Cyware at Auto-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - October 03, 2026

9 min read
Share this article
shutterstock 2053035026

Summary

Attackers are chaining two critical flaws in the Zammad helpdesk platform to seize user sessions and escalate privileges all the way to root, with both vulnerabilities—CVE-2026-102489 and CVE-2026-102490—scoring CVSS 9.4 and already under active exploitation. Cyware highlights how an AI agent autonomously combined these bugs, allowing rapid data exfiltration and takeover across Zammad versions from 1.5.0 through 7.1.3, prompting CISA to add them to its Known Exploited Vulnerabilities catalog.

New botnet activity is turning exposed IoT devices into covert attack platforms by disguising command-and-control traffic as routine STUN protocol exchanges. The Cling botnet exploits CVE-2021-35394 in the Realtek Jungle SDK, persists by copying itself as .cling, and evades detection by spoofing UDP source addresses—leaving organizations with compromised devices that can be quietly controlled for further abuse.

Developer supply chains are under fire as GlassWorm-linked Visual Studio Code themes and extensions, including Coca-Cola Christmas and Aurora Borealis Studio Theme, are weaponized to execute malicious code on trusted machines. These extensions, distributed via both the VS Code Marketplace and Open VSX, leverage MITRE ATT&CK techniques T1195.002 and T1027, turning routine installs into potential breaches of credentials, source code, and internal access.

CTA_1_LI_Tuesday_Saturday_DTI_MTI_After_Overview

Top Malware Reported in the Last 24 Hours

Cling botnet hides in STUN traffic

Cling is a newly identified IoT botnet that takes over vulnerable devices and then camouflages its command-and-control traffic as routine STUN activity, making it harder to spot in noisy networks. It exploits CVE-2021-35394 in the Realtek Jungle SDK to run shell commands and pull down malicious binaries, using BusyBox wget to download and execute its payloads. Once inside, it sticks around by copying itself as .cling into system locations and altering startup scripts so it comes back after reboots. Nozomi Networks Labs reported the campaign, describing how it can even spoof UDP source addresses to blend into normal-looking traffic. For organizations running exposed IoT gear, the real-world consequence is compromised devices that can be quietly controlled and reused for follow-on abuse without obvious symptoms. Defenders are advised to watch for STUN Binding Requests with all-zero transaction IDs and to hunt for .cling, wget.r, wget.p, and altered wget binaries.

GlassWorm booby-traps popular VS Code themes

GlassWorm is tied to high-risk Visual Studio Code extensions that present themselves as harmless themes, but can be positioned to execute malicious code on developer machines. The reported set includes extensions such as Coca-Cola Christmas and Aurora Borealis Studio Theme, spread through the VS Code Marketplace and Open VSX. It uses Windows cmd.exe execution and obfuscation to conceal what it is doing, and a previously weaponized theme (Aurora Nocturne Night Theme) was described as delivering heavily obfuscated JavaScript that fetches and runs attacker-controlled content. Socket linked the activity to GitHub accounts aubineherodvulbdl and lohsebhipolg2s, and mapped it to MITRE ATT&CK techniques T1195.002 (Supply Chain Compromise) and T1027 (Obfuscated Files or Information). For teams that rely on extensions to speed up coding, a poisoned theme can turn routine development work into a stepping stone for broader compromise of credentials, source code, or internal access.

BPFDoor and AVERAT stalk telecom edges

BPFDoor and AVERAT are active malware strains targeting telecom environments in South Korea and Taiwan, using stealthy communications that blend into normal internet plumbing. They rely on droppers to install payloads and then use techniques like process name spoofing and “magic bytes” to evade straightforward detection. Rapid7 reported that the campaign uses compromised devices as relays and leans on protocols including SMTP and HTTPS for command-and-control, keeping traffic looking ordinary at the network edge. For defenders trying to catch it in motion, the write-up calls out raw packet sockets, BPF filters, and port 25 callbacks as key detection angles. In practical terms, a foothold in a telecom edge environment can enable covert access that threatens service reliability and downstream customers who depend on those networks. Rapid7 also recommends collecting process arguments, open file descriptors, and DNS history to support investigation and scoping.

Top Vulnerabilities Reported in Last 24 hours

AI-chained Zammad bugs lead to root

Two critical flaws in the Zammad helpdesk platform (CVE-2026-102489 and CVE-2026-102490, both CVSS 9.4) can be chained to hijack user sessions and escalate privileges, potentially ending in remote code execution and root-level access. In plain terms, an attacker can take over an existing user’s session and then use broken permission controls to climb from regular access to full control of the system. Attackers are already exploiting this in the wild. The Dutch Institute for Vulnerability Disclosure (DIVD) said an AI agent autonomously chained the bugs, highlighting how quickly data exfiltration and takeover can unfold once a target is found. CISA added both to its Known Exploited Vulnerabilities catalog, with affected Zammad versions listed as 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3 for CVE-2026-102489 (Session Fixation), and 1.5.0 through 7.1.0-alpha for CVE-2026-102490 (Improper Privilege Management).

