Cyware at FS-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - October 07, 2026

10 min read
Share this article
shutterstock 1453727786

Summary

A single flaw in Cleo file-transfer software let Termite ransomware operators breach insurance giant Aon, locking up systems and data in a high-stakes extortion play. Cyware highlights how attackers mapped network shares and disabled key services, forcing operational downtime and exposing sensitive information. The incident, discovered just a day after the October 6 breach, links Termite to prior attacks on Blue Yonder and Genea, underscoring the urgent need for patching Cleo products.

A critical vulnerability in Atlassian Data Center products, tracked as CVE-2026-21589 with a CVSSv4 score of 9.3, lets remote attackers read files from the web root using a double-colon path traversal trick. This flaw exposes sensitive configuration data across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye, with public proof-of-concept scripts raising the risk of exploitation. Rapid7 researchers detailed the issue, and Atlassian has issued a fix.

FortiBleed attackers are turning stolen credentials into mass compromise of Fortinet firewalls and VPN gateways, with SOCRadar confirming 86,644 devices breached across 194 countries and up to 450,000 targeted. The campaign enables ransomware affiliates to create new admin accounts, lock out legitimate users, and pivot deeper into networks. Organizations relying on perimeter VPN access face a direct path to outages and extortion if defenses lag.

CTA_1_LI_Wednesday_Friday_DTI_WTI_After_Overview

Top Malware Reported in the Last 24 Hours

Termite ransomware hits Aon via Cleo

Termite has been blamed for a breach at insurance and risk-management giant Aon after attackers exploited a flaw in Cleo file-transfer software, tracked as CVE-2024-50623. The group’s playbook centers on breaking in through exposed applications and then locking up systems and data to force payments, a combination reflected in the cited MITRE ATT&CK techniques Exploit Public-Facing Application (T1190) and Data Encrypted for Impact (T1486). In this case, it uses built-in Windows functions to map out network shares and stop key services, raising the odds of widespread business disruption once encryption begins. The incident was reported as occurring on October 6, 2026, with the breach discovered the next day, and the write-up links the crew to prior attacks on Blue Yonder and Genea. For affected businesses, the immediate consequence is operational downtime paired with extortion pressure tied to stolen data. A patch is referenced as part of recommended actions for Cleo products.

Lunex stealer spreads via fake Cloudflare

Lunex is an infostealer sold as a malware-as-a-service offering, and it is being pushed in Ukraine through the ClickFix campaign after attackers compromised over 100 websites. Instead of a traditional attachment, it tricks visitors with fake Cloudflare-style verification pages that pressure users into running PowerShell commands, which then pull down the payload. Once installed, it targets credentials, authentication tokens, and cryptocurrency wallet data, turning a single bad click into account takeovers and follow-on fraud. CERT-UA is tracking this activity as UAC-0277, and reporting describes Lunex as developed by Russian-speaking operators and marketed to affiliates. It specifically targets seven Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi. Recommended actions mentioned include blocking known malicious infrastructure, watching for unusual PowerShell activity and suspicious browser extensions, and conducting regular security audits.

Partisan Zmiy stalks healthcare via Telegram

Partisan Zmiy is a healthcare-focused espionage campaign that strings together Telegram control channels, DNS tunneling, and scheduled execution to keep access alive even when defenders clean up one pathway. The activity, attributed in the report to the Cyber Partisans, was discovered in December 2025 with evidence reaching back to early 2024. It uses a loader named authd.exe disguised as a “VMware Auth Adapter” service to run the Vasilek backdoor and a GOST tunnel, hiding components under names that resemble legitimate VMware and system files. For victims, the practical impact is long-term surveillance risk: the write-up says attackers maintained access to a medical organization for approximately two years and used trust relationships to reach subsidiary institutions. Recommended actions mentioned include investigating recurring detections and service changes, verifying signatures in trusted directories, and enhancing monitoring for unusual service creation tied to VMware Tools paths.

Top Vulnerabilities Reported in Last 24 hours

Atlassian Data Center flaw exposes files

A critical unauthenticated arbitrary file access flaw in multiple Atlassian products (CVE-2026-21589, CVSSv4 9.3) lets remote attackers read files from an application’s web root, potentially exposing secrets that can enable broader compromise. Attackers can use a path traversal technique that treats double-colon sequences as path separators to reach sensitive configuration data. Public proof-of-concept scripts increase the risk of exploitation. Researchers at Rapid7 detailed the issue affecting Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. A fix is available in Atlassian’s advisory.

Veeam bug enables code execution

A critical flaw in Veeam Backup & Replication (CVE-2025-64393, CVSS 9.4) can let a low-privileged user execute remote code, turning a limited account into a potential takeover path inside backup infrastructure. The weakness stems from insecure deserialization of untrusted data and requires an authenticated account with the Backup Viewer role, according to the report. No exploitation in the wild has been confirmed. The same disclosure also flags additional issues: CVE-2026-58069, CVE-2025-64392, and CVE-2026-93026. A fix is available via Veeam updates for affected builds.

SonicWall patches SMA 1000 bugs

Four critical SonicWall SMA 1000 series vulnerabilities include a pre-authentication SSRF issue (CVE-2026-102255) that could allow remote attackers to carry out unauthorized operations against appliances used for secure remote access. Remote, unauthenticated attackers can exploit the SSRF flaw by sending crafted requests to the appliance, potentially turning an internet-facing gateway into a pivot point toward internal systems. No evidence of active exploitation has been reported for these specific flaws. Researchers Benoît Sevens and Brian Mariani reported the vulnerabilities, and the advisory notes that similar SMA SSRF issues have been targeted in the past, including zero-day activity in 2026. Fixes are available in firmware 12.4.3-03670 or higher, and 12.5.0-03082 or higher.

