Secret CISO 10/8: $19M Ransom ‘Recovery’ Fraud, 1M Emails Leaked, Google ccTLD Hijack, Pwn2Own 32 Zero-Days

A bad day for “trusted third parties”: an IR vendor allegedly paid ransoms in secret, a forgotten analytics box leaked 1M emails, and ccTLD operators let attackers mint Google TLS certs. Plus: Atlassian exploitation, SonicWall SSRF, and fresh pods.

Share
MonsterCloud alleged secret ransom payments fraud

Today’s thread is simple: your security posture is now the sum of the vendors you trust, the infrastructure you forgot, and the internet plumbing you do not control.

Today's Top 5

  1. $19M “recovery” fraud: Prosecutors say a ransomware remediation CEO secretly paid attackers, then billed victims big markups while selling “proprietary decryption.” The uncomfortable question is how many of your incidents were “fixed” this way. Source
  2. 1M emails, 28M Discord IDs: A “retired” server still on the internet became the front door, then a stolen bot token became the phishing cannon. This is what decommissioning looks like when it fails quietly. Source
  3. Google TLS certs minted: Attackers compromised ccTLD registry infrastructure and used DNS control to obtain unauthorized HTTPS certificates for Google domains. It is a reminder that “we have MFA” does not cover the registry operator. Source
  4. Atlassian exploitation starts: Public PoC dropped, then exploitation followed for a critical pre-auth file access flaw across multiple Data Center products. If Jira or Confluence is internet-reachable, you already know what this means. Source
  5. 32 zero-days, one day: Pwn2Own Ireland turned mobile, smart home, printers, and AI infrastructure into a highlight reel of exploit chains. Your board does not need the details, but your patch SLAs do. Source

Why today matters: We are watching attackers move “up the stack” into trust brokers: incident response middlemen, DNS and certificate issuance paths, and admin-heavy collaboration platforms. The winners are teams that can verify, not just believe, including verifying what vendors did during your last crisis. CISOs who should be nervous: anyone with internet-facing admin surfaces, unmanaged SaaS sprawl, and a decommissioning process that is really just “turn it off later.”

Alright. Into the debris field.

Data Breaches

Double Counter breach via forgotten server
  1. MonsterCloud CEO charged over secret ransom payments: U.S. prosecutors allege MonsterCloud’s owner secretly paid ransomware operators for decryptors while marketing “proprietary” recovery, then charged victims substantially more than the ransom. Beyond the criminal case, this is a supplier risk story for every company that outsourced negotiation and recovery. Source: BleepingComputer
  2. Double Counter breach exposes email and Discord identity graphs: Double Counter says an attacker entered via a still-reachable retired server running Metabase, stole cloud credentials, exported about 12GB including around 1M email addresses, and also swept up about 28M Discord usernames and IDs tied to verification workflows. The attacker then abused the stolen bot token to spread malicious invites across large servers. Source: AliasFleet
  3. Advantest confirms data stolen in February ransomware incident: Months after disclosing a ransomware intrusion, Advantest is now notifying people that attackers extracted data including PII such as contact details and government identifiers, with monitoring offered to recipients. The long gap highlights how long it can take to confirm exfiltration scope when logs are incomplete. Source: SecurityWeek
  4. Ransomware affiliate allegedly double-crossed their own operator: Reporting based on CloudSEK research describes an affiliate running a parallel leak brand and keeping extortion proceeds rather than routing them through the RaaS program. For defenders, it is another signal that victim pressure and “negotiation norms” are getting less predictable. Source: ITPro

