Weekly review

ThreatNoir Morning Brief — October 8

2026-10-08Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — October 8, 2026

The threat landscape continues to intensify with critical vulnerabilities affecting enterprise infrastructure, persistent supply chain attacks targeting developers, and coordinated campaigns exploiting cryptocurrency users. Today's briefing covers active exploitation of VPN appliances, malicious package distribution, critical patching requirements, and a sophisticated browser extension fraud operation.

FBI Warns of Ongoing FortiBleed Attacks Against VPN Administrators

The Federal Bureau of Investigation has issued an alert regarding continued FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways. The campaign specifically focuses on locking out legitimate administrators from their own systems, preventing proper management and response to the intrusions. The malware families identified in these attacks include FortiBleed, INC/Lynx ransomware, and Payload ransomware, indicating a coordinated effort to compromise critical network access points. Source: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

Supply Chain Attack Delivers RAT and Stealer Through npm Ecosystem

Researchers have disclosed a long-running malware campaign distributed through the npm package repository, with eight malicious packages downloaded over 40,000 times. The campaign, tracked as MALFEX by CloudSEK and Checkmarx, appears to be the work of a single threat actor who has published twelve packages since August 2023, delivering the Overlord RAT and stealer payloads to compromised systems. The campaign exploits CVE-2026-60137 and CVE-2026-63030 alongside the movinlike malware variant, targeting developers who unknowingly incorporate these packages into their projects. Source: Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

SonicWall Releases Critical Patches for Maximum-Severity SSRF Vulnerability

SonicWall has released hotfixes addressing four vulnerabilities in its SMA1000 appliances, which provide remote access gateways for enterprise networks. The most severe flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to send requests through the appliance to reach internal functions without requiring login credentials. The vulnerability set includes CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-15409, CVE-2026-15410, CVE-2026-83548, and CVE-2026-83549. SonicWall reports no evidence of active exploitation at this time, but organizations should prioritize immediate patching given the maximum severity rating and the critical role these appliances play in network security. Source: SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Coordinated Firefox Extension Campaign Steals Cryptocurrency Wallet Credentials

Socket Threat Research has identified a coordinated campaign comprising sixteen malicious Firefox extensions that target cryptocurrency wallet users through credential theft. The campaign operates two distinct families: four large extensions impersonating Rabby Wallet under the misspelled brand "Raabby WaIIet," and twelve smaller extensions posing as OKX Wallet. The malware intercepts recovery phrases and private keys during wallet import workflows and transmits them to attacker-controlled Cloudflare Workers endpoints, including silent-wind-get.icy-star-f45c.workers.dev, green-firefly-ab28.icy-star-f45c.workers.dev, small-boat-969c.icy-star-f45c.workers.dev, and flat-wildflower-f954.fondationanimalaidrelief.workers.dev. The Rabby clone family transmits secrets via GET requests with exposed query parameters, while OKX variants use POST requests with the raw phrase in parameter w. Mozilla unpublished all identified extensions as of October 5th, and users who entered real recovery phrases or private keys into any variant should immediately create new wallets from clean environments and transfer assets, as changing only the extension password does not invalidate compromised seed phrases or private keys. Source: 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials

The convergence of infrastructure vulnerabilities, supply chain compromises, and targeted credential theft campaigns underscores the importance of rapid patching, dependency management, and user awareness across all technology domains. Organizations and individual users should prioritize remediation of the identified vulnerabilities and removal of the malicious extensions while implementing enhanced monitoring for related attack indicators.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
CVE8
  • Previously exploited command injection vulnerability in SMA1000 appliance.
  • Stored XSS vulnerability in SMA1000 Appliance Management Console (AMC).
  • Previously exploited SSRF vulnerability in SMA1000 WorkPlace portal.
  • Previously exploited command injection vulnerability in SMA1000 appliance.
  • Previously exploited SSRF vulnerability in SMA1000 WorkPlace portal.
  • Critical SSRF vulnerability in SMA1000 WorkPlace portal.
  • OS command injection vulnerability in SMA1000 appliance.
  • Zip Slip vulnerability in SMA1000 Appliance Management Console (AMC).
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Malware1
  • Raabby WaIIet
    Malicious Firefox extension campaign cloning Rabby Wallet
Domain4
  • silent-wind-get.icy-star-f45c.workers.dev
    Rabby-clone C2 endpoint for credential exfiltration via GET requests
  • small-boat-969c.icy-star-f45c.workers.dev
    OKX-clone C2 endpoint for credential exfiltration
  • green-firefly-ab28.icy-star-f45c.workers.dev
    OKX-clone C2 endpoint for credential exfiltration
  • flat-wildflower-f954.fondationanimalaidrelief.workers.dev
    Broken variant OKX-clone C2 endpoint
SHA-2565
  • c550f0860012…
    OKX-clone Web3 Portal background.js variant
  • eb134bbf7304…
    Shared OKX-clone frontend across all 12 OKX variants
  • 7d9d7e80ed52…
    Rabby-clone background.js shared across all four Rabby-clone extensions
  • da447fe02e45…
    OKX-clone core background.js variant
  • be246ca5cb13…
    Broken OKX-clone variant background.js