Cyber Threat Brief — October 10 2026
1. SonicWall SMA1000 — CVE-2026-102255 now seeing exploitation attempts
TL;DR: Previdian honeypots caught live requests that abuse the pre-authentication SSRF in the SMA1000 WorkPlace interface to reach the appliance’s internal CouchDB, three days after the patch. Upgrade to 12.4.3-03670 or 12.5.0-03082 now, because the September fix builds are affected too.
What’s New:
- Previdian’s Ryan Dewhurst told BleepingComputer on Oct 9 that the exploit attempts reached
127.0.0.1:5984through a craftedOPTIONSrequest. - Previdian has not shown that any attempt succeeded, and SonicWall has not confirmed exploitation. It is not in KEV yet.
- CVE-2026-102255 affects 12.4.3-03526 and older, and 12.5.0-02952 and older, so appliances patched in September for CVE-2026-83548 are exposed again.
- SonicWall publishes no workaround and no IOCs. The same bulletin fixes post-authentication CVE-2026-102256 (command injection) and CVE-2026-102257 (Zip Slip in the AMC).
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| SonicWall SMA1000 6210, 7210, or 8200v on build 12.4.3-03526 or older, or 12.5.0-02952 or older (CVE-2026-102255) | Vulnerable version | T1190 | Asset inventory / AMC | Upgrade to 12.4.3-03670 or 12.5.0-03082 (platform hotfix) and confirm the running build in the AMC. A box on 12.5.0-02952 is still vulnerable. |
OPTIONS request whose URL begins http://127.0.0.1:5984/__EXTRAWEB__TRANSLATE/ and contains /_design/ and /_rewrite/ | IOC | T1190 | SMA1000 WorkPlace/Extraweb access log, or the reverse proxy or WAF in front | Search these logs back to 2026-10-06 for request lines containing 127.0.0.1:5984 or _rewrite. Any hit means the appliance was probed; check for success as in the Hunt hint. |
Request header Authorization: Basic YWRtaW46YWRtaW4= (base64 for admin:admin) on a WorkPlace request | IOC | T1078.001 | WAF / reverse-proxy header logging | Alert on this exact header value sent to the appliance from an external address. Previdian saw it on every captured attempt. |
Source IP 146.70.143[.]142 | IOC | T1190 | Firewall / WAF | Block it and search 2026-10-06 onward for any connection to the WorkPlace interface. It is one sensor’s observation, so a miss does not clear you. |
| Internet-reachable SMA1000 WorkPlace interface (Shadowserver counts more than 400 exposed) | Exposure | T1133 | External attack-surface scan | Restrict WorkPlace to known source ranges until patched, and confirm the Appliance Management Console is not reachable from the internet. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | No SMA1000, CouchDB, or WorkPlace SSRF analytic. Exchange PowerShell Abuse via SSRF is Exchange-specific. |
| Elastic | None — verified | The SonicWall rules cover login failures (Multiple SonicWall Login Failures Followed by Successful Login) and first-seen identity sources. None looks at request URLs. |
| Sigma | None — verified | No SonicWall or CouchDB rule. |
Detection index: ESCU 1b2142f (2026-10-09) · elastic detection-rules 195f15c (2026-10-09) · SigmaHQ 8a48134 (2026-10-06)
Hunt hint: Forward SMA1000 access logs, or log the request line and headers on whatever proxy fronts it, if you do not already. Search from 2026-10-06 for _rewrite and 127.0.0.1:5984. Treat any hit followed by an admin login, a new configuration change, or an outbound connection from the appliance as a compromise. The September chain ended in root code execution through the same internal service, so image the appliance rather than clean it. SonicWall published no indicators, so absence of a hit in a log you were not collecting proves nothing.
Sources: BleepingComputer (Previdian quote) · Beazley Security BSL-A1223 (payload and IP) · SC Media · SonicWall advisory SNWLID-2026-0017
2. GhostAction — maintainer accounts used to plant a history-mining workflow
TL;DR: Attackers with stolen maintainer credentials committed a fake “Security Audit” workflow to 345 repositories on Oct 8, and it sends every secret and committed credential it finds to one raw IP address. Search your organization for the workflow file and the C2 address, then rotate everything that ever appeared in any branch’s history.
What’s New:
- The new variant runs
git log -p --allafter a full checkout, so credentials deleted years ago are still stolen. - It pairs AWS key IDs with their secret keys and also targets Anthropic, OpenAI, and OpenRouter keys.
