CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA put Progress Kemp LoadMaster CVE-2026-8037 and N-able N-central CVE-2026-18577 in its Known Exploited Vulnerabilities catalog as attackers targeted edge and management platforms with direct routes into enterprise environments. Metabase, JetBrains TeamCity, Zimbra, BTCPay Server and Coldcard also surfaced in active-exploitation or urgent-patching cases, giving security teams a broad exposure-management queue rather than a single-vendor fire drill.
N-able N-central stands out because the zero-day let attackers gain unauthenticated administrative access, use Take Control to reach managed customer systems, and register Cloudflare Tunnel for persistence. N-able issued mandatory hotfix 2026.3.1.10, and the downstream risk makes this an MSP and customer-network issue, not just a product patch.
Attackers also leaned hard on trust paths: Storm-2945 used hotel and conference Wi-Fi management systems to steal Microsoft 365 credentials, npm malware campaigns abused maintainer and package ecosystems, and AitM phishing targeted payroll and finance mailboxes. The common pressure point is identity and delegated access, especially where one compromise can fan out into customers, tenants, wallets, or build systems.
Editorial: Recommended Actions
01
PRIORITY
Install N-able N-central hotfix 2026.3.1.10 immediately, then review N-central and Take Control activity for unauthenticated administrative access and movement into managed customer systems. Attackers exploited CVE-2026-18577 as a zero-day, used Take Control to reach downstream customer networks, and registered Cloudflare Tunnel for persistence; N-central operators should treat exposed management infrastructure as a customer-impacting incident, not just a single-server patch job.
02
PRIORITY
Patch Progress Kemp LoadMaster systems for CVE-2026-8037 now, especially where appliances support public-facing or high-value services. CISA added the command injection flaw to the Known Exploited Vulnerabilities catalog after active exploitation reports, and federal civilian agencies have an August 10, 2026 remediation deadline under BOD 26-04; private-sector operators should not wait for that date if LoadMaster is in production.
03
PRIORITY
Upgrade JetBrains TeamCity to 2026.1.3 and review access to TeamCity services reachable over HTTP or HTTPS. CVE-2026-63077 is an unauthenticated remote code execution flaw in TeamCity’s agent polling protocol, a proof-of-concept is available, and CISA KEV indicates active exploitation; build servers often hold source, secrets, and deployment paths, so delay expands blast radius beyond the CI host.
04
PRIORITY
Update unpatched Zimbra Collaboration Suite deployments using the Classic web interface and investigate recent mailbox access for credential and message theft. Laundry Bear exploited CVE-2025-66376 by using malicious HTML email that executes when opened or previewed, and attackers could harvest passwords, MFA tokens, and up to 90 days of messages; organizations using Zimbra Classic should assume exposed accounts may need credential and token remediation.
05
PRIORITY
Move funds generated on at-risk Coldcard Mk3 firmware 4.0.1 or later to a new seed on an unaffected device. Coinkite warned that affected seeds may be at risk because a March 2021 firmware bug reduced entropy by relying partly on a software PRNG instead of the hardware random number generator; attackers allegedly stole about 1,816 BTC, roughly $116 million, and affected users were urged to migrate funds immediately.
ROUNDTABLE
Expert Panel Discussion
14 AI experts analyzed this briefing across 4 turns of structured debate
14Agents20Messages35mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_