Cyber Threat Intelligence | PacketWatch

Cyber Threat Intelligence Report | 10/5/2026 | PacketWatch

Written by PacketWatch Team Sixty43 | October 6, 2026

 

This week, for Cybersecurity Awareness Month, we briefed our clients on the basics. While it may seem trivial, fundamentals will thwart most cyberattacks.


 KEY TAKEAWAYS 

  • Cybersecurity Awareness Month Part 1 – The Basics. Review of passwords, MFA, patching, logging, auditing, backups, and configurations.

  • Critical and high-severity vulnerabilities Citrix, Check Point, F5, Cisco, Fortinet, TeamViewer, Dell, and Kiteworks, plus updates to CISA KEV, patch now!


 

Cybersecurity Awareness Month | Part 1 – The Basics

October is Cybersecurity Awareness Month, and in this week's report, we will touch on some key cybersecurity fundamentals that are often overlooked. While these topics may seem trivial, these basic fundamentals will go a long way toward thwarting most cyberattacks, including ransomware. The rise of AI usage in cyberattacks makes these fundamentals even more important, as these systems will commonly abuse them if they are not implemented or configured correctly. 

 

Passwords

It's almost the end of 2026, and some of the most common passwords used today are still "Password!", "123456", and "Fall2026". Poor passwords, combined with a lack of multi-factor authentication (MFA), make it trivially easy for adversaries to brute-force or simply guess the correct password of their target, even on administrator accounts.

 

Making a Strong Password

There are two simple methods for creating and storing secure passwords. One is to use a password manager. These tools have random password generators built in, making it just a single click to generate a strong random password. These passwords can be extremely random and complex, as the user does not need to actually remember them; they will be stored in the password vault. Most modern password managers have web browser extensions that work seamlessly with web authentication pages. Do NOT store passwords in the web browser itself, use a password manager.

An alternative method is to make long, secure passwords that are memorable. This can be done with passphrases. Here's an example of how to build one:

  • Start with a phrase or series of words that are memorable, such as "Four score and seven years ago".
  • Chain the words together: four_score_and_seven_years_ago
  • Optionally modify one or more of the words in a memorable way: five_score_and_twelve_years_ago
  • Add a cypher to the passphrase. In this example, every second letter of each word will be capitalized, and every second vowel (if there are two vowels in the word) will be changed to numbers or special characters: fIv3_sCor3_aNd_tWelv3_yE@rs_aG0

With these short, simple steps, we have taken a regular phrase and turned it into a virtually uncrackable password that is easy to remember. 

 

How Often Should Passwords be Changed

Traditionally, accepted practice was to rotate passwords at regular intervals (every 30-90 days). With this method however, it has been shown that even with complexity requirements such as upper and lower case, numbers, and special characters, changing passwords this frequently forced users to make increasingly simpler and easier to guess passwords over time, actually making password strengths weaker.

NIST guidelines now suggest having users set strong, secure passwords once, and only rotate them if there is evidence of a compromise. 

 

Multi-factor Authentication

Multi-factor authentication (MFA) is one of the most effective ways to protect against unauthorized access of accounts. Regardless of how secure a password is, eventually they get leaked in data breaches. If threat actors are able to obtain these credentials, and the target account does not have MFA, the threat actor can trivially authenticate to the target account and gain initial access to the target environment. MFA should be enabled across ALL accounts for at least every account and application that is internet facing. While MFA is not a silver bullet, it greatly increases the amount of effort required for a threat actor to gain access to an account.

 

Patching

Remote exploitation of unpatched vulnerabilities continues to be one of the most effective ways for threat actors to gain an initial foothold in a target environment. Most cybercriminals, especially modern ransomware groups, tend to abuse known vulnerabilities to gain initial access. With advances in AI accelerating vulnerability discovery and exploit development, patching is more critical now than it has ever been before.

