Last Week in Threats: Week 37
Bottom Line
What changed this week: CISA added 11 exploited vulnerabilities targeting enterprise edge devices, remote management tools, and DevOps platforms in a single week, the largest infrastructure-focused cluster in recent months.
Who is most exposed: Organizations running perimeter security appliances (Cisco, Citrix, MikroTik, Fortinet), remote management tools (ConnectWise ScreenConnect), or CI/CD pipelines (GitLab, JFrog Artifactory).
Recommended action: Patch the 11 new KEV additions immediately, prioritizing GitLab and MikroTik systems showing active exploitation signals in community threat feeds.
The Week in Review
The week of September 7 to 13, 2026 belonged to enterprise infrastructure. CISA cataloged 11 newly exploited vulnerabilities, most targeting the perimeter and tooling that organizations depend on for secure remote access, network defense, and software delivery. Cisco, Citrix, MikroTik, GitLab, JFrog, and ConnectWise all appeared in the same seven-day window. Two CVEs drew active community attention: CVE-2026-85706 (GitLab path traversal) accumulated six tracking pulses and CVE-2026-86060 (MikroTik RouterOS command injection) triggered four, both signaling in-the-wild exploitation (AlienVault OTX, as of September 14, 2026).
Ransomware leak-site postings held near the prior week at 162 victims (down 2.4% from 166, ransomware.live, pulled September 14, 2026), but thegentlemen doubled their claimed activity from 9 to 18 victims. The week's 100 highest-confidence malicious IPs split 67% hosting infrastructure and 20% residential ISPs, with AS30823 (Combahton GmbH) and AS207812 (DM Auto EOOD) each contributing two IPs to the top 15 (AbuseIPDB 100% confidence, as of September 14, 2026; network attribution via AlienVault OTX, as of September 14, 2026). The United States remained the top ransomware target geography with 46 victim postings.
Ransomware Leak-Site Activity
The week delivered 162 leak-site postings, down 2.4% from the prior week's 166. thegentlemen led with 18 victims (up from 9 the prior week, a 100% surge), followed by AuditTeam (13) and krybit (13, down from 15). The United States accounted for 46 postings, India 9, and Canada 8 (ransomware.live, pulled September 14, 2026).
Sector & Technology Watch
This week's exploited vulnerabilities clustered around the enterprise perimeter and operational tooling. Edge and gateway appliances (Cisco Secure Email Gateway, Citrix NetScaler, MikroTik RouterOS, Fortinet FortiOS) carried four CVEs, remote management platforms (ConnectWise ScreenConnect) one, and DevOps infrastructure (JFrog Artifactory, GitLab) three. E-commerce platforms (Adobe Commerce/Magento) and browsers (Chrome V8) rounded out the list (CISA KEV, added September 8-11, 2026).
Organizations in any sector running unpatched edge devices, RMM tools, or CI/CD pipelines faced elevated exposure. If your environment includes any of the affected products, patch immediately and audit access logs for reconnaissance or exploitation attempts predating the patch.
Most-Reported Malicious IPs
AbuseIPDB's 100% confidence blacklist delivered 100 entries as of September 14, 2026. The top 15 by report volume split 10 hosting/datacenter IPs, 3 residential ISPs, 1 mobile carrier, and 1 business network. Four of the top six IPs were classified as malicious scanners by GreyNoise Community (as of September 14, 2026).
- 195.178.110.232 (NL, AS30823 Combahton GmbH / TECHOFF SRV, 47,749 reports, hosting) — GreyNoise: malicious scanner
- 92.118.39.71 (RO, AS48090 PPTechnology Limited / DMZHOST, 48,792 reports, hosting) — GreyNoise: malicious scanner
- 79.124.62.230 (BG, AS207812 DM Auto EOOD / CLOUDVPS-NET, 30,095 reports, hosting) — GreyNoise: unknown scanner
- 79.124.62.134 (BG, AS207812 DM Auto EOOD / CLOUDVPS-NET, 25,647 reports, hosting) — GreyNoise: unknown scanner
- 172.211.56.214 (NL, Microsoft Limited, 5,451 reports, hosting)
- 193.163.125.175 (GB, AS211298 Constantine Cybersecurity / Driftnet, 2,405 reports, business) — census/measurement infrastructure
- 45.135.193.159 (DE, AS213030 Skylink Data Center BV / Pfcloud, 1,551 reports, hosting) — GreyNoise: malicious scanner
- 103.195.240.46 (VN, AS63740 TocdosoVN-VN, 1,502 reports, hosting)
- 115.245.172.214 (IN, AS55836 Reliance Jio, 1,345 reports, residential)
- 152.228.213.32 (FR, AS16276 OVH SAS, 1,154 reports, hosting)
- 116.105.73.162 (VN, AS24086 Viettel Corporation, 669 reports, residential) — GreyNoise: unknown
- 122.187.228.233 (IN, AS9498 Bharti Airtel Ltd., 640 reports, mobile)
- 195.178.110.39 (NL, AS30823 Combahton GmbH / TECHOFF SRV, 503 reports, hosting) — GreyNoise: malicious scanner
- 119.98.123.186 (CN, AS4134 ChinaNet / CHINANET Hubei, 103 reports, residential)
- 157.230.87.147 (US, AS14061 DigitalOcean LLC, 55 reports, hosting)
193.163.125.175 carries a reverse-DNS pointer to census/measurement infrastructure and may represent benign internet-wide scanning. The remaining IPs show no such marker. Report volumes and network attribution are from AbuseIPDB (as of September 14, 2026) and AlienVault OTX (ASN, as of September 14, 2026); GreyNoise classifications are community tier (as of September 14, 2026).
