Threat Research · All Posts
The Research Blog
Field notes, threat breakdowns, and what the fleet is catching — published as we capture it. Every number we print is measured on our own sensors or attributed to its source.
FLEET TELEMETRY 2026-09-04 After the login: what bots sent to a fake FortiGate Across 53,509 sessions, a FortiGate-persona decoy captured 44 command sessions. Seventeen sessions from eight sources resubmitted the same Linux profiling sequence unchanged, alongside GPU checks, password guessing, and an SSH-first loader. Read → ACTIVE EXPLOITATION 2026-09-03 SMA1000 is being exploited again. Third time in nine months. SonicWall confirms active exploitation of two new SMA1000 flaws. CISA added both to KEV with a September 5 deadline. The builds that fixed July are affected again, and Rapid7 assesses the flaws can potentially be chained to unauthenticated remote code execution. Read → VULNERABILITY 2026-08-26 A public PoC changes the priority, not the evidence: CVE-2026-41551 Siemens documents unauthenticated arbitrary file read and write in the ROS# file_server service, and rates it CVSS v4.0 9.3. The fixed release shipped on 22 April 2026, before the advisory. What changed on 25 August is that an independent public proof-of-concept appeared demonstrating the read path. That lowers the effort required to test this flaw. It is not, on its own, evidence that anyone is exploiting it. Read → VULNERABILITY 2026-08-14 The Overflow That Owns the Gateway: CVE-2026-8452 Citrix disclosed this NetScaler flaw in late June and called it a crash. On August 14 a working proof of concept turned the same SAML signature bug into unauthenticated remote code execution as root, with persistence. There is no workaround and no confirmed in-the-wild use of this CVE yet, but the sibling flaw from the same bulletin was exploited within 24 hours, and it was caught on decoy infrastructure. Read → ACTIVE EXPLOITATION 2026-08-12 The Request That Reboots the Firewall: CVE-2026-20349 An actively exploited, unauthenticated denial of service in the Remote Access SSL VPN of Cisco ASA and FTD. One crafted HTTP request reloads the firewall, taking the perimeter, the remote access, and the box's own logs down together. Industrials are the top exposed sector, roughly 19,200 instances face the internet, and the federal deadline is August 14. Read → ACTIVE EXPLOITATION 2026-08-09 Public Exploit Code Is Now Circulating for a Root-Level Palo Alto Firewall Bug: CVE-2026-0300 CVE-2026-0300 gives unauthenticated code execution as root on PA-Series and VM-Series firewalls where the User-ID Authentication Portal is exposed. Disclosed and patched in May, but this week the public exploit tooling matured into a documented exploit with a payload generator and a packaged scanner. We add what our firewall and VPN decoys actually see: roughly 8,000 source IPs, about 2,000 of them research scanners we set aside, and the default credential still being sprayed. Read → ACTIVE EXPLOITATION 2026-08-04 The Public Exploit Has Landed on a VPN Gateway a Ransomware Crew Already Owns: CVE-2026-15409 and CVE-2026-15410 Three weeks after two chained SonicWall SMA 1000 zero-days hit CISA KEV, the two things responders feared most both arrived: a public proof of concept on August 3, and a KEV ransomware flag on August 4, with INC Ransomware named the dominant operator. An update to our July 15 coverage — and because the operators steal credentials, sessions, and MFA seeds, patching alone does not evict them. Read → RESEARCH SPOTLIGHT 2026-08-02 The Inside Is Not a Safe Place Anymore: Implicit Trust, Flat Networks, and Cheap Decoys An academic team used AI agents to find 84 flaws in 4G and 5G cores, 81 now carrying CVEs, and almost all of them trace to one habit: internal components trusting each other without checking. We ran our own cellular-gateway decoys in three postures to test the same idea, then attributed the industrial traffic properly — and found that 82.4% of every industrial-protocol command our fleet has ever recorded comes from two commercial scanning vendors. Read → ACTIVE EXPLOITATION 2026-07-30 A Shipped-In Password on the Box That Runs the Firewalls: CVE-2026-20316 Cisco Secure Firewall Management Center shipped with a static login for a low-privileged account, and an unauthenticated attacker can read sensitive data straight off the appliance. Exploited as a zero-day, on CISA KEV with an August 1 federal deadline, and it governs the firewalls that separate IT from the plant floor. Read → ACTIVE EXPLOITATION 2026-07-28 The Orchestrator