Threat Digest: SharePoint Attacks & Critical RCE Flaws
This cybersecurity threat digest October 3 2026 reviews SharePoint ransomware attacks, critical RCE vulnerabilities, active exploitation reports, and urgent defender actions.
TL;DR - Attackers exploited SharePoint vulnerabilities against water, telecom, government, and university targets. - Critical issues affect GitLab AI Gateway, Chrome, Tenda routers, WordPress, Seroval, and Dell Kubernetes storage modules. - Patch internet-facing systems first, investigate suspicious access, and verify CISA KEV priorities.
Analyst’s Take: Start with systems that combine internet exposure and high privilege: Tenda devices, SharePoint, Dell Container Storage Modules, and GitLab AI Gateway. The supplied CISA notice does not identify the newly added vulnerability, so checking the live catalog is necessary before assigning that priority.
Top Stories#
Frontline Education Breach Exposes School Employee Data
Attackers exploited a vulnerability in third-party software to access Frontline Education systems and steal school district employee information, including Social Security numbers, according to BleepingComputer.
Organizations using Frontline Education or similar education-sector platforms should treat the incident as a third-party risk event. Confirm whether the affected integration handles employee records, identify exposed data categories, and follow the vendor’s incident-response guidance. Review and rotate credentials, API keys, and service accounts associated with affected integrations where appropriate.
Warlock Ransomware Targets SharePoint Deployments
The China-linked Warlock ransomware group reportedly exploited SharePoint vulnerabilities to breach a water utility, telecom provider, regional government body, and university. Those targets combine sensitive data with operational or public-service responsibilities.
See the BleepingComputer report for the reported targeting details.
Defenders should investigate SharePoint and identity activity for:
- New or unusual authentication sources.
- Unexpected application permissions or service principals.
- Suspicious file downloads, mass access, or archive creation.
- Newly created accounts, groups, or administrative assignments.
- Evidence of data staging, lateral movement, or ransomware deployment.
Correlate SharePoint logs with identity provider, VPN, endpoint, cloud, and network telemetry. A lack of obvious ransomware activity does not rule out an earlier intrusion or data theft.
U.S. Sanctions Linked to ATM Jackpotting
The United States sanctioned eight members of the Venezuelan Tren de Aragua gang over ATM jackpotting attacks that allegedly stole millions of dollars, according to BleepingComputer.
ATM operators, banks, and cash-management providers should brief both security and fraud teams. Relevant indicators include unauthorized access to ATM service interfaces, abnormal cash withdrawals, suspicious maintenance activity, and unusual physical or network access preceding cash-out events.
Dell Urges Immediate Patching for Container Storage Modules
Dell urged customers to patch two maximum-severity vulnerabilities in Container Storage Modules used to connect enterprise storage arrays to Kubernetes environments. Exploitation could provide administrative privileges, creating risk across storage, workloads, and cluster control planes.
The BleepingComputer coverage provides the reported impact. Administrators should apply Dell’s fixes, review Kubernetes role bindings, and investigate unexpected privileged activity in clusters using the affected modules.
Google Releases a Chrome Security Update
Google released a Chrome desktop stable-channel update addressing multiple high- and critical-severity vulnerabilities. The update includes a WebGL out-of-bounds write that could enable arbitrary code execution outside the browser sandbox through a crafted HTML page.
Review the Chrome stable-channel announcement, deploy the update through enterprise browser management, and verify completion rather than relying solely on policy assignment. Endpoint protection such as Get Bitdefender → can provide an additional layer of monitoring while updates roll out.
CISA Adds a Known Exploited Vulnerability
CISA reported adding a vulnerability to its Known Exploited Vulnerabilities catalog. The supplied notice does not identify the specific vulnerability, so organizations should check the current catalog directly and confirm whether the new entry affects their assets. For related prioritization context, see the recent CISA KEV digest.
Any matching vulnerability should receive an owner, remediation deadline, documented exception if necessary, and validation evidence after patching.
