CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Immunefi counted a record 207 successful crypto and DeFi attacks in H1 2026, with losses reaching about $972 million, while KDDI disclosed that a zero-day in third-party email software exposed about 12.2 million email addresses and 7.6 million passwords. CISA also warned that attackers are actively exploiting CVE-2026-55255 in Langflow before 1.9.1, giving authenticated users a path to execute another user’s flow by supplying a victim flow ID.
Langflow’s exploited authorization bypass puts AI application infrastructure directly in the patch queue, and it is not the only active-exploitation pressure point. ACSC warned that attackers are compromising WordPress, Joomla, and other CMS sites through file upload, RCE, SSRF, and deserialization flaws to deploy webshells, while Django patched CVE-2026-1207 after reported exploitation against targeted GeoDjango/PostGIS deployments.
The strongest signal is operational breadth: attackers are exploiting application flaws, CMS plugins, identity workflows, software packages, crypto wallets, and cloud-adjacent platforms, while ransomware and data-theft cases continue to land on healthcare, telecom, government, and consumer-facing services. Security teams should treat internet-exposed apps, third-party platforms, and developer tooling as immediate control points, not secondary risks.
Editorial: Recommended Actions
01
PRIORITY
Upgrade Langflow to 1.9.1 or later immediately, then inventory any exposed instances and review activity against the /api/v1/responses endpoint. CISA says CVE-2026-55255 is being actively exploited in Langflow versions before 1.9.1, and authenticated attackers can execute another user’s flow by supplying the victim’s flow ID. Qualys customers can use QID 5014302 to detect affected deployments.
02
PRIORITY
Patch and inspect public WordPress and Joomla sites now, especially Breeze caching plugin deployments affected by CVE-2026-3844 and Joomla extensions JCE, SP Page Builder, and Page Builder CK. ACSC warned that attackers are exploiting CMS and plugin flaws to plant webshells, while researchers tied WP-SHELLSTORM to 25,195 validated compromises and thousands of active webshells. Search web roots and template directories for unexpected files, including cox.json and cox.svg, and treat unexplained file-upload, RCE, SSRF, or deserialization exposure as a likely compromise path.
03
PRIORITY
Update Django applications using GeoDjango with a PostGIS backend to Django 6.0.2, 5.2.11, or 4.2.28, and prioritize systems that use raster field lookups. CVE-2026-1207 is a SQL injection flaw in Django’s GIS module and is reportedly being exploited in the wild against targeted Django instances, so teams should also review database access logs and application telemetry around affected lookup paths.
04
PRIORITY
Audit Microsoft 365 tenants for suspicious device-code authentication, new passkey registrations, abnormal SSO cookie persistence, and unexpected Edge extensions. Forg365 operators are abusing Microsoft device-code and AiTM flows to hijack sessions, O-UNC-066 is using voice calls and fake Entra passkey enrollment to register attacker-controlled passkeys, and Payouts King-linked access brokers are impersonating IT staff in Teams to push malicious Edge extensions for Microsoft 365 and Outlook credential theft.
05
PRIORITY
Force password resets and monitor credential abuse for accounts tied to KDDI’s shared email platform and affected Japanese ISP customers. KDDI reported that attackers exploited an unnamed third-party email software zero-day, maintained access for about a month, and exposed about 12.2 million email addresses and 7.6 million passwords; no CVE or vendor name was public at the time, so providers using comparable shared email software should also press vendors for exposure guidance and review authentication logs.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents18Messages25mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_