Blog

Branch61G Weekly. The force starts upstream

|

The waterfall gives you the ending first.

The drop gets the photograph. The force was built upstream, while the water still looked ordinary. By the time it crosses the edge, the direction and volume are already set.

That is this week. Qilin ransomware, stolen secrets, web shells, and a compromised fleet are the visible drop. The force started upstream inside the systems trusted to direct everything below them. FMC directs the firewalls. GitLab directs the builds. Magento directs the store. N-central directs the fleet.

Branch61G Weekly. Here is what actually hit over the past seven days.

Cisco FMC, three clusters, Qilin on the manager

The most pressing edge story this week is Cisco Secure Firewall Management Center. Two holes. CVE-2026-20079, CVSS 10.0. Authentication bypass on the FMC web interface. An unauthenticated remote caller can run script files and land root on the operating system. CVE-2026-20316, CVSS 5.3. An unauthenticated login as a low privilege account, then a pair into the rest of the FMC surface. CISA already had 20316 in KEV in late July. This week it added 20079 and gave federal agencies until September 12.

Cisco Talos named three post compromise clusters. UAT-12197 used 20079 to drop JSP web shells and a JAR command executor, then queried internal databases for authentication data and credentials. UAT-11823 used both CVEs, stood up a Netcat reverse shell, ran bash to harvest managed device configs, and left a Cyclops Blink variant, the modular ELF implant tied to Sandworm. UAT-11988 used 20316 first, then lived off built in FMC tooling. Recon across the environment. Tunneling tools to keep the path. Credentials. A target list. Security tools killed. Qilin ransomware on selected systems.

Cisco has hotfixes out now and says a broader hardening release is coming. The first hit is a web request into the box that already manages the firewalls.

An EDR agent behind the firewalls never sees root on FMC. A playbook waiting for a Qilin hash is late, and two of the three clusters never needed that family name. The tell is an FMC that starts holding a web shell or a reverse shell, then talks to internals and destinations it has no history with.

And in a separate incident, the still frame was a Git commit.

GitLab commits API, unauthenticated file read, probes the same day

GitLab shipped a maximum severity path traversal in the repository commits API. CVE-2026-85706, CVSS 10.0. Improper path confinement and missing authentication enforcement. An unauthenticated caller can read arbitrary files off the GitLab server when at least one public project exists. watchTowr saw in the wild probes from 0600 UTC on September 11, hours after disclosure. They say the useful files are logs and GitLab config, which hold credentials and secrets.

Patched builds are 19.3.2, 19.2.6, and 19.1.8 for CE and EE. GitLab.com is already on the patched version. Dedicated customers are already covered. Jake Knott at watchTowr called this the second critical GitLab hole in recent weeks after the GraphQL code injection CVE-2026-19478, which went active almost immediately. Hunt for HTTP POST to /api/v4/projects/{id}/repository/commits/ with a file.path parameter. GitLab also patched CVE-2026-87719 in EE, an insecure deserialization in Duo Chat GraphQL that lets an authenticated user pull Advanced Search config and credentials. That one is a different bug. The week’s pressure is the unauthenticated file read.

A commits POST is what this product is for. Signature packs have nothing for an hours old path traversal with no implant name. The miss is treating that first API call as business as usual while someone can already read the secrets the rest of the pipeline trusts.

Different attack, same week, and this time the postcard was a failed payment email.

Magento StyleSmuggler, a failed payment reminder that runs code

Adobe Commerce and Magento Open Source. CVE-2026-75650, CVSS 10.0. Sansec named it StyleSmuggler and saw zero day exploitation starting September 4. Adobe says it knows merchants are being hit. The chain abuses Magento’s template system through PHP injection while generating a Payment Transaction Failed Reminder email. Template processing and dependency injection become unauthenticated remote code execution.

Affected lines include Commerce 2.4.9-2026-aug and earlier on the 2.4 train, matching B2B and Magento Open Source cuts. The hotfix is VULN-39341. Adobe also says rotate encryption keys after you apply it. CISA put the CVE in KEV on September 8 with a September 11 federal clock.

