Last Week in Threats Banner

Last Week in Threats: Week 39

Bottom Line

What changed: Attacks against self-hosted AI and LLM service endpoints surged, with 422 malicious IPs active during the week, 100 new. Model Context Protocol scanners dominated the threat landscape alongside credential harvesters targeting exposed API keys.

Who is most exposed: Organizations running self-hosted Ollama, LiteLLM, OpenAI-compatible, or LM Studio endpoints; edge appliance operators (Citrix NetScaler, MikroTik RouterOS, F5 BIG-IP, Check Point gateways) facing 11 new KEV exploits; and technology and manufacturing firms hit by 146 ransomware attacks.

Recommended action: Audit AI/LLM service exposure, restrict unauthenticated access, and patch the Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) by September 30.

The Week in Review

The week of September 22 to 28, 2026 marked a turning point in adversary reconnaissance patterns. Self-hosted AI and machine learning service endpoints became the dominant scanning target, with 422 attacker IPs probing Ollama, LiteLLM, OpenAI-compatible, and LM Studio honeypots. Model Context Protocol scanners accounted for 159 of those IPs, searching for exposed inference endpoints. Credential harvesters added another 86 IPs targeting API key paths and environment files. This shift reflects the growing adoption of self-hosted LLM infrastructure and the adversary awareness that these endpoints often run without authentication.

Edge appliances faced a concentrated wave of exploitation pressure. CISA added 11 vulnerabilities to the KEV catalog, including two Citrix NetScaler zero-days enabling remote code execution, a MikroTik RouterOS authentication bypass, two Check Point security gateway flaws, and an F5 BIG-IP heap overflow. The edge device concentration signals adversaries prioritizing perimeter footholds over internal lateral movement this week. Ransomware volume dropped 21 percent week-over-week to 146 victims, down from 185 the prior week.

Ransomware Activity

Ransomware groups posted 146 victims this week, down 21 percent from the prior week's 185 (ransomware.live, 2026-09-28). Qilin led with 17 postings, followed by metaencryptor and akira with 9 each. The United States absorbed the highest victim count (50), followed by unknown locations (31) and Italy (6).

Most active groups by victim postings (ransomware.live, pulled 2026-09-28)
qilin 17 metaencryptor 9 akira 9 incransom 8 SilentRansomGroup 8 Wallstreet 7

Sector & Technology Watch

Technology firms faced 32 ransomware attacks this week, followed by manufacturing (28), professional services (21), healthcare (15), and construction (12). The edge appliance exploitation wave put organizations running Citrix NetScaler, MikroTik RouterOS, F5 BIG-IP, and Check Point gateways in the crosshairs. If you run Ollama, LiteLLM, OpenAI-compatible APIs, or LM Studio endpoints, audit authentication controls and restrict access to trusted networks.

  • Most-targeted industries: Technology (32 victims), Manufacturing (28), Professional Services (21), Healthcare (15), Construction (12)
  • Technology in the crosshairs: Edge/VPN appliances, AI/LLM services, security gateways, SD-WAN orchestrators, API gateways, collaboration platforms, web platforms
  • If you run edge appliances or AI endpoints: Patch the Citrix NetScaler zero-days by September 30, audit AI/LLM service authentication, and hunt for unauthenticated external access to non-public services

Most-Reported Malicious IPs

AbuseIPDB's top 100 confidence-score list included 211.51.132.104 (Korea Telecom residential, 6,261 reports), 103.191.14.243 (Indonesian hosting, 6,311 reports), and 134.209.120.216 (DigitalOcean, 5,850 reports) as the week's most-reported addresses (AbuseIPDB, as of 2026-09-28).

  • 100%-confidence entries listed: 100
  • Most-reported this week: 211.51.132.104 (6,261 reports / 1,221 reporters), 103.191.14.243 (6,311 reports / 1,190 reporters), 134.209.120.216 (5,850 reports / 1,177 reporters)
  • What they were doing: Port scanning (11 IPs), SSH brute-force (8 IPs), web application attacks (4 IPs)

Context matters: GreyNoise Community flagged 11 of the top 15 as malicious scanners; one (199.45.154.191) was the benign Censys scanner and should be excluded from block lists.

