🗂️ CASE FILE — October 9, 2026
Lead story: Between September 22 and 27, attackers who had compromised the third-party operators of three country-code top-level domains — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — rewrote authoritative DNS records and used that DNS control to pass certificate-authority domain validation, obtaining at least 12 unauthorized HTTPS certificates for Google and YouTube domains (including google.com.gh, google.sl, and google.as). Let's Encrypt issued 11 of the certificates and ZeroSSL one. Google, which disclosed the campaign on October 6, says its own systems were not breached and that it has no reason to believe the certificate authorities acted improperly. Chrome blocked the rogue certificates via CRLSets; Google worked with the issuing CAs to revoke them — CT logs showed all 12 revoked by October 7. Certificate Transparency data also revealed several other leading global brands and widely used online services hit by the same campaign; Google blocked those certificates and notified the organizations it could reach. Whether any certificate was used to intercept traffic is unconfirmed.
Also covered: Citrix issues a critical bulletin for CVE-2026-107406 (CVSS 9.5 memory overflow → RCE/DoS) in NetScaler ADC and Gateway configured as SAML IdP/SP (October 8) — no known exploitation; the third NetScaler bulletin in under two weeks · DOJ and FBI seize seven domains behind Flax Typhoon's MicroScan vulnerability scanner and FishHub spearphishing platform, operated by PRC contractor Integrity Technology Group (October 8) · FBI/Secret Service joint advisory: the FortiBleed credential-theft campaign is still active — 86,644+ compromised Fortinet devices across 194 countries; attackers are deleting admin accounts and locking owners out; access is feeding INC/Lynx and Payload ransomware affiliates · MonsterCloud owner Zohar Pinhasi arraigned October 7 in Brooklyn on wire fraud charges for secretly paying ransoms while selling "proprietary decryption" — $19M+ billed, $8M+ paid out · Exposure watch: Shodan currently shows ~655,000 exposed NetScaler instances and ~372,000 exposed FortiGate instances across 100 countries.
Sources: 7 linked at the end of this brief.
Today's top stories
The biggest infrastructure story of the week isn't a breach of one company — it's the compromise of three countries' domain namespaces to mint trusted certificates for Google. DNS is the trust root everything else stands on, and for six days in late September, attackers held the keys to three of them. Meanwhile Citrix is patching NetScaler again — the third emergency bulletin in two weeks — the FBI took Flax Typhoon's tooling offline for the second time in as many years, FortiBleed keeps bleeding into lockouts and ransomware initial access, and a ransomware-recovery CEO learned that billing victims $150,000 for an $8,200 secret ransom payment eventually gets you indicted.
Attackers hijack three country-code registries to forge Google HTTPS certificates
On October 6, Google disclosed that attackers had hijacked the administrators of three country-code top-level domain registries — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — and used the compromised DNS control to obtain unauthorized HTTPS certificates for several Google and YouTube domains, per BleepingComputer. During the hijacks, the attackers modified authoritative DNS records; certificate authorities then issued certificates after the attackers passed standard domain-control validation (publishing a CA-supplied random value in DNS). Google stressed that its own systems were not breached, and that it has no reason to believe the issuing CAs acted improperly — the validation worked as designed; the registry underneath it did not.
Google did not name the affected domains, but Certificate Transparency logs — the public ledgers of issued certificates — show at least 12 certificates issued between September 22 and September 27 for Google and YouTube names under the three ccTLDs, including google.com.gh, google.sl, and google.as. Let's Encrypt issued 11 and ZeroSSL one; per CT search tools, all 12 were revoked by October 7. Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets (the browser's emergency certificate-blocking mechanism) and coordinated with each issuing CA on revocation, extending protection to other browsers and applications. CT log analysis then revealed additional organizations — several leading global brands and widely used online services — believed impacted by the same attacks; Google blocked those certificates too and alerted the organizations it could reach. What the certificates were for — whether any was used to impersonate a site or intercept traffic — remains unreported.
🔍 Investigation notes — defender takeaway (click to expand)
This is a trust-anchor compromise: every CA on the planet did its job correctly, and forged Google certificates were still issued — because the compromise was one layer down, at the registry. The controls that matter here are not the CA's but yours: monitor Certificate Transparency logs for your own domains (a new unexpected issuance is your canary), set CAA records to pin which CAs may issue for you, and treat any registry or registrar relationship as a supply-chain dependency with the same rigor you'd apply to a vendor with VPN access. For users, the good news is structural: CT logs made the forgeries visible and CRLSets made them blockable within days — the transparency infrastructure did exactly what it was built for.
Advisory watch: CVE-2026-107406 — CVSS 9.5 RCE in NetScaler SAML deployments
Citrix on October 8 published a critical security bulletin for CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that may lead to remote code execution or denial of service under specific configuration conditions, per The Hacker News and SecurityWeek. The flaw carries a CVSS v4.0 base score of 9.5. Exploitation hinges on the appliance being configured as a SAML identity provider (IdP) or service provider (SP) — check for add authentication samlAction (SP) or add authentication samlIdPProfile (IdP) in the configuration. Fixed releases are 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (FIPS/NDcPP); the bulletin lists no workaround. Citrix says it is not aware of any unmitigated exploits as of publication. The flaw was reported by Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov. Secure Private Access Hybrid deployments that use NetScaler need the same upgrade.
