Last Week in Threats Banner

Last Week in Threats: Week 37

Bottom Line

What changed this week: CISA added 11 exploited vulnerabilities targeting enterprise edge devices, remote management tools, and DevOps platforms in a single week, the largest infrastructure-focused cluster in recent months.

Who is most exposed: Organizations running perimeter security appliances (Cisco, Citrix, MikroTik, Fortinet), remote management tools (ConnectWise ScreenConnect), or CI/CD pipelines (GitLab, JFrog Artifactory).

Recommended action: Patch the 11 new KEV additions immediately, prioritizing GitLab and MikroTik systems showing active exploitation signals in community threat feeds.

The Week in Review

The week of September 7 to 13, 2026 belonged to enterprise infrastructure. CISA cataloged 11 newly exploited vulnerabilities, most targeting the perimeter and tooling that organizations depend on for secure remote access, network defense, and software delivery. Cisco, Citrix, MikroTik, GitLab, JFrog, and ConnectWise all appeared in the same seven-day window. Two CVEs drew active community attention: CVE-2026-85706 (GitLab path traversal) accumulated six tracking pulses and CVE-2026-86060 (MikroTik RouterOS command injection) triggered four, both signaling in-the-wild exploitation (AlienVault OTX, as of September 14, 2026).

Ransomware leak-site postings held near the prior week at 162 victims (down 2.4% from 166, ransomware.live, pulled September 14, 2026), but thegentlemen doubled their claimed activity from 9 to 18 victims. The week's 100 highest-confidence malicious IPs split 67% hosting infrastructure and 20% residential ISPs, with AS30823 (Combahton GmbH) and AS207812 (DM Auto EOOD) each contributing two IPs to the top 15 (AbuseIPDB 100% confidence, as of September 14, 2026; network attribution via AlienVault OTX, as of September 14, 2026). The United States remained the top ransomware target geography with 46 victim postings.

Ransomware Leak-Site Activity

The week delivered 162 leak-site postings, down 2.4% from the prior week's 166. thegentlemen led with 18 victims (up from 9 the prior week, a 100% surge), followed by AuditTeam (13) and krybit (13, down from 15). The United States accounted for 46 postings, India 9, and Canada 8 (ransomware.live, pulled September 14, 2026).

Most active groups by victim postings (ransomware.live, pulled September 14, 2026)
thegentlemen 18 AuditTeam 13 krybit 13 safepay 11 direwolf 8 qilin 8 akira 7 emperador 6 Vexy Ransomware 5 rhysida 5

Sector & Technology Watch

This week's exploited vulnerabilities clustered around the enterprise perimeter and operational tooling. Edge and gateway appliances (Cisco Secure Email Gateway, Citrix NetScaler, MikroTik RouterOS, Fortinet FortiOS) carried four CVEs, remote management platforms (ConnectWise ScreenConnect) one, and DevOps infrastructure (JFrog Artifactory, GitLab) three. E-commerce platforms (Adobe Commerce/Magento) and browsers (Chrome V8) rounded out the list (CISA KEV, added September 8-11, 2026).

Organizations in any sector running unpatched edge devices, RMM tools, or CI/CD pipelines faced elevated exposure. If your environment includes any of the affected products, patch immediately and audit access logs for reconnaissance or exploitation attempts predating the patch.

Technology classes targeted this week (CISA KEV, added September 8-11, 2026)
Edge/Gateway 4 DevOps/CI-CD 3 E-commerce 1 Browser 1 RMM/Remote Mgmt 1

Most-Reported Malicious IPs

AbuseIPDB's 100% confidence blacklist delivered 100 entries as of September 14, 2026. The top 15 by report volume split 10 hosting/datacenter IPs, 3 residential ISPs, 1 mobile carrier, and 1 business network. Four of the top six IPs were classified as malicious scanners by GreyNoise Community (as of September 14, 2026).

