---
title: ThreatsDay Tracks 800+ Patched Flaws, Insider SIM Swaps and Insomnia RAT - Capstone Technologies Group
description: Oracle patched 800+ flaws, ransomware crews exploit vCenter CVE-2026-59310, an AT&T insider sold SIM swaps, and OfferLoader delivered Insomnia RAT to endpoints.
canonical_url: https://captechgroup.com/threat-intelligence-center/threatsday-tracks-800-patched-flaws-insider-sim-sw-e26a77
language: en-GB
date: 2026-09-18T12:38:39Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center/threatsday-tracks-800-patched-flaws-insider-sim-sw-e26a77. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 6327
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center/threatsday-tracks-800-patched-flaws-insider-sim-sw-e26a77. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


Oracle's September 2026 Critical Patch Update fixed more than 800 flaws in one release, none of them flagged as actively exploited. That single number sets the tone for the week: the volume of patching work keeps climbing while the older, already-patched bugs are the ones getting exploited. Details in this article come from analysis published by [The Hacker News](https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html "Source: The Hacker News").

CISA confirmed that ransomware crews are now exploiting **[CVE-2026-59310](https://nvd.nist.gov/vuln/detail/CVE-2026-59310 "NVD: CVE-2026-59310")**, a critical directory traversal flaw in the VMware vCenter Syslog server that allows unauthenticated attackers to run arbitrary code. It was patched in July. A China-nexus APT was already using it in August 2026, according to German [incident response](https://captechgroup.com/services/cybersecurity-services "Cybersecurity Services | Protect Your Business with Capstone Technologies") firm QUIRSO, which means your vCenter deployment has been exposed to two very different classes of attacker on the same bug.

On the fraud side, a former AT&amp;T store employee in Oregon was sentenced to 16 months in prison for selling SIM swaps, taking $1,000 to $2,000 per swap while three victims faced intended losses of nearly $600,000. Insider access at a carrier undercuts SMS-based verification in a way no amount of endpoint hardening fixes.

The quieter story is a pay-per-install marketplace run by **CL-CRI-1171**, tracked by Palo Alto Networks Unit 42. It has operated for at least two years, distributing malware through gaming YouTube channels and an SEO-poisoning funnel aimed at business users. Its loader, **OfferLoader**, delivered **Docro Hijacker**, **ARKTunnel**, and the newly named **Insomnia RAT** between July 2025 and April 2026, then shifted to **GCleaner** and **Socks5Systemz**.

Each of these lands on a different team in your organization. The overlap is what makes the week worth reading as a whole.

## Triaging 800+ Patched Flaws Including CVE-2026-59310

The week's patch volume splits cleanly along one line: a very large set of flaws with no observed exploitation, and a very small set with confirmed attacker activity. Oracle's quarterly release sits entirely in the first group. The vCenter directory traversal issue and two Cisco Secure Firewall Management Center flaws, **CVE-2026-20079** and **CVE-2026-20316**, sit in the second.

Cisco has described the FMC activity as three separate campaigns tied to those two bugs. Two CVEs with named campaigns behind them carry more operational weight than several hundred with none, because exploitation evidence removes the guesswork about whether anyone has written working code.

Worth being precise about what the source material actually establishes for the vCenter flaw. It is a traversal issue in the Syslog server component, reachable without credentials, resulting in arbitrary code execution. That maps to MITRE ATT&amp;CK **T1190 (Exploit Public-Facing Application)** with no prior access requirement, which is why ransomware operators picked it up. A management plane compromise at that layer means an attacker reaches the hypervisor layer rather than a single guest, so one exploited host can put every virtual machine it manages within reach.

What the reporting does not provide is equally relevant to triage. There is no CVSS breakdown, no affected build list, no published indicators, and no statement on whether the ransomware activity and the earlier state-linked exploitation share tooling or infrastructure. Treat the affected-version question as something to answer from the vendor advisory for your specific appliance generation, not from secondary reporting.

The Oracle set has the opposite problem. Nothing in it is flagged as exploited, and the published summary does not apportion the count across product families or give a severity distribution. Risk ranking for a release that size comes from your own asset inventory, specifically which of those components are internet-reachable and which sit behind authentication on internal segments.