Top Threat Actors Reported in Last 24 hours

CL-STA-1178 poses as Dubai recruiters

CL-STA-1178, an Iranian state-aligned threat actor, is luring software engineers with fake “Dubai Airport Careers” recruiting outreach that doubles as a malware delivery scheme. They build credibility with a decoy installer before switching to a malicious Visual Studio “assessment” project that runs ShelbyLoader V2. Once on a machine, the malware uses GitHub for command-and-control and can fall back to GitHub issues to recover if access fails, helping the campaign stay resilient. For developers, the real-world consequence is that a routine-looking hiring test can become a beachhead for broader network access and follow-on intrusion activity. The toolset also uses Chisel to create encrypted tunnels and reverse SOCKS access for pivoting through internal networks; investigators are looking for unexpected DLL loads and unusual GitHub API traffic.

Cyber Partisans linger inside healthcare networks

The Cyber Partisans, a politically motivated hacking group, are tied to the Partisan Zmiy malware campaign that quietly embedded itself in healthcare environments for long stretches of time. Discovered in December 2025 with evidence reaching back to early 2024, they maintained access inside one medical organization for about two years and used trust relationships with subsidiaries to move further. Their toolkit blends Telegram control channels, DNS tunneling, and scheduled payload execution, with components disguised as familiar system files and services. For hospitals and their connected clinics, this kind of long-running access raises the risk of patient data exposure and operational disruption without obvious early warning signs. The Vasilek backdoor can run shell commands, transfer files, and keylog, and responders are checking recurring detections and signature mismatches in trusted directories.

FortiBleed fuels firewall-to-ransomware access

FortiBleed is an active credential-compromise campaign targeting Fortinet firewalls and VPN gateways, with US agencies warning it can set the stage for ransomware. Rather than relying on a single exploit chain described publicly, the attackers use stolen credentials to log in, create new admin accounts, and even lock out legitimate users by changing passwords or disabling accounts. At scale, SOCRadar verified 86,644 compromised devices across 194 countries, while follow-on investigations suggested 400,000 to 450,000 firewalls were targeted. For organizations that depend on perimeter VPN access for staff and contractors, the consequence is that a network edge device can become a fast track to outages and extortion if access is resold. The alert ties activity to initial access brokers supplying ransomware affiliates including INC/Lynx and Payload; defenders are emphasizing MFA and review of firewall/VPN user changes.

CTA_2_LI_Wednesday_Friday_DTI_WTI_Before_FAQ

Frequently Asked Questions

  1. What is Termite? Termite has been blamed for a breach at insurance and risk-management giant Aon after attackers exploited a flaw in Cleo file-transfer software, tracked as CVE-2024-50623. The group’s playbook centers on breaking in through exposed applications and then locking up systems and data to force payments, a combination reflected in the cited MITRE ATT&CK techniques Exploit Public-Facing Application (T1190) and Data Encrypted for Impact (T1486).

  2. What is Lunex? Lunex is an infostealer sold as a malware-as-a-service offering, and it is being pushed in Ukraine through the ClickFix campaign after attackers compromised over 100 websites. Instead of a traditional attachment, it tricks visitors with fake Cloudflare-style verification pages that pressure users into running PowerShell commands, which then pull down the payload.

  3. What is Partisan Zmiy? Partisan Zmiy is a healthcare-focused espionage campaign that strings together Telegram control channels, DNS tunneling, and scheduled execution to keep access alive even when defenders clean up one pathway. The activity, attributed in the report to the Cyber Partisans, was discovered in December 2025 with evidence reaching back to early 2024.

  4. What is CVE-2026-21589? A critical unauthenticated arbitrary file access flaw in multiple Atlassian products (CVE-2026-21589, CVSSv4 9.3) lets remote attackers read files from an application’s web root, potentially exposing secrets that can enable broader compromise. Attackers can use a path traversal technique that treats double-colon sequences as path separators to reach sensitive configuration data.

  5. What is CVE-2025-64393? A critical flaw in Veeam Backup & Replication (CVE-2025-64393, CVSS 9.4) can let a low-privileged user execute remote code, turning a limited account into a potential takeover path inside backup infrastructure. The weakness stems from insecure deserialization of untrusted data and requires an authenticated account with the Backup Viewer role, according to the report.

  6. What is CVE-2026-102255? Four critical SonicWall SMA 1000 series vulnerabilities include a pre-authentication SSRF issue (CVE-2026-102255) that could allow remote attackers to carry out unauthorized operations against appliances used for secure remote access. Remote, unauthenticated attackers can exploit the SSRF flaw by sending crafted requests to the appliance, potentially turning an internet-facing gateway into a pivot point toward internal systems.

  7. What is CL-STA-1178? CL-STA-1178, an Iranian state-aligned threat actor, is luring software engineers with fake “Dubai Airport Careers” recruiting outreach that doubles as a malware delivery scheme. They build credibility with a decoy installer before switching to a malicious Visual Studio “assessment” project that runs ShelbyLoader V2.

  8. What is Cyber Partisans? The Cyber Partisans, a politically motivated hacking group, are tied to the Partisan Zmiy malware campaign that quietly embedded itself in healthcare environments for long stretches of time. Discovered in December 2025 with evidence reaching back to early 2024, they maintained access inside one medical organization for about two years and used trust relationships with subsidiaries to move further.

  9. What is FortiBleed? FortiBleed is an active credential-compromise campaign targeting Fortinet firewalls and VPN gateways, with US agencies warning it can set the stage for ransomware. Rather than relying on a single exploit chain described publicly, the attackers use stolen credentials to log in, create new admin accounts, and even lock out legitimate users by changing passwords or disabling accounts.

Share this article

Discover Related Resources