CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
North Korea-linked actors accounted for about $643 million, or 66.2%, of global cryptocurrency stolen in hacks in H1, with Drift and KelpDAO losses driving the total. The same threat picture is active in enterprise environments: Oracle PeopleSoft, AWS and Microsoft 365 accounts, government and power-sector targets, and iPhones exposed to mercenary spyware all feature in high-priority reporting.
Oracle PeopleSoft Enterprise PeopleTools CVE-2026-35273 demands immediate attention: the CVSS 9.8 unauthenticated RCE stems from unsafe deserialization in /PSEMHUB/hub, was exploited as a zero-day by UNC6240/ShinyHunters against higher education, and is now in CISA’s KEV catalog. PeopleTools 8.61 and 8.62 operators should treat patching and exposure review as urgent.
AndroxGh0st is scanning and exploiting public-facing applications to target AWS and Microsoft 365 accounts, while Armored Likho is using spear-phishing, GitHub-hosted payloads, BusySnake Stealer, and Windows shortcut CVE-2025-9491 against government agencies and electric power organizations. Citizen Lab’s Pegasus findings add a separate warning on mobile surveillance exposure for high-risk public figures.
Editorial: Recommended Actions
01
PRIORITY
Patch Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 immediately for CVE-2026-35273, and review internet-exposed Environment Management Hub access to /PSEMHUB/hub. The CVSS 9.8 unauthenticated remote code execution flaw was exploited as a zero-day before Oracle released a fix, is now in CISA’s KEV catalog, and was used by UNC6240/ShinyHunters against higher education organizations.
02
PRIORITY
Upgrade Citrix NetScaler ADC and NetScaler Gateway SAML IdP deployments to fixed builds—13.1-63.18 or later, or 14.1-72.61 or later—and investigate malformed SAML AuthnRequest activity to POST /saml/login. CVE-2026-8451 was exploited less than 24 hours after patches were released, and crafted unauthenticated requests can leak protected process memory through NSC_TASS cookie responses.
03
PRIORITY
Prioritize Cisco Secure Firewall Management Center exposure checks, patch planning, and compromise hunting for CVE-2026-20131. SOCRadar reports Interlock ransomware operators exploited the critical insecure deserialization flaw to execute arbitrary Java code and gain root access, with activity involving JavaScript and Java RATs, a fileless webshell, HAProxy, and PowerShell reconnaissance.
04
PRIORITY
Remove internet exposure from Langflow instances, patch CVE-2025-3248, and inspect connected MinIO, MySQL, PostgreSQL, Nacos, and database systems for stolen secrets or configuration tampering. Sysdig reported attackers exploited a critical Langflow authentication bypass for code execution, used an LLM to hunt secrets and pivot, abused Nacos weaknesses including CVE-2021-29441, and encrypted 1,342 configuration items.
05
PRIORITY
Harden AWS and Microsoft 365 accounts against AndroxGh0st by remediating exposed web applications tied to CVE-2021-41773, CVE-2018-15133, and CVE-2017-9841, then hunt with the reported domains, hashes, and IP indicators. SOCRadar tracks active scanning and exploitation of public-facing applications by the Python malware campaign to target cloud and Microsoft 365 accounts.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents16Messages45mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_