When planning your patch management program, ensure that ALL internet-exposed devices and services are patched regularly. This includes security devices themselves. Firewalls, load balancers, proxies and gateways, have all had critical remote code execution vulnerabilities in recent years. For these types of critical vulnerabilities, having an emergency patch management system in place is crucial, as threat actors historically abuse and exploit vulnerabilities of these devices within 24 hours of vulnerability disclosure. Ensuring that all internet-facing devices and services are fully patched at all times will greatly reduce your organization's attack surface.

 

Logging

Most organizations do not have the budget or manpower to maintain a central logging system. This means that logs are stored locally on each device. In last November's Threat Intel Report article "Where the Wild Logs Are (Revisited)", it posed a hypothetical scenario where your organization faces a ransomware outbreak, and the IR team requests logs from various devices such as firewalls, virtual machines, and various servers. Without central logging, how do you get those logs? What is the retention policy for logs on each device? What types of events are being logged on each device? What are the commands to run on each device to export the logs?

If the answers to these questions are not known ahead of time, days can be wasted figuring out the answer, and in the context of an IR, this can be devastating. By the time a solution is figured out of how to export logs from your firewall, the data that is needed may have already rolled over, and the data is gone forever. Understand where your logs are and how long they live in your environment. Document the findings and practice exporting logs from various devices at regular intervals.

 

Auditing

As organizations age and grow, user counts grow higher, networks get bigger, and more systems come online. Inevitably, staff with detailed knowledge of the network leave or retire, employees quit, and systems change. Over time, accounts and devices are forgotten, ports are left open, and documentation becomes outdated. Routinely auditing different aspects of the network will help keep documentation up to date and help keep up network hygiene.

  • Users - Ensure accounts in Active Directory are for active users only. Employees who have left the company should no longer have accounts or access to any systems (including 3rd party assets). For active users, ensure each user is assigned to the proper group and only has enough permissions to complete their work (least privilege). Administrative access should be delegated to as few accounts as possible.
  • Endpoints - Ensure all endpoints have EDR coverage and have the proper GPO policies. Rogue or unmanaged devices on the network are a blind spot for security and IT, and give threat actors a way to persist on the network undetected.
  • Network (Firewall rules/network segmentation) - Routinely review firewall rules to ensure proper access control rules are in place at all times. It is often the case where a set of systems on a subnet will be swapped out for a different system using different ports and services, but the firewall rules remain either unchanged, or new ports are opened but the old ones are not closed. Only ports and services that are absolutely necessary to the function of the system should be open. Additionally, review network segmentation to ensure only systems that are supposed to talk to each other can talk to each other. Can the Guest Wi-Fi network reach the Active Directory servers directly? Can the HR system directly connect to production servers?

 

Backups

Data backup solutions are one of the most effective ways to reduce the potential damage of a ransomware incident. Critical data should be backed up regularly, and the data should ideally be stored in multiple locations (on-site and off-site). Once a backup solution is in place, it is also important to regularly test the backup solution. It is often the case where after a ransomware incident, the organization will attempt to restore from backup only to discover that the backups don't work or that the data is corrupted. By regularly testing the backup and restore process, this helps ensure that the system is working to the organization's needs, and will reduce the time for restoration in the event of a ransomware attack.

Additionally, having a "Gold Image" for endpoint restoration will greatly reduce the time to recovery, especially if the backup solution fails or is compromised. These images should also be updated on a regular basis to fit the needs of the organization.

 

(Mis)configurations

Threat actors will often exploit misconfigurations to achieve their goals. This often includes default passwords on network devices (admin:admin), open ports and services that are unused or unnecessary (RDP exposed to the internet). Misconfigurations also include improper setup of security tools, such not enabling "prevent" on EDR or IDS/IPS solutions. It is often the case where a security tool will identify malicious behavior, but due to improper configurations, the tool will either not alert at all, or just simply send a notification that malicious activity is occurring, but not do anything to block or prevent it. Spending the extra time to properly tune and configure security devices will help the organization get the maximum benefit from their investment. 

