Touchpoint Security Advisory

Atlassian Flaw Probed Hours After Exploit Release; FortiBleed Lockouts and a Critical NetScaler Fix

TSTouchpoint Security·October 9, 2026

Attackers began probing a critical Atlassian Data Center flaw within hours of exploit code going public. Citrix fixed a critical NetScaler SAML bug, and the FBI warned that FortiBleed is locking administrators out of their own firewalls. Federal agents also seized Chinese-operated hacking domains named after Outlook, YouTube and LinkedIn. A utility breach and TP-Link lawsuits round out the compliance picture.

Priority at a glance

Atlassian and FortiBleed are both under confirmed, ongoing active exploitation. The new NetScaler flaw isn't yet reported exploited, but it's severe and affects builds patched only weeks ago for a different bug. The Flax Typhoon takedown is a completed law-enforcement action; Southern Company's breach is already disclosed and in the notification phase.

Issue Exploited Fix status Our recommended timing
Atlassian Data Center, CVE-2026-21589 (file read → Jira admin) Yes — 288 attempts, 47 IPs, 17 countries as of Oct 9 Fixed releases available per product Today — this is a live, growing attack
Citrix NetScaler, CVE-2026-107406 (SAML SP/IdP, CVSS 9.5) No known exploitation yet 14.1-73.46 / 13.1-64.29 (see bulletin for FIPS builds) This week — recent patching for other CVEs doesn't cover this
FortiBleed credential campaign (FortiGate / SSL VPN, no CVE) Yes, ongoing — 86,644+ devices, 194 countries No patch — this is credential hygiene, not a bug Today — reset credentials, enforce MFA
FBI seizure of Integrity Tech / Flax Typhoon tools and domains N/A — completed law-enforcement takedown Seized domains now show FBI notices Today — block the advisory's indicators
Southern Company, utility customer portal breach (~400,000) N/A — breach already occurred, now in disclosure Customer notifications and credit monitoring underway Ongoing — affected customers should act now

1. Atlassian Data Center file-read flaw targeted within hours of exploit release (CVE-2026-21589)

What's new. We've tracked this flaw since Atlassian disclosed it October 5. Exploitation telemetry keeps growing: Previdian's sensors recorded the first attempts the evening of October 6, and by October 9 had logged 288 attempts from 47 IP addresses in 17 countries. It is still not in CISA's Known Exploited Vulnerabilities (KEV) catalog.

What happened. The unauthenticated file-read flaw (CVSS 4.0: 9.3) lets a remote attacker retrieve specific files under the web application root if they know the exact path. All versions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye Data Center are affected, while Atlassian Cloud is already patched. watchTowr showed the flaw can expose a plaintext Crowd application password in crowd.properties, and an attacker can use that password to make themselves a Jira administrator.

What to do. — click a step to check it off, click any code snippet to copy it

  1. Upgrade to the fixed releases in Atlassian's advisory, such as Confluence 9.2.26 or 10.2.19.
  2. If you cannot patch, take instances off the internet or apply Atlassian's WAF or URL-rewrite mitigations.
  3. Search access logs for URL-encoded .. sequences next to /, \ or ::, and rotate Crowd application passwords on exposed instances.

2. Citrix patches critical NetScaler flaw in SAML deployments (CVE-2026-107406)

What happened. On October 8, Citrix fixed CVE-2026-107406 (CVSS 9.5). This memory overflow in NetScaler ADC and Gateway can allow remote code execution or denial of service when the appliance acts as a SAML Service Provider or Identity Provider. Secure Private Access hybrid deployments are also affected. Citrix knows of no exploitation.

Why this matters even if you patched recently. Two other NetScaler flaws were added to KEV on September 27, and IdP builds as recent as 14.1-73.41 and 13.1-64.28, patched only weeks ago for those earlier bugs, are still affected by this one. This is the same pattern we've flagged before with this product line: a fixed build today doesn't mean fixed for the next flaw.

What to do. — click a step to check it off

  1. Check for authentication samlAction (SP) or authentication samlIdPProfile (IdP) entries in your configuration.
  2. Upgrade to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1-37.283 (FIPS/NDcPP) or later.

