Cyware at Auto-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - October 05, 2026

10 min read
Share this article
shutterstock 2285963477

Summary

Attackers are turning the software supply chain into a high-speed conduit for data theft and extortion, as seen in Azazel’s raid on CI/CD secrets that exposed over two dozen organizations and led to multi-stage exfiltration from an AI platform. Cyware.com tracks how these breaches transform developer infrastructure into a direct path for sensitive customer and internal data to reach public leak sites.

Developers face mounting risks from poisoned dependencies, with Ghost Dev pushing 42 malicious RubyGems packages that masquerade as crypto tools but deliver reverse shells and wallet stealers. A single compromised library can silently redirect funds or expose keys, making routine installs a vector for direct financial loss.

Critical vulnerabilities are under active attack, including CVE-2026-63077 in JetBrains TeamCity, which ransomware gangs exploit to seize CI/CD servers and extract AWS credentials, and CVE-2026-61500 in Rejetto HFS, where a China-linked actor forges admin sessions to gain remote code execution on U.S. hosts. Citrix’s rapid-fire NetScaler patches underscore the operational strain as enterprises scramble to keep up with evolving threats.

CTA_1_LI_Monday_DTI_After_Overview

Top Malware Reported in the Last 24 Hours

Azazel exploits CI/CD secrets to extort

Azazel, a Russian-speaking affiliate tied to the Gentlemen ransomware ecosystem, compromised more than two dozen organizations by raiding CI/CD secrets and then publishing stolen data on its own leak site. It used that access to move from developer tooling into broader environments, including a deep compromise of an AI platform that enabled multi-stage data theft. Researchers at CloudSEK said the threat ran a three-node setup for victim operations, staging, and long-term storage, and kept exfiltrating data while the investigation was underway. For affected businesses, this kind of breach turns build pipelines and code infrastructure into a shortcut to sensitive customer and internal data—followed by public exposure pressure. A fix is available in the form of stronger secrets handling, including using a dedicated secrets manager, auditing git history for exposed secrets, restricting MinIO bucket access, and alerting on unauthorized CI/CD variable access.

Ghost Dev poisons RubyGems for crypto

Ghost Dev has pushed 42 malicious RubyGems packages that masquerade as crypto and web3 tools, turning routine developer installs into a path to a reverse shell and wallet theft. The campaign hides its payload inside what looks like a native-extension build script, then delays activation by checking whether it is running in CI environments or on developer workstations. Once active, it drops components such as inject_proxy.py (to intercept traffic), _grab.py (to collect wallet data), and wg_install.sh (to help maintain persistence), and it can also swap cryptocurrency withdrawal addresses for attacker-controlled ones. The packages were flagged by the OpenSourceMalware detection engine and were published under the account name reqthrottle_3474. For developers and small teams, a single poisoned dependency can silently redirect funds or expose keys, turning a build step into a direct financial loss. Mitigation is available through blocking known command-and-control infrastructure, checking endpoints for a bundled root CA plus proxy/autostart changes, and rotating wallet or exchange secrets from a clean device if they were present on an affected host.

ScreenConnect phishing lures victims into remote control

ScreenConnect is being abused in refund-scam phishing emails that trick recipients into installing a legitimate, digitally signed remote-access client that connects back to an attacker-run environment. The emails push a “payment was unauthorized” pretext and route victims through a malicious link path, where the download is configured with specific campaign parameters including a dedicated delivery URL and a named relay host. Because the client appears authentic, it reduces the need for custom malware and enables hands-on-keyboard access for follow-on theft, fraud, or internal network intrusion. The activity was reported by GBHackers as part of a wider pattern of criminals leaning on familiar RMM tools like AnyDesk and TeamViewer to blend in. For victims, the consequence can look like routine IT software—until someone else is viewing the screen and controlling the machine. Mitigation is available via monitoring for unexpected ScreenConnect installations, alerting on unapproved deployments, and tightening remote-access controls such as MFA and restrictions on unauthorized remote-management products.

Top Vulnerabilities Reported in Last 24 hours

Ransomware gangs hit JetBrains TeamCity servers

A critical remote-code-execution flaw in JetBrains TeamCity (CVE-2026-63077, CVSS 9.8) is being used by ransomware gangs to run arbitrary OS commands with server-level privileges. In real terms, that can turn a CI/CD server into a launchpad for stealing secrets and pushing malicious code into software pipelines, and attackers have already used it to extract AWS credentials from JetBrains’ own Cadence environments. Attackers are already exploiting this in the wild. JetBrains privately received the report on July 10, 2026, released patches on July 25, and CISA warned about exploitation on September 23, 2026. The incident also reflects a broader shift in ransomware tactics toward targeting infrastructure like build systems, and it may influence application security budgets and enterprise risk assessments of TeamCity versus competitors; a fix is available in 2025.11.7 or 2026.1.3+.

Rejetto HFS bug enables admin takeover

A critical flaw in Rejetto HTTP File Server (HFS) (CVE-2026-61500) is under active exploitation, letting attackers forge admin sessions and reach remote code execution on affected servers. That combination means an exposed HFS instance can be quietly taken over, with attackers gaining unauthorized administrative access and the ability to run arbitrary code. Attackers are already exploiting this in the wild, with VulnCheck reporting exploitation attempts on October 1, 2026 after a public proof-of-concept appeared in late September. Researchers at Horizon3.ai and Alejandro Ramos disclosed the issue, and reporting links activity to a Chinese threat actor targeting vulnerable U.S. hosts. A fix is available in version 3.2.1.

