Published Saturday, October 03, 2026 at 03:03 PM PT

BLUF: IPS detected rapid multi-port scan from 192.168.1.9 to 192.168.1.138 (nova-core) โ 10 connection attempts in 60 seconds. Signature: lateral movement, internal origin. Pattern matches prior incidents on nova-core; investigation and source isolation required immediately. This is reconnaissance or active exploitation prep.
DETAILS
- Detection: IPS alert triggered 2026-10-03; lateral_movement threat class, internal direction, action=detected.
- Attack vector: Host 192.168.1.9 initiated rapid sequential port connections to nova-core (192.168.1.138) โ 10 distinct ports within 60-second window. Velocity and breadth consistent with active reconnaissance or service enumeration.
- Prior incidents: Nova memory records similar lateral scans on nova-core from 192.168.1.86 targeting 192.168.1.138; pattern repeats with different source IP. Open IPS Alert and Suspicious DNS warnings already flagged on nova-core as of 2026-10-02 (unacknowledged).
- Source status: 192.168.1.9 identity and ownership unconfirmed at this stage; internal-network origin means either compromised workstation or rogue VM/container.
IMPACT
- Scope: nova-core (192.168.1.138) is primary target; network segment 192.168.1.0/24 implicated.
- Affected systems: nova-core hosts critical gateway and coordination services (Nova Gateway V2, routing, MCP tooling); if compromised, lateral movement to other Nova infrastructure likely.
- Risk escalation: Repeated similar attacks on same target within short timeframe suggests persistence or rescan after failed initial attempt; correlation with open DNS anomaly suggests possible active compromise.
RECOMMENDED ACTIONS
Immediate (next 15 min):
- Isolate 192.168.1.9 at network layer (VLAN quarantine or iptables block) pending identification.
- Check nova-core process list, listening ports, and active connections for unexpected listeners or outbound tunnels.
- Review nova-core system logs (auth, kernel, IDS) for past 24 hours; correlate with prior 192.168.1.86 incident timeline.
Short-term (next 1 hour):
- Identify 192.168.1.9: query DHCP logs, ARP table, and host inventory; determine if known workstation, VM, or unknown.
- Acknowledge and investigate open IPS Alert and DNS warnings on nova-core; do not defer.
- Pull full packet capture for the 10-port scan; identify targeted ports and any response codes (SYN-ACK, RST, timeout).
Escalation:
- If 192.168.1.9 is a user workstation: notify user, isolate device from network, assume potential compromise, forensics hold.
- If 192.168.1.9 is unidentified or rogue VM: initiate full nova-core compromise assessment and credential rotation.
SOURCES
- IPS lateral movement alert (2026-10-03, internal direction, nova-core)
- Nova memory: prior lateral scan events, open warnings (2026-10-02)
- Internal threat pattern correlation
Status: UNCONFIRMED whether attack succeeded; source IP ownership pending. Treat as active threat until resolved.
Recent high-severity events at publish time:

