Weekly review

ThreatNoir Afternoon Brief — October 9

2026-10-09Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — October 9, 2026

The threat landscape continues to evolve rapidly, with multiple critical vulnerabilities and active campaigns targeting organizations worldwide. Today's review covers significant developments ranging from widespread FortiGate compromises to firmware-level malware affecting millions of budget Android devices globally.

FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

The FortiBleed campaign remains an active and widespread threat to enterprise infrastructure. According to SOCRadar's latest findings, more than 86,644 FortiGate devices have been compromised across 194 countries, demonstrating the global scale of this ongoing attack. The FBI continues to warn organizations about this persistent threat, which exploits stolen credentials and leverages multiple attack techniques including credential dumping, command-line execution, log deletion, and brute-force authentication attempts. Source: FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

Organizations running Fortinet FortiGate devices should prioritize immediate security assessments and credential rotation protocols. The breadth of this campaign underscores the critical importance of maintaining robust access controls and monitoring for suspicious authentication patterns on network perimeter devices.

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Two critical vulnerabilities in AhsayCBS backup software, designated CVE-2026-105133 and CVE-2026-105134, are currently being actively exploited by threat actors in the wild. These flaws enable attackers to bypass authentication mechanisms and inject arbitrary operating system commands, creating a direct pathway to remote code execution on affected systems. Attackers are leveraging these vulnerabilities to deploy webshells and cryptocurrency mining malware such as XMRig. Source: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

The active exploitation of these vulnerabilities highlights the critical urgency for organizations using AhsayCBS to apply security patches immediately. Backup systems represent high-value targets for attackers, and compromise of these systems can have cascading impacts across an entire infrastructure.

Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

A malware campaign dubbed Midnight Mimosa has compromised budget Android devices through pre-installation at the firmware level, affecting devices across more than 150 countries. This supply-chain attack represents a particularly insidious threat vector, as the malware is embedded in devices before they reach end users, making traditional post-purchase security measures ineffective. The widespread distribution of these compromised devices demonstrates the vulnerability of the low-cost mobile device supply chain. Source: Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Organizations and individuals using budget Android devices should implement enhanced network monitoring and consider restricting these devices from accessing sensitive corporate resources or personal financial data. This campaign underscores the importance of device procurement security and vendor vetting practices.

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A critical vulnerability in GoBalance, a tool widely used by dark-web sites to maintain service availability during distributed denial-of-service attacks, allows attackers to recover the secret cryptographic keys that control .onion addresses using only publicly available information. Disclosed by Searchlight Cyber on October 8, this flaw enables attackers to completely hijack compromised .onion addresses and redirect visitors to attacker-controlled copies of legitimate sites. An attacker exploiting this vulnerability gains full control over a site's Tor identity and can conduct sophisticated phishing or malware distribution campaigns. Source: GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

This vulnerability represents a significant threat to the integrity of Tor-based services and highlights the importance of cryptographic implementation security even in specialized infrastructure tools. Organizations operating .onion services should immediately audit their GoBalance deployments and implement appropriate mitigations.

Today's threat intelligence demonstrates the continuing sophistication and scale of cyber threats across multiple attack vectors. Organizations should prioritize patching critical vulnerabilities, implementing credential security measures, and conducting supply-chain security assessments to address these emerging risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
MITRE ATT&CK8
  • Valid Accounts: Default Accounts (suspicious admin account names)
  • Application Layer Protocol: DNS (for scanning and enumeration)
  • Command and Scripting Interpreter: Windows Command Shell (for enumeration)
  • Indicator Removal: File Deletion (implied by removing accounts)
  • Application Layer Protocol: Web Protocols (for scanning and access)
  • Credential stuffing and password spraying
  • OS Credential Dumping (via legacy SHA-256 storage)
  • Create or Modify System Process: Registry Run Keys / Startup Folder (implied by persistence via account changes)