CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
7 October 2026 at 13:11
Four incidents, four completely different initial access paths:
The writeup reconstructs each attack chain with MITRE mappings and detection strategies: egress baselining on dev subnets, Slack audit-log heuristics, and behavioral baselines for non-human identities in Snowflake.
Full breakdown: https://www.lares.com/blog/rockstar-games-attacks/
Question for the defenders here: which of these four would be hardest to catch in your environment? The OAuth token replay is arguably the nastiest of the bunch. No user to phish-train, no endpoint alert to fire.