  • 195.178.110.232 (NL, AS30823 Combahton GmbH / TECHOFF SRV, 47,749 reports, hosting) — GreyNoise: malicious scanner
  • 92.118.39.71 (RO, AS48090 PPTechnology Limited / DMZHOST, 48,792 reports, hosting) — GreyNoise: malicious scanner
  • 79.124.62.230 (BG, AS207812 DM Auto EOOD / CLOUDVPS-NET, 30,095 reports, hosting) — GreyNoise: unknown scanner
  • 79.124.62.134 (BG, AS207812 DM Auto EOOD / CLOUDVPS-NET, 25,647 reports, hosting) — GreyNoise: unknown scanner
  • 172.211.56.214 (NL, Microsoft Limited, 5,451 reports, hosting)
  • 193.163.125.175 (GB, AS211298 Constantine Cybersecurity / Driftnet, 2,405 reports, business) — census/measurement infrastructure
  • 45.135.193.159 (DE, AS213030 Skylink Data Center BV / Pfcloud, 1,551 reports, hosting) — GreyNoise: malicious scanner
  • 103.195.240.46 (VN, AS63740 TocdosoVN-VN, 1,502 reports, hosting)
  • 115.245.172.214 (IN, AS55836 Reliance Jio, 1,345 reports, residential)
  • 152.228.213.32 (FR, AS16276 OVH SAS, 1,154 reports, hosting)
  • 116.105.73.162 (VN, AS24086 Viettel Corporation, 669 reports, residential) — GreyNoise: unknown
  • 122.187.228.233 (IN, AS9498 Bharti Airtel Ltd., 640 reports, mobile)
  • 195.178.110.39 (NL, AS30823 Combahton GmbH / TECHOFF SRV, 503 reports, hosting) — GreyNoise: malicious scanner
  • 119.98.123.186 (CN, AS4134 ChinaNet / CHINANET Hubei, 103 reports, residential)
  • 157.230.87.147 (US, AS14061 DigitalOcean LLC, 55 reports, hosting)

193.163.125.175 carries a reverse-DNS pointer to census/measurement infrastructure and may represent benign internet-wide scanning. The remaining IPs show no such marker. Report volumes and network attribution are from AbuseIPDB (as of September 14, 2026) and AlienVault OTX (ASN, as of September 14, 2026); GreyNoise classifications are community tier (as of September 14, 2026).

Attacker Infrastructure & Networks

The week's most-reported malicious IPs traced back to hosting providers and consumer ISPs. AS30823 (Combahton GmbH, operating as TECHOFF SRV LIMITED) and AS207812 (DM Auto EOOD, operating as CLOUDVPS-NET) each contributed two IPs to the top 15, both datacenter networks. Ten of the 15 enriched IPs originated from hosting/datacenter infrastructure (67%), three from residential fixed-line ISPs (20%), one from a mobile carrier (7%), and one from a commercial/business network (7%) (AbuseIPDB usage-type as of September 14, 2026; AlienVault OTX ASN as of September 14, 2026).

The residential entries (Viettel, Reliance Jio, ChinaNet) represent compromised consumer endpoints, not malicious providers. The hosting-heavy composition is consistent with attack infrastructure rented or abused for scanning, brute-force, and command-and-control activity.

Top networks by count of high-confidence malicious IPs (AbuseIPDB 100% confidence + AlienVault OTX ASN, as of September 14, 2026)
AS30823 Combahton (hosting) 2 AS207812 DM Auto (hosting) 2 AS48090 PPTech (hosting) 1 AS24086 Viettel (residential) 1 AS213030 Skylink DC (hosting) 1
Origin composition: hosting vs. residential/mobile/business (AbuseIPDB usage-type, as of September 14, 2026; 15 IPs enriched)
Hosting: 10 Res: 3 M:1 B:1 Hosting (datacenter/web hosting) · Residential (fixed-line ISP) · Mobile (mobile carrier) · Business (commercial/institutional)

Exploited Vulnerability Watch

CISA added 11 exploited vulnerabilities to the Known Exploited Vulnerabilities catalog between September 8 and 11, 2026. Two CVEs drew active community tracking: CVE-2026-85706 (GitLab path traversal) accumulated 6 AlienVault OTX pulses and CVE-2026-86060 (MikroTik RouterOS command injection) triggered 4 pulses, both signaling observed exploitation (AlienVault OTX, as of September 14, 2026).