Attacker Infrastructure & Networks

The week's malicious IPs originated from a mix of compromised residential endpoints and hosting infrastructure. AS209371 (Private Network / Global Communication Net Plc, Bulgaria) contributed 2 IPs, both in hosting environments. The distribution was 8 hosting, 6 residential, and 1 business network (Censys scanner). (AlienVault OTX ASN, AbuseIPDB usage type, 2026-09-28)

Networks hosting the most malicious IPs (AlienVault OTX ASN + AbuseIPDB usage type, 2026-09-28)
AS209371 (hosting) 2 AS48090 (hosting) 1 AS7922 (residential) 1 AS4766 (residential) 1 AS398324 (business) 1
Where the attack traffic originates (AbuseIPDB usage type, 2026-09-28)
Hosting (8) Residential (6) 1 Hosting Residential Business
  • Nastiest networks: AS209371 Private Network (2 IPs, hosting), AS48090 Pptechnology Limited (1 IP, hosting)
  • Hosting vs. home: 6 of 15 traced to consumer/residential connections (compromised endpoints), 8 to hosting/datacenter providers, 1 business network (Censys scanner)
  • Also known malware infrastructure: None of the top 15 IPs are also active C2 or payload hosts this week (ThreatFox/URLhaus, 2026-09-28)

The highest-volume residential IP (211.51.132.104, Korea Telecom, 6,261 reports) reflects a compromised endpoint rather than a malicious provider. The hosting networks with elevated report volumes warrant separate attention as potential bad infrastructure.

Exploited-Vuln Watch

CISA added 11 vulnerabilities to the Known Exploited Vulnerabilities catalog this week, including two Citrix NetScaler zero-days (CVE-2026-88772, CVE-2026-88771) enabling remote code execution (due September 30), a MikroTik RouterOS authentication bypass (CVE-2026-67279, due September 28), and Microsoft SharePoint code injection (CVE-2026-65660, due September 28). (CISA KEV, 2026-09-27 catalog)

  • New KEV additions this week: 11
  • Citrix NetScaler zero-days: CVE-2026-88772 (buffer overflow RCE), CVE-2026-88771 (input validation RCE), both due 2026-09-30
  • Other critical adds: CVE-2026-67279 (MikroTik RouterOS), CVE-2026-65660 (Microsoft SharePoint), CVE-2026-87902 (WordPress Core RFI), CVE-2026-5430 (WSO2), CVE-2026-94127 (F5 BIG-IP APM), two Check Point flaws (CVE-2026-93616, CVE-2026-85102)
  • Weaponized-CVE signal: AlienVault OTX pulse counts confirm in-the-wild weaponization for CVE-2026-88772 (3 pulses), CVE-2026-88771 (3 pulses), CVE-2026-67279 (4 pulses), CVE-2026-65660 (4 pulses) (AlienVault OTX, 2026-09-28)

The edge appliance concentration is notable: Citrix NetScaler, MikroTik RouterOS, F5 BIG-IP APM, and two Check Point products all received KEV additions within a six-day window. For full CVE details and patch guidance, see the CISA KEV catalog.

Malware & C2

ThreatFox cataloged 6,182 indicators over a 2-day window, with 593 fresh C2 IOCs added (ThreatFox, 2026-09-28). AsyncRAT dominated with 3,785 indicators, a near-quadruple increase from the prior week's 974. Unknown Loader added 1,004 indicators, followed by ClearFake (279), Cobalt Strike (113), and Mirai (109).