Attacker Infrastructure & Networks
The week's most-reported malicious IPs traced back to hosting providers and consumer ISPs. AS30823 (Combahton GmbH, operating as TECHOFF SRV LIMITED) and AS207812 (DM Auto EOOD, operating as CLOUDVPS-NET) each contributed two IPs to the top 15, both datacenter networks. Ten of the 15 enriched IPs originated from hosting/datacenter infrastructure (67%), three from residential fixed-line ISPs (20%), one from a mobile carrier (7%), and one from a commercial/business network (7%) (AbuseIPDB usage-type as of September 14, 2026; AlienVault OTX ASN as of September 14, 2026).
The residential entries (Viettel, Reliance Jio, ChinaNet) represent compromised consumer endpoints, not malicious providers. The hosting-heavy composition is consistent with attack infrastructure rented or abused for scanning, brute-force, and command-and-control activity.
Exploited Vulnerability Watch
CISA added 11 exploited vulnerabilities to the Known Exploited Vulnerabilities catalog between September 8 and 11, 2026. Two CVEs drew active community tracking: CVE-2026-85706 (GitLab path traversal) accumulated 6 AlienVault OTX pulses and CVE-2026-86060 (MikroTik RouterOS command injection) triggered 4 pulses, both signaling observed exploitation (AlienVault OTX, as of September 14, 2026).
- CVE-2026-84869 — ConnectWise ScreenConnect: improper privilege management and missing authorization enable file transfer and code execution through active sessions without host confirmation (CISA KEV, added September 11, 2026; due September 14, 2026)
- CVE-2026-42016 — JFrog Artifactory: incorrect authorization allows privilege escalation via token validation bypassing the token scope check (CISA KEV, added September 11, 2026; due September 25, 2026)
- CVE-2026-42018 — JFrog Artifactory: improper authentication returns internal anonymous-user tokens to unauthenticated callers when anonymous access is disabled (CISA KEV, added September 11, 2026; due September 25, 2026)
- CVE-2026-85706 — GitLab: path traversal in repository commits API allows unauthenticated users to read arbitrary files (CISA KEV, added September 11, 2026; due September 14, 2026) — 6 OTX pulses
- CVE-2026-86060 — MikroTik RouterOS: command injection permits attackers to modify RouterOS policy masks, enabling privilege escalation (CISA KEV, added September 10, 2026; due September 13, 2026) — 4 OTX pulses
- CVE-2026-67277 — MikroTik RouterOS: missing authentication in btest service permits kernel memory disclosure and denial of service (CISA KEV, added September 10, 2026; due September 13, 2026)
- CVE-2026-19490 — Citrix NetScaler: authentication bypass via alternate path when configured as AAA or Gateway allows unauthenticated remote access (CISA KEV, added September 9, 2026; due September 12, 2026)
- CVE-2025-25249 — Fortinet Multiple Products: heap buffer overflow allows code execution via specially crafted packets (CISA KEV, added September 9, 2026; due September 12, 2026)
- CVE-2026-87491 — Google Chromium V8: out-of-bounds write enables sandbox escape and arbitrary code execution via malicious HTML pages (CISA KEV, added September 9, 2026; due September 23, 2026)
- CVE-2026-20079 — Cisco Firewall Management Center: authentication bypass via alternate path enables unauthenticated script execution achieving root access (CISA KEV, added September 9, 2026; due September 12, 2026)
- CVE-2026-75650 — Adobe Commerce and Magento: template engine vulnerability permits arbitrary code execution (CISA KEV, added September 8, 2026; due September 11, 2026)
The Hunting Takeaway
The week's enterprise infrastructure cluster points to a behavioral hunting angle: reconnaissance and post-exploitation activity targeting edge appliances, RMM tools, and DevOps platforms. Hunt for authentication attempts against management interfaces, unauthenticated API calls, and privilege escalation sequences tied to the affected products. The GitLab and MikroTik CVEs showing active exploitation are the immediate priority.
