Touchpoint Security Advisory

FortiBleed Lockouts, an Exploited Atlassian Flaw and a 1.3 Million-Person Court Breach

TSTouchpoint Security·October 8, 2026

Perimeter devices and self-hosted tools dominate today's brief. Federal agencies say the FortiBleed credential campaign is now locking administrators out of their own firewalls, and attackers probed a critical Atlassian flaw within hours of a public exploit. Arizona's courts confirmed that Social Security numbers for about 1.3 million people were copied.

Priority at a glance

FortiBleed and the Atlassian flaw are both under confirmed active exploitation right now. SonicWall's new CVSS 10.0 flaw isn't yet reported exploited, but the product line has been hit by zero-days twice this year already. The ccTLD hijacks and Arizona breach are both already-happened incidents now in the response and disclosure phase.

Issue Exploited Fix status Our recommended timing
FortiBleed credential campaign (FortiGate / SSL VPN, no CVE) Yes, ongoing — 86,644+ devices, 194 countries No patch — this is credential hygiene, not a bug Today — reset credentials, enforce MFA
Atlassian Data Center, CVE-2026-21589 (file read → Jira admin) Yes, within 2 hours of public PoC (Oct 6) Fixed releases available per product Today — this is now a live attack, not a precaution
SonicWall SMA1000, CVE-2026-102255 (CVSS 10.0 pre-auth SSRF) No known exploitation yet 12.4.3-03670 or 12.5.0-03082+ Today — September's patch does not cover this
.gh / .sl / .as registry hijacks → rogue HTTPS certificates N/A — registry-operator compromise, not your stack Google revoked the certs it found Ongoing — monitor CT logs for your domains
Arizona courts, FARE program data (~1.3M people, SSNs) N/A — breach occurred Sept 24, now in disclosure No evidence data has been shared, per the court Ongoing — affected individuals should act now

1. FBI and Secret Service: FortiBleed is still active and locking out administrators

What happened. On October 6, the FBI and US Secret Service warned in a joint advisory (JCSA-20261006-01) that FortiBleed, a credential-theft campaign against internet-facing FortiGate firewalls and SSL VPN gateways, remains active. Citing SOCRadar, the agencies count more than 86,644 compromised devices in 194 countries.

How it works. No CVE is involved. Attackers use leaked or reused credentials, password spraying and credential stuffing, then crack weakly stored (legacy SHA-256) password hashes offline. They create rogue administrator accounts and sometimes delete or change real ones, locking owners out. The agencies say this access has fed INC/Lynx and Payload ransomware affiliates.

What to do. — click a step to check it off

  1. Remove internet-facing management, or restrict it to trusted hosts.
  2. End all administrator and VPN sessions, reset every Fortinet credential and enforce phishing-resistant MFA.
  3. Look for unfamiliar admin accounts (the advisory lists 19 observed names, such as "forticloud-sync") and unknown REST API keys.
  4. Store admin credentials with PBKDF2 (FortiOS 7.2.11 and later) and hunt for lateral movement. Patching alone will not evict an attacker who holds valid credentials.

2. Critical Atlassian Data Center flaw exploited after public proof of concept

What's new. We've covered CVE-2026-21589 since it was disclosed on October 5 — on day one it was an unexploited critical flaw, and we noted yesterday that no exploitation had been reported. That's changed: watchTowr published technical details and a proof of concept on October 6, and a honeypot operator reported exploitation attempts within two hours of that release.

What happened. The flaw (CVSS v4 9.3) lets unauthenticated attackers read specific files in the web root of self-hosted Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye. Atlassian Cloud is already patched. watchTowr's proof of concept showed that in Crowd-connected Jira deployments, plaintext Crowd credentials can be read and used to create a Jira administrator — turning a file-read bug into full admin access.

What to do. — click a step to check it off

  1. Upgrade to the fixed versions in Atlassian's advisory (for example, Confluence 9.2.26 or 10.2.19; Jira Software 9.12.40, 10.3.26 or 11.3.12).
  2. If you cannot patch today, remove internet exposure or apply Atlassian's WAF or rewrite rules.
  3. Search URL-decoded access logs for ".." next to "/", "" or "::". If you find hits, rotate Crowd credentials and review administrator accounts.