Fortra's Tyler Reguly pointed to **CISA BOD 26-04** as a usable filter, built around four questions: is the affected system publicly exposed, is the flaw on the Known Exploited Vulnerabilities list, can exploitation be automated, and does it grant complete control.

> "I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference," Reguly said, adding that once you know what risk looks like for your organization, you can prioritize patches more appropriately.

Those four questions separate the two groups almost automatically. An unauthenticated traversal bug in an internet-facing management service answers yes to all four. A database flaw requiring authenticated local access on an internal host answers yes to none.

KEV membership and EPSS scoring do different jobs and should not be substituted for each other. KEV records observed exploitation, so it is backward-looking evidence. EPSS estimates the probability that a given flaw will be exploited in the near term, which gives a way to rank the large set of bugs that have no exploitation history yet. Flaws absent from KEV but exposed, automatable, and capable of granting full control belong in the same queue as the confirmed ones.

The practical consequence is that patch count is a poor planning input. Exposure and exploitability of individual components determine how much of that 800-plus set actually needs to move first.

## Insider-Enabled SIM Swaps and the Telecom Trust Gap

A former employee of an **AT&amp;T retail store in Oregon** used his authorized access to carrier systems to perform SIM swaps for criminals who then took over customers' bank accounts. He worked at the store from May 2018 to November 2019, pleaded guilty in March, and was ordered to pay **$99,528 in restitution**.

The mechanic behind a SIM swap is simple. A retail or care employee with provisioning rights reassigns a subscriber's phone number to a SIM card the criminal controls, which is a routine service action performed for legitimate customers every day. In ATT&amp;CK terms this sits at `T1451` (SIM card swap) executed through `T1078` (valid accounts), meaning there is no malware, no phishing page, and no unauthorized login to detect.

Once the number moves, every message and call intended for the victim arrives on the attacker's handset. That turns SMS one-time passcodes into attacker-readable text (`T1111`, multi-factor authentication interception) and unlocks the password reset chain that most consumer and business accounts still depend on.

- **Banking and payment apps:** reset the password using an SMS code, then approve transfers with the same channel.
- **Email recovery:** take the mailbox first, then use it to reset everything that mails a reset link.
- **Cryptocurrency exchanges:** reset access and withdraw, with no reversal mechanism afterward.
- **Corporate identity:** self-service password reset and help desk recovery flows that fall back to a text message treat the phone number as proof of identity.

That last item is where a consumer fraud case becomes a business problem. If your single sign-on portal offers SMS as a recovery factor, or your help desk verifies a caller by reading back a code sent to a mobile number, then control of that number is functionally control of the account. The phone company, not your identity provider, is deciding who owns the second factor.

SMS-based MFA fails here because it authenticates possession of a number rather than possession of a device or a key. Number ownership is a record in a carrier database that frontline staff can edit. App-based and hardware authenticators bind the factor to a specific device or secure element, so reassigning the number does nothing.

Target selection in the Oregon case ran in one direction. Criminals brought the phone numbers, the insider executed the reassignment, and the payment per swap was a small flat fee set well below the intended losses those swaps produced. Three victims accounted for the bulk of the intended loss total noted earlier, which tells you the targets were picked for account balances before any technical work began.

The recruitment pattern follows the same economics. Provisioning authority sits with low-wage staff at thousands of independently operated retail locations, and the fee per swap is immediate cash against a fraud that pays out elsewhere. Insider involvement also strips away the friction attackers would otherwise face, since there is no social engineering script to fumble and no supervisor approval to bypass.

For the carrier and for every downstream institution, the fraud looked like a legitimate service change made by an authenticated employee during business hours. The court record shows the loss was realized in customer bank accounts, while the action that caused it was recorded as normal subscriber maintenance.

## Insomnia RAT, Socks5Systemz and the Supporting Malware Stack

CL-CRI-1171 ran a pay-per-install marketplace for at least two years before Palo Alto Networks Unit 42 documented it, renting distribution to other criminal groups rather than operating its own malware. The "CL" prefix marks it as an activity cluster, which means Unit 42 has grouped the infrastructure and tradecraft together without tying it to a named, established crew. That distinction matters for anyone reading threat reports: this is a service provider, and its customers change.

