CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA and allied agencies warned that Russian state-backed hackers are exploiting vulnerable and poorly configured internet-facing routers to steal configuration files, infiltrate critical infrastructure, and support persistence and lateral movement. The same threat environment includes Progress telling customers to shut down self-managed ShareFile Storage Zone Controller servers after active exploit attempts against a critical authentication bypass flaw, and researchers tying live Microsoft 365 Evilginx-style phishing to exposed attacker infrastructure.
Apple alleges a former employee used a rare authentication bug after leaving the company to access internal network storage and download confidential files and unreleased product details over several weeks. Apple says server logs showed the former employee was the only person to use the flaw after departure, and the company reportedly fixed the bug after learning of the incident.
Attackers are pressing on identity, edge devices, cloud access, and AI-assisted intrusion workflows at the same time. Researchers reported Microsoft 365 phishing that harvested credentials and session cookies to bypass MFA, while Sygnia and Sysdig research described attackers using LLM-powered agents and automation for credential theft, service mapping, lateral movement, and persistence in incidents involving Langflow and AWS.
Editorial: Recommended Actions
01
PRIORITY
Shut down self-managed ShareFile Storage Zone Controller servers now if you operate them, and keep them offline until Progress’ mitigation path is complete. Progress warned customers of a credible external threat, and honeypots have observed active exploit attempts against a critical authentication bypass flaw. ShareFile customers should also preserve logs and review recent access, even though Progress said it had no indication of unauthorized ShareFile account or data access at the time of its update.
02
PRIORITY
Patch or isolate PAN-OS User-ID Authentication Portal and Captive Portal deployments affected by CVE-2026-0300, especially PAN-OS 10.2, 11.0, 11.1, and 11.2 systems exposed to untrusted networks. The flaw enables unauthenticated remote code execution as root, is reportedly exploited in the wild, and has been added to CISA’s Known Exploited Vulnerabilities catalog, making perimeter-exposed instances a priority for immediate remediation and compromise review.
03
PRIORITY
Inventory Oracle PeopleSoft PeopleTools 8.61 and 8.62 instances and apply Oracle’s fix for CVE-2026-35273 as a top emergency change. ShinyHunters/UNC6240 allegedly exploited the CVSS 9.8 unauthenticated RCE before Oracle’s advisory, breaching more than 100 organizations across 300 instances; affected teams should look for MeshCentral C2, SSH credential spraying, and data exfiltration to leak-site infrastructure.
04
PRIORITY
Harden Microsoft 365 against adversary-in-the-middle phishing by treating stolen session cookies and refreshed tokens as active account compromise, not just failed MFA hygiene. Researchers found live Evilginx-style Microsoft 365 campaigns tied to codemado and other operators, including a Microsoft OAuth Device Code Flow campaign that reportedly captured 218 victims across 12 countries. Security teams should review suspicious OAuth device-code activity, revoke sessions for suspected victims, and investigate mailbox access after credential prompts that appeared to pass MFA.
05
PRIORITY
Lock down internet-facing routers and edge devices used by critical infrastructure, especially Cisco devices with Smart Install exposure or older SNMP settings. CISA and allied agencies warned Russian FSB Center 16-linked actors are stealing configuration files from vulnerable or poorly configured routers to expose credentials and internal network details, supporting persistence and lateral movement across communications, defense, energy, finance, government, and healthcare environments.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents16Messages23mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_