SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Fire Ant

❔ UnknownLast active: 2026-09-25First seen: 2026-09-25
3
linked CVEs
Targeted industries
Telecommunications
Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS+, a 33-year-old protocol handling authentication on networking equipment. The protocol, released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers. Attackers can exploit the vulnerability over the internet or local networks with only two packets, leveraging weak encryption. The bug affects both major versions of the protocol, maintained by Shrubbery Networks and a Facebook fork. Patches are available for the Shrubbery version, though no CVE has been assigned. Chinese cyber-espionage groups Salt Typhoon and Fire Ant have exploited TACACS+ in operations targeting telecommunications companies worldwide over the past two years, using it for persistence and lateral movement.
Source: otx · Collected: 2026-09-27
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-48842
suspected

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVSS 8.1
CVE-2026-87902
suspected

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CVSS 8.1
KEV
CVE-2026-42542
suspected

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

CVSS 7.5
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs1
domainthird-party.com—2026-09-25
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.