3. FortiBleed campaign now locking administrators out of FortiGate devices

What happened. An FBI and US Secret Service advisory (JCSA-20261006-01) warns that FortiBleed remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It exploits weak and reused passwords rather than a software flaw: operators spray and stuff credentials, then crack dumped FortiOS hashes on rented GPUs. They create their own admin accounts and lock out legitimate administrators. SOCRadar has verified more than 86,644 compromised devices in 194 countries, and the advisory says this access has gone to INC/Lynx and Payload ransomware affiliates.

What to do. — click a step to check it off

  1. Remove internet-facing administration, or at least restrict it with a local-in policy.
  2. End active admin and VPN sessions, reset all VPN and admin passwords, and enforce phishing-resistant MFA.
  3. Compare configurations against a known-good baseline and look for accounts on the advisory's list, such as support_fortinet or forticloud-sync. Remove unknown REST API keys.
  4. Move administrator credential storage to PBKDF2 (FortiOS 7.2.11 and later), and review VPN and domain controller logs for lateral movement.

4. FBI seizes Chinese contractor's hacking tools, including brand-lookalike phishing domains

What happened. On October 8, the Justice Department announced court-authorized seizures that disrupted MicroScan, a vulnerability scanner, and FishHub, a spear-phishing and malware platform. US authorities allege both were run by Integrity Technology Group, a Chinese government contractor whose activity overlaps with Flax Typhoon. A joint advisory (AA26-281A) from the FBI, CISA, NSA and partners in six other countries describes password spraying against Exchange and Office 365. FishHub's confirmed victims were about 20 Taiwanese universities.

Lookalike domains. Three seized FishHub delivery domains borrow trusted brand names: outlook3650[.]com (echoing Outlook/Office 365), youtubecard[.]com (echoing YouTube) and linkedinns[.]net (echoing LinkedIn). The other seized domains were c0cc[.]cc, 98aicai[.]com and 98aicode[.]com. The advisory's indicators also include twimg.co[.]uk, a TLD swap on X's image domain (twimg.com). Neither the DOJ nor the advisory states these domains were built to imitate those specific brands; this describes only what their names resemble. All the seized domains now show FBI seizure notices.

What to do. — click a step to check it off

  1. Block the advisory's vetted indicators in DNS, web and email filtering, and search past logs for connections to them.
  2. Require phishing-resistant MFA on webmail and VPNs, and alert on unexpected Active Directory replication.
  3. Remind staff to check the real domain before signing in. Password managers and passkeys will not fill in credentials on a lookalike site.

5. Southern Company notifies about 400,000 utility customers of portal breach

What happened. Southern Company is notifying about 400,000 Georgia Power, Alabama Power and Mississippi Power customers that an unauthorized party viewed account information through its online customer portal. Exposed data includes names, mailing addresses, phone numbers, email addresses, basic account details and, in some cases, the last four digits of Social Security numbers. No bank, payment card or driver's license numbers were accessed. The company is offering a year of free Equifax credit monitoring.

What to do. — click a step to check it off

  1. Affected customers should expect convincing follow-up scams, enroll in the monitoring and consider a credit freeze.
  2. If a call threatens immediate disconnection, hang up and call the number on your bill — the company says it never makes such threats.
  3. Portal operators should defend against credential stuffing with MFA and rate limiting.

Compliance and personal data

States sue TP-Link over security claims On October 6, Florida, Iowa, Montana and Nebraska sued TP-Link Systems under state consumer protection laws. They allege overstated router security, undisclosed China ties and exploited models left without updates. Florida seeks an injunction, disgorgement and penalties of up to $10,000 per willful violation. On October 7, 21 attorneys general urged the FCC to scrutinize TP-Link. TP-Link calls the suits baseless. Buyers should inventory consumer-grade routers and retire end-of-life models.
Southern Company's notification exposure Names, contact details and partial Social Security numbers across three states are likely to engage each state's breach-notification law. As a public company, Southern must also assess whether the incident is material for SEC disclosure.
Document your response If FortiBleed or Atlassian activity leads to data access, notification clocks start running: 72 hours to the regulator under GDPR, and as little as 30 days under some US state laws. Keep records of when patches, mitigations and credential resets were applied.

