TABLE OF CONTENT
This week’s intelligence highlights an intense wave of structural zero-day exploitation and advanced evasion techniques. Threat actors are weaponizing edge network appliances, deploying fileless rootkits into enterprise web servers, utilizing self-propagating VBScript worms via RMM tools, and actively bypassing Microsoft Defender patches to achieve unconstrained SYSTEM privileges.
SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.
1. Critical Edge & Perimeter Exploitation
Edge network appliances and perimeter firewalls are under active, critical bombardment from unauthenticated threat actors executing remote code and deploying advanced RATs.
- Active Exploitation of Fortinet Infrastructure — Threat actors are actively weaponizing CVE-2025-25249, a critical heap-based buffer overflow in the FortiOS
cw_acddaemon. Using automated scripts, attackers trigger the exploit to deploy PivotC2, an AI-assisted Node.js RAT that automates FortiGate credential extraction and proxy tunneling. Simultaneously, an Agentless ZTNA portal flaw (CVE-2026-84393) allows unauthenticated MitM interception of encrypted backend traffic. - Active Exploitation of Cisco Secure FMC — Ongoing in-the-wild exploitation is targeting an authentication bypass (CVE-2026-20079, CVSS 10.0) in Cisco Secure FMC. Multiple threat clusters have been identified dropping JSP web shells, deploying the Sandworm-linked
Cyclops Blinkmalware, and detonating Qilin Ransomware via living-off-the-land abuse of thepackage_info.plutility. - Palo Alto PAN-OS & Check Point VPN RCE Flaws — Palo Alto Networks disclosed CVE-2026-0310 (CVSS 9.2), an out-of-bounds write buffer overflow in XML processing granting root-level RCE on PA-Series firewalls. Check Point disclosed two critical flaws (CVE-2026-85102/3) in Security Gateways, allowing unauthenticated RCE via improper certificate validation and ASN.1 parsing heap overflows during VPN negotiation.
- Advanced Stealth Linux Rootkit (PoisonedRefresh) — Targeting F5 BIG-IP APM environments, this rootkit dynamically intercepts Apache
mmap()calls to inject fileless PHP web shells directly into APM webtop scripts. It evades network monitors by establishing a covert local UNIX domain socket (/run/bigtlog.pipe) for backdoor access, persisting via/usr/sbin/httpdand SELinux modifications.
2. Defense Evasion & Kernel Privilege Escalation
Threat actors are weaponizing local path resolution and bypassing incomplete vendor patches to achieve SYSTEM-level execution while blinding EDR tools.
- ShieldCrash Zero-Day (Defender Bypass) — A public PoC named ShieldCrash acts as an explicit patch bypass for CVE-2026-69414 (ShieldBreak). By manipulating specific scanning interactions in
mpengine.dll, local low-privileged users bypass Microsoft's incomplete mitigation to perform arbitrary file reads of sensitive system files (e.g.,SAM) withNT AUTHORITY\SYSTEMprivileges. - Windows Kernel Zero-Days & Ubuntu Baseline Updates — Two actively exploited local privilege escalation flaws affect Windows endpoints: CVE-2026-81963 allows local users to abuse symlinks in the Windows Update Stack, while CVE-2026-85880 uses a heap overflow in Windows ALPC to allow isolated AppContainer processes to achieve full
SYSTEMaccess. Concurrently, Canonical released Ubuntu 24.04.5 LTS, enforcing strict restrictions on unprivileged user namespaces to prevent container breakouts.
3. Supply Chain Attacks & Remote Management Worms
Adversaries are masquerading as legitimate brands and exploiting trusted remote monitoring and management (RMM) software to automate lateral network spread.
- Rogue ConnectWise ScreenConnect Worm — Deployed via tech support scams, rogue ScreenConnect clients execute a multi-stage VBScript chain. The malware exhibits worm-like behavior by exploiting ScreenConnect's Guest File Transfer capability—when a new guest connects to an infected instance, the client automatically transfers and executes the VBScript chain onto the newly connected host, dropping crypto-miners and secondary RMM tools (e.g., UltraViewer).
- Silver Fox Fake Software Campaign — Operating primarily against China-nexus targets, this campaign uses counterfeit download sites spoofing brands like Razer, Microsoft Edge, and Kaspersky. The malicious wrappers drop payloads disguised with fabricated PE metadata (e.g., "TrueUpdate Client") and establish persistence via Scheduled Tasks to communicate with attacker-controlled Alibaba Cloud OSS buckets.
4. Enterprise Software RCE Vulnerabilities
- Microsoft September 2026 Patch Tuesday — Microsoft addressed two major RCE vulnerabilities: CVE-2026-69449, an Important-rated heap buffer overflow in Windows BitLocker accessible over the network via crafted RPC calls, and CVE-2026-69485, an uninitialized resource flaw in the Windows Remote Desktop Client (
mstsc.exe) allowing code execution without user interaction.
Proactive Steps for the Week
- Apply Edge Infrastructure Patches Immediately: Upgrade affected FortiOS and FortiProxy units to fixed releases (e.g., 7.6.4+, 7.4.9+) to resolve the active PivotC2 exploitation. Deploy patches for Palo Alto PAN-OS (12.2.3+, 12.1.10+) and Check Point Security Gateways (LivePatch Take 24) to close unauthenticated RCE flaws. Update Cisco Secure FMC to version 7.2.11+ to prevent web shell deployment.
- Disable RMM File Transfers: Log into the ConnectWise ScreenConnect Administration console and disable
TransferFiles(orTransferFilesInSession) across all Scoped Permissions to halt the automated, worm-like propagation of the VBScript chain. - Harden Endpoint Memory and Service Execution: To mitigate ShieldCrash, enforce Application Control (WDAC/AppLocker) to restrict untrusted binary execution from user-writable directories. Audit local memory protections to block non-SYSTEM tools from inspecting security agent memory.
- Apply Microsoft September 2026 Cumulative Updates: Deploy the latest cumulative updates (e.g., KB5124012, KB5122871) via WSUS/Intune to patch the BitLocker and Remote Desktop Client RCE flaws, as well as the actively exploited Windows Update Stack and ALPC zero-days.
- Audit Web Servers for Fileless Artifacts: To detect the F5 BIG-IP rootkit, conduct volatile memory forensics on running Apache (
httpd) worker processes, verify the binary integrity of/usr/sbin/httpd, and inspect active UNIX domain sockets for unauthorized endpoints like/run/bigtlog.pipe
Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.
.png)