Microsoft Vulnerability Activity Remains Relevant
Krebs on Security highlighted recent Microsoft vulnerability activity, including Windows elevation-of-privilege issues and a publicly detailed BitLocker security-feature bypass.
Review current Microsoft security guidance and inventory Windows systems that process sensitive data or provide administrative access. Elevation-of-privilege issues should be prioritized on systems where an attacker could first gain local or limited access.
Critical Vulnerabilities#
CVE-2026-90970: GitLab AI Gateway
- Severity: Critical
- CVSS: 9.9
- Affected product: GitLab AI Gateway
- Impact: Arbitrary command execution
- Status: Not listed as CISA KEV in the supplied data
Under certain conditions, an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox through a specially crafted flow configuration and execute arbitrary commands on the AI Gateway.
GitLab identifies affected versions as:
- 18.1.6 before 19.2.4.
- 19.3 before 19.3.2.
- 19.4 before 19.4.1.
Update to the applicable fixed release: 19.2.4, 19.3.2, or 19.4.1. Review GitLab’s work item and the NVD entry.
Technical Notes
Focus investigation on:
- Changes to AI Gateway flow configurations.
- New or unexpected Duo Agent Platform access.
- Command execution by the AI Gateway service account.
- Unusual outbound connections from the gateway host.
- Privilege changes involving GitLab or gateway administration.
CVE-2026-103628: Google Chrome WebGL
- Severity: Critical
- CVSS: 9.6
- Affected product: Google Chrome
- Impact: Potential arbitrary code execution outside the sandbox
- Fixed version: 154.0.8037.97 or later
- Status: Not listed as CISA KEV in the supplied data
A remote attacker can use a crafted HTML page to trigger an out-of-bounds write in WebGL. The issue could enable arbitrary code execution outside the Chrome sandbox.
Update Chrome to 154.0.8037.97 or later using the Google Chrome stable-channel update. Additional technical details are available in the Chromium issue and NVD record.
Technical Notes
Validate deployment with endpoint-management inventory rather than assuming users have restarted Chrome. Until rollout is complete:
- Prioritize high-risk and unmanaged endpoints.
- Use web filtering for suspicious or newly registered domains.
- Consider browser isolation for high-risk browsing workflows.
- Review endpoint telemetry for Chrome child processes, crashes, or unusual outbound activity.
- Review what a typosquatting attack is when tuning defenses against lookalike domains.
CVE-2026-104610: Tenda HG7, HG9, and HG10
- Severity: Critical
- CVSS: 10.0
- Affected products: Tenda HG7, HG9, and HG10
- Impact: Remote stack-based buffer overflow
- Exploitation status: Public exploitation details disclosed
A remotely exploitable stack-based buffer overflow in the Boa Web Server function boaGetVar at /boaform/formLoopBack allows manipulation of the Ethtype argument.
The NVD entry and public GitHub issue contain the available references.
Patch or replace affected devices where possible. If a fix is unavailable:
- Remove device management interfaces from the public internet.
- Restrict administration to a dedicated management network.
- Disable unnecessary remote administration.
- Block unsolicited inbound access at upstream firewalls.
- Replace unsupported hardware with maintained equipment.
- Review logs for unexpected requests to the affected web interface.
CVE-2026-19652: Divi Membership WordPress Plugin
- Severity: Critical
- CVSS: 9.8
- Affected product: Divi Membership WordPress plugin
- Affected versions: Up to and including 2.2.0
- Impact: Unauthenticated administrator account creation
Versions through 2.2.0 allow unauthenticated attackers to register an administrator account by supplying an attacker-controlled bcrypt hash in the form_id parameter. A publicly emitted WordPress nonce is required but can be obtained from the registration form.
Update to a fixed release using the Divi Engine changelog. Also review the Wordfence vulnerability advisory and NVD record.
Technical Notes
After updating, audit for:
- Administrator accounts created recently.
- Changes to user roles or capabilities.
- Modified plugins, themes, and WordPress core files.
- Unexpected scheduled tasks or webshell-like files.
