Friday’s brief: forgotten servers on a seven-country advisory, then Splunk, Bricksforge and exposed dashboards

By George Bailey   Published: 10/09/26   2 min read

Happy Friday. One big advisory and three things you can finish before the weekend. The theme: attackers keep winning with systems people assumed were too old, too internal or too boring to matter.

Lead Story

Seven countries just warned that attackers are still hunting forgotten FTP, DNS and Struts servers. Joint advisory AA26-281A describes a China-linked operation that scans for old bugs (ProFTPD, BIND, Struts, ONLYOFFICE, Strapi), sprays Exchange passwords, hides behind SoftEther VPN and walks off with email. CISA added five of the bugs to KEV with a Sunday federal due date.

Find your forgotten servers →

Also Worth Your Attention

Splunk Enterprise search head clusters can be taken over without a login. A 9.8 bug in 10.2 and 10.4, fixed in the October 7 release alongside 16 other bugs. Not exploited yet. Upgrade path and workaround →

Bricksforge for WordPress is being used to plant web shells. Exploited since Wednesday evening, no login needed. Version 3.1.8.10 fixes it. Check your sites →

Your internal dashboards were never meant to be public. Attackers found them anyway. JPCERT ties a wave of data leaks to exposed BI tools, admin APIs and an unpatched Metabase bug. Use the checklist →

Slack paste: Fri Oct 9: (1) AA26-281A: find and patch/retire exposed ProFTPD, BIND, Struts 2.3, ONLYOFFICE, Strapi; MFA on webmail; KEV due Sun. (2) Splunk to 10.4.3/10.2.7/10.0.10/9.4.15. (3) Bricksforge to 3.1.8.10 + hunt uploads for PHP. (4) Inventory internet-exposed BI/admin tools; Metabase to the patched point release.

Go Deeper

Get this in your inbox every weekday morning: subscribe to the Daily Brief.

George Bailey

George Bailey is the byline of the CyberExperts editorial desk, the team behind the CyberExperts Daily Brief. The desk covers vulnerabilities, breaches and security news from vendor advisories, CISA alerts and other primary sources, and links those sources in every story. Questions or corrections: [email protected].