- It exfiltrates over plain HTTP to
193.32.204[.]199with no DNS lookup, and StepSecurity confirmed a successful run inuber/athenadriver. - Socket reports more than 500 accounts have committed the workflow to tens of thousands of repositories since Oct 7. No malicious package release has been seen yet.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
.github/workflows/security-audit.yml (workflow name Security Audit, job audit) | Path | T1195.002 | GitHub code search / audit log | Search org:<yourorg> path:.github/workflows security-audit.yml and the same for every fork your people own. Delete the file from every branch, not only the default. |
.github/workflows/github_actions_security.yml (workflow Github Actions Security, job send-secrets) | Path | T1195.002 | GitHub code search / audit log | Search for this file name too; it is the earlier variant still deployed. StepSecurity also lists security-check.yml. |
Commit message Add security audit workflow or Update security audit workflow on a default branch with no pull request | IOC | T1195.002 | GitHub audit log git.push | Search the audit log since 2026-08-31 for pushes with these messages. Revoke the pushing user’s PATs, sessions, and SSH keys. |
C2 193.32.204[.]199 (ports 80 and 3000; URL markers /?c=monami and /?c=new) | IOC | T1041 | Runner egress / firewall / proxy | Block it and search egress logs since 2026-09-04 for connections from GitHub-hosted-runner egress or self-hosted runners. Any connection means a run exfiltrated data. |
Request body markers REPO=, AKIA_CTX_START, and AKIA_CTX_END | IOC | T1041 | Proxy / TLS-inspection logs | Search outbound HTTP POST bodies for AKIA_CTX_START to confirm what was sent. |
Workflow trigger on: push with no branch filter plus actions/checkout with fetch-depth: 0 in a workflow added by a single-file commit | Behavior | T1552.001 | GitHub audit log / repository scan | List workflows added in one-file commits to a default branch since 2026-08-31 and read each for git log -p --all. |
Any credential that ever appeared in repository history, matching AKIA, ASIA, sk-ant-, sk-proj-, sk-or-, ghp_, github_pat_, glpat-, AIza, xox[baprs]-, or SG. | Exposure | T1552.001 | Secret scanning / CloudTrail | For infected repositories, rotate each credential found in history. For AWS keys, review CloudTrail userIdentity.accessKeyId for the exposure window. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | No GitHub workflow-injection analytic in the mirror. |
| Elastic | None — verified | GitHub Actions Workflow Modification Blocked needs a rejected push and GitHub Actions Unusual Bot Push to Repository needs the bot user, but the attacker pushed as the human maintainer. |
| Sigma | None — verified | The GitHub Enterprise rules cover runner registration, 2FA, and branch-rule changes, not workflow file creation. |
Hunt hint: Run the three code searches StepSecurity published: "AKIA_CTX_START" path:.github/workflows, "c=monami", and "193.32.204.199" path:.github/workflows, scoped with org:. Then list Actions runs of any workflow named Security Audit or Github Actions Security and treat every completed run as exfiltration. Turn on required approval for workflow runs, because StepSecurity saw that single setting stop exfiltration in typecho-fans/plugins. Hold package releases from any repository that held PyPI, npm, or crates.io tokens until they are rotated.
Sources: StepSecurity writeup · Socket writeup · GitGuardian · The Hacker News
Status Updates
- CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894 (Flax Typhoon KEV additions): The CISA due date is tomorrow, Sunday 2026-10-11, and no further KEV additions appeared since Oct 8. Original brief.
- CVE-2026-105133 and CVE-2026-105134 (AhsayCBS): Huntress still reports 10.3.4 as affected and no vendor fix or statement has appeared as of Oct 10. Original brief.
- CVE-2026-102255 (SonicWall SMA1000): Promoted to section 1 today after Previdian reported exploitation attempts. Prior mention.
- CVE-2026-107406 (NetScaler SAML): Still no exploitation or independent analysis; Citrix CTX697191 remains the only origin. Original brief.
- HPE ClearPass (HPESBNW05158, not yet briefed): Still no ITW or public PoC; we retire it from the deferred queue on 2026-10-12 if that holds.
- Retired from watch: CVE-2026-102255 as a watch item, now a full section (last update 2026-10-08).
- Watching (no change): CVE-2026-85097 (10-09), CVE-2026-104286 (10-02), CVE-2026-102489 and CVE-2026-102490 (10-03), CVE-2026-88779 (10-04), CVE-2026-61500 and CVE-2026-88062 (10-04), CVE-2026-76504 (10-01), CVE-2026-21589 (10-06), CVE-2026-83548 and CVE-2026-83549 (09-03).