Sansec saw the hole used to drop a Rust Linux backdoor that connects out and waits for instructions, and separately a PHP dropper that writes a web shell. Disrex said a Magento server they manage was compromised 50 minutes after the first confirmed StyleSmuggler report late on September 4 UTC. Previdian later logged 12 unsuccessful honeypot attempts from two addresses in China and Romania.

A failed payment reminder is a Magento job. An EDR waiting for a named skimmer family is watching the checkout while the first code run is already in the template path. The tell is a commerce box that starts holding a web shell or a Rust callback to a host it has no history with.

Three names in and the fourth was the RMM the MSP already trusts.

N-able N-central, unauthenticated RCE, fourth hotfix

N-able N-central. CVE-2026-86218, CVSS 10.0. Static code injection. Unauthenticated remote code execution on the RMM server. Hotfix 4 is build 2026.3.1.14, shipped September 6 UTC. Every on premises build below that number needs it, including boxes that took Hotfix 3 a few hours earlier. Hosted NCOD is already patched. Agents do not need an upgrade for this CVE. CISA put it in KEV and gave federal agencies until September 11.

N-able’s own channels disagree on wild use. The incident notice says the flaw has been observed exploited in the wild. The release notes say there is no confirmation in production. Huntress started an investigation on September 4 after a customer’s fully patched N-central production box was compromised. Appliance logs had already rotated. Huntress cannot say whether that intrusion used 86218 or the Hotfix 3 pair, CVE-2026-86206 and CVE-2026-86207, which Rapid7’s Stephen Fewer said can be chained to create a System Administrator account with no login. watchTowr reproduced 86218 and said changes on N-central can propagate across every connected system.

This is the fourth hotfix on the 2026.3 line since August 2. The August path already showed why this product matters. Attackers used an earlier auth bypass, then Take Control, then Cloudflare tunnels on the endpoints so the path survived after N-central was cut.

A request into the console is what this product is for. A playbook waiting for a ransomware family name is watching the endpoints while the manager is already owned. The tell is a new admin on N-central, then that manager reaching hosts and destinations it has no history with.

What this week means

Cisco FMC, GitLab, Magento, N-central. Four separate incidents. The same shape underneath. Each attacker reached a system trusted to direct what happens next. The firewall manager holds the network. The source platform feeds the build. The commerce engine runs the store. The RMM controls the fleet. Once that upstream layer bends, malicious movement inherits the shape of legitimate administration. Credentials leave. A backdoor waits. The fleet starts answering a manager that is no longer yours.

Detections stay broken for attacks that do not match a named playbook. LogLM is a foundation model built as an encoder on network metadata. It learns normal deeply enough that a genuine deviation is legible on its own, with no prewritten signature for that CVE or family required first.

Walk those four back through the wire. On Cisco FMC, the first web request can be thin in netflow. A completed campaign still needs a web shell or reverse shell, tunnels off the manager, or Qilin reaching the endpoints that box already owns. That traffic sits outside a healthy FMC baseline. On GitLab, a commits POST with file.path can look like git. Secrets leaving toward a new destination, or CI jobs talking somewhere that project has no history with, sit outside a healthy GitLab baseline. On Magento, the failed payment email can look like store mail. The Rust callback and the web shell are C2 on a commerce host that has no history with those destinations. On N-central, the first unauthenticated hit can look like console admin. A manager that starts reaching agents or standing up new outbound paths is C2 and lateral across a fleet that already trusted it.

That is the generalizability. New name on the board, same grammar underneath it.

AI SOCs are only as good as the detections that feed them. When a zero day or a novel sequence slips past those detections, the rest of the stack has nothing left to reason over.

The drop gets the photograph. Branch61G watches where the force gets its direction.

See the threats your tools can’t.

DeepTempo’s LogLM works with your existing stack to uncover evolving threats that traditional systems overlook — without adding complexity or replacing what already works.