  • CVE-2026-84869 — ConnectWise ScreenConnect: improper privilege management and missing authorization enable file transfer and code execution through active sessions without host confirmation (CISA KEV, added September 11, 2026; due September 14, 2026)
  • CVE-2026-42016 — JFrog Artifactory: incorrect authorization allows privilege escalation via token validation bypassing the token scope check (CISA KEV, added September 11, 2026; due September 25, 2026)
  • CVE-2026-42018 — JFrog Artifactory: improper authentication returns internal anonymous-user tokens to unauthenticated callers when anonymous access is disabled (CISA KEV, added September 11, 2026; due September 25, 2026)
  • CVE-2026-85706 — GitLab: path traversal in repository commits API allows unauthenticated users to read arbitrary files (CISA KEV, added September 11, 2026; due September 14, 2026) — 6 OTX pulses
  • CVE-2026-86060 — MikroTik RouterOS: command injection permits attackers to modify RouterOS policy masks, enabling privilege escalation (CISA KEV, added September 10, 2026; due September 13, 2026) — 4 OTX pulses
  • CVE-2026-67277 — MikroTik RouterOS: missing authentication in btest service permits kernel memory disclosure and denial of service (CISA KEV, added September 10, 2026; due September 13, 2026)
  • CVE-2026-19490 — Citrix NetScaler: authentication bypass via alternate path when configured as AAA or Gateway allows unauthenticated remote access (CISA KEV, added September 9, 2026; due September 12, 2026)
  • CVE-2025-25249 — Fortinet Multiple Products: heap buffer overflow allows code execution via specially crafted packets (CISA KEV, added September 9, 2026; due September 12, 2026)
  • CVE-2026-87491 — Google Chromium V8: out-of-bounds write enables sandbox escape and arbitrary code execution via malicious HTML pages (CISA KEV, added September 9, 2026; due September 23, 2026)
  • CVE-2026-20079 — Cisco Firewall Management Center: authentication bypass via alternate path enables unauthenticated script execution achieving root access (CISA KEV, added September 9, 2026; due September 12, 2026)
  • CVE-2026-75650 — Adobe Commerce and Magento: template engine vulnerability permits arbitrary code execution (CISA KEV, added September 8, 2026; due September 11, 2026)

The Hunting Takeaway

The week's enterprise infrastructure cluster points to a behavioral hunting angle: reconnaissance and post-exploitation activity targeting edge appliances, RMM tools, and DevOps platforms. Hunt for authentication attempts against management interfaces, unauthenticated API calls, and privilege escalation sequences tied to the affected products. The GitLab and MikroTik CVEs showing active exploitation are the immediate priority.

A generalizable hunt for edge-device reconnaissance and compromise targeting the perimeter and remote-management tooling:

Splunk SPL:

index=web OR index=proxy OR index=firewall
(uri_path="*/api/v4/projects/*/repository/commits*" OR uri_path="*/api/sessions*" OR uri_path="*/btest*" OR uri_path="*/saml/acs*" OR uri_path="*/artifactory/api/*")
| stats count by src_ip, uri_path, http_status, dest_host
| where count > 5
| sort -count

Microsoft KQL:

union W3CIISLog, AzureDiagnostics, CommonSecurityLog
| where RequestURL has_any ("/api/v4/projects/", "/api/sessions", "/btest", "/saml/acs", "/artifactory/api/")
| summarize RequestCount=count() by ClientIP, RequestURL, HttpStatus, DestinationHost=Computer
| where RequestCount > 5
| order by RequestCount desc

Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.

Check Your Environment

Use these queries to sweep your environment for connections from this week's highest-confidence malicious IPs and to reconcile your vulnerability inventory against the new KEV additions. Exclude 193.163.125.175 (census/measurement infrastructure) from blocking.

Splunk SPL (IP sweep):

index=* src_ip IN ("195.178.110.232","92.118.39.71","79.124.62.230","79.124.62.134","172.211.56.214","45.135.193.159","103.195.240.46","115.245.172.214","152.228.213.32","116.105.73.162","122.187.228.233","195.178.110.39","119.98.123.186","157.230.87.147")
| stats earliest(_time) as first_seen, latest(_time) as last_seen, count by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort -count

Microsoft KQL (IP sweep):

let MaliciousIPs = dynamic(["195.178.110.232","92.118.39.71","79.124.62.230","79.124.62.134","172.211.56.214","45.135.193.159","103.195.240.46","115.245.172.214","152.228.213.32","116.105.73.162","122.187.228.233","195.178.110.39","119.98.123.186","157.230.87.147"]);
union isfuzzy=true CommonSecurityLog, SecurityEvent, Syslog, AzureDiagnostics
| where SourceIP in (MaliciousIPs) or ClientIP in (MaliciousIPs)
| extend SourceAddress=coalesce(SourceIP, ClientIP)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), EventCount=count() by SourceAddress, DestinationIP, DestinationPort, Action
| order by EventCount desc

Vulnerability reconciliation: Cross-check your asset inventory against the 11 new KEV CVEs listed in the Exploited Vulnerability Watch section. Each CVE hyperlinks to its NVD detail page for vendor-specific patch guidance. Prioritize GitLab (CVE-2026-85706) and MikroTik (CVE-2026-86060) systems first, as both show active exploitation signals.

Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.

