Cyber Threat Brief — October 9 2026
1. AhsayCBS — CVE-2026-105133 and CVE-2026-105134 exploited for SYSTEM RCE
TL;DR: Huntress is seeing attackers chain two AhsayCBS bugs for unauthenticated code execution as SYSTEM, then drop JSP webshells and a Monero miner disguised as Microsoft Edge. Huntress says the newest release, 10.3.4, is still vulnerable, so take the AhsayCBS web interface off the internet and hunt for children of cbssvcX64.exe today.
What’s New:
- Huntress first saw exploitation at 2026-10-07 23:20 UTC and counted five targeted organizations by Oct 8.
- CVE-2026-105133 bypasses authentication, then CVE-2026-105134 in
/rps/api/json/UpdateReceivers.doruns commands asNT AUTHORITY\SYSTEM. - The sources disagree on the fix: NVD and the discovering researcher at Armadin say 10.3.4 fixes it, but Huntress’s Oct 8 update says 10.3.4 is also affected and no patch exists yet.
- NVD flagged published exploit code on Oct 4, so expect more actors.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
ParentImage ending \cbssvcX64.exe (or \cbssvcX86.exe) with a child cmd.exe, powershell.exe, curl.exe, or certutil.exe | Process | T1059.003 | Sysmon 1 | Alert on any child of cbssvcX64.exe or cbssvcX86.exe outside the service’s normal startup commands. Huntress saw curl.exe and certutil.exe children pulling payloads into %TEMP%. |
URL path /rps/api/json/UpdateReceivers.do | IOC | T1190 | Web/proxy access | Search AhsayCBS and reverse-proxy logs back to 2026-10-04 for requests to this path from any address that is not one of your replication peers. A hit followed by a new .jsp file means the server is compromised. |
New .jsp file in the web application directory that AhsayCBS serves | Path | T1505.003 | Sysmon 11 | Alert on .jsp creation by cbssvcX64.exe and list any recently added .jsp files. Also review the Replication Receiver entries in the AhsayCBS console, because the actor configured a malicious receiver. |
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/ serving Taskgmr.ps1, edge.exe, msedge.exe, config.json, and WinRing0x64.sys | IOC | T1105 | Web/proxy access | Block the host imagefiles-backup.oss-ap-southeast-7.aliyuncs.com and search proxy and DNS logs back to 2026-10-07 23:20 UTC for it. |
Service MicrosoftEdgeUpdateSvc running msedge.exe from a Temp folder | Process | T1543.003 | Windows Security 4697 | The real Edge updater service is edgeupdate. Alert on Security 4697 (or System 7045) with ServiceName=MicrosoftEdgeUpdateSvc or a service file name ending \Temp\msedge.exe. The binary is a renamed NSSM, SHA-256 05f69ae6b2b89c1c4dcf836bff032232f11bf0109f2b498e2345045d06139034. |
edge.exe in a Temp folder (XMRig, SHA-256 4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d) | IOC | T1036.005 | Sysmon 1 | Alert on edge.exe or msedge.exe running from \AppData\Local\Temp\ or \Windows\Temp\. The genuine Edge binary lives under Program Files (x86)\Microsoft\Edge\Application. |
xmr.kryptex[.]network:8029 (resolves to 51.195.127[.]124) | IOC | T1571 | Firewall/egress | Block TCP 8029 to xmr.kryptex.network and 51.195.127.124, and search egress logs for connections from the AhsayCBS host. |
Taskgmr.ps1 in a Temp folder (SHA-256 481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21) | IOC | T1564 | EDR process | Search PowerShell script-block events (4104) for a script that checks whether Task Manager is running and then stops or starts a service. It also kills Task Manager at 18:00 local time. |
C:\Users\<user>\AppData\Local\Temp\WinRing0x64.sys | IOC | T1496.001 | Sysmon 6 | Alert on ImageLoaded ending \WinRing0x64.sys from a Temp folder. Huntress saw it fetched with certutil.exe, which gives the miner kernel-level hardware access. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Windows File Download Via CertUtil | Covers only the certutil download step, and only if the command uses urlcache, verifyctl, or -URL. Huntress did not publish the exact flags. Nothing keys on cbssvcX64.exe children or the JSP webshell. |
| Elastic | Partial — Suspicious Service was Installed in the System | Fires on 4697 or 7045 only when the service path contains \Users\, so it misses a service binary in C:\Windows\Temp. |
| Sigma | Partial — Vulnerable WinRing0 Driver Load | Covers only the driver-load step. Huntress published four AhsayCBS Sigma rules in its own threat-intel repo; they are not in SigmaHQ and I did not read them. |
