Daily Security Intel

Archives
Log in
Subscribe
July 27, 2026

[SecurityIntel] 27 Jul | Active scans target ESAFENET CDG weak logins

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, July 27, 2026

INTEL CONFIDENCE  58%

THREAT LEVEL

HIGH

THREAT OF THE DAY

Active scans target ESAFENET CDG weak logins

HIGH

5

C2 IPs

0

OTX IOCs

3

ARTICLES

■ ANALYST TLDR

Active scanning has been detected targeting ESAFENET CDG 3 (Content Data Guard) document management systems, looking to exploit weak or default login credentials. Concurrently, GitHub and PyPI have introduced time-based defense mechanisms within Dependabot to mitigate the risk and rapid propagation of software supply-chain attacks. Organizations utilizing ESAFENET CDG 3 should immediately secure their login portals, while development teams should adopt the new Dependabot delay policies.

■ CRITICAL STORIES

HIGH#1

Scans for ESAFENET CDG 3 Document Management System Weak Logins

Attackers are actively scanning the internet for ESAFENET Content Data Guard (CDG) version 3 systems, attempting to exploit weak or default credentials to gain unauthorized access to sensitive corporate documents and data leakage prevention systems.

INFO#2

GitHub, PyPI add time-based defenses against supply chain attacks

GitHub and PyPI have implemented time-based delay mechanisms in Dependabot to protect software pipelines from rapid supply-chain attacks, giving security researchers and maintainers a critical window to detect and revoke malicious package releases before they are automatically integrated.

■ CVEs IDENTIFIED

[CVE-TBD-1]

ESAFENET CDG 3 — Unauthorized access and data exposure via weak or default administrative login credentials

High

[CVE-TBD-2]

GitHub Dependabot & PyPI Packages — Supply chain compromise via immediate automated updates of malicious packages

Medium

■ THREAT ACTORS

Unknown

Opportunistic Threat Actors

Scanning internet-facing ESAFENET CDG 3 instances to exploit weak login portals

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active scanning and targeting of ESAFENET CDG 3 login portals
T1110
Brute Force | Attempting to leverage weak or default credentials on ESAFENET CDG 3 systems
T1195.002
Supply Chain Compromise: Compromise Software Dependencies | Mitigated by GitHub and PyPI's new time-based Dependabot defenses

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

ESAFENET — CDG 3 — Enforce strong credentials and restrict external access to prevent complete document store compromise — SANS

[P3 PATCH NOW]≤1 week

GitHub — Dependabot — Configure time-based delay policies for dependency updates — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Audit all ESAFENET CDG 3 deployments immediately to ensure default administrative credentials have been changed and strong password policies are enforced.
2[P2] Restrict external network access to ESAFENET CDG 3 portals using firewalls, IP whitelisting, or VPNs to block unauthorized scanning.
3[P2] Configure and enable the new time-based Dependabot defenses on GitHub and PyPI to delay automated dependency updates and mitigate supply chain risks.
4[P3] Monitor web server logs for anomalous scanning patterns targeting ESAFENET CDG 3 login endpoints.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 28 Jul | Active Zero-Day Exploitation of FastJson and Arista Older → [SecurityIntel] 26 Jul | Cl0p Exploits Exposed PTC Windchill Enterprise Software
Powered by Buttondown, the easiest way to start and grow your newsletter.