Citrix rushes new NetScaler fixes

Citrix issued a fresh patch round for NetScaler vulnerabilities including CVE-2026-88779, just days after an emergency patch cycle—an operational headache for enterprises that thought they were already done. The practical risk centers on service availability: exploitation can disrupt access to applications and remote work services even if customer data integrity is not the primary concern described in the report. Attackers are already exploiting these flaws in the wild. Citrix disclosed multiple issues at once—CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779—with CVE-2026-88779 tied to specific SAML preconditions that triggered the additional release. Fixed builds are available, including 14.1-73.41 and 13.1-64.28.

Top Threat Actors Reported in Last 24 hours

Azazel breaks from Gentlemen ransomware playbook

Azazel, a Russian-speaking affiliate tied to the Gentlemen ransomware ecosystem, compromised over two dozen organizations across six countries by raiding CI/CD secrets and then running the operation independently. After gaining access, they used a three-node setup split between victim-facing activity, a staging layer, and long-term storage, with infrastructure that exceeded 50TB and continued exfiltration observed during the investigation. The group’s CI/CD attack chain centered on GitLab enumeration and credential extraction, turning build and deployment systems into a pathway to broader network access. They also performed a deep compromise of an AI platform, using multi-stage data exfiltration to move information out in steps rather than all at once. For affected businesses, the immediate risk isn’t just encryption—it’s the publication of stolen data, which Azazel posted via the LEAKNED site after bypassing the Gentlemen program.

Ghost Dev plants malware in RubyGems

Ghost Dev is a threat actor targeting crypto and web3 developers by publishing 42 malicious RubyGems packages that masquerade as legitimate libraries but install a reverse shell and cryptostealer. The campaign, flagged by the OpenSourceMalware detection engine, relies on typosquatting and a payload disguised as a Ruby native-extension build script that behaves like a delayed backdoor. To reduce the chance of being caught quickly, they check for CI environments and developer workstations before activating. Once running, the malware sets up a local proxy on 127[.]0[.]0[.]1:8899 to intercept web traffic, and it can swap cryptocurrency withdrawal addresses and hijack clipboard contents to redirect funds. The tooling referenced in the report includes filenames such as inject_proxy[.]py, _grab[.]py, and wg_install[.]sh, underscoring how a poisoned dependency can turn routine development work into direct financial loss.

China-linked actor exploits Rejetto HFS flaw

A China-linked threat actor has been targeting U.S. hosts by exploiting CVE-2026-61500, a critical vulnerability in Rejetto HTTP File Server (HFS) that enables admin session forgery and remote code execution. The issue affects versions 3.0.0 to 3.2.0 and stems from a weak PRNG used for session-cookie signing, letting attackers reconstruct the signing key and impersonate an administrator. For organizations running HFS, that means an exposed file server can quickly become a foothold for deeper compromise and disruptive follow-on activity. VulnCheck detected exploitation attempts on October 1, 2026, shortly after a public proof-of-concept appeared in late September, even though a patch was released in July 2026. The flaw was discovered by Horizon3.ai and Alejandro Ramos.

CTA_2_LI_Monday_DTI_Before_FAQ

Frequently Asked Questions

  1. What is Azazel? Azazel, a Russian-speaking affiliate tied to the Gentlemen ransomware ecosystem, compromised more than two dozen organizations by raiding CI/CD secrets and then publishing stolen data on its own leak site. It used that access to move from developer tooling into broader environments, including a deep compromise of an AI platform that enabled multi-stage data theft.

  2. What is Ghost Dev? Ghost Dev has pushed 42 malicious RubyGems packages that masquerade as crypto and web3 tools, turning routine developer installs into a path to a reverse shell and wallet theft. The campaign hides its payload inside what looks like a native-extension build script, then delays activation by checking whether it is running in CI environments or on developer workstations.

  3. What is ScreenConnect? ScreenConnect is being abused in refund-scam phishing emails that trick recipients into installing a legitimate, digitally signed remote-access client that connects back to an attacker-run environment. The emails push a “payment was unauthorized” pretext and route victims through a malicious link path, where the download is configured with specific campaign parameters including a dedicated delivery URL and a named relay host.

  4. What is CVE-2026-63077? A critical remote-code-execution flaw in JetBrains TeamCity (CVE-2026-63077, CVSS 9.8) is being used by ransomware gangs to run arbitrary OS commands with server-level privileges. In real terms, that can turn a CI/CD server into a launchpad for stealing secrets and pushing malicious code into software pipelines, and attackers have already used it to extract AWS credentials from JetBrains’ own Cadence environments.

  5. What is CVE-2026-61500? A critical flaw in Rejetto HTTP File Server (HFS) (CVE-2026-61500) is under active exploitation, letting attackers forge admin sessions and reach remote code execution on affected servers. That combination means an exposed HFS instance can be quietly taken over, with attackers gaining unauthorized administrative access and the ability to run arbitrary code.

  6. What is CVE-2026-88779? Citrix issued a fresh patch round for NetScaler vulnerabilities including CVE-2026-88779, just days after an emergency patch cycle—an operational headache for enterprises that thought they were already done. The practical risk centers on service availability: exploitation can disrupt access to applications and remote work services even if customer data integrity is not the primary concern described in the report.

Share this article

Discover Related Resources