 

Conclusion

Reading cybersecurity news today can be terrifying, with constant 0-day threats, AI systems wreaking havoc across the internet, ransomware and data breaches impacting organizations all over the world. These headlines have a way of convincing security stakeholders that they need the latest and greatest advanced security toolset to protect themselves against modern threats. However, in most cases, cyber intrusions still happen in very predictable and preventable ways. Going back to security fundamentals and ensuring all the "low-hanging fruit" is removed will go an incredibly long way toward preventing the next cyber attack. 

 

 

Vulnerability Roundup

 

Citrix NetScaler 0-days Under Active Exploitation 

On September 27, Citrix confirmed rumors that two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were being actively exploited in the wild. These vulnerabilities are as follows:

  • CVE-2026-88771 - Improper input validation flaw that allows an unauthenticated remote attacker to run arbitrary commands, affecting all NetScaler ADC and NetScaler Gateway deployments.
  • CVE-2026-88772 - Memory overflow flaw that can lead to remote code execution or denial-of-service, affecting appliances with DTLS enabled (default configuration for VPN virtual servers).

The fixed versions are as follows:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The Citrix advisory and the patches listed above also address 6 other high-severity vulnerabilities.

Documented exploitation attempts go back to at least September 22. Post-exploitation activity is also varied depending on which report you read. However, a common thread is the deployment of a webshell on the impacted server. In addition to applying the patches, administrators are strongly encouraged to review Citrix NetScaler servers for indicators of compromise. Detailed post-compromise reviews and indicators of compromise can be found here and here.

 

Citrix NetScaler Denial-of-Service 0-day

Over the weekend, Citrix disclosed yet another actively exploited vulnerability in their NetScaler ADC and NetScaler Gateway products. Tracked as CVE-2026-88779, this memory overflow flaw can lead to a denial-of-service condition "under specific deployment conditions." For the vulnerability to be successfully exploited, the NetScaler ADC or NetScaler Gateway device must be configured either as a SAML service provider (SP) or SAML identity provider (IdP). The fixed versions are listed below:

  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Administrators are urged to apply the patch as soon as possible as it is under active exploitation.

 

Check Point Management Server 0-day

Check Point recently disclosed CVE-2026-93616, a critical directory traversal and file upload vulnerability affecting Check Point Management Server that is under active exploitation. Successful exploitation allows an unauthenticated attacker to execute arbitrary scripts on affected systems. The following versions are affected:

  • R82.20
  • R82.10 Jumbo Hotfix Take 44 or lower
  • R82 Jumbo Hotfix Take 126 or lower
  • R81.20 Jumbo Hotfix Take 166 or lower
  • R81.10 Jumbo Hotfix Take 190 or lower (EoS)
  • R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)

Administrators are urged to apply the Hotfix as soon as possible. Additional mitigations include restricting access to port TCP/19009 to only trusted IP addresses, and restricting Trusted Clients to trusted internal IP addresses.



F5 BIG-IP APM 0-Day Actively Exploited

F5 recently disclosed an actively exploited critical-severity flaw in their BIG-IP Access Policy Manager (APM) systems. Tracked as CVE-2026-94127, successful exploitation allows an unauthenticated remote attacker to perform remote code execution. The vulnerability affects systems where APM acts as an OAuth authorization server along with the following software versions:

 

Fig. 1: F5 BIG-IP APM vulnerable versions and corresponding Hotfix | Source: TheHackerNews

 

 

Cisco SD-WAN 0-Day Actively Exploited

 Cisco recently disclosed a 0-day authentication bypass vulnerability in their Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, successful exploitation allows an unauthenticated remote attacker to access an affected system with privileges of the admin user. Additional indicators of compromise that can be found in the Catalyst SD-WAN Manager server logs can be reviewed in the advisory here. Administrators are urged to apply the patch and review server logs as soon as possible. The table below shows vulnerable SD-WAN Manager versions and their corresponding fixes:

