Cyber Threat Brief — October 8 2026

⚠️ This report is AI-generated. Always validate findings.

1. FortiBleed — rogue FortiGate admins, owner lockouts, FBI IOCs

TL;DR: The FBI and Secret Service say FortiBleed operators are still logging into exposed FortiGate SSL VPN and admin interfaces with leaked or cracked passwords, adding their own admins, and sometimes deleting or re-passwording the real ones to lock owners out. Sweep FortiGate event logs for the advisory’s account names and IPs today, then kill sessions and reset every admin and VPN credential.

What’s New:

  • Joint advisory JCSA-20261006-01 (dated Oct 6, widely covered Oct 7–8) adds the lockout step: after creating new admins, the actor deletes or changes the password on existing ones.
  • It publishes 19 rogue admin names seen on victim devices and 20 actor IPs (C2, proxies, relay, Hashtopolis, brute-force sources).
  • Access is resold: the FBI names INC/Lynx and Payload ransomware affiliates as downstream users of FortiBleed access.
  • This is credential abuse, not a new FortiOS bug. Legacy SHA-256 admin hashes were cracked offline, so the fix is PBKDF2 plus MFA, not a patch.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
FortiOS event logid=0100044547 with cfgpath="system.admin" and action="Add"ConfigT1136.001Appliance syslogAlert on every FortiGate admin add. Read cfgobj for the new account name and ui for the source IP, and treat any add from outside your management subnet as compromise.
FortiOS event logid=0100044547 with cfgpath="system.admin" and action="Delete" or action="Edit" on an existing adminConfigT1531Appliance syslogAlert when an existing admin account is deleted or edited shortly after a new admin appears. That pairing is the FBI’s lockout pattern; keep out-of-band console access ready before you respond.
Rogue admin names adminin, fortiAdmin, forticloud-sync, forticloud-tech, fgtsecure, fgtsec, pakedge, districtadmin, system_config, gttadmin, roadmin, itadmin, Technical_support, adminsslvpn, IT_Manager, my_admin, support_fortinet, forti_support2 (FBI list)IOCT1136.001Config/inventoryRun show system admin and show user local on every FortiGate, then match account names against this list. The FBI list also includes admin, which is the factory default, so verify its password and last login instead of matching on the name.
Actor infrastructure IPs 45.154.12.132 (C2), 154.202.59.169 and 103.27.186.156 (proxies), 45.155.250.158 (beacon relay), 193.8.187.2 (jump box per CloudSEK), 193.8.187.42 (attack chain), 85.11.187.8 (Hashtopolis)IOCT1071.001Firewall/egressBlock these seven IPs and search firewall and proxy logs for any session to or from them. The FBI says the actor uses ports including TCP 4332 and 4432 but usually beacons over HTTPS.
Brute-force / successful-login IPs 104.28.155.27, 185.136.15.43, 185.136.15.66, 185.199.199.56, 193.8.186.33, 45.227.254.210, 77.91.118.10, 80.75.212.113, 87.251.64.13, 87.251.64.16, 87.251.64.17, 87.251.64.44, 66.175.220.111 (seen Jun 18 – Jul 23)IOCT1110.004Appliance syslogSearch FortiGate admin-login and SSL VPN login events back to June for these 13 source IPs. A successful login from any of them means that account’s password is burned: reset it and review what that session changed.
FortiGate REST API admins under config system api-userConfigT1098Config/inventoryList every system api-user entry and its trusted hosts. Delete any key you cannot tie to an owner and regenerate the legitimate ones, per the advisory.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedOnly Fortinet logic is Fortinet Appliance Auth bypass (Web datamodel /api/v2/cmdb/system/admin, CVE-2022-40684). No FortiOS event-log rule for admin adds, deletes, or VPN spraying.
ElasticPartial — FortiGate Administrator Account Creation from Unusual Source; FortiGate Super Admin Account CreationBoth key on 0100044547 + system.admin + Add. First needs a never-seen source IP; second fires only on super_admin profiles. Nothing on admin deletes or password changes.
SigmaPartial — FortiGate - New Administrator Account Created; FortiGate - New Local User CreatedMatch action: Add on system.admin / user.local. No lockout (Delete/Edit) or SSL VPN spraying logic.

Hunt hint: Pull FortiGate event logs back to June if you have them. List every system.admin Add, Edit, and Delete, and check new names against the FBI list. Join admin and SSL VPN logins against the 20 IPs above. If an owner admin was deleted or changed, rebuild from a known-good config and rotate any LDAP or RADIUS bind accounts stored on the box. Then check domain controllers for password spraying sourced from the SSL VPN address pool.

Sources: FBI/USSS JCSA-20261006-01 (PDF) · CloudSEK open-directory analysis · Fortinet PSIRT · BleepingComputer · SecurityWeek


2. [email protected] npm worm — Shai-Hulud with a token-revoke wiper

TL;DR: The tensorlake npm SDK shipped a malicious 0.5.144 on Oct 8 at 01:12 UTC that runs a preinstall credential stealer and self-spreading worm on developer machines. Find every host that installed it, remove the gh-token-monitor persistence before revoking anything, then rotate every credential that user could reach.

