Cyber Threat Brief — October 7 2026

⚠️ This report is AI-generated. Always validate findings.

1. Atlassian CVE-2026-21589 — PoC paths, Crowd chain, scanning

TL;DR: watchTowr published working pre-auth file-read paths for CVE-2026-21589 on 2026-10-06 (:: ↔ / in atlassian-plugins-webresource 6.0.7). A Nuclei template and DAG are public; SecurityOnline attributes Previdian honeypot hits as ITW. Patch internet-facing DC nodes today, then hunt the named ..:: resource paths and any Crowd REST abuse.

What’s New:

  • Root cause is shared library atlassian-plugins-webresource 6.0.7 (patched 6.0.8): Router.unescapeSlashes maps :: to /, so ..:: bypasses slash-stripping and reads files inside the Tomcat webroot (not outside it).
  • Concrete unauth GETs: Jira /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml; Confluence /s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::…::WEB-INF::web.xml; Bitbucket /s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::…::WEB-INF::urlrewrite.xml (Bitbucket blocks web.xml).
  • Crowd-integrated Jira: read WEB-INF/classes/crowd.properties for plaintext application.password, then Crowd REST create-user / add to jira-administrators. Crowd IP allowlists blunt remote follow-on.
  • Public tooling: watchTowr DAG (watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589); Nuclei http/cves/2026/CVE-2026-21589.yaml (authors include DhiyaneshDk). SecurityOnline 2026-10-07 cites Previdian honeypot ITW — treat as sensor-attributed; exploitgrid on X still said “no exploitation observed” the evening of 2026-10-06.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Self-hosted Atlassian DC builds below Bitbucket 9.4.26/10.2.8/10.5.1, Confluence 9.2.26/10.2.19, Jira Software 9.12.40/10.3.26/11.3.12, JSM 5.12.40/10.3.26/11.3.12, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible/Fisheye 4.9.15Vulnerable appT1190App admin → System info / install inventory / CMDBInventory every internet-facing node (incl. Bitbucket mirrors). If below the fixed line for that branch, upgrade to the matching fixed build before relying on WAF.
atlassian-plugins-webresource-6.0.7.jar (patched 6.0.8)Vulnerable libraryT1190$CATALINA_HOME / product WEB-INF/lib inventoryOn each node, confirm the webresource JAR is ≥6.0.8 after upgrade; if 6.0.7 remains, the host is still vulnerable even if the product UI version looks current.
GET …/images/..::..::…::WEB-INF::web.xml (Jira/Confluence) or …/avatar/..::…::WEB-INF::urlrewrite.xml (Bitbucket)Exploit pathT1190Access / reverse-proxy / WAF logsDouble-URL-decode request lines and alert on ..:: next to resource download paths above, or on decoded WEB-INF reads via /download/resources/ / /s/*/download/resources/. Preserve matching windows for IR.
WEB-INF/classes/crowd.properties with plaintext application.passwordSensitive file / pivotT1552.001Access logs + Crowd audit / REST logsIf Crowd is wired in, treat any successful read of crowd.properties as credential theft. Rotate the Crowd application password, then hunt Crowd REST user-create and jira-administrators group adds.
watchTowr DAG + Nuclei template CVE-2026-21589.yamlScanner / PoCT1190External scan telemetry / attack surface mgmtAuthorize DAG/Nuclei only against owned hosts to validate exposure. Expect noisy third-party scans now that both are public.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedConfluence ESCU stories still match OGNL ${ / older privilege-escalation URLs, not ..:: web-resource reads for CVE-2026-21589.
ElasticNone — verifiedLocal elastic_dr has no rule whose logic targets Atlassian :: webresource traversal.
SigmaNone — verifiedPath Traversal Exploitation Attempts only matches hard-coded etc/windows/lib/password strings — would miss WEB-INF::web.xml via ::. Older Atlassian ET rules cover 2019–2023 CVEs.

Hunt hint: Pull versions (and the webresource JAR) from every public Atlassian DC VIP. Upgrade or pull off-net first. Sweep seven days of access logs for decoded ..:: on the Jira/Confluence/Bitbucket resource paths above and for crowd.properties hits. On Crowd, review recent REST user creates and jira-administrators membership changes.

Sources: watchTowr Labs · SecurityOnline ITW/Nuclei · watchTowr DAG · Nuclei CVE-2026-21589.yaml · Oct 6 brief


2. ClickFix cache-smuggles VBScript via browser cache

TL;DR: Microsoft Threat Intelligence describes a ClickFix variant that pre-fetches a VBScript into the browser cache as a fake PNG, then uses a short Run-dialog command to find Firefox f_* cache files by size, copy to %LOCALAPPDATA%\Temp\t.vbs, and run wscript.exe — bypassing the ~260-character Run limit. Hunt RunMRU, t.vbs/wscript, and the named C2 hosts; do not rely on download events alone.