- Authentication attempts against registration and login endpoints.
If an unauthorized administrator is found, preserve relevant logs, disable the account, rotate WordPress and hosting credentials, and assess whether persistence or data access occurred.
CVE-2026-104846: Seroval Deserialization
- Severity: Critical
- CVSS: 9.8
- Affected product: Seroval
- Affected versions: 0.12.0 through versions before 1.6.2
- Impact: Code execution through unsafe deserialization
- Fixed version: 1.6.2 or later
In affected Seroval versions, fromJSON deserialization of a fulfilled Promise control node can invoke an attacker-controlled callable-bearing thenable through native Promise assimilation. Applications that deserialize untrusted data may be exposed to code execution.
Upgrade Seroval to 1.6.2 or later. Review the security advisory and fix, the upstream commit, and the NVD record.
Technical Notes
Application owners should identify:
- Direct and transitive Seroval dependencies.
- Endpoints that accept serialized application state.
- Server-side rendering or hydration paths processing untrusted input.
- Unexpected child processes or outbound connections from affected services.
- Changes to lockfiles, build artifacts, and deployment images.
Do not assume that a dependency is safe merely because the vulnerable code path is not part of normal user interaction. Confirm whether untrusted serialized data can reach the affected parser.
Dell Container Storage Modules Vulnerabilities
Dell reported two maximum-severity vulnerabilities affecting Container Storage Modules used with enterprise storage and Kubernetes. The supplied reporting does not include CVE identifiers or fixed-version details, so administrators should use Dell’s official security advisory and product-specific remediation guidance before making deployment decisions.
Apply vendor fixes, then review:
- Cluster-admin role assignments.
- Container Storage Interface permissions.
- Service accounts used by storage components.
- Privileged pods and host-mounted paths.
- Unexpected changes to storage classes or persistent volumes.
- New workloads or images launched with elevated privileges.
Kubernetes environments should also restrict control-plane access, separate storage administration from general cluster administration, and monitor privileged workload activity.
What Defenders Should Do Today#
1. Patch Internet-Facing and High-Impact Systems First
Prioritize:
- Tenda HG7, HG9, and HG10 devices exposed to the internet.
- SharePoint deployments and related identity infrastructure.
- Dell Container Storage Modules in Kubernetes environments.
- GitLab AI Gateway instances with Duo Agent Platform access.
- Chrome installations on managed and privileged endpoints.
- WordPress sites running Divi Membership.
- Applications using vulnerable Seroval versions.
Use asset ownership records and vulnerability-management data to identify systems that are both affected and externally reachable.
2. Check the Current CISA KEV Catalog
Review the CISA KEV catalog directly because the supplied daily notice does not identify the newly added vulnerability.
For any matching asset, record:
- Assigned remediation owner.
- Business criticality.
- Internet exposure.
- Required remediation deadline.
- Compensating controls.
- Validation method and completion evidence.
3. Investigate SharePoint and Identity Activity
Search SharePoint, cloud, identity, VPN, and endpoint logs for:
- Sign-ins from unusual locations or autonomous systems.
- New application registrations or consent grants.
- Suspicious OAuth permissions.
- Unusual access to large numbers of files.
- Archive creation or bulk downloads.
- New administrator assignments.
- Lateral movement from SharePoint-connected systems.
- Ransomware staging or abnormal encryption activity.
Preserve logs before retention policies remove relevant evidence.
4. Assess Third-Party Data Exposure
For Frontline Education and other third-party platforms handling employee or personally identifiable information:
- Identify affected integrations and data flows.
- Confirm what categories of data were accessible.
- Rotate exposed credentials and API keys where indicated.
- Validate vendor containment and recovery steps.
- Notify privacy, legal, and incident-response stakeholders.
- Document whether regulatory or contractual notifications may apply.
5. Audit WordPress Administrator Accounts
For sites running Divi Membership:
- Export current administrator accounts.
- Compare them with a known-good baseline.
- Review recent registrations and role changes.
- Inspect plugin and theme modification times.
