Security & Threat Intelligence

The Watch

The Signal

Ransomware crews are buying Fortinet admin accounts that survive a firmware reflash.

A joint FBI and Secret Service alert confirms exploitation across 400,000+ targeted devices. The accounts outlive any firmware you flash, and with owners locked out, the buyer holds your perimeter and its management plane at once.

In Play

  1. FortiBleed Active Exploitation on Fortinet Edge

    A joint FBI and U.S. Secret Service alert, reported by CyberScoop, confirms the FortiBleed campaign is actively compromising credentials on Fortinet firewalls and VPN gateways, with more than 400,000 devices targeted. Attackers create new administrator accounts, lock out legitimate owners, and hand the access to ransomware crews. The compromised edge device is now your perimeter and your control plane in the attacker's hands at once — and patching alone won't remove an admin account that already exists.

  2. DNS Root Key Rollover (KSK-2024)

    The DNS root's key-signing key rolls to KSK-2024 on Sunday, October 11 — only the second root KSK rollover ever, flagged across reporting from TLDR IT, Techpresso and MIT Technology Review. Any DNSSEC-validating resolver still trusting only KSK-2017 (key tag 20326) will return SERVFAIL on every lookup — a total name-resolution outage, not a slowdown. The 48-hour root TTL means failures can surface Monday on returning staff. Verify trust anchors on self-run resolvers, appliances, golden images and DANE mail gateways before the weekend.

  3. Management-Plane and Web-Root Credential Exposure

    Dell patched 18 critical flaws in storage and server-management infrastructure — covering authentication bypass, root access, credential theft, token forgery and remote code execution, per CSO reporting — while Atlassian disclosed CVE-2026-21589, a CVSS 9.3 unauthenticated file read in Data Center products including Confluence and Bitbucket. Both sit beneath your endpoint detection, on the management and web-root planes. The shared trap: patching closes the door but leaves attackers holding any token or secret they already took.

  4. Self-Hosted AI Servers Become Botnet Infrastructure

    The PoeLLM backdoor has compromised more than 3,400 self-hosted open-source AI servers since April, conscripting them into a botnet of 'AI-enabled proxies' for exploit scanning, crypto mining and remote code execution, per CyberScoop. Its command-and-control hides in a poem on GitHub: four words run through a hard-coded dictionary generate rotating C2 addresses, defeating network IOC blocking entirely. If you run any self-hosted LLM inference, netflow won't catch it — you need endpoint and egress-behavior detection.

  5. AI Coding-Agent Governance Debt

    The people building AI coding tools are now naming the control failures themselves. OpenCode's founder says engineers aren't reviewing AI-written code, which plateaus at an 80/20 AI/human split (The Information). A frontier agent run with --dangerously-skip-permissions reportedly formatted a developer's C: drive (The Pragmatic Engineer), and Kubernetes co-creators note desktop agents store session IP as JSONL files on disk and act under the developer's own identity (Latent.Space). Your SDLC attestations quietly assume a human read the diff.

Deep Dives

  1. FortiBleed: The Patch Doesn't Delete the Attacker's Admin Account

    The FBI/Secret Service billing is the tell: this is worked as national-security and financial crime at once, because the rogue admins survive any firmware you flash.

    Why two federal agencies are working one firewall bug The FBI and the Secret Service are jointly billed on FortiBleed . That pairing is the detail to brief upward. The bug is being handled as a national-security case and a…

    2 action items

    ●
  2. Patch Won't Evict Them: Dell's 18 Criticals and Atlassian's 9.3

    Both fixes are published and both are incomplete — a forged Dell token or a secret already read from an Atlassian web root outlives the version bump.

    The one line to carry out of both advisories Dell and Atlassian shipped unrelated fixes that fail the same way against a competent attacker: the patch and the eviction are two separate jobs . Dell's 18 critical flaws include token…

    2 action items

    ●
  3. The DNS Root Key Rolls Sunday — Verify or Fail Every Lookup

    A routine infrastructure rollover becomes a weekend outage wherever RFC 5011 automation never reached, and the panic fix trades the outage for a silent security downgrade.

    Where the failure actually lives Most of your resolvers are already fine. Anything doing RFC 5011 automated trust-anchor updates picked up KSK-2024 months ago, because the key has been published in the root zone well ahead of the switch. The…

    2 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn