practice exporting logs from various devices at regular intervals.
Auditing
As organizations age and grow, user counts grow higher, networks get bigger, and more systems come online. Inevitably, staff with detailed knowledge of the network leave or retire, employees quit, and systems change. Over time, accounts and devices are forgotten, ports are left open, and documentation becomes outdated. Routinely auditing different aspects of the network will help keep documentation up to date and help keep up network hygiene.
Backups
Data backup solutions are one of the most effective ways to reduce the potential damage of a ransomware incident. Critical data should be backed up regularly, and the data should ideally be stored in multiple locations (on-site and off-site). Once a backup solution is in place, it is also important to regularly test the backup solution. It is often the case where after a ransomware incident, the organization will attempt to restore from backup only to discover that the backups don't work or that the data is corrupted. By regularly testing the backup and restore process, this helps ensure that the system is working to the organization's needs, and will reduce the time for restoration in the event of a ransomware attack.
Additionally, having a "Gold Image" for endpoint restoration will greatly reduce the time to recovery, especially if the backup solution fails or is compromised. These images should also be updated on a regular basis to fit the needs of the organization.
(Mis)configurations
Threat actors will often exploit misconfigurations to achieve their goals. This often includes default passwords on network devices (admin:admin), open ports and services that are unused or unnecessary (RDP exposed to the internet). Misconfigurations also include improper setup of security tools, such not enabling "prevent" on EDR or IDS/IPS solutions. It is often the case where a security tool will identify malicious behavior, but due to improper configurations, the tool will either not alert at all, or just simply send a notification that malicious activity is occurring, but not do anything to block or prevent it. Spending the extra time to properly tune and configure security devices will help the organization get the maximum benefit from their investment.
Conclusion
Reading cybersecurity news today can be terrifying, with constant 0-day threats, AI systems wreaking havoc across the internet, ransomware and data breaches impacting organizations all over the world. These headlines have a way of convincing security stakeholders that they need the latest and greatest advanced security toolset to protect themselves against modern threats. However, in most cases, cyber intrusions still happen in very predictable and preventable ways. Going back to security fundamentals and ensuring all the "low-hanging fruit" is removed will go an incredibly long way toward preventing the next cyber attack.
Vulnerability Roundup
On September 27, Citrix confirmed rumors that two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were being actively exploited in the wild. These vulnerabilities are as follows:
The fixed versions are as follows:
The Citrix advisory and the patches listed above also address 6 other high-severity vulnerabilities.
Documented exploitation attempts go back to at least September 22. Post-exploitation activity is also varied depending on which report you read. However, a common thread is the deployment of a webshell on the impacted server. In addition to applying the patches, administrators are strongly encouraged to review Citrix NetScaler servers for indicators of compromise. Detailed post-compromise reviews and indicators of compromise can be found here and here.
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
https://sh3llc0d3.com/blog/inside-the-netscaler-zero-day-siege-chained-pre-auth-rces-weaponized-in-the-wild-watchtowr-disclosure/
https://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/
Over the weekend, Citrix disclosed yet another actively exploited vulnerability in their NetScaler ADC and NetScaler Gateway products. Tracked as CVE-2026-88779, this memory overflow flaw can lead to a denial-of-service condition "under specific deployment conditions." For the vulnerability to be successfully exploited, the NetScaler ADC or NetScaler Gateway device must be configured either as a SAML service provider (SP) or SAML identity provider (IdP). The fixed versions are listed below:
Administrators are urged to apply the patch as soon as possible as it is under active exploitation.
https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html
Check Point recently disclosed CVE-2026-93616, a critical directory traversal and file upload vulnerability affecting Check Point Management Server that is under active exploitation. Successful exploitation allows an unauthenticated attacker to execute arbitrary scripts on affected systems. The following versions are affected:
Administrators are urged to apply the Hotfix as soon as possible. Additional mitigations include restricting access to port TCP/19009 to only trusted IP addresses, and restricting Trusted Clients to trusted internal IP addresses.
