- Zammad zero-day enabling unauthenticated RCE and session leak (CVSS 9.4)
- Zammad zero-day allowing local privilege escalation to root (CVSS 9.4)
ThreatNoir Afternoon Brief — October 1
Afternoon Review in IT Security — October 1, 2026
The cybersecurity landscape continues to face significant threats as critical vulnerabilities are actively exploited across multiple platforms and sectors. From zero-day flaws in widely-used ticketing systems to authentication bypasses in enterprise networking equipment, organizations face mounting pressure to patch and defend their infrastructure. Meanwhile, the financial sector grapples with the fallout from a major cryptocurrency exchange breach, while law enforcement intensifies its response to organized cybercriminal networks.
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Multiple zero-day vulnerabilities in the Zammad ticketing system have been exploited in a sophisticated attack against the Dutch Institute for Vulnerability Disclosure (DIVD). The attackers chained together flaws tracked as CVE-2026-102489 and CVE-2026-102490 to achieve session hijacking, remote code execution, and privilege escalation to root access. The attack demonstrates how threat actors continue to target open-source infrastructure used by security organizations themselves. Source: Zammad Zero-Days Exploited in AI-Powered DIVD Hack
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities catalog following active exploitation in the wild. Tracked as CVE-2026-76504 with a CVSS score of 9.8, the flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems. The rapid addition to CISA's KEV list reflects the severity and active abuse of this vulnerability across networks. Source: CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget has confirmed that the $387.5 million theft that occurred last week resulted from exploitation of a zero-day vulnerability in third-party security products. Investigation findings from SlowMist revealed malicious activity involving the zero-day flaw and identified a customized tool deployed by the attackers, including web shell components. The breach underscores the cascading risks posed when zero-day flaws exist in security tools trusted to protect critical financial infrastructure. Source: Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The U.S. Treasury Department has blacklisted a prominent developer of ATM jackpotting malware and his associated network as part of the government's ongoing crackdown on organized cybercriminal operations. The action targets the malware family known as Ploutus, which has been used extensively in ATM theft schemes. The designation reflects escalating enforcement efforts against actors exploiting physical and digital security gaps in financial infrastructure. Source: Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
As threats continue to evolve across infrastructure, financial, and open-source ecosystems, organizations must prioritize rapid patching of critical vulnerabilities while strengthening supply chain security practices. The convergence of zero-day exploits, active nation-state targeting, and organized cybercriminal activity underscores the need for comprehensive threat intelligence integration and incident response readiness.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical authentication bypass in Cisco Catalyst SD-WAN Manager allowing unauthenticated remote admin access
- web shellDeployed by threat actor onto security appliance B
- PloutusMalware used in ATM jackpotting attacks.