Detection index: ESCU d84e86d7 (2026-10-09) · elastic detection-rules 195f15c0 (2026-10-09) · SigmaHQ 8a481340 (2026-10-06)
Hunt hint: Pull Sysmon process creation for cbssvcX64.exe and cbssvcX86.exe parents back to 2026-10-07 23:20 UTC. Look for .jsp files and for services named MicrosoftEdgeUpdateSvc. Check egress logs for these six addresses that Huntress lists as IOCs without saying what role each plays: 177.4.12[.]11, 38.60.252[.]110, 107.191.47[.]199, 185.220.236[.]49, 104.234.26[.]10, and 123.202.208[.]37. Until a fix is confirmed, restrict the AhsayCBS web interface to a VPN or trusted IPs. Huntress says to re-image a host that shows any of these indicators, because the actors hid secondary backdoors.
Sources: Huntress writeup · Huntress X post · Huntress X update on 10.3.4 · Armadin X post (discoverer) · Rapid7 CVE-2026-105134 entry · SecurityWeek
2. Bricksforge — CVE-2026-85097 WordPress upload-to-RCE exploited since Oct 7
TL;DR: Patchstack says attackers have been exploiting an unauthenticated file-upload flaw in the Bricksforge WordPress plugin since 2026-10-07 21:47 UTC to plant PHP webshells. Update to 3.1.8.10 and look for stray PHP files in your uploads directories.
What’s New:
- CVE-2026-85097 affects Bricksforge through 3.1.8.9, and the fix is 3.1.8.10.
- The plugin checks an upload’s MIME type once, then trusts the client’s
urlmetadata when the form is submitted. - Attackers upload a GIF/PHP polyglot and set that
urlto a.phppath, so the server writes executable PHP. - Patchstack saw 63 source IPs in two automated clusters and several extension and encoding bypass attempts.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
POST /wp-json/bricksforge/v1/form_submit with a temporaryFileUploads parameter | IOC | T1190 | WAF | Search request logs back to 2026-10-07 21:47 UTC for this path and parameter. Patchstack saw all but one attempt here, so an unpatched site with any hit should be treated as compromised. |
/wp-admin/admin-ajax.php with action=bricksforge_form_submit | IOC | T1190 | Web/proxy access | Search for this action from unauthenticated clients. Patchstack saw one attempt through this fallback route. |
action=bricksforge_regenerate_nonce called by an unauthenticated client | IOC | T1190 | Web/proxy access | Alert on this action when it is followed by an upload and a form_submit call from the same IP. It is the first step of the chain. |
temporaryFileUploads entry whose file ends .gif or .png while its url ends .php, .php5, .phtml, or an encoded form such as %2ephp | IOC | T1190 | WAF | Alert when the image path and the destination URL extensions disagree. Case variants such as .PHP and double-encoded dots were also seen. |
/wp-content/uploads/bricksforge/tmp/*.php | Path | T1505.003 | EDR file | Run find /var/www -path '*/uploads/bricksforge/tmp/*' -name '*.php*' on every WordPress host. Any hit is a webshell, so isolate the site before cleanup. |
login_admin_*.php under /wp-content/uploads/YYYY/MM/ | Path | T1505.003 | Web/proxy access | Search for requests to files matching login_admin_*.php in dated uploads directories and delete any that exist. Patchstack saw this name used to escape the plugin’s temp folder. |
WordPress plugin bricksforge at version 3.1.8.9 or lower | Version | T1190 | Config/inventory | List installed plugin versions (for example wp plugin list --name=bricksforge) and update every site to 3.1.8.10 or later. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | No WordPress, Bricksforge, or polyglot-upload analytic in the mirror. |
| Elastic | Partial — Potential Polyglot Bypass File Created by Web Server | Linux file events only. It fires when a web process writes a script-extension file whose header bytes are GIF or PNG, and sees nothing on the request side. |
| Sigma | None — verified | No WordPress or polyglot upload rule. Generic web rules do not match this payload. |
Hunt hint: Search WAF or reverse-proxy logs for form_submit requests from 2026-10-07 21:47 UTC onward and list the source IPs. Patchstack’s six busiest were 177.75.57.20, 23.97.62.146, 84.247.60.125, 38.154.185.97, 150.109.16.166, and 153.75.90.146, but the actor rotates proxies, so do not rely on IPs. Then list PHP files created after that time anywhere under wp-content/uploads. For each one found, check access logs for later requests to it. If you cannot update, put a WAF rule on temporaryFileUploads first.