Was Never Supposed to Face the Internet: CVE-2026-16812 A perfect-10 command injection flaw in Arista's on-premises VeloCloud Orchestrator lets an unauthenticated attacker run commands on the box that manages an entire SD-WAN fabric. Exploited as a zero-day, on CISA KEV with a three-day clock, and sitting exactly where SD-WAN carries traffic into operational networks. Read → FLEET TELEMETRY 2026-07-27 One Source, Twenty Decoys: the IT/OT divide is an org chart One automated source touched our fake Linux servers, our fake hospital, and our fake water plant in a single sweep, speaking SSH and Modbus alike. To the machines scanning the internet, there is no line between IT and OT. Part 1 of 2. Read → FLEET TELEMETRY 2026-07-27 The Same Scanners Phone Home: what a compromised Redis pool does and does not tell you We took the scanners that crossed our IT and OT decoys and pivoted them through Shodan. They led us to a population of genuinely compromised Redis and ZooKeeper servers — and to a hard limit on what a client list can tell you about who runs them. Part 2 of 2. Read → ACTIVE EXPLOITATION 2026-07-26 One Packet to the Edge: CVE-2025-9242 in WatchGuard Firebox A single crafted VPN packet gives an unauthenticated attacker code execution on a WatchGuard Firebox, the firewall at the edge of tens of thousands of small offices and remote sites. Actively exploited, on CISA KEV, 75,000+ exposed, and a fresh public exploit-plus-scanner just widened the pool of who can hit it. Read → FLEET TELEMETRY 2026-07-22 The 52-Command Playbook: how a botnet sizes you up before it strikes A 52-command reconnaissance playbook ran 886 times, byte-for-byte identical, from a small botnet, resolving CPU architecture, checking for a GPU, and writing a test script to confirm the shell is real. That last step is anti-honeypot detection, and we take the whole thing apart. Read → ACTIVE EXPLOITATION 2026-07-22 A Token to the Top of the Trust Chain: CVE-2026-16232 in Check Point SmartConsole An unauthenticated attacker lifts a login token and takes full administrative control of a Check Point management server, the box that writes firewall policy for every gateway beneath it. Exploited in the wild, added to CISA KEV with a three-day deadline, and dangerous exactly where a firewall enforces the IT-to-OT boundary. Read → ACTIVE EXPLOITATION 2026-07-21 An Old Router Bug, Newly Exploited: CVE-2021-27137 in DD-WRT and the C0XMO Botnet A five-year-old UPnP buffer overflow in DD-WRT router firmware is being used to spread the C0XMO botnet, and CISA just added it to the Known Exploited Vulnerabilities catalog. One unauthenticated packet to UDP 1900 crashes the router or runs code on it, on the edge gear that sits between the internet and everything behind it. Read → VULNERABILITY 2026-07-19 Brute-forcing the Ground Station: CVE-2026-44595 & CVE-2026-44596 in Yamcs Two medium-severity flaws in Yamcs, the open-source mission-control platform that flies real spacecraft: a missing authorization check enumerates every admin, and a login endpoint with no rate limit invites brute force. Chained, they point from any low-privilege account toward operator access on a spacecraft ground station. Not in KEV — but public PoCs exist, and un-throttled brute force is the single most common behavior our sensors see. Read → ACTIVE EXPLOITATION 2026-07-17 When the sandbox that judges your files gets taken over: CVE-2026-39808 & CVE-2026-25089 Two Fortinet FortiSandbox command injection flaws on CISA KEV (July 16). An unauthenticated attacker runs commands as root on the appliance a network trusts to decide which files are safe — and every downstream firewall and mail gateway keeps trusting its verdicts. Read → VULNERABILITY 2026-07-16 CVE-2023-4346: a lockout with no key on the KNX bus CISA added a three-year-old KNX flaw to KEV after confirmed exploitation. An attacker who reaches the building-automation bus can purge a building’s controllers and set a BCU key no operator can remove — an availability attack on the OT that runs hospitals, data centers, and plants. Read → ACTIVE EXPLOITATION 2026-07-15 Two zero-days on the SonicWall SMA front door: CVE-2026-15409 and CVE-2026-15410 Two SonicWall SMA 1000 zero-days chained from an unauthenticated request-forgery bug to admin command execution, added to CISA KEV on July 14. The SSL VPN gateway that fronts OT and critical infrastructure, taken over, and the vendor says patching alone is not enough. Read → FLEET TELEMETRY 2026-07-15 The Week the Noise Quadrupled: a fleet-wide attack surge On July 6, 