BlueTeamSec briefing for Thursday the 1st of October 2026, with six stories from the infosec.pub community.
CISA have added a critical authentication bypass in Cisco SD-WAN Manager to the known exploited vulnerabilities catalogue. The flaw allows unauthenticated remote attackers to gain admin-level API access by sending crafted requests with URI-encoded characters, and it's actively exploited in the wild. No workarounds exist, so patching is the only option โ worth flagging if you're running SD-WAN infrastructure.
Microsoft have written up a new technique from Star Blizzard, the Russian group attributed to FSB Centre 18. They've shifted from targeted spear-phishing to large-scale campaigns using a method called RedFlick โ representing an evolution in their phishing and malware delivery tradecraft since January.
Dutch police have arrested a twenty-four-year-old Amsterdam man suspected of playing a significant role in ShinyHunters โ the group linked to major breaches at Odido, Pornhub, and TicketMaster. The suspect faces charges related to participation in a criminal organisation, and there's evidence suggesting he solicited murders abroad. Brian Krebs has more detail: the arrest was of Pepijn van der Stap, also known as Umbreon, and it's triggered a leadership shift within the group to a Jordanian teenager. ShinyHunters are actively exploiting a vulnerability in Oracle PeopleSoft using URL-encoding to bypass web application firewalls โ they've compromised FBI systems, defaced infrastructure, and stolen data on over five thousand officials.
ANSSI have published an incident report on cyberattacks against France's Directorate General of Public Finance over the summer. Two waves of data exfiltration occurred between May and August, exploiting weak identity management, poor network segmentation that allowed lateral movement from Ministry of National Education systems, and insufficient detection capabilities. One for those working on segmentation or identity hygiene in large government networks.
And finally, Ntop have released the nDPI TCP Fingerprint, a patent-free method for passive TCP stack identification. It's integrated into the nDPI library and enables correlation of OS-level TCP fingerprints with application-layer signals to detect anomalies and identify network scanners. Worth noting it should only be used as a supplementary detection signal, not for authentication โ it relies on SYN packet fields that are easily manipulated.
That's all for today. Attribution goes to the original authors โ the analysis here was automated.