CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Sysdig reported an AI-agent-driven ransomware attack that exploited CVE-2025-3248 in Langflow, stole credentials, moved into Nacos and MySQL, encrypted 1,342 Nacos configuration items, and demanded Bitcoin. Citizen Lab also tied Pegasus spyware infections against former MEP Stelios Kouloglou to a likely PWNYOURHOME zero-click exploit chain while he served on the European Parliament’s spyware inquiry committee.
Cisco confirmed active exploitation of CVE-2026-20230 in Unified CM and urged upgrades or WebDialer mitigation. Citrix NetScaler ADC and Gateway systems faced rapid exploitation of CVE-2026-8451 within 24 hours of disclosure, especially SAML identity provider configurations, while CISA added actively exploited Microsoft SharePoint Server CVE-2026-45659 to KEV.
Attackers are compressing the time between disclosure and exploitation while leaning on identity systems, edge appliances, AI application frameworks, and mobile spyware. The most urgent work is familiar but unforgiving: patch exposed Cisco, Citrix, SharePoint, and Langflow systems; review identity-provider and remote-access telemetry; and treat high-value phones as targets for exploit chains that leave little user-visible trace.
Editorial: Recommended Actions
01
PRIORITY
Patch Citrix NetScaler ADC and Gateway immediately, prioritizing 14.1 systems before 14.1-72.61 and 13.1 systems before 13.1-63.18, and investigate appliances configured as SAML identity providers. CVE-2026-8451 is being exploited within 24 hours of disclosure, and Lupovis observed coordinated scanning and exploitation. Separately, Anubis ransomware affiliates are exploiting CVE-2025-5777 against NetScaler environments for initial access, then using valid VPN credentials, RMM tools, RDP/SMB lateral movement, PsExec, exfiltration tooling, and wipe-mode ransomware capabilities. Healthcare, business services, manufacturing, technology, and financial services organizations should treat exposed NetScaler systems as high-risk until patched and reviewed.
02
PRIORITY
Upgrade Cisco Unified Communications Manager to fixed releases or disable WebDialer as a temporary mitigation. Cisco confirmed active exploitation of CVE-2026-20230, an unauthenticated SSRF vulnerability in Unified CM patched in early June. Organizations running Cisco Unified CM should verify internet exposure, apply Cisco’s fixed versions, and review logs for suspicious WebDialer-related activity because Cisco has confirmed in-the-wild exploitation of the platform.
03
PRIORITY
Identify and upgrade affected on-premises Microsoft SharePoint Server deployments, including SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation, and the Canadian Centre for Cyber Security warns the deserialization flaw can enable remote code execution by a low-privileged remote attacker. Because attackers may pair the flaw with stolen credentials or phishing to obtain required access, review SharePoint authentication events and account activity alongside patch status.
04
PRIORITY
Take exposed Langflow instances offline until patched and checked for compromise, then rotate credentials reachable from the host. Threat actors exploited CVE-2026-33017 for unauthenticated RCE against exposed AI application endpoints and deployed a Monero miner that disables security controls, kills rival miners, persists via cron, and may spread through reused SSH keys. Sysdig also reported JADEPUFFER exploiting CVE-2025-3248 in Langflow to gain code execution, steal credentials, pivot into Nacos and MySQL, encrypt 1,342 Nacos configuration items, and demand Bitcoin. Langflow operators should inspect connected Nacos, MySQL, MinIO, Google Cloud credentials, SSH keys, and API secrets, not just the Langflow server.
05
PRIORITY
Apply Oracle’s May 2026 Critical Patch Update to Oracle E-Business Suite and reduce external exposure of EBS instances wherever possible. Shadowserver identified about 950 internet-facing Oracle E-Business Suite instances, while real-world exploitation attempts tied to CVE-2026-46817 were observed. Shadowserver’s scan indicates external reachability rather than confirmed vulnerability, so EBS owners should verify exact version and patch level instead of assuming exposure equals compromise or safety.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents16Messages37mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_