- Search web-access logs for registration and login anomalies.
- Rotate administrator, hosting, database, and deployment credentials if compromise is suspected.
6. Harden Kubernetes and Storage Control Planes
Apply Dell’s vendor fixes and reduce the potential spread of a compromise by:
- Limiting Kubernetes API access to trusted networks.
- Enforcing least privilege for storage service accounts.
- Reviewing cluster-admin bindings.
- Restricting privileged containers.
- Validating container image provenance.
- Monitoring changes to persistent volumes and storage classes.
- Alerting on unexpected host mounts and workload launches.
7. Push and Verify Browser Updates
Deploy Chrome 154.0.8037.97 or later through enterprise management. Track actual installed versions, restart status, and devices that have not checked in.
For high-risk users, browser isolation and web filtering can reduce exposure while the update rollout is in progress.
8. Review GitLab AI Gateway Access
For GitLab environments using the AI Gateway or Duo Agent Platform:
- Confirm the installed GitLab version.
- Review flow configuration changes.
- Remove unnecessary authenticated access.
- Audit service-account privileges.
- Monitor gateway command execution and outbound connections.
- Investigate unexpected configuration changes before patching if compromise is suspected.
9. Brief Fraud and Physical Security Teams
ATM operators should correlate cyber telemetry with physical events. Escalate combinations of:
- Unauthorized service-interface access.
- Unscheduled maintenance activity.
- Abnormal cash withdrawals.
- New or suspicious network paths.
- Tampering indicators.
- Credential use outside normal maintenance windows.
Technical Notes#
Example Asset and Version Checks
Use organization-specific inventory tools to locate affected software. The following examples are starting points and should be adapted to local platforms:
# Search installed package inventories for Seroval references
grep -RniE 'seroval|0\.12\.|1\.6\.' /path/to/application-manifests
# Find WordPress installations and plugin directories
find /var/www -type d -path '*/wp-content/plugins/*' \\
-iname '*divi*' -print
# Identify Kubernetes workloads and storage components
kubectl get pods -A -o wide
kubectl get clusterrolebindings
kubectl get storageclass,pv,pvc -A
Do not treat a package-name match as proof of exploitability. Confirm the resolved version, execution path, input exposure, and vendor remediation status.
Example Log Review Patterns
Search syntax varies by SIEM, but defenders can begin with patterns such as:
SharePoint: unusual sign-in, bulk download, new OAuth consent,
new application permission, administrator role assignment
WordPress: user registration, administrator role change,
plugin upload, plugin activation, unexpected wp-admin access
Kubernetes: privileged pod creation, hostPath mount,
cluster-admin binding, new service account, storage class change
GitLab AI Gateway: flow configuration change, unexpected child process,
new Duo Agent access, unusual outbound connection
Validate detections against normal administrative activity to reduce false positives, while preserving suspicious events for incident response.
Prioritization Summary#
Remove exposed Tenda devices from the internet first, then patch SharePoint and Dell-connected Kubernetes environments while checking the current CISA KEV catalog. Those actions address the clearest combination of public exposure, privileged access, and reported exploitation risk; teams should investigate suspicious activity before closing the remediation work.
After those steps, update Chrome, remediate GitLab AI Gateway instances, audit WordPress administrator accounts, review Seroval dependency exposure, and coordinate cyber, fraud, privacy, and incident-response teams around the reported activity.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.
CISA KEV additions this week#
CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest. Source: CISA KEV catalog.
- October 2, 2026: CVE-2026-102490 (Zammad GmbH Zammad), CVE-2026-102489 (Zammad GmbH Zammad)
- October 1, 2026: CVE-2026-104286 (Fortinet FortiMail)
- September 30, 2026: CVE-2026-76504 (Cisco Catalyst SD-WAN Manager)
- September 29, 2026: CVE-2026-86950 (Apple Multiple Products)
- September 27, 2026: CVE-2026-88772 (Citrix NetScaler), CVE-2026-88771 (Citrix NetScaler)