  • Fresh C2 IOCs this week: 593 (vs 440 last week)
  • Top malware families: AsyncRAT (3,785 indicators), Unknown Loader (1,004), ClearFake (279), Cobalt Strike (113), Mirai (109)
  • AsyncRAT surge: 3,785 indicators (vs 974 last week), reflecting sustained infrastructure buildout by multiple operators

Attacks on AI Infrastructure

Self-hosted AI and LLM service endpoints faced 422 attacker IPs during the week, with 100 new and 322 persistent from prior weeks (AI Honeypot Observatory, 2026-09-28). Model Context Protocol (MCP) scanners dominated with 159 IPs probing for exposed inference endpoints. Credential harvesters (86 IPs) targeted API key paths, environment files, and configuration endpoints.

Top AI attacker categories (AI Honeypot Observatory, 2026-09-28)
MCP-SCANNER 159 SCANNER-MASS 88 CREDENTIAL-HARVESTER 86 RELAY-CUSTOMER 41 SCANNER-ENUM 35 IDENTITY-PROBER 9 RELAY-VERIFIER 4
  • Attacker IPs active this week: 422 (100 new, 322 persistent)
  • Dominant categories: MCP-SCANNER (159 IPs probing Model Context Protocol endpoints), CREDENTIAL-HARVESTER (86 IPs), SCANNER-MASS (88 IPs)
  • Top MITRE ATT&CK techniques: T1046 Network Service Discovery (422 IPs), T1190 Exploit Public-Facing Application (159 IPs), T1552.001 Unsecured Credentials (88 IPs)

If you expose Ollama, LiteLLM, OpenAI-compatible, or LM Studio endpoints, enforce authentication on all paths, restrict access to trusted networks only, monitor for prompt injection attempts, and audit for exposed environment variables or API keys in public-facing directories.

The Hunting Takeaway

The AI infrastructure attack surge and the edge appliance KEV concentration both point to the same hunting angle: externally reachable services with weak or absent authentication. Hunt for unauthenticated external access to non-public services. Look for successful authentication to internal services from external IPs, web requests to admin or API paths without corresponding authentication events, and requests to paths commonly associated with service metadata or configuration (e.g., /api/health, /v1/models, /.env, /api/keys). Cross-reference successful external access against your asset inventory: if the service was never intended for public exposure, investigate immediately.

For AI/LLM endpoints specifically, look for prompt submission patterns without a corresponding internal user context, repeated model enumeration requests, and API key reuse across multiple source IPs (shadow relay pool signal). The telemetry is in your web proxy logs, firewall permit logs, and application authentication logs.

Check Your Environment

Use these IOCs and CVEs to sweep your environment. Each query targets this week's high-confidence threats.

Malicious IP Sweep

Splunk SPL

index=* (sourcetype=stream:http OR sourcetype=fortigate_traffic OR sourcetype=paloalto:traffic OR sourcetype=cisco:asa OR sourcetype=aws:cloudfront:accesslogs)
| search src_ip IN ("45.148.10.40","211.51.132.104","103.191.14.243","134.209.120.216","116.135.67.93","174.78.139.165","109.160.32.137","109.160.32.178","196.250.67.161","61.129.41.146","101.36.108.202","35.205.224.26","47.79.207.47","98.58.154.60")
| table _time, src_ip, dest_ip, dest_port, action, bytes
| sort - _time

Malicious IP Sweep

Microsoft KQL

union CommonSecurityLog, AzureDiagnostics, SigninLogs, OfficeActivity
| where SourceIP in ("45.148.10.40","211.51.132.104","103.191.14.243","134.209.120.216","116.135.67.93","174.78.139.165","109.160.32.137","109.160.32.178","196.250.67.161","61.129.41.146","101.36.108.202","35.205.224.26","47.79.207.47","98.58.154.60")
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, Activity, SentBytes
| sort by TimeGenerated desc

Vulnerability Check

Cross-reference this week's KEV additions against your asset inventory. For CVE details and patch guidance, see the Exploited-Vuln Watch section above and the CISA KEV catalog.

Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.

