Cyware at Auto-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - October 06, 2026

10 min read
Share this article
shutterstock 1951619836

Summary

A poisoned npm package has turned routine software updates into a direct pipeline for credential theft, with attackers using @subql/common@5.8.3 to exfiltrate CI secrets and cloud credentials from developer environments. Cyware highlights how the malicious release, published through a trusted pipeline, can let adversaries pivot from stolen GitHub tokens into source code and cloud accounts, threatening the integrity of entire software supply chains.

A newly disclosed Citrix NetScaler zero-day, CVE-2026-88779, is actively knocking out authentication gateways for organizations using SAML-enabled appliances. Attackers are exploiting this flaw in the wild, locking out legitimate users and potentially chaining the bug with other vulnerabilities for deeper access, while Citrix and CISA urge immediate patching to restore secure logins.

Midnight Blizzard, operating as Storm-2945, has revived its CaptiveCrunch campaign by hijacking hotel Wi-Fi logins at major North American chains. The group manipulates captive portal systems and DNS traffic to push travelers toward malicious payloads, with Microsoft and Black Lotus Labs tying the operation to 70 affected IP addresses and warning of risks to business travelers’ credentials and devices.

Booba ransomware has struck the University of Illinois Chicago’s College of Medicine, with the group claiming to have stolen 344 GB of data and targeting both Windows and Linux systems. The attack, assessed by SentinelOne as a possible rebrand of Frag ransomware, underscores the ongoing threat to educational institutions and the long-term exposure created by stolen academic and personal data.

CTA_1_LI_Tuesday_Saturday_DTI_MTI_After_Overview

Top Malware Reported in the Last 24 Hours

@subql/common@5.8.3 steals CI secrets

@subql/common@5.8.3 is a poisoned npm release that turns a routine dependency update into credential theft, with the malicious payload executed from a newly added manifest-cache.js. It runs during post-install and grabs environment variables and cloud credentials, then attempts to use stolen GitHub tokens to create a branch named dependabot/github_actions/format/setup-formatter while spoofing the commit author. The same activity also drops a reverse-shell implant, raising the stakes from data theft to potential hands-on access inside build and developer environments. The report says the version was published through a trusted pipeline, pointing to a compromise in the release process rather than a simple rogue upload. For teams that pulled this “latest” tag, the real-world consequence can be downstream: attackers can quietly pivot from CI secrets into source code, cloud accounts, and software supply chains. Exfiltration is directed to hxxps://ci-artifacts[.]dev/router.

Midnight Blizzard hijacks hotel Wi‑Fi logins

Midnight Blizzard, via its subcluster Storm-2945, has restarted the CaptiveCrunch campaign by abusing the captive-portal ecosystem used by major North American hotel chains. It manipulates DNS and HTTP traffic on shared hospitality equipment to funnel travelers toward attacker-controlled infrastructure, then uses ClickFix-style instructions to trick victims into downloading malicious payloads. Researchers warned there is potential targeting of Android users through APK installation prompts, though they have not confirmed deployment at scale across Android devices. Microsoft and Black Lotus Labs tied the operation to 70 affected IP addresses, and described CornFlake RAT’s command-and-control as using ECDH P-256 key exchange with SHA-256-derived session keys, supporting a more resilient remote-access capability. For business travelers, the practical risk is that a routine hotel Wi‑Fi login can become the first step to losing credentials or having a work laptop pulled into a wider intrusion. Attackers are already using this in active campaigns.

Booba ransomware steals 344GB from UIC

Booba ransomware hit the University of Illinois Chicago’s College of Medicine and the group claims it stole 344 GB of data, even as the university said its main network and patient care delivery were not affected. It locks files by appending the .booba extension and is described as having variants for both Windows and Linux environments, widening where it can do damage. SentinelOne assesses the operation may be a rebrand of Frag ransomware, based on similarities in the leak site style and negotiation flow. The same reporting says it has targeted educational institutions and small county governments, including an attack claim involving Merrimack County, New Hampshire. For victims, the impact extends beyond downtime: stolen academic, research, or personal data can create long-tail exposure even after systems are restored. An investigation is ongoing to determine what information was compromised.

Top Vulnerabilities Reported in Last 24 hours

Citrix NetScaler zero-day knocks out logins

A newly disclosed Citrix NetScaler zero-day, CVE-2026-88779, lets attackers remotely trigger denial-of-service conditions that can take down authentication gateways on affected appliances. In practice, the bug hits NetScaler instances with SAML enabled, meaning legitimate users can be locked out when single sign-on paths are disrupted. Attackers are already exploiting this in the wild. Security commentary cited by CyberScoop included Jake Knott and Joe Toomey, with Toomey warning the issue may be simple to trigger and could potentially be chained with other flaws for code execution. CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, and Citrix says a patch is available.

GitHub Enterprise bug lets insiders run code

A critical GitHub Enterprise Server vulnerability, CVE-2026-3854, allows an attacker to execute commands as the git service user by abusing a trust-boundary failure in the git push pipeline. The attack hinges on crafting push options so that delimiter confusion (a semicolon treated as a field separator) enables field injection into internal request metadata and overrides security-sensitive settings. No active exploitation was stated in the source, but the write-up describes a clear, weaponizable path for authenticated users with push access. Researchers at Seqrite detailed the technique and its impact on enterprise environments hosting private code. Fixes are available in GHES 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7, 3.19.4, and 3.20.0.

KVM escape claim raises cloud risk

A newly reported zero-day in the Linux KVM hypervisor is being described as a full guest-to-host escape that could let an attacker break out of a virtual machine and take control of the underlying host. The report says the issue affects Firecracker MicroVMs, the lightweight virtualization technology created by AWS and used by Vercel, raising concerns for environments that rely on strong isolation between tenants. No in-the-wild exploitation was confirmed in the article, but the impact described is severe because a compromised host could expose other guest systems running on the same machine. The disclosure was reported by The Register, which framed it as the second major KVM bug found this year following “Januscape.” A fix may require downtime or disruption to deploy, according to the report.