What’s New:

  • The payload was pushed straight to tensorlakeai/tensorlake main under a maintainer identity, so the npm release carries a valid provenance attestation.
  • The preinstall hook runs node lib/setup.mjs, which pulls the Bun runtime and runs the obfuscated lib/Math_Symbol.js. StepSecurity says the loader skips itself on CI, so laptops are the target.
  • Stolen data goes to a new public repo in the victim’s GitHub account (description “Shai-Hulud: Here We Go Again”) or to iseekaigogo[.]com.
  • Revoking the stolen GitHub token while gh-token-monitor is running wipes the user’s home directory (Linux/macOS) or profile (Windows).

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
npm package [email protected]VersionT1195.002Config/inventorySearch lockfiles, npm ls tensorlake, CI build logs, and developer-machine package inventory for tensorlake 0.5.144. Pin 0.5.143 and treat any host that ran the install as compromised.
lib/setup.mjs SHA-256 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5efIOCT1059.007EDR fileSweep EDR file events for this hash under node_modules/tensorlake/. A hit means the preinstall loader landed on that host.
lib/Math_Symbol.js SHA-256 b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fecIOCT1059.007EDR processSweep for this hash, and hunt a bun process whose command line references Math_Symbol.js with a node parent.
~/.config/gh-token-monitor/ and ~/.local/bin/gh-token-monitor.sh (systemd user unit gh-token-monitor.service)PathT1543.002EDR fileAlert on creation of these paths. On a hit, back up the host, run systemctl --user disable --now gh-token-monitor.service, and delete the files before anyone revokes the GitHub token.
~/Library/LaunchAgents/com.user.gh-token-monitor.plistPathT1543.001EDR fileSame macOS persistence. Run launchctl bootout on that plist and delete it before revoking tokens.
Windows ONLOGON scheduled task that runs monitor.ps1ProcessT1053.005Windows Security 4698Hunt task-creation events whose action runs monitor.ps1, and PowerShell polling api.github.com/user about every 60 seconds. Delete the task before revoking tokens.
Domain iseekaigogo[.]comIOCT1071.001DNSBlock it and search DNS and proxy logs since Oct 7 for lookups, prioritizing queries from node or bun processes.
Commit author [email protected] with message chore: update dependenciesIOCT1195.002App audit logSearch GitHub org audit and commit history for this author adding .claude/settings.json or .vscode/tasks.json. Revert those files and treat the pushing token as stolen.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedShai-Hulud Workflow File Creation or Modification and Shai-Hulud 2 Exfiltration Artifact Files match 2025 filenames (shai-hulud*.yml, truffleSecrets.json), not setup.mjs, Math_Symbol.js, or gh-token-monitor.
ElasticPartial — Node.js Pre or Post-Install Script ExecutionLinux/macOS only. Fires on any child of node install, so it sees the preinstall launch, but it is generic and has no tensorlake, hash, or gh-token-monitor logic.
SigmaNone — verified2025 Shai-Hulud rules match bun_environment.js, a bun.sh/install one-liner, or a package list without tensorlake. How setup.mjs fetches Bun is unpublished.

Hunt hint: Inventory first: lockfiles, CI caches, and dev laptops. On any hit, back up, remove gh-token-monitor (systemd unit, LaunchAgent, or ONLOGON task), and only then revoke GitHub and npm tokens. Rotate AWS, Vault, Kubernetes, SSH, .env, and AI-tool keys that user could read. Check your GitHub org for new public repos with the Shai-Hulud description. Set ignore-scripts=true in .npmrc where builds allow it.

Sources: StepSecurity · Socket · Aikido · Semgrep on X · The Hacker News


Detection index: ESCU 8742898 (2026-10-08) · elastic detection-rules bc5b7c3 (2026-10-08) · SigmaHQ 8a48134 (2026-10-06)

Status Updates

  • CVE-2026-21589 (Atlassian Data Center): Exploitation is now confirmed by two origins. Previdian honeypots logged 15 attempts from 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225, and watchTowr reports in-the-wild traffic that so far only fingerprints products and sweeps config files. Block those IPs and keep the ..:: hunts; still not KEV. Oct 7 brief.
  • CVE-2026-88779 (NetScaler): The CISA KEV due date 2026-10-07 has passed, so this is now overdue. Confirm every SAML SP/IdP appliance runs 14.1-73.41, 13.1-64.28, or the matching FIPS/NDcPP build; no new vendor IOCs. Oct 5 brief.
  • CVE-2026-102489 (Zammad): Horizon3 published the unauthenticated trigger on Oct 7: one WebSocket message to /ws makes the error reply carry every active session cookie. Keep the DIVD "Cookie"=>" and @clients={ log greps; KEV overdue since 2026-10-05. Oct 3 brief.
  • SonicWall SMA1000 (CVE-2026-83548 line): SonicWall’s Oct 6 hotfix advisory fixes a new pre-auth WorkPlace SSRF, CVE-2026-102255 (CVSS 10, no exploitation reported), and the September fix builds 12.4.3-03526 / 12.5.0-02952 are affected. Move to 12.4.3-03670 or 12.5.0-03082. Sep 3 brief.
  • Retired from watch (KEV backfill): CVE-2026-59822 (BerriAI LiteLLM), CVE-2026-48710 (Starlette) — KEV added 2026-09-02, due 2026-09-16; never briefed (cap overflow); retired 2026-10-07.

Watching (no change): CVE-2026-104286 FortiMail, KEV overdue (Oct 2 brief) · CVE-2026-102490 Zammad LPE, KEV overdue (Oct 3 brief) · CVE-2026-61500 Rejetto HFS (Oct 4 brief) · CVE-2026-88062 OmniRoute (Oct 4 brief) · ClickFix cache smuggling (Oct 7 brief)