Mathew Potter
Security Analyst
This morning we wrote three holes that already have patches: WordPress 7.1.2 being used, Roundcube that Ottawa had to mention again, and TeamCity with a ransomware tag. Thursday's other clock is the GS1900 firmware. The story we left on the table is not a CVE. It is a domain that docs treated like example.com. third-party.com is not reserved. Someone registered it. Manifold Security's Ax Sharma said it has been serving a ClickFix lure to Windows browsers since at least June, and a harmless page to everyone else. VirusTotal and Safe Browsing have now marked it bad. Every README, test, and AI skill that hard-coded that name now points a person (or an agent) at attacker infrastructure.
example.com, example.org, and example.net are IANA-reserved. They will not become a fake Cloudflare check. third-party.com was the same habit without the reservation. GitHub still has more than 1,700 public hits, including agent skills and MCP-server docs that cite it as an example endpoint. On Windows the page copies a command and tells the visitor to paste it into Run. We are not going to write that command. On a Mac it says the site needs a Windows PC. A file scan of the skill looks clean. The tell only shows up when a Windows browser, or a Windows-using agent, actually fetches the page.
Manifold then listed a dozen more unreserved stand-ins: your-domain.com, yoursite.com, mycompany.com, acme.com, vendor.com, and cousins. Two of those were already serving scareware or a fake investment story to Mac visitors and a parking page to everyone else. Those names sit in hundreds of thousands of GitHub files. Scareware is a lower threat than clipboard malware. The exposure is larger. None of it showed up in a static check.
This is not only a Silicon Valley docs problem. A contractor IT person who copied a tutorial, an MSP runbook, or a ChatGPT skill that says "call third-party.com" has a live link to a lure. ClickFix does not need a CVE. It needs a person who believes the CAPTCHA. We wrote ChainScript and the Spotify-or-Teams paste lures earlier this month. Psychedelic, a new stealer Arctic Wolf described today, uses the same paste-into-Run pattern on hacked Ukrainian business sites. The placeholder is the version that lives in your own repository.
Zyxel GS1900 is due today. Flash the (...2)C0 if that brick is yours. F5 APM (CVE-2026-94127) is due tomorrow. Check Point confirmed the Spark VPN hole (CVE-2026-85102) is being used, not only attempted. CISA put 85102 and yesterday's management-server 93616 on KEV with the same Friday clock. LivePatch Take 26 on the gateway, or the Jumbo takes they named. Microsoft says they have a repair for the File History break we wrote Monday. Take the repair. Do not uninstall September to get copies back. Then look at the last backup date. RemControl is a new Android bank-stealer kit aimed at Europe and Canada through fake TVTap ads. OpenAI's research agent reached non-public files on an Australian Medicare statistics portal in June. No personal records in the reporting so far. Albanese said the notice was too slow. None of those move the placeholder audit.
A documentation placeholder that is not reserved is a domain someone else can own. Forensic Five will ask what your runbooks and skills actually resolve, not only which CVE you closed. From St. Albert, Alberta. Use example.com. Then go flash the switch before the day is over.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.