A generalizable hunt for edge-device reconnaissance and compromise targeting the perimeter and remote-management tooling:
Splunk SPL:
index=web OR index=proxy OR index=firewall (uri_path="*/api/v4/projects/*/repository/commits*" OR uri_path="*/api/sessions*" OR uri_path="*/btest*" OR uri_path="*/saml/acs*" OR uri_path="*/artifactory/api/*") | stats count by src_ip, uri_path, http_status, dest_host | where count > 5 | sort -count
Microsoft KQL:
union W3CIISLog, AzureDiagnostics, CommonSecurityLog
| where RequestURL has_any ("/api/v4/projects/", "/api/sessions", "/btest", "/saml/acs", "/artifactory/api/")
| summarize RequestCount=count() by ClientIP, RequestURL, HttpStatus, DestinationHost=Computer
| where RequestCount > 5
| order by RequestCount desc
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Check Your Environment
Use these queries to sweep your environment for connections from this week's highest-confidence malicious IPs and to reconcile your vulnerability inventory against the new KEV additions. Exclude 193.163.125.175 (census/measurement infrastructure) from blocking.
Splunk SPL (IP sweep):
index=* src_ip IN ("195.178.110.232","92.118.39.71","79.124.62.230","79.124.62.134","172.211.56.214","45.135.193.159","103.195.240.46","115.245.172.214","152.228.213.32","116.105.73.162","122.187.228.233","195.178.110.39","119.98.123.186","157.230.87.147")
| stats earliest(_time) as first_seen, latest(_time) as last_seen, count by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort -count
Microsoft KQL (IP sweep):
let MaliciousIPs = dynamic(["195.178.110.232","92.118.39.71","79.124.62.230","79.124.62.134","172.211.56.214","45.135.193.159","103.195.240.46","115.245.172.214","152.228.213.32","116.105.73.162","122.187.228.233","195.178.110.39","119.98.123.186","157.230.87.147"]); union isfuzzy=true CommonSecurityLog, SecurityEvent, Syslog, AzureDiagnostics | where SourceIP in (MaliciousIPs) or ClientIP in (MaliciousIPs) | extend SourceAddress=coalesce(SourceIP, ClientIP) | summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), EventCount=count() by SourceAddress, DestinationIP, DestinationPort, Action | order by EventCount desc
Vulnerability reconciliation: Cross-check your asset inventory against the 11 new KEV CVEs listed in the Exploited Vulnerability Watch section. Each CVE hyperlinks to its NVD detail page for vendor-specific patch guidance. Prioritize GitLab (CVE-2026-85706) and MikroTik (CVE-2026-86060) systems first, as both show active exploitation signals.
