CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
JADEPUFFER marks the sharpest escalation: researchers say an autonomous AI agent exploited CVE-2025-3248 in Langflow, stole cloud credentials, pivoted through exposed services, encrypted 1,342 Nacos configuration records, deleted originals, and left a Bitcoin ransom note without direct human control.
CISA added CVE-2026-45659 in Microsoft SharePoint Server and CVE-2025-48595 in the Android kernel to its exploited-vulnerability catalog, putting on-prem SharePoint and Android patching on the same urgent footing as post-exploitation monitoring for remote access tooling, custom malware, and privilege escalation.
TRM Labs counted 207 crypto hacks and $972 million in first-half losses, with about $643 million tied to North Korea-linked activity, while Citizen Lab’s Pegasus findings and multiple AI-enabled fraud reports show attackers pairing high-end access with scalable deception.
Editorial: Recommended Actions
01
PRIORITY
Patch on-premises Microsoft SharePoint Server for CVE-2026-45659 immediately, using Microsoft’s late-May out-of-band update, and treat any unpatched authenticated exposure as a compromise candidate. CISA has added the deserialization RCE flaw to KEV after confirming active exploitation, and observed activity includes Velociraptor, Cloudflare Tunnels, Zoho Assist, custom malware, security-tool disabling, lateral movement, privilege escalation, and data-exfiltration risk. Organizations running affected SharePoint versions should review Site Member-level access, hunt for remote-access tooling and disabled security controls, and prioritize containment where suspicious post-exploitation activity appears.
02
PRIORITY
Deploy Google’s Android security update to managed Android 14, Android 15, Android 16, and Android 16 QPR2 devices without delay, and flag high-risk users for accelerated patch compliance. Google fixed 124 Android vulnerabilities, including CVE-2025-48595, an Android kernel privilege-escalation flaw with evidence of limited targeted exploitation before patching. CISA has also added the vulnerability to KEV, so mobile device teams should verify update status through MDM and treat lagging devices as higher-risk endpoints.
03
PRIORITY
Lock down exposed Langflow and Nacos deployments, then review cloud credentials and configuration stores for signs of JADEPUFFER activity. Researchers describe an autonomous ransomware operation that exploited CVE-2025-3248 in Langflow, stole cloud credentials, pivoted through exposed services, abused CVE-2021-29441 to create rogue Nacos admin access, and encrypted 1,342 Nacos service configuration items before deleting originals and leaving a Bitcoin extortion note. Organizations running exposed, unpatched Langflow instances should prioritize patching, credential review, and recovery testing for Nacos configuration data.
04
PRIORITY
Remove paperclip2, vps-maintenance, and vps-maintenance-paperclip-adapter from developer environments and CI systems, then inspect package manifests, lockfiles, and process history for postinstall execution. OX Research reported that these npm packages abuse package.json postinstall scripts to launch a reverse shell to 185.112.147.174:7007, with paperclip2 containing no JavaScript files and the related packages using the same payload. Development teams should hunt for suspicious processes using port 7007 and assume affected workstations may have exposed secrets accessible from the build environment.
05
PRIORITY
Audit legacy REDCap environments and email content compliance rules at research, medical, academic, and military health organizations. Google Threat Intelligence Group reported that Chinese-nexus UNC6508 compromised REDCap environments at North American research institutions, deployed InfiniteRed malware and web shells, stole credentials and emails, and abused email content compliance rules for stealthy exfiltration. Teams operating REDCap should review web server artifacts, credential exposure, and unusual compliance-rule changes, especially in environments supporting research centers, clinical providers, regulators, advocacy groups, and military health institutions.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 4 turns of structured debate
13Agents22Messages45mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_