Sources: Patchstack writeup · Patchstack vulnerability entry · Bricksforge changelog · GitHub advisory GHSA-jfvp-gc8p-45gp
3. Integrity Tech (Flax Typhoon) — AA26-281A and five legacy KEV additions
TL;DR: The FBI, CISA, and partners published advisory AA26-281A on Oct 8 about China-linked intrusions enabled by Integrity Technology Group, and CISA added five of the advisory’s older CVEs to KEV with a federal due date of Oct 11. Check for those old internet-facing products first, then hunt for SoftEther installers renamed conhost.exe or dllhost.exe and DCSync from non-DC accounts.
What’s New:
- The DOJ and FBI seized seven domains tied to the MicroScan scanner, the FishHub phishing platform, and SoftEther hosting.
- KEV added CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894 on 2026-10-08, all due 2026-10-11. Forensic triage is required for every one except BIND.
- The actors rename SoftEther VPN clients to
conhost.exeordllhost.exe, spray Exchange with EBurst, run DCSync withDC.exe, and pull Microsoft 365 mail withoffice-cli. - The advisory warns that some of its IOCs date back to 2016, so vet them before you block.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
FTP commands SITE CPFR then SITE CPTO against ProFTPD 1.3.5 (CVE-2015-3306) | IOC | T1190 | App audit log | Search ProFTPD logs for SITE CPFR and SITE CPTO from unauthenticated sessions. Upgrade ProFTPD or disable the module that provides those commands, and check for files written outside the FTP root. |
method: prefix in a request to a Struts .action URL (CVE-2016-3081, Struts 2.3.19 to 2.3.28 with Dynamic Method Invocation on) | IOC | T1190 | Web/proxy access | Search access logs for method: in the URL or query string on Struts applications, and turn off Dynamic Method Invocation or upgrade past 2.3.28. |
/.. inside an image-upload parameter sent to ONLYOFFICE DocumentServer 5.1.5 to 5.6.2 (CVE-2021-3199) | IOC | T1190 | Web/proxy access | Search DocumentServer and proxy logs for upload requests with /.. in a parameter value. Upgrade any DocumentServer still on 5.6.2 or older. |
| Strapi 4.5.5 or older (CVE-2023-22894) | Version | T1190 | Config/inventory | Run npm ls @strapi/strapi on every Strapi host. CISA says this bug chains with CVE-2023-22621 to reach RCE, so move off unsupported versions and rotate admin credentials. |
| DNS queries of type TKEY (record type 249) to ISC BIND before 9.9.7-P2 or 9.10.x before 9.10.2-P3 (CVE-2015-5477) | IOC | T1499.004 | DNS | Search BIND query logs for TKEY queries from external sources. Check syslog for named assertion failures or restarts, and upgrade past 9.9.7-P2 or 9.10.2-P3. |
conhost.exe or dllhost.exe with OriginalFileName matching vpnbridge*.exe or Company containing SoftEther | Process | T1036.003 | Sysmon 1 | Alert when either name runs with SoftEther metadata. The advisory says the actors download SoftEther with PowerShell or curl and set it to reconnect at startup. |
dns.studiocloud[.]xyz | IOC | T1071.001 | DNS | Search DNS and proxy logs for this name, which DiagTrack.exe contacts. It is one of many studiocloud[.]xyz hosts listed in the advisory’s IOC appendix. |
