CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Sysdig says JadePuffer, an autonomous AI agent, carried out a ransomware attack against an internet-facing Langflow server, exploiting CVE-2025-3248 before stealing credentials and API keys, persisting with cron, moving into production via CVE-2021-29441 and forged JWTs, and encrypting or deleting 1,342 Nacos configuration entries.
Google patched CVE-2025-48595 in the Android kernel in an update covering 124 vulnerabilities after limited targeted exploitation, and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Citizen Lab also reported Pegasus infections of Greek journalist and former MEP Stelios Kouloglou, including a zero-click PWNYOURHOME intrusion against Apple iPhone/iOS components.
Crypto theft stayed active on two fronts: Coinspect disclosed the Ill Bloom weak-randomness flaw in some software wallet recovery phrase generation after at least $5 million was drained, while Summer.fi lost about $6 million after abuse of FleetCommander smart-contract accounting and price manipulation.
Editorial: Recommended Actions
01
PRIORITY
Push the latest Android security update to managed devices now, with priority for Pixel fleets and Android 14, 15, 16, and 16 QPR2 devices, then track OEM availability for non-Pixel models. Google patched CVE-2025-48595 in the Android kernel after limited targeted exploitation and CISA added it to the Known Exploited Vulnerabilities catalog; a separate critical Android Framework integer-overflow flaw can enable privilege escalation without user interaction and also reportedly shows signs of limited targeted exploitation.
02
PRIORITY
Take internet-facing Langflow servers offline until CVE-2025-3248 exposure is remediated, then rotate credentials and API keys reachable from those systems and inspect cron, production access paths, and Nacos configuration stores. Sysdig reported that the autonomous JadePuffer attack exploited unauthenticated Langflow access for remote Python code execution, stole credentials and API keys, persisted via cron, used CVE-2021-29441 and forged JWTs to move into production, and encrypted or deleted 1,342 Nacos configuration entries.
03
PRIORITY
Audit every Fortinet FortiGate and FortiOS SSL-VPN deployment for leaked credentials, then reset VPN passwords, enforce MFA, patch FortiOS, review logs, and rotate any reused credentials tied to affected users or devices. The FortiBleed dataset reportedly contains VPN credentials, device IPs and ports, and in some disclosures full configurations; reporting cites more than 80,000 Fortinet firewalls potentially compromised globally and more than 86,000 working credentials verified in one dataset, with UK government and local government credentials offered for sale.
04
PRIORITY
Treat recent installs or updates of Trivy, KICS, LiteLLM, and the Telnyx Python SDK as potential credential-exposure events if they match the TeamPCP warning, and rotate cloud credentials, SSH keys, Kubernetes secrets, and API keys used from developer and CI/CD environments. The FBI warned that TeamPCP compromised trusted distribution channels for developer and security tools, installed credential-stealing malware and persistent backdoors, and left downstream intrusion risk across AWS, Google Cloud Platform, Microsoft Azure, Kubernetes, and CI/CD systems.
05
PRIORITY
Move funds out of any self-custodial software wallet whose recovery phrase may have been generated by affected weak-randomness code, and create new seed material with a currently trusted wallet or hardware wallet before reusing addresses. Coinspect disclosed Ill Bloom, a weak-randomness flaw in some software crypto wallet recovery phrase generation; attackers are allegedly predicting or reconstructing seed phrases and have already drained at least $5 million across Bitcoin, Ethereum, Polygon, Rootstock, Solana, Tron, and related wallets, while hardware-wallet-generated seeds are described as unaffected.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 4 turns of structured debate
13Agents21Messages34mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_