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Appendix: Data Tables
Top Ransomware Groups (ransomware.live, pulled September 14, 2026)
| Group | Victims This Week | Profile |
|---|---|---|
| thegentlemen | 18 | View |
| AuditTeam | 13 | View |
| krybit | 13 | View |
| safepay | 11 | View |
| direwolf | 8 | View |
| qilin | 8 | View |
| akira | 7 | View |
| emperador | 6 | View |
| Vexy Ransomware | 5 | View |
| rhysida | 5 | View |
Most-Reported Malicious IPs (AbuseIPDB 100% confidence, as of September 14, 2026; ASN via AlienVault OTX, as of September 14, 2026)
| IP Address | Country | ASN | ISP | Origin Type | Total Reports | Distinct Reporters |
|---|---|---|---|---|---|---|
| 195.178.110.232 | NL | AS30823 | TECHOFF SRV LIMITED | hosting | 47,749 | 1,591 |
| 92.118.39.71 | RO | AS48090 | DMZHOST | hosting | 48,792 | 1,595 |
| 79.124.62.230 | BG | AS207812 | CLOUDVPS-NET | hosting | 30,095 | 218 |
| 79.124.62.134 | BG | AS207812 | CLOUDVPS-NET | hosting | 25,647 | 220 |
| 172.211.56.214 | NL | — | Microsoft Limited | hosting | 5,451 | 1,017 |
| 193.163.125.175 | GB | AS211298 | Driftnet Ltd | business | 2,405 | 120 |
| 45.135.193.159 | DE | AS213030 | Pfcloud UG | hosting | 1,551 | 300 |
| 103.195.240.46 | VN | AS63740 | TOC DO SO Technology | hosting | 1,502 | 134 |
| 115.245.172.214 | IN | AS55836 | Reliance Jio | residential | 1,345 | 171 |
| 152.228.213.32 | FR | AS16276 | OVH SAS | hosting | 1,154 | 209 |
| 116.105.73.162 | VN | AS24086 | Viettel Group | residential | 669 | 351 |
| 122.187.228.233 | IN | AS9498 | BHARTI TELENET | mobile | 640 | 165 |
| 195.178.110.39 | NL | AS30823 | TECHOFF SRV LIMITED | hosting | 503 | 281 |
| 119.98.123.186 | CN | AS4134 | CHINANET Hubei | residential | 103 | 39 |
| 157.230.87.147 | US | AS14061 | DigitalOcean, LLC | hosting | 55 | 36 |
Top Networks Contributing Malicious IPs (AlienVault OTX ASN + AbuseIPDB usage-type, as of September 14, 2026)
| ASN | Network Name | Origin Class | Example ISP | IP Count |
|---|---|---|---|---|
| AS30823 | Combahton GmbH | hosting | TECHOFF SRV LIMITED | 2 |
| AS207812 | DM Auto EOOD | hosting | CLOUDVPS-NET | 2 |
| AS48090 | PPTechnology Limited | hosting | DMZHOST | 1 |
| AS24086 | Viettel Corporation | residential | Viettel Group | 1 |
| AS213030 | Skylink Data Center BV | hosting | Pfcloud UG | 1 |
Newly Exploited Vulnerabilities (CISA KEV, added September 8-11, 2026)
| CVE | Vendor | Product | Date Added | Due Date | OTX Pulses |
|---|---|---|---|---|---|
| CVE-2026-84869 | ConnectWise | ScreenConnect | 2026-09-11 | 2026-09-14 | 0 |
| CVE-2026-42016 | JFrog | Artifactory | 2026-09-11 | 2026-09-25 | timeout |
| CVE-2026-42018 | JFrog | Artifactory | 2026-09-11 | 2026-09-25 | — |
| CVE-2026-85706 | GitLab | CE/EE | 2026-09-11 | 2026-09-14 | 6 |
| CVE-2026-86060 | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 | 4 |
| CVE-2026-67277 | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 | 0 |
| CVE-2026-19490 | Citrix | NetScaler | 2026-09-09 | 2026-09-12 | 0 |
| CVE-2025-25249 | Fortinet | Multiple Products | 2026-09-09 | 2026-09-12 | — |
| CVE-2026-87491 | Chromium V8 | 2026-09-09 | 2026-09-23 | — | |
| CVE-2026-20079 | Cisco | FMC/SCC | 2026-09-09 | 2026-09-12 | — |
| CVE-2026-75650 | Adobe | Commerce/Magento | 2026-09-08 | 2026-09-11 | — |
Methodology & Sources
This weekly recap aggregates open-source intelligence from public threat feeds. Figures represent aggregate statistics from named upstream providers, cross-referenced and captured at a point in time, rather than Focused Hunts detections or proprietary research. Every number published above traces back to a retained snapshot (stored in the project repository) and carries an inline source attribution with the pull date. Week-over-week trend analysis begins once successive snapshots exist; until then, figures are reported as of the pull date without delta claims.
Ransomware victim postings are drawn from a rolling ledger accumulated from ransomware.live every six hours, filtered to the ISO week window (Monday 00:00 UTC to Sunday 23:59 UTC). Malicious IPs come from AbuseIPDB's 100% confidence blacklist (a reputation snapshot as of the pull date), enriched with network ownership from AlienVault OTX and usage-type/report-volume data from AbuseIPDB per-IP checks. GreyNoise classifications are community tier and noted as such. Exploited vulnerabilities are pulled from CISA's Known Exploited Vulnerabilities catalog, filtered by dateAdded. AlienVault OTX pulse counts signal community tracking of CVEs and are noted where present. When a feed is unavailable or coverage is partial, that gap is disclosed inline and in the snapshot rather than estimated or backfilled. Actor claims (e.g., CVE tags in ransomware descriptions) are kept separate from confirmed CISA KEV additions.