Context matters: this is the third NetScaler bulletin in under two weeks. It follows the exploited CVE-2026-88771 and CVE-2026-88772 zero-days (RCE, hitting government, financial services, education, legal, and professional services) and CVE-2026-88779, the SAML DoS zero-day whose CISA KEV deadline passed October 7. Shodan currently shows ~655,000 exposed NetScaler instances across 100 countries — the same population these bulletins keep racing.
🔍 Investigation notes — defender takeaway (click to expand)
Patch cadence is now the vulnerability. Three emergency upgrades in under two weeks for SAML deployments — teams that "just patched" on the 27th of September are exposed again, and the builds in between (14.1-73.37 through 73.41, 13.1-64.23 through 64.28) are where this one stops. If your NetScaler fleet's upgrade cycle is measured in weeks, NetScaler is now outrunning it: move emergency appliances to a days-scale patch lane and verify the SAML scope flags in your config inventory before the next bulletin. And watch CISA KEV: the last NetScaler flaw in this family got a 21-day federal clock; if 107406 lands there, you want to already be on 73.46/64.29.
FBI and DOJ seize Flax Typhoon's MicroScan and FishHub tooling
The Justice Department and FBI announced court-authorized seizures of seven domains on October 8 to deny access to MicroScan and FishHub, two intrusion tools allegedly operated by Integrity Technology Group — a China-based company with PRC government contracts — as part of the hacking activity tracked as Flax Typhoon, per BleepingComputer and the DOJ press release. Officials called it their second disruption of Integrity Tech's operations in as many years. MicroScan is a Python-based vulnerability scanner with more than 1,300 penetration-testing scripts, powered by a Mirai-variant IoT botnet for internet-scale reconnaissance; FishHub, active as of March 2026, is a spearphishing platform whose malware delivered remote access or file-search-and-exfiltration. Five seized domains fed FishHub's malware delivery (98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, linkedinns.net), 98aiblog.com anchored SoftEther VPN persistence on victim systems, and c0cc.cc hosted MicroScan.
The FBI affidavit ties the tooling to successful intrusions: scanning led to breaches at two Taiwanese universities (scanned August 2022 and March 2023), and FishHub's server held files and data from more than 20 organizations, including six Taiwanese universities — roughly 20 Taiwanese universities are confirmed victims. Other scanned targets include a South Carolina power company, airports in Japan and Poland, and Taiwanese natural gas and electricity companies. The operation was accompanied by a joint advisory from the FBI, CISA, NSA, and international partners covering sectors from government and critical manufacturing to healthcare, education, and law enforcement across the US, Southeast Asia, Africa, and North America — the same front-company contractor model (an ostensibly private security firm working for state intelligence) seen in this week's Hafnium bounty case. The advisory names eight frequently targeted CVEs — including ProFTPD CVE-2015-3306, Apache Struts CVE-2016-3081, Pulse Secure CVE-2019-11510, and GitLab CVE-2021-22205 — and notes the actors used the EBurst tool for password spraying against Microsoft Exchange plus a custom web app for browsing stolen emails.
🔍 Investigation notes — defender takeaway (click to expand)
Two signals in one seizure. First, the vulnerability list is a museum: a 2015 ProFTPD bug, a 2016 Struts bug, a 2019 Pulse Secure bug — state-sponsored actors are still harvesting internet-facing services that missed patches years ago, which means your perimeter patch backlog is their reconnaissance list. Second, the tooling is dual-use: SoftEther VPN for persistence, Exchange password spraying, stolen-mail browsing — none of it is exotic malware, so signature-based detection won't see this campaign coming. Hunt for the behaviors instead: unexpected SoftEther installations, Exchange spray patterns, and outbound mail-store access that doesn't match any mailbox owner.
FortiBleed still active: FBI warns attackers are locking admins out of their own firewalls
The FBI and the US Secret Service published a joint cybersecurity advisory on October 6 confirming the FortiBleed credential-theft campaign is still actively targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, per BleepingComputer. The advisory cites SOCRadar research verifying more than 86,644 compromised devices across 194 countries. The new escalation: attackers are not just harvesting credentials — in some cases they delete or change the passwords of legitimate administrator accounts, locking organizations out of their own devices while retaining control and pivoting internally. Shodan currently shows ~372,000 exposed FortiGate instances across 100 countries.
The campaign runs on bad hygiene at industrial scale — no new CVE: reused credentials from earlier Fortinet leak dumps and infostealer logs, credential stuffing and password spraying, then password-hash extraction from compromised devices cracked offline on rented GPU infrastructure running Hashcat and Hashtopolis. The operators run it like a business — screening out honeypots, ranking targets by revenue — and then sell working VPN configurations and target lists to downstream actors. The FBI says the FortiBleed chain has been observed as initial entry for ransomware affiliates, currently INC/Lynx and Payload. The agencies urge: restrict internet-facing management access, terminate active admin and VPN sessions, reset passwords, and enable phishing-resistant MFA.
