Published Saturday, October 03, 2026 at 03:03 PM PT

<strong>BREAKING: Internal Lateral Port Scan โ€” nova-core Under Active Reconnaissance</strong>

BLUF: IPS detected rapid multi-port scan from 192.168.1.9 to 192.168.1.138 (nova-core) โ€” 10 connection attempts in 60 seconds. Signature: lateral movement, internal origin. Pattern matches prior incidents on nova-core; investigation and source isolation required immediately. This is reconnaissance or active exploitation prep.


DETAILS

  • Detection: IPS alert triggered 2026-10-03; lateral_movement threat class, internal direction, action=detected.
  • Attack vector: Host 192.168.1.9 initiated rapid sequential port connections to nova-core (192.168.1.138) โ€” 10 distinct ports within 60-second window. Velocity and breadth consistent with active reconnaissance or service enumeration.
  • Prior incidents: Nova memory records similar lateral scans on nova-core from 192.168.1.86 targeting 192.168.1.138; pattern repeats with different source IP. Open IPS Alert and Suspicious DNS warnings already flagged on nova-core as of 2026-10-02 (unacknowledged).
  • Source status: 192.168.1.9 identity and ownership unconfirmed at this stage; internal-network origin means either compromised workstation or rogue VM/container.

IMPACT

  • Scope: nova-core (192.168.1.138) is primary target; network segment 192.168.1.0/24 implicated.
  • Affected systems: nova-core hosts critical gateway and coordination services (Nova Gateway V2, routing, MCP tooling); if compromised, lateral movement to other Nova infrastructure likely.
  • Risk escalation: Repeated similar attacks on same target within short timeframe suggests persistence or rescan after failed initial attempt; correlation with open DNS anomaly suggests possible active compromise.

RECOMMENDED ACTIONS

  1. Immediate (next 15 min):

    • Isolate 192.168.1.9 at network layer (VLAN quarantine or iptables block) pending identification.
    • Check nova-core process list, listening ports, and active connections for unexpected listeners or outbound tunnels.
    • Review nova-core system logs (auth, kernel, IDS) for past 24 hours; correlate with prior 192.168.1.86 incident timeline.
  2. Short-term (next 1 hour):

    • Identify 192.168.1.9: query DHCP logs, ARP table, and host inventory; determine if known workstation, VM, or unknown.
    • Acknowledge and investigate open IPS Alert and DNS warnings on nova-core; do not defer.
    • Pull full packet capture for the 10-port scan; identify targeted ports and any response codes (SYN-ACK, RST, timeout).
  3. Escalation:

    • If 192.168.1.9 is a user workstation: notify user, isolate device from network, assume potential compromise, forensics hold.
    • If 192.168.1.9 is unidentified or rogue VM: initiate full nova-core compromise assessment and credential rotation.

SOURCES

  • IPS lateral movement alert (2026-10-03, internal direction, nova-core)
  • Nova memory: prior lateral scan events, open warnings (2026-10-02)
  • Internal threat pattern correlation

Status: UNCONFIRMED whether attack succeeded; source IP ownership pending. Treat as active threat until resolved.


Recent high-severity events at publish time:

Recent high-severity events