 

Fig. 2: Cisco Catalyst SD-WAN vulnerable versions and corresponding fixed releases | Source: Cisco

 

 

Fortinet FortiMail 0-Day Actively Exploited

On October 1, Fortinet published an advisory detailing a critical path traversal 0-day vulnerability in their FortiMail product. Tracked as CVE-2026-104286, successful exploitation allows an unauthenticated attacker to write arbitrary files on the underlying system via HTTP or HTTPs requests. Administrators are urged to apply the updates as soon as possible. Additional workarounds and event log indicators of compromise can be found in the Fortinet advisory. The chart below shows affected versions and their corresponding fixed version. 

 

Fig. 3: FortiMail vulnerable versions and corresponding fixes | Source: Fortinet

 

 

Multiple High-Severity Vulnerabilities in TeamViewer

TeamViewer recently addressed a series of vulnerabilities, including a high-severity access control bypass flaw that affects the TeamViewer Full Client and Host software for Windows, Linux, and MacOS. Tracked as CVE-2026-92370, successful exploitation can allow an authenticated threat actor to perform unauthorized actions potentially leading to remote code execution. Administrators are urged to upgrade to version 15.82 or higher as soon as possible.

 

Multiple Critical Vulnerabilities in Dell Container Storage Modules

On October 1, Dell released fixes for a series of maximum-severity and critical vulnerabilities for their Container Storage Modules (CSM) products. The most severe of these vulnerabilities are CVE-2026-63688 & CVE-2026-63692, both of which carry a maximum-severity CVSS score of 10.0, and are both due to missing authentication for critical functions. Successful exploitation of these vulnerabilities allow an unauthenticated remote attacker to take over the system. Administrators are urged to upgrade to version 1.18.0 or later as soon as possible. In addition to applying the patch, Dell also recommends rotating any JWT signing secrets.

 

Maximum-Severity Vulnerability in Kiteworks Email Protection Gateway

Kiteworks, formerly known as Accellion, issued patches for 126 vulnerabilities across their products, including a maximum-severity flaw affecting Kiteworks Email Protection Gateway versions below 9.4.1. Tracked as CVE-2026-54154, the vulnerability allows an unauthenticated remote attacker to execute arbitrary code, which can then be chained with other flaws to gain full administrative control of the server. Administrators are urged to apply the patches as soon as possible.

 

CISA KEV Additions

The following vulnerabilities were added to CISA's Known Exploited Vulnerabilities Catalog in the last 2 weeks:

  • CVE-2026-102489 - Zammad GmbH Zammad Session Fixation Vulnerability
  • CVE-2026-102490 - Zammad GmbH Zammad Improper Privilege Management Vulnerability
  • CVE-2026-104286 - Fortinet FortiMail Path Traversal Vulnerability
  • CVE-2026-76504 - Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
  • CVE-2026-86950 - Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-88771 - Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 - Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-87902 - WordPress Core Remote File Inclusion Vulnerability
  • CVE-2026-65660 - Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-67279 - Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
  • CVE-2026-71362 - Adobe Commerce and Magento Incorrect Authorization Vulnerability
  • CVE-2026-5430 - WSO2 Multiple Products Path Traversal Vulnerability
  • CVE-2026-85102 - Check Point Multiple Products Improper Certificate Validation Vulnerability
  • CVE-2026-93616 - Check Point Multiple Products Path Traversal Vulnerability
  • CVE-2026-94127 - F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
  • CVE-2026-93952 - Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
  • CVE-2026-7273 - Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability


 

 

This report is provided FREE to the cybersecurity community.

Visit our Cyber Threat Intelligence Blog for additional reports.

Visit our Cyber Threat Profile Blog for detailed intelligence profiles.

Visit our Beyond the Threat Feed Blog for more articles.

 

Subscribe to be notified of future Reports:

NOTE
We have enhanced our report with data from SOCRadar. You may need to register to view their threat intelligence content.