- FortiBleedCredential compromise campaign targeting Fortinet devices.
ThreatNoir Morning Brief — October 7
Morning Review in IT Security — October 7, 2026
October 7, 2026 brings renewed warnings of active threats targeting critical infrastructure and widely deployed software platforms. Federal agencies are escalating alerts on persistent campaigns, while vulnerabilities in enterprise collaboration tools and WordPress plugins continue to pose significant risks to organizations worldwide.
FortiBleed Remains Active Campaign, Can Lock Out Users or Lead to Ransomware Attacks
The FBI and Secret Service have issued a joint warning that FortiBleed, a vulnerability discovered earlier this summer, continues to be actively exploited in the wild. The campaign poses a dual threat to Fortinet users: attackers can leverage the flaw to lock out legitimate users or establish a foothold for deploying ransomware payloads. Organizations running unpatched Fortinet devices remain particularly vulnerable to this ongoing threat. Source: Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Ninja Forms Plugin Flaw Exploited to Hack WordPress Sites
Threat actors are actively exploiting stored cross-site scripting vulnerabilities in WordPress plugins to compromise websites at scale. The Ninja Forms plugin and WPC Product Bundles for WooCommerce both contain XSS flaws that attackers are weaponizing to install backdoors and create unauthorized administrator accounts. This supply chain attack vector allows adversaries to gain persistent access to compromised WordPress installations. Source: Ninja Forms plugin flaw exploited to hack WordPress sites
Atlassian Warns of Critical File-Access Flaw in Jira, Confluence
Atlassian has disclosed a critical vulnerability affecting multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. Tracked as CVE-2026-21589, the flaw enables unauthenticated attackers to access arbitrary files on affected systems. Organizations operating self-hosted instances of these widely deployed collaboration tools should prioritize patching efforts immediately. Source: Atlassian warns of critical file-access flaw in Jira, Confluence
Fake ChatGPT, Gemini Sites Steal Advertising Accounts, MFA Codes
A sophisticated phishing campaign is targeting advertising account managers through counterfeit websites impersonating popular AI chatbot platforms including ChatGPT, Gemini, Claude, and Perplexity. The attackers employ browser-in-browser attacks to harvest login credentials and multi-factor authentication codes, enabling account takeover of high-value advertising accounts. This threat demonstrates how threat actors continue to exploit the popularity of AI services to conduct credential theft at scale. Source: Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Today's threat landscape underscores the critical importance of timely patch management, robust authentication controls, and user awareness training. Organizations must prioritize remediation of the disclosed vulnerabilities while maintaining heightened vigilance against credential theft campaigns targeting their personnel.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Vulnerability in WPC Product Bundles for WooCommerce.
- Vulnerability in Ninja Forms.
- WP Smart ThumbnailsMalicious plugin installed by the attackers.
- Critical arbitrary file access vulnerability in Atlassian Data Center products.
- Browser-in-Browser (BitB) Phishing KitMulti-platform phishing kit targeting ad account credentials, supports Windows, macOS, iOS, Android with socket.io control channel