3. SonicWall fixes CVSS 10.0 pre-authentication flaw in SMA1000 gateways

What happened. SonicWall's advisory SNWLID-2026-0017 fixes four flaws in SMA1000 appliances (models 6210, 7210 and 8200v). The most serious, CVE-2026-102255, now confirmed at CVSS 10.0, is a pre-authentication server-side request forgery in the WorkPlace interface that could let a remote attacker reach internal functions. The other three (CVSS 7.8, 7.2 and 5.5) require a login.

Why this matters even if you already patched in September. SonicWall reports no exploitation so far, but attackers exploited SMA1000 SSRF flaws as zero-days in July and September. Appliances already patched for the September flaws (12.4.3-03526, 12.5.0-02952) are still vulnerable to this one — the earlier patch does not cover it.

What to do. — click a step to check it off

  1. Install hotfix 12.4.3-03670 or 12.5.0-03082 (or later) — plan for a reboot.
  2. Restrict management and WorkPlace exposure where you can. SonicWall firewall SSL-VPN and the SMA 100 series are not affected.

4. Registry hijacks yield rogue HTTPS certificates for Google and other brands

What happened. Google disclosed on October 6 that attackers compromised the third-party operators of the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) registries. By changing authoritative DNS records, they obtained valid HTTPS certificates for several Google domains and for unnamed large brands and online services. Google says its own systems were not breached.

Why it matters. Google blocked the certificates in Chrome and had them revoked, but warns that browser-side blocking will not protect every client. A domain you've long since forgotten about, especially a regional or parked ccTLD property, is still a lever an attacker can pull against your brand.

What to do. — click a step to check it off

  1. Monitor Certificate Transparency logs for all of your domains, including parked and regional ccTLD properties, and check any .gh, .sl or .as domains for unexpected issuance.
  2. Publish restrictive CAA records, including ACME account binding, so only your chosen CAs and validation methods can issue certificates.

5. Arizona courts: data on about 1.3 million people copied in phishing-led breach

What happened. The Arizona judiciary confirmed that attackers who got in on September 24 copied backup court files. Its FAQ says data from the Fines/Fees and Restitution Enforcement (FARE) program covers about 1.3 million people with court debts going back 30 years, including names, case numbers and Social Security numbers. More than 150,000 Foster Care Review Board reports and protective-order records were also copied. The Record, citing investigators, reported that a phishing email started the attack.

1.3M people with Arizona court debts, plus over 150,000 Foster Care Review Board and protective-order records, copied from backup files.

Who is affected. Those affected include protected parties and children in foster care, whose safety can depend on confidentiality. The court says it has no evidence the data has been shared.

What to do. — click a step to check it off

  1. Affected individuals can use the court's lookup tool, place credit freezes with Equifax, Experian and TransUnion, and visit IdentityTheft.gov.
  2. Be cautious with unexpected messages about court debts — legitimate court texts come from short code 83958.
  3. Organizations: this is another case for phishing-resistant authentication and encrypted, segmented backups.

Compliance and personal data

States sue TP-Link On October 6, Florida's attorney general announced a lawsuit against TP-Link Systems, and SecurityWeek reports that Iowa, Montana and Nebraska filed near-identical consumer-protection suits that day. The complaints allege overstated security marketing and devices exploited by state-linked botnets, which TP-Link calls baseless. Vendor reviews should now cover suppliers' security claims and patch lifecycles.
Notification clocks The Arizona and Southern Company incidents (see Also notable) involve full or partial Social Security numbers. That engages breach-notification laws in the states where affected people live, several of which also require notice to the attorney general. Have notice templates, call-center scripts and credit-monitoring contracts ready in advance.
Perimeter compromises Confirmed access through FortiGate, Atlassian or SMA1000 systems may trigger sector and state notification duties. For public companies, it may also require an SEC Form 8-K Item 1.05 filing within four business days of determining the incident is material. Document when compromise was confirmed and how materiality was decided. Separately, CISA's CIRCIA final rule (72-hour incident and 24-hour ransom-payment reporting) has been under White House review since October 1.

This section is general information, not legal advice.

