- Valid Accounts: Default Accounts (suspicious admin account names)
- Application Layer Protocol: DNS (for scanning and enumeration)
- Command and Scripting Interpreter: Windows Command Shell (for enumeration)
- Indicator Removal: File Deletion (implied by removing accounts)
- Application Layer Protocol: Web Protocols (for scanning and access)
- Credential stuffing and password spraying
- OS Credential Dumping (via legacy SHA-256 storage)
- Create or Modify System Process: Registry Run Keys / Startup Folder (implied by persistence via account changes)
ThreatNoir Afternoon Brief — October 9
Afternoon Review in IT Security — October 9, 2026
The threat landscape continues to evolve rapidly, with multiple critical vulnerabilities and active campaigns targeting organizations worldwide. Today's review covers significant developments ranging from widespread FortiGate compromises to firmware-level malware affecting millions of budget Android devices globally.
FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
The FortiBleed campaign remains an active and widespread threat to enterprise infrastructure. According to SOCRadar's latest findings, more than 86,644 FortiGate devices have been compromised across 194 countries, demonstrating the global scale of this ongoing attack. The FBI continues to warn organizations about this persistent threat, which exploits stolen credentials and leverages multiple attack techniques including credential dumping, command-line execution, log deletion, and brute-force authentication attempts. Source: FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
Organizations running Fortinet FortiGate devices should prioritize immediate security assessments and credential rotation protocols. The breadth of this campaign underscores the critical importance of maintaining robust access controls and monitoring for suspicious authentication patterns on network perimeter devices.
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Two critical vulnerabilities in AhsayCBS backup software, designated CVE-2026-105133 and CVE-2026-105134, are currently being actively exploited by threat actors in the wild. These flaws enable attackers to bypass authentication mechanisms and inject arbitrary operating system commands, creating a direct pathway to remote code execution on affected systems. Attackers are leveraging these vulnerabilities to deploy webshells and cryptocurrency mining malware such as XMRig. Source: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The active exploitation of these vulnerabilities highlights the critical urgency for organizations using AhsayCBS to apply security patches immediately. Backup systems represent high-value targets for attackers, and compromise of these systems can have cascading impacts across an entire infrastructure.
Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
A malware campaign dubbed Midnight Mimosa has compromised budget Android devices through pre-installation at the firmware level, affecting devices across more than 150 countries. This supply-chain attack represents a particularly insidious threat vector, as the malware is embedded in devices before they reach end users, making traditional post-purchase security measures ineffective. The widespread distribution of these compromised devices demonstrates the vulnerability of the low-cost mobile device supply chain. Source: Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
Organizations and individuals using budget Android devices should implement enhanced network monitoring and consider restricting these devices from accessing sensitive corporate resources or personal financial data. This campaign underscores the importance of device procurement security and vendor vetting practices.
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
A critical vulnerability in GoBalance, a tool widely used by dark-web sites to maintain service availability during distributed denial-of-service attacks, allows attackers to recover the secret cryptographic keys that control .onion addresses using only publicly available information. Disclosed by Searchlight Cyber on October 8, this flaw enables attackers to completely hijack compromised .onion addresses and redirect visitors to attacker-controlled copies of legitimate sites. An attacker exploiting this vulnerability gains full control over a site's Tor identity and can conduct sophisticated phishing or malware distribution campaigns. Source: GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
This vulnerability represents a significant threat to the integrity of Tor-based services and highlights the importance of cryptographic implementation security even in specialized infrastructure tools. Organizations operating .onion services should immediately audit their GoBalance deployments and implement appropriate mitigations.
Today's threat intelligence demonstrates the continuing sophistication and scale of cyber threats across multiple attack vectors. Organizations should prioritize patching critical vulnerabilities, implementing credential security measures, and conducting supply-chain security assessments to address these emerging risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- AhsayCBS vulnerability allowing RCE
- AhsayCBS vulnerability allowing RCE
- XMRigCryptominer deployed by attackers
- webshellDeployed by attackers after exploitation
- Masquerading via Google Play Store apps with same ad-fraud markers
- DLL Side-Loading / Privilege Escalation via firmware preinstallation
- Midnight MimosaPreinstalled firmware malware targeting budget Android devices; enables ad fraud, click fraud, and botnet operations
- GoBalanceVulnerable load balancer tool used by dark-web sites; flawed Tor private key signing implementation