Distribution ran on two funnels. The first used YouTube channels posting genuine gaming content, with operators replying to viewers to push download links for "tools" that carried malware. The second was an SEO poisoning funnel aimed at a professional audience, surfacing trojanized versions of legitimate software. Unit 42 reports that second path put malware on corporate endpoints, including critical infrastructure operators and government entities.

Both funnels terminated in the same place. A custom loader called **OfferLoader** handled staging and payload selection, which is the piece that makes a PPI model work. One loader, many tenants, and the operator decides which customer's payload lands on which infected host.

Between July 2025 and April 2026, OfferLoader delivered three payloads:

- **Docro Hijacker**, a Chrome backdoor capable of bypassing modern browser integrity protections. Browser-resident access reaches saved credentials and authenticated sessions, so an attacker inherits whatever your staff are already logged into.
- **ARKTunnel**, a WebSocket tunneling RAT. Tunneling over WebSocket (ATT&amp;CK T1572, Protocol Tunneling) rides the same ports and handshake shapes as ordinary web traffic, which keeps command-and-control inside flows most egress policies permit.
- **Insomnia RAT**, a new variant of a previously unnamed cross-platform backdoor that runs on both Windows and macOS. Mac fleets in design, engineering, and executive roles fall inside the targeting set, not outside it.

After April 2026, the same infrastructure began delivering **GCleaner** and **Socks5Systemz**. Socks5Systemz is the monetization tail of this economy. It converts an infected machine into a proxy node (T1090), then rents that node's IP address out to other criminals who want traffic that originates from a residential or corporate network. Fraud, credential stuffing, and scraping then leave your address space, which is how organizations end up on blocklists and fielding abuse complaints for activity they never generated.

The delivery mechanics depend on user execution (T1204.002) rather than an exploit, with SEO poisoning and social interaction doing the persuasion work. That is why the professional funnel is the more consequential of the two. A developer or sysadmin searching for a utility has local admin more often than a gamer does, and trojanized installers arrive with the privileges needed to establish the initial foothold.

Read the sequence as a supply chain. Access is acquired cheaply at volume, sorted by value, and then sold onward. The initial infection may look like adware or a browser nuisance for weeks, while the same host sits in a broker's inventory waiting for a buyer with a ransomware payload or an espionage objective. The technically unremarkable first-stage infection is what sets the price for everything that follows.

## Operational and Financial Exposure for Organisations

CISA's BOD 26-04 sets a three-day turnaround for the highest-risk fixes, and Fortra's Tyler Reguly points out the obvious problem with that: three days is very tight when you also need to test patches before they touch production. Your change windows are finite. The advisory volume is not.

That mismatch is the real cost driver. When a quarterly release drops hundreds of fixes on your team at once, the work that gets deferred is rarely chosen deliberately, and the flaws sitting in your deferred pile are the ones attackers reach first if they happen to be internet-facing. Reguly's framing is worth borrowing for budget conversations: exposure, known exploitation, automatability, and whether the bug hands over complete control are what separate a genuine emergency from a queue item.

The LocalAI campaign shows what happens when an exposed service never enters the queue at all. Oasis Security found that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable, with callback logs confirming command execution at root privilege on 23 servers. From there the operator collected 127 AWS credential records and stole AWS ECS task credentials, which gives an attacker paid-for compute and downstream access under your own account.

The data pulled from one compromised workstation is the part your legal team will care about:

- Personal information and national ID card scans
- Banking application screenshots
- GPS coordinates tied to an individual

That is notifiable personal data in most jurisdictions you operate in, and the clock on notification starts when you become aware, not when you finish the investigation.

Ransomware raises the forensic cost separately. Settra, which has claimed 70 victims since June 2026 across technology, professional services, manufacturing, and retail, clears Windows event logs and disables Windows recovery options before leaving its ransom note. If your logs are gone, you cannot easily prove what was accessed, and an investigation that cannot scope the data exposure usually ends with broader notification and a slower insurance claim than one that can.