Also notable

Southern Company utility customers notified Georgia Power says an unauthorized party reached customer account data through its online portal. The data includes names, mailing addresses, phone numbers, email addresses and the last four digits of Social Security numbers, but not bank, card or driver's license numbers. SecurityWeek puts the total at about 400,000 Georgia, Alabama and Mississippi Power accounts. Affected customers are offered a year of Equifax credit monitoring and should be wary of calls threatening immediate disconnection.
ASOS links its breach to social engineering After an unauthorized push notification reached app users on October 6, the UK retailer said names and contact details may have been accessed through third-party messaging platforms. It does not believe payment cards or passwords were affected. ASOS later told BleepingComputer the attacker impersonated a trusted contact to obtain an employee's credentials. Customers should expect targeted phishing that uses their real details.
Advantest confirms personal data theft In October 6 notification letters, the chip-test equipment maker said data stolen in its February ransomware attack includes Social Security, passport, driver's license, medical and financial information. It is offering 18 months of Kroll monitoring (enroll by January 4, 2027) but has not said how many people are affected.
Oracle Health breach tally grows SecurityWeek reports that state filings now put the early-2025 breach of legacy Cerner systems at nearly 20 million people, including about 3 million Texans. Exposed data may include names, Social Security numbers and medical record details, so affected patients should review explanation-of-benefits statements for services they did not receive.
Tensorlake npm package hijacked StepSecurity found that tensorlake 0.5.144, published October 8, carries a Shai-Hulud-style worm that steals developer and cloud credentials and republishes the victim's packages. Remove its token monitor before revoking tokens, because revocation can trigger deletion of the user's home directory. Pin to 0.5.143.
Ransomware recovery firm owner charged The DOJ charged MonsterCloud owner Zohar Pinhasi with wire fraud. Prosecutors allege he told victims not to pay, then secretly paid over $8 million in ransoms while billing clients more than $19 million. Check what your incident-response providers actually do on your behalf.
$10 million reward for alleged Hafnium hacker The State Department is offering up to $10 million for information on Zhang Yu, charged with China's Ministry of State Security-directed intrusions in 2020-2021, including theft of COVID-19 research.
Empire Market co-creator sentenced to 40 years Raheim Hamilton received 40 years and a $5 million fine for running a dark web marketplace that processed over $430 million in transactions.

Touchpoint's Take

Today's common thread is trust at the edge. FortiBleed needs only reused or weakly stored credentials. The Atlassian and SonicWall flaws show how quickly one request to an exposed system can become administrative access. The registry hijacks turn DNS and certificates against a brand.

The response is unglamorous: know what you expose, take management interfaces off the internet, require phishing-resistant MFA, and verify that patched systems were not already compromised.

Arizona is the human counterweight. One phishing email exposed people with court debts, protected parties and children in foster care, none of whom chose to share that data. What an organization keeps, how it segments it, and how quickly it can tell people what to do next matter as much as the technical fix.

If you would like help assessing your exposure to today's issues or your notification readiness, the Touchpoint Security team is available to talk it through.

Sources

  • FBI/USSS Joint Cybersecurity Advisory JCSA-20261006-01: FortiBleed Operations Continue Targeting Exposed Systems
  • BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
  • The Hacker News: FBI Warns FortiBleed Remains Active
  • Atlassian: CVE-2026-21589 Arbitrary File Access Vulnerability Impacts Multiple Products
  • watchTowr Labs: Atlassian pre-auth arbitrary file read (CVE-2026-21589)
  • BleepingComputer: Hackers exploit critical Atlassian flaw after public PoC release
  • SonicWall PSIRT: SNWLID-2026-0017
  • CVE Record: CVE-2026-102255
  • The Hacker News: SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000
  • Google: Chrome's response to recent ccTLD registry hijacks
  • Help Net Security: Hackers hijack three country-code domain registries
  • Arizona Judicial Branch: Cybersecurity Alert and FAQ
  • The Record: Arizona courts say hackers stole info on more than 1.3 million people
  • Florida Attorney General: Attorney General James Uthmeier Files Lawsuit Against TP-Link Systems
  • SecurityWeek: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
  • OIRA (reginfo.gov): CIRCIA Reporting Requirements final rule, RIN 1670-AA04
  • The HIPAA Journal: CISA Sends CIRCIA Final Rule for White House Review
  • Georgia Power: Information regarding recent incident involving customer information
  • SecurityWeek: Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
  • ASOS plc: Statement on Cyber Incident
  • BleepingComputer: ASOS links data breach to social engineering attack
  • Advantest notice of data breach (California AG filing)
  • SecurityWeek: Oracle Health Data Breach Tally Climbs to Nearly 20 Million
  • StepSecurity: tensorlake npm compromised with hostage-token worm
  • US DOJ: Owner of Florida ransomware remediation company charged
  • The Record: US posts $10 million reward for accused Chinese Hafnium hacker
  • US Attorney's Office, N.D. Illinois: Co-creator of dark web marketplace sentenced to 40 years

Not sure where you stand on any of this?

Our team is available to talk through your exposure to today's issues.

Contact us