Appendix: Data Tables

Top Ransomware Groups (ransomware.live, pulled September 14, 2026)

Group Victims This Week Profile
thegentlemen18View
AuditTeam13View
krybit13View
safepay11View
direwolf8View
qilin8View
akira7View
emperador6View
Vexy Ransomware5View
rhysida5View

Most-Reported Malicious IPs (AbuseIPDB 100% confidence, as of September 14, 2026; ASN via AlienVault OTX, as of September 14, 2026)

IP Address Country ASN ISP Origin Type Total Reports Distinct Reporters
195.178.110.232NLAS30823TECHOFF SRV LIMITEDhosting47,7491,591
92.118.39.71ROAS48090DMZHOSThosting48,7921,595
79.124.62.230BGAS207812CLOUDVPS-NEThosting30,095218
79.124.62.134BGAS207812CLOUDVPS-NEThosting25,647220
172.211.56.214NLMicrosoft Limitedhosting5,4511,017
193.163.125.175GBAS211298Driftnet Ltdbusiness2,405120
45.135.193.159DEAS213030Pfcloud UGhosting1,551300
103.195.240.46VNAS63740TOC DO SO Technologyhosting1,502134
115.245.172.214INAS55836Reliance Jioresidential1,345171
152.228.213.32FRAS16276OVH SAShosting1,154209
116.105.73.162VNAS24086Viettel Groupresidential669351
122.187.228.233INAS9498BHARTI TELENETmobile640165
195.178.110.39NLAS30823TECHOFF SRV LIMITEDhosting503281
119.98.123.186CNAS4134CHINANET Hubeiresidential10339
157.230.87.147USAS14061DigitalOcean, LLChosting5536

Top Networks Contributing Malicious IPs (AlienVault OTX ASN + AbuseIPDB usage-type, as of September 14, 2026)

ASN Network Name Origin Class Example ISP IP Count
AS30823Combahton GmbHhostingTECHOFF SRV LIMITED2
AS207812DM Auto EOODhostingCLOUDVPS-NET2
AS48090PPTechnology LimitedhostingDMZHOST1
AS24086Viettel CorporationresidentialViettel Group1
AS213030Skylink Data Center BVhostingPfcloud UG1

Newly Exploited Vulnerabilities (CISA KEV, added September 8-11, 2026)

CVE Vendor Product Date Added Due Date OTX Pulses
CVE-2026-84869ConnectWiseScreenConnect2026-09-112026-09-140
CVE-2026-42016JFrogArtifactory2026-09-112026-09-25timeout
CVE-2026-42018JFrogArtifactory2026-09-112026-09-25
CVE-2026-85706GitLabCE/EE2026-09-112026-09-146
CVE-2026-86060MikroTikRouterOS2026-09-102026-09-134
CVE-2026-67277MikroTikRouterOS2026-09-102026-09-130
CVE-2026-19490CitrixNetScaler2026-09-092026-09-120
CVE-2025-25249FortinetMultiple Products2026-09-092026-09-12
CVE-2026-87491GoogleChromium V82026-09-092026-09-23
CVE-2026-20079CiscoFMC/SCC2026-09-092026-09-12
CVE-2026-75650AdobeCommerce/Magento2026-09-082026-09-11

Methodology & Sources

This weekly recap aggregates open-source intelligence from public threat feeds. Figures represent aggregate statistics from named upstream providers, cross-referenced and captured at a point in time, rather than Focused Hunts detections or proprietary research. Every number published above traces back to a retained snapshot (stored in the project repository) and carries an inline source attribution with the pull date. Week-over-week trend analysis begins once successive snapshots exist; until then, figures are reported as of the pull date without delta claims.

Ransomware victim postings are drawn from a rolling ledger accumulated from ransomware.live every six hours, filtered to the ISO week window (Monday 00:00 UTC to Sunday 23:59 UTC). Malicious IPs come from AbuseIPDB's 100% confidence blacklist (a reputation snapshot as of the pull date), enriched with network ownership from AlienVault OTX and usage-type/report-volume data from AbuseIPDB per-IP checks. GreyNoise classifications are community tier and noted as such. Exploited vulnerabilities are pulled from CISA's Known Exploited Vulnerabilities catalog, filtered by dateAdded. AlienVault OTX pulse counts signal community tracking of CVEs and are noted where present. When a feed is unavailable or coverage is partial, that gap is disclosed inline and in the snapshot rather than estimated or backfilled. Actor claims (e.g., CVE tags in ransomware descriptions) are kept separate from confirmed CISA KEV additions.