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
F5 recently disclosed an actively exploited critical-severity flaw in their BIG-IP Access Policy Manager (APM) systems. Tracked as CVE-2026-94127, successful exploitation allows an unauthenticated remote attacker to perform remote code execution. The vulnerability affects systems where APM acts as an OAuth authorization server along with the following software versions:
Fig. 1: F5 BIG-IP APM vulnerable versions and corresponding Hotfix | Source: TheHackerNews
Cisco recently disclosed a 0-day authentication bypass vulnerability in their Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, successful exploitation allows an unauthenticated remote attacker to access an affected system with privileges of the admin user. Additional indicators of compromise that can be found in the Catalyst SD-WAN Manager server logs can be reviewed in the advisory here. Administrators are urged to apply the patch and review server logs as soon as possible. The table below shows vulnerable SD-WAN Manager versions and their corresponding fixes:
Fig. 2: Cisco Catalyst SD-WAN vulnerable versions and corresponding fixed releases | Source: Cisco
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
On October 1, Fortinet published an advisory detailing a critical path traversal 0-day vulnerability in their FortiMail product. Tracked as CVE-2026-104286, successful exploitation allows an unauthenticated attacker to write arbitrary files on the underlying system via HTTP or HTTPs requests. Administrators are urged to apply the updates as soon as possible. Additional workarounds and event log indicators of compromise can be found in the Fortinet advisory. The chart below shows affected versions and their corresponding fixed version.
Fig. 3: FortiMail vulnerable versions and corresponding fixes | Source: Fortinet
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
TeamViewer recently addressed a series of vulnerabilities, including a high-severity access control bypass flaw that affects the TeamViewer Full Client and Host software for Windows, Linux, and MacOS. Tracked as CVE-2026-92370, successful exploitation can allow an authenticated threat actor to perform unauthorized actions potentially leading to remote code execution. Administrators are urged to upgrade to version 15.82 or higher as soon as possible.
On October 1, Dell released fixes for a series of maximum-severity and critical vulnerabilities for their Container Storage Modules (CSM) products. The most severe of these vulnerabilities are CVE-2026-63688 & CVE-2026-63692, both of which carry a maximum-severity CVSS score of 10.0, and are both due to missing authentication for critical functions. Successful exploitation of these vulnerabilities allow an unauthenticated remote attacker to take over the system. Administrators are urged to upgrade to version 1.18.0 or later as soon as possible. In addition to applying the patch, Dell also recommends rotating any JWT signing secrets.
https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities
https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html
Kiteworks, formerly known as Accellion, issued patches for 126 vulnerabilities across their products, including a maximum-severity flaw affecting Kiteworks Email Protection Gateway versions below 9.4.1. Tracked as CVE-2026-54154, the vulnerability allows an unauthenticated remote attacker to execute arbitrary code, which can then be chained with other flaws to gain full administrative control of the server. Administrators are urged to apply the patches as soon as possible.
The following vulnerabilities were added to CISA's Known Exploited Vulnerabilities Catalog in the last 2 weeks:
This report is provided FREE to the cybersecurity community.
Visit our Cyber Threat Intelligence Blog for additional reports.
Visit our Cyber Threat Profile Blog for detailed intelligence profiles.
Visit our Beyond the Threat Feed Blog for more articles.
Subscribe to be notified of future Reports:
NOTE
We have enhanced our report with data from SOCRadar. You may need to register to view their threat intelligence content.
11 min read
This week, for Cybersecurity Awareness Month, we briefed our clients on the basics. While it may seem trivial, fundamentals will thwart most...
8 min read
This week, we briefed our clients on a CISA/NSA document, "Detecting and Mitigating Active Directory Compromises." Be sure to implement these AD...
8 min read
This week, we briefed our clients on a new ClickFix variant, TerminalFix, that establishes a Websocket tunnel to the threat actor's C2 domain.