Security Research

Google ccTLD registry hijack and rogue certificates
  1. ccTLD registry hijacks and Chrome’s emergency response: Google detailed how attackers compromised third-party ccTLD operators (.gh, .sl, .as), modified authoritative DNS, and obtained unauthorized certificates, prompting Chrome to block the certs via CRLSets and push revocations with CAs. If you operate brands in “smaller” TLDs, treat CT monitoring and registry account hardening as first-class controls. Source: Google Security Blog
  2. Pwn2Own Ireland Day 1 results: 32 zero-days were demonstrated across categories including mobile phones and AI infrastructure, with Samsung Galaxy S26 compromised in the Mobile category and AI targets also featured. This is a preview of what exploit chains look like when researchers can trade complexity for prize money, then vendors inherit the mess. Source: Zero Day Initiative
  3. Atlassian Data Center critical file access flaw exploited: A critical vulnerability (CVE-2026-21589) impacting multiple Atlassian product families is now being exploited following public PoC release, with no auth required in affected deployments. Expect opportunistic scanning and rapid pivoting into internal secrets. Source: BleepingComputer
  4. SonicWall SMA1000 gets a CVSS 10 pre-auth SSRF hotfix: SonicWall released hotfixes for SMA1000 series appliances addressing a maximum-severity pre-auth SSRF (CVE-2026-102255) plus additional post-auth issues. If you leave these gateways exposed, you are volunteering for someone else’s weekend. Source: Censys
  5. PoeLLM malware targets exposed AI services for cryptomining: A campaign is compromising exposed AI services and using PoeLLM malware to turn the hosts into scanners and launchpads, then monetizing through mining. This is what “shadow AI infrastructure” looks like in the wild. Source: BleepingComputer
  6. Splunk MCP Server SSRF issue disclosed: Splunk published an advisory for a vulnerability in Splunk MCP Server (CVE-2026-76286) involving SSRF via a configurable tool, requiring specific capabilities to configure and execute. If you are experimenting with MCP in prod, now is a fine time to stop being brave. Source: Splunk

Top CVEs

Atlassian Data Center CVE-2026-21589 exploited
  1. CVE-2026-21589: Critical arbitrary file access affecting multiple Atlassian Data Center products (including Jira, Confluence, Bitbucket families), with exploitation reported after public PoC. If your Atlassian DC stack is reachable from the internet, treat this as an incident until proven otherwise. Source
  2. CVE-2026-102255: Pre-auth server-side request forgery and unintended proxy issue in SonicWall SMA1000 Work Place interface (CVSS 10.0), enabling unauthenticated abuse of internal functionality via the appliance. Patch to the fixed hotfix builds and review exposure immediately. Source
  3. CVE-2026-104286: Fortinet FortiMail critical path traversal allowing unauthenticated arbitrary file writes, reported exploited in the wild and added to KEV. If FortiMail management is internet-exposed, you are on borrowed time. Source
  4. CVE-2026-88779: Citrix NetScaler ADC and Gateway memory overflow leading to denial of service when configured for SAML SP or IdP, with national authorities warning of exploitation in the wild. Patch even if you already upgraded for the earlier NetScaler issues. Source
  5. CVE-2026-76286: Splunk MCP Server SSRF risk via configurable custom API tools, requiring elevated app capabilities to set up and execute. Lock down who can create and run tools, or remove the app if you do not need it. Source

Podcasts & Talks

Darknet Diaries episode on Conti ransomware
  1. Darknet Diaries EP 180: Conti: A tight history of the Conti ransomware brand and how internal fractures and leaks dismantled it. Worth sharing with your exec team because it explains why “the group is gone” never means “the threat is gone.” Listen: Episode page
  2. Security Now #1099 (TWiT): “An Alien Mind”: This week’s episode spans RSA weakness through agentic attacks, and it is a good prompt for how quickly “weird crypto detail” turns into “operational incident” when attackers automate discovery. Listen: Show page
  3. SANS Stormcast (Oct 7): RMM tools, libHEIF RCE, SonicWall SMA1000: A fast daily brief that stitches together multiple threads defenders are actively triaging this week, including gateway flaws and exploitation patterns. Listen: Episode listing

Final Words

The underlying pattern is not “more CVEs.” It is more failure in trust intermediaries: the company that negotiates for you, the platform that verifies your users, and the registry that vouches for your domain. Your threat model just expanded to include business processes that security teams rarely audit, like how an IR vendor proves they did not pay, and how you certify a server is truly dead. The uncomfortable implication: a clean SOC does not mean a clean supply chain.

This week, do three things:

  • Audit every contract and invoice from ransomware recovery and IR vendors for disclosure language, and require written attestation on whether ransom negotiation or payment occurred in your last incident.
  • Patch or isolate Atlassian Data Center products for CVE-2026-21589, and add an external scan to confirm there is no internet-facing Jira or Confluence left “temporarily” exposed.
  • Inventory and hotfix SonicWall SMA1000 for CVE-2026-102255, then run a decommissioning sweep for forgotten systems, especially analytics tools like Metabase and admin consoles.

Your turn: If your ransomware recovery vendor told you last year, “we did not pay,” could you prove it with logs and contracts, or would you just be trusting the same kind of story MonsterCloud allegedly sold? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.

Know a colleague who still treats DNS and certificate issuance as “someone else’s problem”? Forward them the ccTLD hijack story above. It costs 30 seconds, and the alternative costs incident response. If this was forwarded to you, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!

Read more