CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA urged utilities to remove internet-exposed PLCs after attacks disrupted more than 30 Minnesota community water systems, where suspected Iran-linked actors changed passwords or IP addresses and forced some operators into manual operations or boil-water notices. The same threat picture includes mass iPhone exploitation via the Coruna kit, an almost $300 million Kelp DAO/rsETH-linked crypto theft, and two actively exploited Cisco Secure Firewall Management Center flaws now requiring urgent action.
Coruna reportedly reuses exploit code from the 2023 Triangulation chain and includes five exploit chains spanning 23 iOS vulnerabilities from iOS 13 through iOS 17.2.1. Apple had already fixed the underlying techniques, but the reporting underscores a persistent exposure problem: older or unpatched mobile devices remain reachable targets when leaked exploit tooling is repurposed at scale.
Cisco Secure Firewall Management Center is under active exploitation on two fronts: CVE-2026-20131, an unauthenticated remote code execution flaw tied by researchers to Interlock ransomware activity, and CVE-2026-20316, which can allow unauthenticated remote login through a low-privileged account. Cisco issued hot fixes for the latter and advised rotating credentials, keys, and certificates.
Editorial: Recommended Actions
01
PRIORITY
Patch Cisco Secure Firewall Management Center immediately for CVE-2026-20131 and CVE-2026-20316, apply Cisco hot fixes across affected Secure FMC versions, and rotate credentials, keys, and certificates on impacted systems. CISA warned both flaws are being actively exploited: CVE-2026-20131 is an unauthenticated remote code execution issue, while CVE-2026-20316 can allow unauthenticated remote login through a low-privileged account. Cisco Secure Firewall Management Center customers should treat exposed management systems as high-priority intrusion risks, especially where ransomware-linked activity could turn access into broader compromise.
02
PRIORITY
Remove internet-exposed Allen-Bradley and Rockwell Automation PLCs from direct public access and review HMI and SCADA configurations for unauthorized changes. CISA urged utilities to act after suspected Iran-linked actors disrupted more than 30 Minnesota community water systems by abusing internet-facing PLC exposure, weak configurations, password and IP changes, and manipulated HMI/SCADA display data. Water and wastewater operators should prioritize systems that support remote monitoring or control and be ready to operate manually if monitoring access is blocked.
03
PRIORITY
Tighten Kubernetes workload identity now: reduce mounted credentials, remove overly permissive identities, and investigate environments where pod execution could expose service account tokens. Unit 42 reported a 282% year-over-year rise in Kubernetes token-theft activity, with attackers abusing misconfigurations, pod code execution, mounted credentials, and overly permissive identities to pivot into cloud infrastructure. Teams running Kubernetes workloads should also prioritize exposure to React2Shell CVE-2025-55182, which was rapidly exploited for unauthenticated RCE in Kubernetes workloads.
04
PRIORITY
Update managed Apple iOS and Samsung Galaxy fleets without delay, giving priority to Apple iOS 13 through iOS 17.2.1, older iOS versions, and Samsung Galaxy devices exposed to malicious image or zero-click delivery paths. Coruna reportedly includes five exploit chains and 23 vulnerabilities affecting iOS 13 through iOS 17.2.1 and reuses Triangulation exploit code; Apple also patched CVE-2026-20700 across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS after reports of targeted exploitation. Unit 42 also found LANDFALL spyware exploiting Samsung Galaxy CVE-2025-21042 to record microphones, track location, and steal photos, contacts, and call logs.
05
PRIORITY
Move funds off affected Coldcard Mk3 wallets by installing Coinkite’s emergency firmware, regenerating wallet seeds, and migrating Bitcoin to new addresses generated after remediation. The reported Coldcard Mk3 firmware issue affected versions 4.0.1 and later by weakening seed generation through deterministic software PRNG use instead of the hardware RNG, and attackers allegedly drained 1,367.05 BTC worth about $88.6 million from 4,585 addresses. Coldcard Mk4, Q, and Mk5 are not believed to be affected, but Coldcard Mk3 users should not rely on old seeds.
ROUNDTABLE
Expert Panel Discussion
14 AI experts analyzed this briefing across 4 turns of structured debate
14Agents20Messages30mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_