Proxy and tunneling abuse carries a quieter bill. The tunneling capability in the CL-CRI-1171 payload set and the Go-based SOCKS5 proxy used against Brazilian financial targets both turn a compromised host into criminal transit. When your address space is the origin of that traffic, your mail gets blocked, your customer-facing IPs land on reputation lists, and partners start asking questions you cannot answer quickly.

On the fraud side, SIM swap account takeover matters most for the handful of people at your firm who can authorise payments or approve password resets. Carriers, meanwhile, carry their own exposure when provisioning rights are abused from inside a retail store, including restitution and regulatory attention on access controls. Financial institutions have parallel reporting duties: FinCEN analysed 33,904 Bank Secrecy Act reports filed between September 8, 2023 and December 31, 2025, covering roughly $12.7 billion in activity tied to suspected digital asset investment scams. Physical cash fraud is still measurable too, with more than 700 ATM jackpotting incidents in 2025 and more than $20 million in losses.

One regulatory point is new this quarter. Spain's data protection agency, the AEPD, received its first breach report in which a third party used an AI agent to chain the attack phases together. Your notification obligations do not change because the intruder was automated, and regulators are now logging that detail.

## Patching, Detection and Account-Recovery Hardening Steps

Patch the vCenter Syslog directory traversal flaw first, then work outward to the Cisco Secure FMC appliances. On those FMC devices, check for generic System V init persistence and unexpected long-running processes, because the 2026 implant runs on x86-64 Linux and includes selective packet capture and content surveillance among its worker modules. An edge appliance quietly capturing traffic gives an intruder visibility into internal sessions that never touch your endpoint agents.

Next, take internet-facing AI infrastructure offline or behind authentication. Unauthenticated LocalAI instances were exploitable at scale, and command execution came through MCP STDIO configuration with root privileges. If you run LocalAI anywhere, assume credential material on that host is compromised and rotate it, including AWS access keys and ECS task credentials.

Then move your privileged and executive accounts off SMS-delivered MFA codes. Number-reassignment fraud does not require any technical flaw in your systems, which is why an app-based authenticator or a FIDO2 hardware key removes the attack path entirely rather than monitoring for it. Adlumin watches authentication behaviour across environments Capstone manages, surfacing logins that follow a factor change or a recovery event.

Hunting work for this week, in priority order:

- Egress logs for persistent WebSocket tunnels and Go-based SOCKS5 proxy traffic from workstations that have no business proxying anything, plus TCP sessions on port 3308 carrying MessagePack, which is the VectraRAT control protocol.
- `%LOCALAPPDATA%\Temp` for build-specific obfuscated folders holding a renamed but legitimately signed AutoIT interpreter alongside an `.ini` loader script and an extensionless encrypted file. The companion persistence is a batch file in the Startup folder with no registry key, so registry-only autorun checks miss it.
- Microsoft Defender exclusion paths added by a process chain that began with a Windows shortcut masquerading as a PDF. Azalea RAT sets those exclusions before launching, and an unexplained exclusion is one of the cheapest high-signal alerts you can build.
- Files named `RESTORE_FILES.txt`, MeshAgent installations you did not authorise, cleared Windows event logs, and disabled Windows recovery options. Settra intrusions showed all four, with vulnerable-driver abuse in one case.

Rotate AI agent tokens the same way you rotate service account keys. Infostealers now collect MCP configurations, prompt histories, conversation databases, and access and refresh tokens belonging to Claude, Cursor, OpenCode, Cline, and Continue. A refresh token survives a password reset, so a developer who got infected last month may still be leaking access today unless you revoke the session server-side.

Over the next few weeks, set port-out locks and account PINs with your carrier for every executive and administrator line, and ask for alerting on SIM or number-change events. Apply the same scrutiny to your own help desk: any workflow where a human can reset a factor or reassign an identifier should require a second approver and leave an audit record.

For embedded and Linux fleets, disable Telnet and replace default credentials. Brute-forced Telnet logins remain a working entry path, and the KATARU family chains that access with Linux local privilege escalation exploits and encrypted C2.

