CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
JADEPUFFER exploited Langflow CVE-2025-3248 in what researchers describe as the first known agentic ransomware attack in the wild, harvesting cloud and API keys, moving through internal systems, establishing persistence, and destroying databases. FortiBleed added scale to the ransomware picture, with credential theft from FortiGate firewalls in about 150 countries tied to a Russian initial access broker and at least 12 ransomware deployments.
Oracle E-Business Suite and Microsoft SharePoint Server now sit in the urgent patch lane. Shadowserver found about 950 internet-exposed Oracle E-Business Suite instances while exploitation attempts target CVE-2026-46817, and Oracle’s May 2026 Critical Patch Update is available. CISA added SharePoint Server CVE-2026-45659 to KEV after confirmed exploitation, with Canadian authorities warning the deserialization flaw can enable remote code execution.
Exposed enterprise platforms, identity tokens, and AI-connected tools remain the pressure points. Cisco Unified CM, Citrix NetScaler, Langflow, Microsoft 365 OAuth flows, poisoned package ecosystems, and AI agent tooling all feature in active or high-impact reporting, while breach disclosures at KDDI, Medtronic, DHS, and Tata Electronics show how quickly infrastructure exposure turns into data, credential, and operational risk.
Editorial: Recommended Actions
01
PRIORITY
Apply Oracle’s May 2026 Critical Patch Update to Oracle E-Business Suite 12.2.3 through 12.2.15 and remove direct internet exposure for EBS, especially the Payments File Transmission component. Shadowserver identified about 950 internet-facing EBS instances while attackers are actively exploiting CVE-2026-46817, including exploitation before public exploit code was released. Organizations running EBS should treat exposed systems as priority incident-response candidates, not just routine patch targets.
02
PRIORITY
Patch Microsoft SharePoint Server 2016, 2019, Subscription Edition, and Enterprise Server 2016 against CVE-2026-45659, then assess exposure, review logs, and hunt for compromise or lateral movement. CISA added the deserialization RCE flaw to KEV after confirmed active exploitation; an authenticated attacker with valid credentials and Site Member permissions can remotely execute code. SharePoint administrators should prioritize internet-reachable and business-critical collaboration farms.
03
PRIORITY
Upgrade Citrix NetScaler ADC and NetScaler Gateway appliances and investigate SAML IdP and remote-access activity for signs of abuse. CVE-2026-8451 affects SAML IdP configurations without authentication and was reportedly exploited less than 24 hours after disclosure, with scanning and exploitation observed from 146.70.139[.]154. Anubis ransomware affiliates are also exploiting NetScaler CVE-2025-5777 for initial access and using legitimate RMM tools, so review MeshAgent, Remotely, ScreenConnect, Total Software Deployment, UltraVNC, and Zoho Assist usage in affected environments.
04
PRIORITY
Audit FortiGate firewalls and Fortinet VPN portals for unauthorized administrative access, harvested credentials, and follow-on ransomware activity. FortiBleed reportedly hit FortiGate operators in about 150 countries, gave attackers administrative access on 409 targets, led to full intrusion chains on 354, and was tied to at least 12 INC Ransom and Lynx ransomware deployments. FortiGate owners should rotate exposed credentials, review admin sessions, and treat suspicious firewall access as a possible ransomware precursor.
05
PRIORITY
Remove internet exposure from Langflow endpoints, investigate for exploitation of CVE-2025-3248 and CVE-2026-33017, and rotate cloud, API, SSH, and database credentials found on affected hosts. JADEPUFFER reportedly exploited exposed Langflow to harvest keys, pivot through internal systems, persist, and destroy databases, while separate attackers used unauthenticated Langflow RCE CVE-2026-33017 to deploy a Monero miner with persistence, log removal, security-control disabling, and possible SSH-key-based spread.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents18Messages44mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_