🔍 Investigation notes — defender takeaway (click to expand)
A password reset will not evict this. If FortiBleed actors added admin accounts, harvested API keys, or took the lockout route on your device, rotating the one password you knew about leaves their footholds intact — diff the running config against your last known-good backup (admin users, VPN users, local-in policies, trusted hosts, API keys) before you touch anything. The lockout scenario is the real lesson: if your only path back into the firewall is through the firewall, you've already lost — keep out-of-band administrative recovery for every edge device. And note the economics: this is an initial-access-broker pipeline feeding ransomware affiliates, so a FortiBleed finding in your logs is a pre-ransomware indicator. Treat it like one.
MonsterCloud owner charged: the ransomware "recovery" that secretly paid the ransom
Zohar Pinhasi, 50 — also known as "Zack Silver" and "Zack Green" — owner of Florida ransomware-remediation company MonsterCloud LLC, was arraigned October 7 in federal court in Brooklyn on two counts of wire fraud and one count of wire fraud conspiracy, per BleepingComputer. A federal grand jury in the Eastern District of New York indicted him September 23; he pleaded not guilty and was released on a $2 million bond. Prosecutors allege that from June 2018 to June 2023, MonsterCloud marketed itself as an alternative to paying ransoms — its website warned victims against paying and claimed "proprietary tools" and "advanced decryption techniques" — while in reality it contacted the very ransomware operators who had attacked its clients, paid them for decryption keys, and billed clients a heavy markup. The indictment acknowledges some contracts disclosed possible attacker contact, but says those terms limited it to a last resort — while paying was allegedly the first step.
The numbers: prosecutors say MonsterCloud collected more than $19 million from hundreds of companies in the US and Canada while facilitating more than $8 million in ransom payments. One August 2023 case cited: an $8,200 ransom paid, a ~$150,000 bill to the client; another: ~$236,000 to attackers, ~$380,000 billed. Each count carries up to 20 years. "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said US Attorney Joseph Nocella Jr. MonsterCloud was previously spotlighted in a 2019 ProPublica exposé on recovery firms secretly paying ransoms — the same pattern, now an indictment.
🔍 Investigation notes — defender takeaway (click to expand)
Vet your incident-response vendors the way you'd vet an acquisition target. The red flags were public for seven years — a 2019 ProPublica investigation described this exact scheme — and hundreds of companies still signed. Before you engage a recovery firm: demand written disclosure of when and how they pay ransoms (some contracts quietly reserve the right), ask for technical specifics behind "proprietary decryption" claims, and remember the legal exposure — your ransom money may fund sanctioned entities, and your IR vendor's markup doesn't change that. The cheapest incident response is the one whose methods you'd be comfortable explaining to a regulator.
Incident timeline — September 22 to October 9, 2026
| Date | Event | Status |
|---|---|---|
| Sep 22–27 | Attackers obtain ≥12 unauthorized HTTPS certificates for Google/YouTube domains (Let's Encrypt 11, ZeroSSL 1) under hijacked .gh/.sl/.as namespaces | Confirmed (Google, CT logs) |
| Oct 6 | Google discloses the ccTLD registry hijacks; Chrome blocks rogue certificates via CRLSets | Confirmed (Google) |
| Oct 6 | FBI + US Secret Service joint advisory: FortiBleed campaign still active; attackers deleting admin accounts and locking owners out of FortiGate devices | Confirmed (federal advisory) |
| Oct 7 | CT logs show all 12 rogue certificates revoked; Google says other global brands also hit, blocks their certs, notifies affected orgs | Confirmed (CT logs, Google) |
| Oct 7 | MonsterCloud owner Zohar Pinhasi arraigned in Brooklyn: two wire-fraud counts + conspiracy for secretly paying ransoms | Confirmed (DOJ) |
| Oct 8 | DOJ/FBI seize 7 domains behind Flax Typhoon's MicroScan & FishHub tools; joint advisory with CISA, NSA and international partners | Confirmed (DOJ) |
| Oct 8 | Citrix critical bulletin CVE-2026-107406 (CVSS 9.5): RCE/DoS in NetScaler ADC/Gateway configured as SAML IdP/SP; no known exploitation; no workaround | Advisory (Citrix) |
| Oct 9 | Exposure watch refresh: Shodan shows ~655,000 NetScaler and ~372,000 FortiGate instances exposed across 100 countries | Confirmed (Shodan) |
Source links
- BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries
- The Hacker News: Citrix patches critical NetScaler flaw (CVE-2026-107406)
- SecurityWeek: Citrix urges immediate patching of critical NetScaler vulnerability
- BleepingComputer: FBI disrupts Chinese hacking tools used to breach critical infrastructure
- US DOJ: Justice Department and FBI seize vulnerability scanning and spear phishing tools
- BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
- BleepingComputer: Ransomware recovery CEO charged over secret ransom payments
