TL;DR
Country-code domain registries (.gh, .sl, .as) were compromised to obtain unauthorized HTTPS certificates for Google domains; SonicWall patched a CVSS 10.0 pre-auth SSRF flaw in SMA1000 appliances; PoeLLM malware has infected 3,400+ exposed AI servers for cryptomining. Eight malicious npm packages with numerous+ downloads delivered RATs and stealers.
Executive Summary
- Attackers compromised country-code TLD registries to obtain unauthorized HTTPS certificates for Google domains, gaining potential certificate interception capability.
- SonicWall released patches for a CVSS 10.0 pre-authentication SSRF vulnerability in SMA1000 remote access appliances that requires no login to exploit.
- PoeLLM malware campaign has infected over 3,400 exposed AI and LLM infrastructure servers to deploy cryptominers and expand botnet reach.
- A coordinated supply-chain attack delivered eight malicious npm packages downloaded 40,767 times, distributing information stealers and remote access trojans.
- Microsoft will block .msix and .msixbundle attachments in Outlook beginning November to counter attachment-based attack vectors.
Top Threats Today
1. Country-Code TLD Registries Compromised to Hijack Google Certificates
Severity: HIGH Affected: technology
Attackers compromised the registries for three country-code top-level domains (.gh for Ghana, .sl for Sierra Leone, and .as for American Samoa) and obtained unauthorized HTTPS certificates for multiple Google domains [1][2]. Google confirmed the certificate issuance but stated its own systems were not breached; instead, the attackers leveraged third-party registry operators and modified authoritative DNS records to enable certificate acquisition [2]. The scope of Google domains affected and potential for downstream domain hijacking or certificate interception attacks remains unclear from available disclosures.
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Review and audit DNS records and Certificate Transparency logs for your organization's domains, especially those in .gh, .sl, and .as zones.
- Implement DNS query logging and alerting to detect unauthorized DNS modifications or zone transfers.
- Consider implementing DNSSEC validation and pinning HTTPS certificates using HPKP or similar mechanisms where feasible.
2. SonicWall SMA1000 SSRF Flaw (CVSS 10.0) Allows Pre-Auth RCE
Severity: HIGH Affected: technology
SonicWall has released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, with the most critical flaw rated CVSS 10.0 for pre-authentication server-side request forgery (SSRF) [1]. The vulnerability allows an attacker without login credentials to send requests through the appliance and reach internal functions, creating a direct path to remote code execution or lateral movement into protected networks [1].
Sources:[1] The Hacker News
Recommended Action
- Prioritize patching all SMA1000 appliances to the latest hotfix version immediately; verify patch deployment across all remote access gateways.
- Segment SMA1000 appliances on dedicated VLAN with strict inbound access controls; restrict management interfaces to trusted IP ranges only.
- Monitor SMA1000 logs for unexpected request patterns targeting internal functions and alert on SSRF-like behavior.
3. PoeLLM Malware Targets Exposed AI Infrastructure for Cryptomining Botnet Expansion
Severity: HIGH Affected: technology
A new malware family designated PoeLLM has been observed infecting more than 3,400 exposed AI and large language model (LLM) infrastructure servers to deploy cryptocurrency miners and expand the scale of an active botnet [1][2]. The campaign specifically targets exposed artificial intelligence services and LLM deployments, leveraging publicly accessible interfaces to gain initial footholds [1]. Two CVE identifiers have been identified in connection with PoeLLM exploitation: CVE-2026-42271 and CVE-2026-48710 [2].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Inventory all AI and LLM servers and services; audit network exposure and disable public internet access for any services that do not require it.
- Apply patches addressing CVE-2026-42271 and CVE-2026-48710 to all affected AI infrastructure immediately.
- Monitor CPU usage, network traffic, and process execution on AI servers for signs of unauthorized cryptominer activity; check for unexpected child processes launched by service accounts.
4. Malicious npm Packages Distribute Overlord RAT and Stealer via Supply Chain
Severity: HIGH Affected: technology
A long-running npm supply-chain malware campaign has been uncovered distributing information stealers and remote access trojans (RAT) through eight malicious packages that accumulated 40,767 downloads [1]. The campaign, codenamed MALFEX by CloudSEK and Checkmarx, demonstrates active adversary exploitation of the JavaScript/Node.js ecosystem to compromise developer ⚠ environments and downstream applications.
Sources:[1] The Hacker News
Recommended Action
- Audit npm dependencies in all projects; use npm audit and verify integrity of installed packages against checksums from trusted sources.
- Block or immediately remove any installations of the eight identified malicious packages; regenerate credentials for any accounts that may have been active on compromised developer machines.
- Implement npm package allowlisting and require code review for third-party dependency updates; consider using private package registries with integrity checks.
5. Microsoft Outlook to Block MSIX Attachments Starting November
Severity: MEDIUM Affected: technology
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked file types in Outlook Web and the new Outlook Windows client beginning ⚠ in November, citing active abuse of these package formats in phishing and malware delivery attacks [1]. This defensive measure addresses a known attack vector in which MSIX packages can execute arbitrary code upon installation, often evading traditional email security filters.
Sources:[1] BleepingComputer
Recommended Action
- Notify users of the upcoming Outlook MSIX attachment block; establish alternative delivery methods for legitimate MSIX packages if required for business purposes.
- Test Outlook client behavior in staging environments ahead of November deployment to identify any legitimate MSIX workflows that may be disrupted.
- Monitor mail gateway logs for MSIX attachment attempts to identify potential attack patterns in your organization.
Today’s Action Checklist
- ☐ URGENT: Patch SonicWall SMA1000 appliances to latest hotfix; verify all remote access gateways are updated.
- ☐ URGENT: Audit and inventory exposed AI and LLM servers; apply patches for CVE-2026-42271 and CVE-2026-48710.
- ☐ Review npm audit results; remove or quarantine the eight malicious MALFEX packages from your supply chain and regenerate developer credentials.
- ☐ Review DNS records and Certificate Transparency logs for unauthorized entries in .gh, .sl, .as domains and your organization’s domain registration.
- ☐ Test Outlook client configuration for the upcoming November MSIX attachment block; plan user communication and alternative workflows if needed.