2026, distinct attackers jumped almost fivefold and stayed there — broad scanners that swept the fleet, and single-target floods that hammered one node tens of thousands of times. The data behind the surge, with an honest read on what it proves. Read → VULNERABILITY 2026-07-14 CVE-2008-4128: an 18-year-old Cisco router flaw returns to the exploited list A 2008 cross-site request forgery bug in Cisco IOS web management, added to CISA KEV on July 13, 2026 with a three-day BOD 26-04 deadline. Not pre-auth — but the exposure it rides, an internet-facing router console on long-lived edge gear, is exactly what our decoys watch. Read → VULNERABILITY 2026-07-12 One crafted packet, and the cameras go dark: CVE-2026-29116 An unauthenticated, remote denial-of-service flaw across a broad range of Dahua surveillance gear. One crafted packet trips a fatal assertion and reboots the device; a fresh public PoC made it low-effort and automatable. Read → VULNERABILITY 2026-07-11 CVE-2025-22457: a fresh PoC reopens the Ivanti front door A pre-auth, unauthenticated RCE in Ivanti Connect Secure — the VPN appliance that fronts remote access into hospitals, utilities, and plant networks. An old, nation-state-exploited flaw whose fresh public exploit just lowered the bar to abuse. Read → VULNERABILITY 2026-07-09 CVE-2026-11405: a hidden password that lets anyone into the router Several Tenda router firmware builds ship with an undocumented second password that hands full admin to any username. No patch, vendor unreachable, public PoC circulating. Read → VULNERABILITY 2026-07-08 CVE-2026-8451: CitrixBleed comes back to the NetScaler front door A pre-authentication memory overread in NetScaler appliances configured as SAML identity providers — a malformed login makes the box leak fragments of its own memory. Already under active exploitation on the appliances that front remote access into hospitals, utilities, and plant networks. Read → VULNERABILITY 2026-07-05 CVE-2026-13768: one hard-coded cloud key, an entire fleet of gardens A hard-coded, owner-level Azure IoT Hub key shipped on every Gardyn indoor garden: one extracted key enumerates the whole device fleet, runs commands on any unit, and pivots onto the owner’s home network. CISA rated it a perfect 10.0. Read → RESEARCH 2026-07-01 We went looking for AI attackers in our honeypots Anthropic mapped how attackers use AI. We run honeypots and watched the same adversaries from the other side — out of 8,887 attackers, eight looked like AI, with a clear machine-speed fingerprint. Read → ACTIVE EXPLOITATION 2026-06-30 CVE-2026-48558: a forged token, a trusted technician, an entire fleet A critical, actively exploited authentication bypass in SimpleHelp RMM: with OIDC enabled, the server never verifies the login token signature, so a forged token becomes full technician access to every managed endpoint. On CISA KEV, ~14,000 servers exposed. Read → ACTIVE EXPLOITATION 2026-06-30 BlueHammer Is Loose: How Fast Ransomware Inherits a Public Exploit A leaked Windows Defender zero-day went from a researcher's GitHub repo to confirmed ransomware use in under three weeks. The pattern is not new, but the timeline keeps shrinking, and the consequences keep landing on the defenders least staffed to absorb them. Read → FLEET TELEMETRY 2026-06-30 We Went Looking for RustDuck in Our Honeypots On the morning XLab named a new Rust botnet, its home network was already one of the busiest attackers on our decoy fleet. Here is the first-party view, including the honest limits. Read → ACTIVE EXPLOITATION 2026-06-27 CVE-2026-12569: PTC Windchill and FlexPLM A pre-authentication remote code execution flaw in PTC Windchill and FlexPLM, the systems that hold a manufacturer's product designs. On CISA's KEV list with a three-day federal deadline. Read → ACTIVE EXPLOITATION 2026-06-24 The Bridge Nobody Watches: Lantronix EDS5000 on KEV A critical, pre-authentication flaw in Lantronix serial converters is now under active attack. What OT and IT leaders need to know, and what to do this week. Read → ACTIVE EXPLOITATION 2026-06-04 CVE-2026-20245: A Zero-Day in the Network's Brain Attackers turned a routine file upload on Cisco Catalyst SD-WAN Manager into a hidden root account. How the chain works, why the controller is such a prize, and what our sensors do and do not see. Read →
Deception Check builds deception-based detection. First-party figures across these posts are measured on our own honeypot and edge-decoy fleet; external figures are attributed where cited. Source addresses are redacted or generalized.