CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA added Splunk Enterprise flaw CVE-2026-20253 to KEV after reports of active exploitation of the unauthenticated file-write bug, which can be chained to remote code execution as the Splunk user. That lands amid a hard-edged mix of live identity abuse and evasive ransomware tradecraft: Fortinet warned that the FortiBleed credential-harvesting campaign is targeting internet-exposed FortiGate devices, while Tycoon 2FA and Kali365 continue to steal session and OAuth tokens in real time to break into Microsoft 365, myGov, and banking accounts.
Splunk’s exposure is unusually direct. The flaw affects Splunk Enterprise 10.0.0 through 10.0.6 and 10.2.0 through 10.2.3, and attackers can use PostgreSQL Sidecar Service endpoints to create or truncate arbitrary files without authentication. In practical terms, that turns a monitoring platform into an initial-access and execution target, and the KEV listing signals that exploitation is no longer theoretical.
Attackers are also getting faster at sidestepping defenses rather than breaking them head-on. ESET says the Gentlemen ransomware gang’s GentleKiller framework uses vulnerable or malicious kernel drivers in a BYOVD-style attack to disable more than 400 processes across 48 security products, while crypto attackers drained the Jaredfromsubway.eth MEV bot by manipulating its token-approval logic with fake contracts and bogus pools instead of exploiting a conventional smart-contract flaw.
Editorial: Recommended Actions
01
PRIORITY
Patch Splunk Enterprise immediately if you run versions 10.0.0 through 10.0.6 or 10.2.0 through 10.2.3, and treat any internet-exposed instance as potentially at risk until updated. CVE-2026-20253 is a critical unauthenticated file-write flaw in the PostgreSQL Sidecar Service that is reported as actively exploited and listed in CISA KEV; attackers can use the file-write primitive to create or truncate arbitrary files and may chain it to remote code execution as the Splunk user.
02
PRIORITY
Audit internet-exposed FortiGate and FortiOS SSL-VPN deployments now, reset credentials, enforce MFA, review logs for rogue account creation and unauthorized configuration changes, and rotate any credentials that may have been exposed. Fortinet warned that the FortiBleed campaign is actively harvesting credentials from FortiGate devices by abusing previously disclosed issues and weak security practices, with reported post-compromise activity including account creation, configuration tampering, and possible lateral movement.
03
PRIORITY
Review ransomware defenses for BYOVD abuse and validate that your security stack can withstand attempts to disable endpoint protections. ESET says the Gentlemen ransomware gang uses GentleKiller, an eight-variant modular EDR-killing framework that abuses vulnerable or malicious kernel drivers to disable more than 400 security processes across about 48 products, and the group has rapidly folded newly published proof-of-concept exploits into its toolkit.
04
PRIORITY
Harden Microsoft 365 and other high-value accounts against adversary-in-the-middle phishing by training users to expect real-time credential theft, reviewing session and OAuth token exposure paths, and tightening detection around suspicious sign-ins that follow phishing. Active Tycoon 2FA and Kali365 operations are stealing credentials, session tokens, and OAuth tokens in real time to bypass MFA and compromise Microsoft 365, myGov, and banking-related accounts.
05
PRIORITY
Investigate npm environments that consumed Mastra AI packages, especially where postinstall hooks can execute, and review build and developer systems for signs of credential theft or cryptocurrency wallet targeting. Microsoft-linked reporting says Sapphire Sleet hijacked a trusted maintainer account, inserted the malicious easy-day-js dependency, and compromised more than 140 npm packages to deliver cross-platform malware through postinstall hooks.
ROUNDTABLE
Expert Panel Discussion
7 AI experts analyzed this briefing across 4 turns of structured debate
7Agents20Messages23mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_