FortiMail RCE exploited against email gateways

A critical remote code execution flaw in Fortinet FortiMail (CVE-2026-104286) lets attackers run arbitrary code on vulnerable email security appliances, opening the door to full system compromise. For organizations relying on FortiMail as a front line for inbound and outbound email, a successful takeover can quickly turn into data theft, surveillance, or disruption of business communications. Attackers are already exploiting this in the wild. The issue is tracked in Fortinet’s bulletin FG-IR-26-175 and relayed by CERT-FR, which also notes that indicators of compromise are published in the original advisory. The affected versions include FortiMail post 7.2.0 and pre-7.4, post 7.4.0 and pre-7.4.9, post 7.6.0 and pre-7.6.7, and post 8.0.0 and pre-8.0.2.

GitLab AI Gateway bug enables command execution

A critical vulnerability in GitLab’s AI Gateway service (CVE-2026-90970) allows an attacker with basic privileges to execute arbitrary commands on unpatched, self-hosted deployments. That kind of foothold can quickly become a broader breach when the target sits close to development workflows and the systems that build and deploy software. No active exploitation has been observed yet. GitLab disclosed that it contacted Self-Hosted AI Gateway customers ahead of the public announcement, a sign the company expects real-world interest from attackers. The warning lands amid GitLab’s wider security history, including prior issues such as CVE-2026-85706 that were serious enough to draw CISA attention. Fixes are available in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.

Top Threat Actors Reported in Last 24 hours

GlassWorm booby-traps popular VS Code themes

GlassWorm, a malware-distribution cluster, is abusing developer trust by planting high-risk VS Code themes and extensions that can execute malicious code through a supply-chain style setup tied to MITRE ATT&CK techniques T1195.002 (Supply Chain Compromise) and T1027 (Obfuscated Files or Information). They have been linked to extensions such as Coca-Cola Christmas and Aurora Borealis Studio Theme, with prior history that includes a weaponized Aurora Nocturne Night Theme masquerading as a legitimate Microsoft extension while running obfuscated scripts. The activity spans both the VS Code Marketplace and Open VSX, with development connected to GitHub accounts the report ties to shared code patterns, suggesting coordinated publishing. For software teams, this kind of tainted “productivity” add-on can turn a routine install into unauthorized code execution on machines that often have access to source code and internal systems. The report’s mitigation guidance centers on blocking listed IOCs, watching for suspicious cmd.exe and scripting-interpreter execution, removing questionable extensions, and conducting threat hunting tied to the cluster’s footprint, a reminder that AI-accelerated attacker workflows are shrinking the time between new lures and real-world abuse.

BPFDoor and AVERAT probe telecom edges

BPFDoor and AVERAT are actively targeting telecom environments in South Korea and Taiwan, using stealth features like process-name spoofing and “magic bytes” to hide command execution while keeping long-running access. They deploy via droppers and then blend into normal network activity by using SMTP and HTTPS for communications, including scenarios where compromised devices are used as relays. For network-edge operators, that combination raises the risk that routine traffic patterns can mask intrusion activity until service reliability, customer data, or internal access is affected. Rapid7 reports the malware can run multiple concurrent shells and uses tooling such as Tiny Shell for upload/download-style operations, underscoring its focus on practical control rather than noisy destruction. Recommended defensive measures in the report include monitoring for specified IOCs (including file paths and constants), focusing on raw packet sockets/BPF filters and port 25 callbacks, and building network detection around TLS fingerprinting and outbound SMTP traffic—pressures that align with Microsoft’s broader warning that AI adoption is driving up both phishing and exploitation of public-facing systems.

CTA_2_LI_Tuesday_Saturday_DTI_MTI_Before_FAQ

Frequently Asked Questions

  1. What is Cling? Cling is a newly identified IoT botnet that takes over vulnerable devices and then camouflages its command-and-control traffic as routine STUN activity, making it harder to spot in noisy networks. It exploits CVE-2021-35394 in the Realtek Jungle SDK to run shell commands and pull down malicious binaries, using BusyBox wget to download and execute its payloads.

  2. What is GlassWorm? GlassWorm is tied to high-risk Visual Studio Code extensions that present themselves as harmless themes, but can be positioned to execute malicious code on developer machines. The reported set includes extensions such as Coca-Cola Christmas and Aurora Borealis Studio Theme, spread through the VS Code Marketplace and Open VSX.

  3. What is BPFDoor? BPFDoor and AVERAT are active malware strains targeting telecom environments in South Korea and Taiwan, using stealthy communications that blend into normal internet plumbing. They rely on droppers to install payloads and then use techniques like process name spoofing and “magic bytes” to evade straightforward detection.

  4. What is CVE-2026-102489? Two critical flaws in the Zammad helpdesk platform (CVE-2026-102489 and CVE-2026-102490, both CVSS 9.4) can be chained to hijack user sessions and escalate privileges, potentially ending in remote code execution and root-level access. In plain terms, an attacker can take over an existing user’s session and then use broken permission controls to climb from regular access to full control of the system.

  5. What is CVE-2026-104286? A critical remote code execution flaw in Fortinet FortiMail (CVE-2026-104286) lets attackers run arbitrary code on vulnerable email security appliances, opening the door to full system compromise. For organizations relying on FortiMail as a front line for inbound and outbound email, a successful takeover can quickly turn into data theft, surveillance, or disruption of business communications.

  6. What is CVE-2026-90970? A critical vulnerability in GitLab’s AI Gateway service (CVE-2026-90970) allows an attacker with basic privileges to execute arbitrary commands on unpatched, self-hosted deployments. That kind of foothold can quickly become a broader breach when the target sits close to development workflows and the systems that build and deploy software.

Share this article

Discover Related Resources