🛡️ InfoSec Blue Team Briefing

Saturday, October 03, 2026

🎧 Audio Briefing

Download MP3

This is the security briefing for Saturday the 3rd of October 2026, drawn from the BlueTeamSec community on infosec.pub. A busy one today, with fourteen stories to get through.

CISA have added a critical Zammad helpdesk vulnerability to the Known Exploited catalog. CVE-2026-102489 allows session hijacking leading to remote code execution, and it's being actively exploited in the wild, often chained with a privilege escalation flaw to achieve full root compromise. If you're running Zammad versions 6.3 through 6.5, upgrade to 7.0 immediately and assume compromise.

DIVD discovered those Zammad vulnerabilities the hard way, during investigation of their own breach. Their write-up covers both the remote code execution flaw and the local privilege escalation issue, which affects versions going back to 1.5. They're actively scanning for vulnerable instances and notifying system owners.

Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated command injection in Zimbra Collaboration Suite. Attackers hit internet-facing mail servers between late July and mid-August, deploying webshells and escalating to root. One for anyone running Zimbra externally.

eSentire have written up a pair of zero-days in PaperCut print servers that led to full domain compromise of an education sector organization within 48 hours. The attack chain involved SQL injection, an in-memory Java loader, and a trojanized Microsoft Copilot binary hiding the AdaptixC2 implant. Worth a read if you manage PaperCut deployments.

Truffle Security analysed 224 million GitHub repositories and found over half a million unique, active credentials still valid as of July 2026. The median exposure age was 784 days, which tells you most organizations aren't revoking leaked secrets even when they're publicly available. This one adds useful context to supply chain risk conversations.

OX Security flagged a malicious npm campaign called PhantomSub that's racked up roughly 490,000 downloads. The packages silently subscribe developers to WhatsApp spam channels using the Baileys API library, mostly to inflate follower counts for channels advertising illegal services. We covered similar supply chain abuse with PolinRider late last month.

And another supply chain story: SafeDep reported that PolinRider has now compromised 35 GitHub repositories, injecting malicious code into build scripts. The malware uses Ethereum blockchain transactions as decentralized command and control to retrieve server IPs, while stealing credentials and cloud provider keys from developer environments. This follows our coverage of the initial discovery a few weeks back.

Cisco Talos have tracked a China-nexus actor, UAT-11587, running a persistent espionage campaign since September 2025 across Asia. They're using a previously undocumented backdoor called Antino, delivered via spear-phishing and DLL sideloading, with command and control conducted entirely through Microsoft Graph API. Approximately 350 endpoints compromised across India, Thailand, Taiwan, and several other countries as of July.

The Dutch intelligence service AIVD have published a warning on espionage risks from modern connected vehicles. They note that smart cars collect vast amounts of data about occupants and environments, creating attack surfaces that state actors can exploit for intelligence gathering. Particularly relevant if you're responsible for protecting government officials or personnel with access to sensitive information.

The U.S. Department of Justice announced the arrest and indictment of a Dutch national tied to the KillSec ransomware group. The group hit roughly a thousand organizations between March and November 2025, exploiting known vulnerabilities for data exfiltration and double extortion. An international law enforcement operation in September took down their dark web leak site, which contained 110 terabytes of stolen data.

And the government of Montenegro confirmed extradition of a dual Turkish-Iranian citizen to the United States. He faces charges related to a decade-long cyberattack campaign beginning in 2013, targeting over 150 U.S. universities. The stolen credentials and data allegedly benefited Iran's Revolutionary Guard and Iranian universities, with estimated damages of three and a half billion dollars.

K7 Computing analysed a multi-stage intrusion campaign using malicious KMS Auto activators to deploy cryptocurrency miners and remote management tools, wrapped up with scareware branded as APT36. The researchers assess this is likely a false flag or prank rather than genuine espionage, given the lack of data exfiltration and the use of scareware instead of actual ransomware.

S2 Grupo have documented the DragonForce threat group abusing the MQTT protocol to manage backdoors on compromised systems. They're targeting web applications, particularly WordPress sites, and using MQTT's publish-subscribe architecture to blend malicious traffic with legitimate IoT communications. Adds useful context to unusual protocol abuse in web compromise cases.

And finally, researchers published a proof of concept for bypassing Windows Protected Process Light protections using a vulnerability in SysInternals Process Explorer driver versions 17.00 through 17.09. The flaw allows full-access handles to protected processes like Microsoft Defender, enabling shellcode injection into high-privilege security processes. Microsoft patched it in driver version 17.11.

That's your briefing for today. The articles are the work of their original authors — the analysis here was automated. We'll be back with the next one soon.

📰 Articles Covered