Skip to content
eastbaycyber

Threat Digest — Oct. 10, 2026: SonicWall & ClickFix

Threat digests 10 min read
EC
East Bay Cyber Editorial Team Updated
Week of 10 OCT 2026

TL;DR - SonicWall SMA1000 and AhsayCBS systems are reportedly being exploited. - ShinyHunters and Qilin arrests add pressure on ransomware and extortion operations. - Patch exposed systems, disable vulnerable WordPress plugins, and investigate ClickFix indicators today.

This cybersecurity threat digest October 10 2026 covers reported exploitation, ransomware-related arrests, software vulnerabilities, and ClickFix delivery campaigns requiring immediate defensive attention.

Top Stories#

ShinyHunters investigation leads to multiple arrests

The FBI arrested the co-founder of a Canadian ransomware negotiation firm as part of an investigation into the ShinyHunters hacking group. The investigation follows reports that sensitive data belonging to thousands of FBI agents was accessed.

A second suspected ShinyHunters member was also arrested after the reported breach of FBI systems. The arrests show continued law-enforcement pressure on the group. They also make evidence preservation especially important after extortion, data theft, or suspected affiliate activity.

Read the reports from Krebs on Security and BleepingComputer.

Germany arrests alleged Qilin ransomware member

German authorities arrested a Russian national suspected of being a core member of the Qilin ransomware operation after his extradition from Japan. The arrest indicates that international cooperation is targeting individuals involved in major ransomware ecosystems.

Incident-response plans should cover both technical containment and legal escalation. Preserve ransom notes, attacker communications, authentication records, endpoint telemetry, and evidence of data access.

BleepingComputer reports on the arrest.

Fake Claude installers deliver ClickFix attacks through search advertising

Threat actors are abusing Google Ads and legitimate Bing search-result redirects to direct users to fake Claude installers. The campaigns reportedly use ClickFix-style social engineering, in which victims are instructed to paste commands into a terminal, PowerShell, or another system interface.

Search advertising is not a trust boundary. Sponsored results, redirects, and convincing software branding can lead users to malware or attacker-controlled instructions.

BleepingComputer details the campaign.

AhsayCBS flaws exploited to deploy webshells and miners

Threat actors are exploiting unpatched vulnerabilities in AhsayCBS backup-management software to deploy webshells and cryptocurrency miners. Backup platforms are high-value targets because they commonly have privileged access, contain sensitive data, and connect to production systems.

Administrators should verify the software version, restrict management interfaces, and inspect both the AhsayCBS host and systems reachable from it. A clean-looking backup environment does not rule out persistence through webshells, scheduled tasks, newly created accounts, or unauthorized remote access.

See BleepingComputer’s report on the AhsayCBS exploitation.

Plano cybersecurity center opens

A new cybersecurity center in Plano is reportedly monitoring threats targeting businesses worldwide. Its monitoring activity gives defenders another source of external threat intelligence.

Use external reporting to guide exposure checks, detection updates, and incident triage, then validate those findings against internal telemetry.

Critical Vulnerabilities#

SonicWall SMA1000: CVE-2026-102255 exploited in attacks

Attackers are exploiting the maximum-severity vulnerability CVE-2026-102255 in SonicWall SMA1000 appliances. The flaw was reportedly patched three days before exploitation was observed.

Organizations using SMA1000 appliances should treat exposed or unverified systems as an immediate incident-response priority:

  • Confirm whether the appliance is deployed and internet-accessible.
  • Verify that the emergency update was applied successfully.
  • Review administrative, VPN, authentication, and system logs for suspicious activity.
  • Check for unexpected configuration changes, accounts, access policies, or outbound connections.
  • Restrict administrative access to trusted networks or approved VPN paths.

AhsayCBS: exploited flaws enable webshells and cryptocurrency mining

Unpatched AhsayCBS vulnerabilities are being used to deploy webshells and cryptocurrency miners. The available reporting identifies one critical and one medium-severity flaw but does not provide vulnerability identifiers in the supplied material.