Top Threat Actors Reported in Last 24 hours

Midnight Blizzard hijacks hotel Wi‑Fi logins

Midnight Blizzard (also tracked as Storm-2945), a Russia-linked espionage-focused group, has revived its CaptiveCrunch campaign by turning hotel Wi‑Fi sign-in pages into a trap for traveling professionals. They abuse shared equipment and management systems in the “captive portal” ecosystem at several North American hotel chains, then manipulate DNS and HTTP traffic to steer guests toward malicious infrastructure. Victims are pushed through ClickFix-style instructions that trick them into downloading a payload, with possible Android targeting via APK prompts (though broader Android deployment is not confirmed). For business travelers, this raises the stakes of routine connectivity: a hotel login can become the start of a device compromise and downstream access to corporate accounts and data. The activity was attributed by Microsoft and Black Lotus Labs, which identified 70 affected IP addresses tied to major hotel chains; the CornFlake RAT (a Rust variant) persists via service registration and scheduled tasks, while the FruitStone console is used to manage implants, deliver payloads, and rotate infrastructure.

Recommended actions: correlate connectivity with suspicious downloads, persistence changes, and anomalous device-code authentication; implement private connectivity where possible and reject portal-delivered software updates.

ShinyHunters claims Oracle PeopleSoft zero-day

ShinyHunters, a financially motivated hacking group, is claiming it exploited a new Oracle PeopleSoft zero-day that enables pre-authentication remote code execution. They say the flaw helped them breach an FBI system and steal sensitive information, a claim that—if true—would widen the blast radius for enterprises that rely on PeopleSoft for HR and finance operations. For affected organizations, the practical risk is straightforward: unauthorized access and data theft that can trigger operational disruption and costly incident response. The report also flags skepticism around the “zero-day” label because there is no independent forensic confirmation, and Oracle has not acknowledged the vulnerability, leaving customers without official guidance. The issue is described as distinct from CVE-2026-35273, while the arrest of a ShinyHunters member could help investigators map the group’s methods and targets.

Recommended actions: remove the Environment Management Hub and the Integration Broker from the public internet to reduce exposure; apply Oracle’s patch if available.

Belarusian Cyber Partisans linger in healthcare

The Belarusian Cyber Partisans, a Belarusian hacktivist group, quietly maintained access inside a Russian healthcare network for nearly two years—an unusually long dwell time that points to sustained espionage rather than quick disruption. They used the Vasilek backdoor, which communicates via Telegram, to keep their foothold while accessing sensitive medical data. For patients and healthcare providers, that kind of prolonged access raises the risk of privacy harms, coercion, and follow-on intrusions that exploit trusted relationships between hospitals, vendors, and partners. The Record reports that despite Telegram restrictions in Russia, the group could switch communications methods, suggesting resilience and an intent to stay embedded. Russian authorities have labeled the group an “extremist organization,” and the adversary has signaled it intends to keep operating.

CTA_2_LI_Tuesday_Saturday_DTI_MTI_Before_FAQ

Frequently Asked Questions

  1. What is @subql/common@5.8.3? @subql/common@5.8.3 is a poisoned npm release that turns a routine dependency update into credential theft, with the malicious payload executed from a newly added manifest-cache.js. It runs during post-install and grabs environment variables and cloud credentials, then attempts to use stolen GitHub tokens to create a branch named dependabot/github_actions/format/setup-formatter while spoofing the commit author.

  2. What is Midnight Blizzard? Midnight Blizzard, via its subcluster Storm-2945, has restarted the CaptiveCrunch campaign by abusing the captive-portal ecosystem used by major North American hotel chains. It manipulates DNS and HTTP traffic on shared hospitality equipment to funnel travelers toward attacker-controlled infrastructure, then uses ClickFix-style instructions to trick victims into downloading malicious payloads.

  3. What is Booba? Booba ransomware hit the University of Illinois Chicago’s College of Medicine and the group claims it stole 344 GB of data, even as the university said its main network and patient care delivery were not affected. It locks files by appending the .booba extension and is described as having variants for both Windows and Linux environments, widening where it can do damage.

  4. What is CVE-2026-88779? A newly disclosed Citrix NetScaler zero-day, CVE-2026-88779, lets attackers remotely trigger denial-of-service conditions that can take down authentication gateways on affected appliances. In practice, the bug hits NetScaler instances with SAML enabled, meaning legitimate users can be locked out when single sign-on paths are disrupted.

  5. What is CVE-2026-3854? A critical GitHub Enterprise Server vulnerability, CVE-2026-3854, allows an attacker to execute commands as the git service user by abusing a trust-boundary failure in the git push pipeline. The attack hinges on crafting push options so that delimiter confusion (a semicolon treated as a field separator) enables field injection into internal request metadata and overrides security-sensitive settings.

  6. What is ShinyHunters? ShinyHunters, a financially motivated hacking group, is claiming it exploited a new Oracle PeopleSoft zero-day that enables pre-authentication remote code execution. They say the flaw helped them breach an FBI system and steal sensitive information, a claim that—if true—would widen the blast radius for enterprises that rely on PeopleSoft for HR and finance operations.

  7. What is Belarusian Cyber Partisans? The Belarusian Cyber Partisans, a Belarusian hacktivist group, quietly maintained access inside a Russian healthcare network for nearly two years—an unusually long dwell time that points to sustained espionage rather than quick disruption. They used the Vasilek backdoor, which communicates via Telegram, to keep their foothold while accessing sensitive medical data.

Share this article

Discover Related Resources