Appendix: Raw Data Tables

Top Ransomware Groups

ransomware.live, pulled 2026-09-28

Group Victims This Week
qilin17
metaencryptor9
akira9
incransom8
SilentRansomGroup8
Wallstreet7
Storm6
everest6
thegentlemen5
Booba Project5

Most-Reported Malicious IPs

AbuseIPDB (confidence 100), pulled 2026-09-28

IP Country Reports Users Origin Type
211.51.132.104KR62611221Residential
103.191.14.243ID63111190Hosting
134.209.120.216US58501177Hosting
199.45.154.191HK5496207Business (Censys)
45.148.10.40NL2053665Hosting
116.135.67.93CN1572617Residential
61.129.41.146CN1260554Residential
174.78.139.165US591167Residential
101.36.108.202HK440143Hosting
35.205.224.26BE13562Hosting

Top Networks

AlienVault OTX (ASN), AbuseIPDB (usage type), pulled 2026-09-28

ASN Network Name Origin Class IP Count
AS209371Private NetworkHosting2
AS48090Pptechnology LimitedHosting1
AS7922ComcastResidential1
AS4766Korea TelecomResidential1
AS398324Censys IncBusiness1
AS4837China United Network CommunicationsResidential1
AS22773Cox CommunicationsResidential1

New KEV Additions

CISA Known Exploited Vulnerabilities, catalog 2026.09.27

CVE Vendor Product Due Date
CVE-2026-88772CitrixNetScaler2026-09-30
CVE-2026-88771CitrixNetScaler2026-09-30
CVE-2026-67279MikroTikRouterOS2026-09-28
CVE-2026-65660MicrosoftSharePoint2026-09-28
CVE-2026-87902WordPressCore2026-09-28
CVE-2026-5430WSO2Multiple Products2026-09-27
CVE-2026-71362AdobeCommerce/Magento2026-09-27
CVE-2026-93952AristaVeloCloud Orchestrator2026-09-25
CVE-2026-94127F5BIG-IP APM2026-09-25
CVE-2026-93616Check PointMultiple Products2026-09-25
CVE-2026-85102Check PointMultiple Products2026-09-25

Top AI Attacker Categories

AI Honeypot Observatory (ai-honeypots.com), pulled 2026-09-28

Category IP Count
MCP-SCANNER159
SCANNER-MASS88
CREDENTIAL-HARVESTER86
RELAY-CUSTOMER41
SCANNER-ENUM35
IDENTITY-PROBER9
RELAY-VERIFIER4

Methodology & Sources

This weekly recap aggregates open-source threat intelligence from public feeds, cross-referenced and captured point-in-time during the week of September 22 to 28, 2026. All figures are aggregate public statistics rather than Focused Hunts detections and trace back to the retained snapshot at output/weekly/data/2026-W39.json. Week-over-week trends reflect successive snapshot comparisons. Partial-coverage totals are reported as a floor with disclosed date ranges; unavailable source classes are omitted rather than estimated. Actor claims are kept separate from confirmed listings.

Feed attribution is inline throughout the body and appendix. Ransomware victim data: ransomware.live ledger, aggregated via scripts/aggregate-week.py. Malicious IP data: AbuseIPDB blacklist (confidence 100, top 100), with GreyNoise Community tags and infrastructure context from AlienVault OTX (ASN) and AbuseIPDB (usage type). Exploited vulnerabilities: CISA Known Exploited Vulnerabilities catalog. Malware/C2 indicators: ThreatFox (abuse.ch), 2-day window. Weaponized-CVE signal: AlienVault OTX pulse search. AI infrastructure attacks: AI Honeypot Observatory 28-day feed, sliced to the ISO week window. All feeds pulled 2026-09-28 unless otherwise noted. GreyNoise and AlienVault OTX operate on community-tier access; Censys is a legitimate security research scanner and excluded from malicious counts. Enrichment includes cross-correlation against ThreatFox and URLhaus for C2/malware-host flagging; none of this week's top IPs matched.