What’s New:

  • Compromised sites stage the payload in cache before the paste step, so the Run command only has to locate and launch what is already local.
  • Chain: cmd enumerates f_* under %LOCALAPPDATA%\Mozilla\Firefox\Profiles, size-matches, copies to %LOCALAPPDATA%\Temp\t.vbs, executes with wscript.exe; WMI host harvest; fetches v.ps1 from cocojambo[.]us[.]com/alfa; later cab.dat; injects into timeout.exe; further stages from capsysnet[.]vg / ciliabula[.]cc.
  • MS guidance: cloud/web/network protection, app control, PowerShell script-block logging; hunt RunMRU, browser-cache activity, WScript/PowerShell children, scheduled tasks — beyond download events.
  • Classic FakeCAPTCHA/ClickFix public rules still help on the paste/RunMRU stage, but they do not encode the f_* size-match → t.vbs cache-smuggle specifically.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
%LOCALAPPDATA%\Temp\t.vbs created then executed by wscript.exeProcess / file IOCT1059.005Sysmon 1/11, EDR process+fileAlert when wscript.exe runs %LOCALAPPDATA%\Temp\t.vbs (or a freshly copied .vbs under Temp) shortly after a Run-dialog / explorer parent. Quarantine the host and collect the script.
cmd.exe enumerating f_* under %LOCALAPPDATA%\Mozilla\Firefox\Profiles then copying a size-matched file to TempProcess behaviorT1036 / T1059.003Sysmon 1, EDR command lineHunt cmd.exe command lines that recurse Firefox Profiles for f_* and copy to Temp; treat size-match-only (no content marker) as this campaign’s tell.
Domains cocojambo[.]us[.]com (path /alfa → v.ps1), capsysnet[.]vg, ciliabula[.]ccNetwork IOCT1071.001Proxy / DNS / firewallBlock and retrospectively query DNS/proxy for these three hosts; prioritize endpoints that also show t.vbs/wscript or RunMRU activity.
Process injection into newly launched timeout.exe followed by PowerShell outboundProcess behaviorT1055Sysmon 1/8/10, EDRHunt timeout.exe started then injected, especially when its child is PowerShell reaching the C2 domains above.
RunMRU registry values with short cmd/wscript lines after fake CAPTCHA luresHunt pivotT1204.001Sysmon 13 / Registry, Splunk ESCU RunMRUQuery RunMRU for recent cmd/wscript/powershell pastes; correlate with browser parents and the Temp t.vbs artifact within minutes.

Detection

SourceRuleGap
Splunk ESCUPartial — Windows PowerShell FakeCAPTCHA Clipboard Execution; Windows RunMRU Command Execution (Fake CAPTCHA story)Catch classic CAPTCHA-string / RunMRU paste. Do not match f_* size-match → Temp\t.vbs cache smuggle.
ElasticPartial — Potential Fake CAPTCHA Phishing AttackMatches explorer→powershell/cmd/mshta with CAPTCHA/verification strings. Misses cache-file size enumeration and t.vbs unless those strings appear.
SigmaPartial — Potential ClickFix Execution Pattern - Registry; Potentially Suspicious Command Executed Via Run Dialog Box - RegistryRunMRU http/captcha/LOLBin patterns. No f_* / t.vbs / Firefox-cache logic.

Hunt hint: Pull 14 days of RunMRU and wscript.exe children. Stack any Temp\t.vbs create+execute with Firefox profile f_* file reads and DNS to the three C2 domains. Educate users that a CAPTCHA must never ask them to paste into Run.

Sources: The Hacker News · iTnews (MS TI summary)


Status Updates

  • CVE-2026-88779 (NetScaler): CISA KEV due TODAY 2026-10-07; forensic triage Yes. Still vendor/KEV DoS on SAML SP/IdP. Fixed builds 14.1-73.41 / 13.1-64.28 / FIPS 14.1-73.41 / NDcPP 13.1-37.282. No new KEV add overnight (catalog still 2026.10.04, count 1734). Oct 5 brief.
  • CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. FG-IR-26-175 solution update 2026-10-05 now names fixed builds 8.0.2, 7.6.7, 7.4.9; 7.2 → migrate to 7.4+. Keep IBE disable / management ACL and /data/etc/ld.so.preload / liblog.so hunts until upgraded. Oct 2 brief.
  • CVE-2026-102489 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Confirm interim 7.2.0 and DIVD IOC script. Oct 3 brief.
  • CVE-2026-102490 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Local zammad to root; no confirmed fixed build beyond leaving the affected line. Oct 3 brief.
  • CVE-2026-61500 (Rejetto HFS): Still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1, /~/api/loginSrp1, server_code, and 173.239.211.248/249. Oct 4 brief.
  • CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep POST /api/acp/agents and requireLogin=false hunts. Oct 4 brief.