Prioritize AhsayCBS systems that are internet-facing or have broad access to backup repositories. Patch according to the vendor’s available guidance, restrict management access, and investigate the host for:

  • Unexpected web-accessible files
  • New or modified scripts
  • Cryptocurrency-mining processes
  • Unusual CPU consumption
  • New scheduled tasks or services
  • Unexpected outbound connections
  • Accounts or API credentials that were recently created or modified

JetBrains Exposed: CVE-2026-108474

CVE-2026-108474 affects JetBrains Exposed versions before 1.5.1. The reported SQL injection issue involves unescaped string arguments in several SQL functions. The listed CVSS score is 9.8.

Upgrade to version 1.5.1 or later. Until the update is deployed, review applications using affected functionality and ensure database accounts have only the permissions required for their workload.

Advanced IP Blocker WordPress plugin: CVE-2026-104732

CVE-2026-104732 allows unauthenticated attackers to bypass two-factor authentication for enabled accounts, including administrators. The listed CVSS score is 9.8, and no fixed version is provided in the supplied vulnerability data.

Disable or remove the plugin pending vendor remediation. Then review administrator accounts, authentication logs, password-reset activity, and recently modified WordPress files. Reset credentials and revoke active sessions if unauthorized access is possible.

Extensions For CF7 WordPress plugin: CVE-2026-94589

CVE-2026-94589 allows unauthenticated executable-file uploads through the signature-field upload handler. The listed CVSS score is 9.8, and no fixed version is provided in the supplied data.

Disable or remove the plugin. Search upload directories for executable files and investigate web requests associated with unexpected uploads. Do not assume that deleting a suspicious file completes containment; check for additional persistence, modified PHP files, new administrator accounts, and altered site configuration.

Astron Agent: CVE-2026-108263

CVE-2026-108263 affects Astron Agent versions before 1.1.2. An authenticated low-privilege tenant could execute arbitrary Python as root in the core-workflow container through the default unsandboxed workflow code-node path. The issue can bypass tenant isolation and expose shared credentials or data. The listed CVSS score is 9.9.

Upgrade to version 1.1.2 or later. Review tenant activity, workflow definitions, container execution logs, and access to shared secrets. Rotate credentials if an affected deployment may have been accessed by an unauthorized tenant.

Sipay OpenCart Virtual POS Module: CVE-2026-85531

CVE-2026-85531 affects Sipay OpenCart Virtual POS Module versions 26.8.2 through versions before 26.9.1. Improper signature verification can allow transaction-validation bypass through signature spoofing. The listed CVSS score is 9.8.

Upgrade to version 26.9.1. Review payment and order records for mismatched transaction states, suspicious callbacks, duplicate orders, or transactions that lack expected provider verification.

Prioritization

The listed CVEs are not marked as CISA Known Exploited Vulnerabilities in the supplied data. However, the SonicWall SMA1000 and AhsayCBS issues have reported exploitation and should take priority over vulnerabilities without confirmed exploitation. Internet exposure, privilege level, access to sensitive data, and evidence of suspicious activity should determine the final remediation order.

Analyst’s Take: Start with SonicWall SMA1000 and AhsayCBS, because both have reported exploitation and can provide attackers with access to exposed systems or sensitive backup infrastructure. Treat the WordPress plugin issues as containment work, not routine patching, since the supplied data says they lack fixed versions and one permits administrator authentication bypass.

What Defenders Should Do Today#

  1. Check SonicWall SMA1000 exposure immediately. Confirm appliance inventory, internet exposure, firmware status, administrative access paths, and recent configuration changes.

  2. Patch or isolate AhsayCBS systems. Restrict management access to trusted networks, verify backups remain available, and inspect the host for webshells, miners, persistence, and unauthorized accounts.

  3. Disable vulnerable WordPress plugins. Remove Advanced IP Blocker and Extensions For CF7 until fixes are available. Scan WordPress files, upload directories, administrator accounts, and authentication logs.

  4. Apply the available software updates. - JetBrains Exposed: version 1.5.1 or later - Astron Agent: version 1.1.2 or later - Sipay OpenCart Virtual POS Module: version 26.9.1

  5. Review identity and session activity. Look for unexpected administrator logins, MFA changes, password resets, new API tokens, impossible-travel events, and access from unfamiliar infrastructure. Review guidance on session hijacking and cookie theft when investigating suspicious sessions.

