- Critical authentication bypass vulnerability in BoKS Manager.
- Critical command injection vulnerability in crlserver.
- Critical stack buffer overflow vulnerability in autoregistration.
ThreatNoir Weekend Brief — October 3
Afternoon Review in IT Security — October 3, 2026
The afternoon security landscape reflects continued threats across multiple fronts, from zero-day exploits targeting critical infrastructure to emerging AI-powered safeguards. Today's coverage spans a Dutch vulnerability disclosure organization's breach, critical patches for privileged access management, new funding for AI agent security, and expanding nation-state activity in critical infrastructure.
Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
The Dutch Institute for Vulnerability Disclosure fell victim to a sophisticated AI-powered attack leveraging two previously unknown Zammad vulnerabilities. The breach resulted in remote code execution and root access to the organization's systems, demonstrating the escalating risk posed by zero-day exploits in widely deployed software. Source: Hackread
Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches addressing critical vulnerabilities in its BoKS privileged access management platform. The flaws, tracked as CVE-2026-12627, CVE-2026-79898, and CVE-2026-79901, could enable authentication bypass, shell command execution, and memory corruption. These vulnerabilities underscore the persistent security challenges in identity and access control systems. Source: SecurityWeek
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net has secured $38 million in funding to advance its ADN platform, designed to prevent autonomous AI agents from causing unintended harm while operating under user authority. The platform addresses emerging risks as AI agents gain increasing autonomy in network environments, providing guardrails to mitigate exposure to malware and phishing threats. Source: SecurityWeek
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based Warlock hacking group continues to expand its exploitation of SharePoint vulnerabilities in attacks targeting critical infrastructure. The group has been actively exploiting these flaws since July 2025, leveraging multiple CVEs including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040. This sustained campaign highlights the persistent threat posed by nation-state actors to essential services. Source: SecurityWeek
Today's threat landscape reinforces the importance of rapid patching cycles, zero-day awareness, and emerging defensive technologies as attackers continue to evolve their tactics across multiple vectors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- malwareADN platform blocks known malware destinations.
- phishing sitesADN platform blocks known phishing sites.
- Exploited SharePoint vulnerability
- Exploited SharePoint vulnerability
- Exploited SharePoint vulnerability
- Exploited SharePoint vulnerability
- Exploited SharePoint vulnerability
- Exploited SharePoint vulnerability