Longer term, drive patch order with the Known Exploited Vulnerabilities catalogue and EPSS scores instead of severity ratings alone, and record which deferred items are internet-facing. That list is your actual exposure inventory.

Remediation and hunting order

1

Close the vCenter Syslog directory traversal flaw first, before working outward to other appliances.High



2

Second, check the FMC appliances for System V init persistence and unexpected long-running processes. The x86-64 Linux implant carries selective packet capture and content surveillance modules.High



3

Third, move internet-facing AI infrastructure offline or behind authentication. Command execution came through MCP STDIO configuration with root privileges, so rotate host credentials including AWS access keys and ECS task credentials.High



4

Fourth, move privileged and executive accounts to an app-based authenticator or a FIDO2 hardware key. Number-reassignment fraud needs no flaw in your systems, so removal beats monitoring.Medium



5

Finally, hunt egress logs for persistent WebSocket tunnels, Go-based SOCKS5 proxy traffic, and MessagePack sessions on the VectraRAT control port. Review temp folders for a renamed signed AutoIT interpreter with an .ini loader, Startup batch persistence, Defender exclusions set by Azalea RAT after a shortcut masquerading as a PDF, and Settra artefacts such as unauthorised MeshAgent, cleared event logs, and disabled recovery.%LOCALAPPDATA%\\Temp — RESTORE\_FILES.txt







## Where to Focus First

The three threads this week point in the same direction. Your patch queue is now large enough that working it in order is the same as working it at random, your privileged accounts still depend on a phone number a store employee can reassign, and your endpoint telemetry is competing with malware that changes its own command syntax at runtime.

Treat those as one prioritisation problem instead of three projects. The exploited subset of the week's patch volume is small and named, so it is the part you can act on with confidence. Everything else in that 800-plus release can follow your normal test-and-deploy cadence without much argument.

The second half of the same decision is authentication. If your administrative accounts, your banking portals, or your account-recovery flows still accept an SMS code as proof of identity, the control depends on a provisioning system your organisation does not operate and cannot audit. Moving those paths to phishing-resistant factors removes an entire class of takeover from your risk register.

Endpoint hunting sits third, because it is the thread with the longest time horizon. Signature-based detection is losing ground against payloads that rewrite themselves, and that shifts the value toward behavioural telemetry and the discipline of actually reviewing it. That is a capability you build over quarters, not a task you close this month.

So the useful takeaway is narrow. Confirm which of your systems carry the flaws with observed exploitation, and confirm which of your privileged logins can still be completed with a text message. Those two answers tell you where the next month of your team's effort belongs.

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http:\/\/schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
            },
            "dateModified": "2026-09-18T12:38:39Z",
            "datePublished": "2026-09-18T12:38:39Z",
            "description": "Oracle patched 800+ flaws, ransomware crews exploit vCenter CVE-2026-59310, an AT&T insider sold SIM swaps, and OfferLoader delivered Insomnia RAT to endpoints.",
            "headline": "ThreatsDay Tracks 800+ Patched Flaws, Insider SIM Swaps and Insomnia RAT",
            "image": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/threatsday-tracks-800-patched-flaws-insider-sim-sw-e26a77"
            },
            "publisher": {
                "@id": "https:\/\/captechgroup.com\/#defaultPublisher"
            },
            "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/threatsday-tracks-800-patched-flaws-insider-sim-sw-e26a77"
        },
        {
            "@type": "Person",
            "name": "Brian",
            "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultLogo",
            "@type": "ImageObject",
            "url": "https:\/\/captechgroup.com\/images\/hotlink-ok\/logo-light.jpg",
            "width": 1300,
            "height": 300
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPublisher",
            "@type": "Organization",
            "url": "https:\/\/captechgroup.com\/",
            "logo": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "name": "Capstone Technologies Group",
            "location": {
                "@id": "https:\/\/captechgroup.com\/#defaultPlace"
            }
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https:\/\/captechgroup.com\/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday"
                    ],
                    "opens": "09:00",
                    "closes": "17:00"
                }
            ]
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "Springfield",
            "addressRegion": "Ohio",
            "postalCode": "45504-1583",
            "streetAddress": "2071 N Bechtle Ave, Box 143",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