  6. Hunt for webshells and miners. Correlate web-server requests with process creation, file modification, outbound network activity, and resource-consumption alerts.

  7. Warn users about ClickFix behavior. Make clear that legitimate software providers do not normally require users to paste commands into terminals, PowerShell, Run dialogs, or browser developer tools to complete an installation.

  8. Investigate search-advertising redirects. Block or review fake Claude installer domains, suspicious Bing redirect chains, and newly downloaded installers associated with sponsored search results.

  9. Rotate potentially exposed credentials. Prioritize credentials stored or reachable by vulnerable backup, workflow, payment, and WordPress systems, including shared service accounts and administrator credentials. A password manager such as Try 1Password → can help teams generate and manage unique replacement credentials.

  10. Preserve evidence and brief response teams. Retain relevant logs, endpoint images, suspicious files, ransom notes, attacker communications, and payment records. Confirm that legal, communications, insurance, and law-enforcement escalation procedures are current.

Technical Notes#

Basic exposure and version checks

Use asset-management data first, then validate directly through approved administrative channels. The following examples are starting points and should be adapted to local tooling:

# Search an inventory export for potentially affected product names
grep -Ei 'SMA1000|AhsayCBS|JetBrains Exposed|Astron Agent|OpenCart|Advanced IP Blocker|Extensions For CF7' assets.csv

# Find WordPress plugin directories that may require review
find /var/www -type d \( \\
  -iname '*advanced*ip*blocker*' -o \\
  -iname '*extensions*for*cf7*' \\
\) -print

Do not rely on a package name alone. Confirm the installed version, deployment location, exposure, and whether the system has been modified since the last known-good state.

Webshell and unexpected upload review

Review web roots and upload directories for recently modified executable files. File extensions and paths vary by platform, so combine file review with web-server and process telemetry:

# Review recently modified files under a web root
find /var/www -type f -mtime -14 -printf '%TY-%Tm-%Td %TH:%TM %p\\n' 2>/dev/null | sort

# Look for common executable extensions in upload locations
find /var/www -type f \( \\
  -path '*/upload*/*' -o \\
  -path '*/media/*' -o \\
  -path '*/files/*' \\
\) \( -iname '*.php' -o -iname '*.phtml' -o -iname '*.php5' -o -iname '*.jsp' \) -print

Treat suspicious files as evidence. Preserve hashes and timestamps before deletion when an incident investigation may be required.

Process and outbound-connection review

Cryptocurrency miners and webshells may appear as unusual processes or persistent outbound connections:

# Review high-CPU processes
ps aux --sort=-%cpu | head -n 20

# Review listening services and established connections
ss -tulpn
ss -tp state established

# Review common persistence locations
systemctl list-unit-files --state=enabled
crontab -l

Commands should be run through approved response procedures. Avoid restarting or cleaning a suspected compromised host before collecting the evidence needed for scoping.

ClickFix detection opportunities

Security teams can monitor for combinations of:

  • Browsers launching shells or scripting interpreters
  • Office or browser processes spawning PowerShell, Command Prompt, or terminal processes
  • Newly downloaded installers from advertising or redirect domains
  • Clipboard-related activity preceding command execution
  • User-initiated script execution shortly after visiting a software download page
  • New persistence created immediately after a suspicious installer launch

A practical endpoint hunting query should correlate the parent process, command interpreter, downloaded file, user, URL, and timestamp rather than alerting only on a single process name.

Incident-response decision points

Escalate from vulnerability remediation to incident response when any of the following are present:

  • A vulnerable system was internet-facing during the relevant exposure window.
  • Logs show successful authentication from an unexpected source.
  • Files, services, scheduled tasks, or accounts changed without authorization.
  • Webshell-like files or mining processes are found.
  • Payment records or transaction states do not match provider verification.
  • Shared credentials or tenant-isolated data may have been accessed.

For affected systems, rotate credentials from a trusted device, revoke active sessions and tokens, preserve forensic evidence, and validate restoration paths before returning the system to normal service.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

CISA KEV additions this week#

CISA added 6 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest. Source: CISA KEV catalog.

All KEV additions by date

Last verified: 2026-10-10

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.