This section is general information, not legal advice.

Also notable

Critical Cisco NX-OS flaws On October 7, Cisco disclosed five critical NX-OS flaws affecting Nexus 3000 and 9000 switches in standalone mode, including CVE-2026-76471 in NX-API (CVSS 9.8) plus NGOAM and MPLS OAM bugs that can allow root-level code execution. They're reachable only where those features are enabled, and no exploitation is known. Upgrade using Cisco's Software Checker and disable unused features.
Ransomware hits Japan's IDCF Cloud On October 7, IDC Frontier said a ransomware attack disrupted its East Japan Region 1, used by 495 companies and local governments. Management consoles in all regions are suspended while it investigates, and it hasn't said whether data was taken. A provider's incident does not transfer its customers' own notification duties.
ASOS customer data accessed The UK's NCSC says some ASOS customers' names and contact details were accessed after attackers sent an unauthorized push notification on October 6. ASOS says no payment card data or passwords were affected and hasn't given a count. UK GDPR is likely engaged; customers should assume they're affected and consider passkeys.
Registry hijacks used to mint certificates for Google domains Google reported on October 6 that attackers compromised third-party operators of the .gh, .sl and .as country-code registries, altered DNS records and obtained valid HTTPS certificates for several Google domains and other major brands. Chrome has blocked the certificates and the CAs revoked them. Monitor Certificate Transparency logs and publish restrictive CAA records.

Touchpoint's Take

Today's stories share one theme: attackers are going after the systems that decide who gets in. FortiBleed runs on cracked passwords, and the Atlassian flaw can leak stored credentials. The NetScaler bug sits in single sign-on, and Integrity Tech relied on password spraying and lookalike domains. Rotate credentials, end live sessions and require phishing-resistant MFA. When exploit code goes public, move faster than a monthly patch cycle.

Behind the Southern Company and ASOS incidents are customers who now face scams that will sound credible. As the TP-Link suits show, regulators are also starting to hold security claims to account.

If you would like help assessing your exposure to any of today's issues, or your readiness to meet notification obligations, the Touchpoint Security team is available to help.

Sources

  • Atlassian: CVE-2026-21589 — Arbitrary File Access vulnerability impacts multiple products
  • watchTowr Labs: Atlassian pre-auth arbitrary file read (CVE-2026-21589)
  • Previdian: CVE-2026-21589 exploitation telemetry
  • SecurityWeek: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
  • Help Net Security: Atlassian urges immediate patching of CVE-2026-21589
  • Citrix security bulletin CTX697191
  • Citrix: Immediate guidance for CVE-2026-107406
  • The Hacker News: Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
  • SecurityWeek: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
  • CISA Known Exploited Vulnerabilities catalog (data feed)
  • FBI and USSS: FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01)
  • BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
  • US Department of Justice: Justice Department and FBI Seize Vulnerability Scanning and Spear-Phishing Tools Operated by PRC Company
  • FBI, CISA, NSA and partners: Joint Cybersecurity Advisory AA26-281A
  • BleepingComputer: FBI disrupts Chinese hacking tools used to breach critical infrastructure
  • Southern Company / Georgia Power: Information regarding recent incident involving customer information
  • SecurityWeek: Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
  • Florida Attorney General: Complaint, State of Florida v. TP-Link Systems Inc.
  • Montana Attorney General: Knudsen asks FCC to review TP-Link's China ties
  • SecurityWeek: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
  • Cisco: NX-OS NX-API advisory (cisco-sa-napi-rce-r2shwu2j)
  • BleepingComputer: Cisco warns of critical flaws allowing Nexus switch takeover
  • IDC Frontier: Report on unauthorized access to IDCF Cloud
  • BleepingComputer: Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
  • UK NCSC: Incident affecting ASOS customers
  • The Record: ASOS says hackers tricked employee into giving access
  • Google: Chrome's response to recent ccTLD registry hijacks
  • BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries

Not sure where you stand on any of this?

Our team is available to talk through your exposure to today's issues.

Contact us