DiagTrack.exe launched by live700_v1.exe (SHA-256 c4503db6ece93eddf4511e787607cb14606a1df9f526f1e39992497119437cec) | Process | T1036.003 | Sysmon 1 | Alert on DiagTrack.exe that does not run from C:\Windows\System32. The malware copy has SHA-256 804a53be802378a8ec4c94602fd3d6584e0d472d83148e8a42c731950fec415d. |
Event 4662 with Properties containing 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 or 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 from a non-machine account | IOC | T1003.006 | Windows Security 4662 | Alert on replication rights used by an account whose name does not end in $. The actors ran DC.exe for this, and it needs the directory-replication audit SACL enabled. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Windows SoftEther VPN Masquerading as Legitimate Binary | Covers only the renamed SoftEther step. I found no ESCU rule for the five CVEs or for EBurst spraying. |
| Elastic | Partial — Potential Credential Access via DCSync | Covers only the DCSync step, via event 4662. Nothing found for SoftEther or the five CVEs. |
| Sigma | Partial — Active Directory Replication from Non Machine Account - DcSync Indicator | Covers only DCSync and needs the same 4662 audit setup. Nothing found for ProFTPD, Struts, ONLYOFFICE, Strapi, or BIND. |
Hunt hint: Inventory the five legacy products on internet-facing hosts first, because KEV already lists them as exploited and they are due Oct 11. Search proxy and DNS logs for the seized domains c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net, and for the PHP bot’s C2 natcloudservice[.]com/ews. Check web roots for the advisory’s webshell names b374.php, gf.phtml, and error.jsp. Review Exchange logs for password spraying across EWS, OWA, ECP, Autodiscover, and ActiveSync from one source.
Sources: CISA advisory AA26-281A · DOJ press release · CISA KEV catalog · BleepingComputer · The Hacker News
Status Updates
- CVE-2026-86950 (Apple CoreGraphics): CISA’s KEV record now shows a due date of 2026-10-13 with forensic triage “No”; we had recorded 2026-10-02 and “Yes”. Fixed builds are unchanged. Original brief.
- CVE-2026-88771 (NetScaler): watchTowr published post-exploitation IOCs on Oct 7: marker
/var/tmp/wtw888, a Sliver implant at/var/vpn/ns_helper, a Perl stagerupdate_c08937.plthat adds agw_healthsuperuser tons.conf, and a hidden PHP webshell under/var/netscaler/logon/LogonPoint/. Original brief. - CVE-2026-107406 (NetScaler SAML, new): Citrix bulletin CTX697191 (Oct 9) covers a memory overflow with RCE or DoS when the appliance is a SAML SP or IdP, CVSS v4 9.5. Citrix reports no exploitation and it is not in KEV. Fixed in 14.1-73.46 and 13.1-64.29 or later, so the builds that fixed CVE-2026-88779 are still affected as SAML IdP. CVE-2026-88779 brief.
- HPE ClearPass (HPESBNW05158, not yet briefed): HPE’s Oct 6 advisory fixes 28 CVEs, including unauthenticated RCE (CVE-2026-76750) and authentication bypass (CVE-2026-76752), in 6.14.1 and 6.11.16. No exploitation reported; still deferred.
- Retired from watch: None today.
- Watching (no change): CVE-2026-104286 (10-02), CVE-2026-102489 and CVE-2026-102490 (10-03), CVE-2026-88779 (10-04), CVE-2026-61500 and CVE-2026-88062 (10-04), CVE-2026-76504 (10-01), CVE-2026-21589 (10-06), CVE-2026-102255 (10-08).