CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Gunra ransomware affiliates are actively exploiting Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472, according to U.S. and South Korean agencies, using administrative access for theft, encryption, and extortion. Microsoft SharePoint Server CVE-2026-45659 is also under ransomware exploitation, while Head Mare is abusing TrueConf Server flaws for SYSTEM-level code execution.
Check Point’s DPRK-linked Operation Dream Job report adds a state-backed edge to the vulnerability picture: attackers used trojanized PDF viewers, exploited Windows AFD.sys CVE-2026-68820 as a zero-day, and hit Roundcube CVE-2025-49113 against defense, aerospace, and aviation organizations in Europe and India. The priority for exposed enterprise systems is rapid patching paired with compromise checks, not patching alone.
Coreum halted XRPL bridge operations after a deposit-verification flaw drained 199,916.3 XRP in 97 minutes, underscoring how quickly logic bugs can turn into losses. The same urgency runs through Fortinet, SharePoint, TrueConf, Rancher, SAP, Cisco, and Microsoft updates: internet-facing services, identity paths, and operational platforms remain the fastest route from vulnerability to business impact.
Editorial: Recommended Actions
01
PRIORITY
Patch Fortinet FortiOS and FortiProxy systems for CVE-2024-55591 and CVE-2025-24472 immediately, then review internet-facing Fortinet VPN gateways and firewalls for unauthorized administrative access. Gunra ransomware affiliates are actively exploiting these flaws before stealing and encrypting data, with finance, government, enterprise, and critical infrastructure organizations among the affected sectors. Enforce MFA, segment exposed services from internal systems, and verify that offline or immutable backups can restore priority workloads.
02
PRIORITY
Update on-premises Microsoft SharePoint Server without delay and check affected servers for compromise, prioritizing systems exposed to untrusted networks. CVE-2026-45659 is being actively exploited in ransomware attacks and CISA added it to the Known Exploited Vulnerabilities catalog; separate research also showed an on-premises SharePoint exploit chain using CVE-2026-55040 and CVE-2026-63520 to reach unauthenticated remote code execution, with Microsoft and Rapid7 saying the July update breaks that chain. SharePoint Online is not identified as affected by the latter chain.
03
PRIORITY
Upgrade internet-reachable TrueConf Server deployments to the latest patched releases and inspect them for web shells, unexpected NT AUTHORITY\SYSTEM-level activity, and replaced client installers. Kaspersky reported Head Mare exploited KLCERT-26-057 and KLCERT-26-058 in TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, and 5.5.x through 5.5.5 to gain arbitrary code execution as NT AUTHORITY\SYSTEM, access data, deploy a web shell, and swap a TrueConf client installer with an infected build.
04
PRIORITY
Patch self-hosted Metabase 1.58 and later immediately, and treat exposed instances as potentially compromised until logs, sessions, credentials, API keys, and tokens have been reviewed. Metabase disclosed a critical zero-day SQL injection flaw in /api/session/reset_password that was exploited to gain direct SQL access and could expose credentials, API keys, and tokens; Metabase Cloud blocked exploited endpoints, patched the issue, terminated sessions, and revoked credentials used in the incident, but self-hosted deployments may remain exposed if not updated.
05
PRIORITY
Defense, aerospace, and aviation organizations in Europe and India should patch Windows AFD.sys CVE-2026-68820 and Roundcube CVE-2025-49113, then hunt for fake job-offer lures, trojanized PDF viewers, RelayShell web shells, FudModule/rootkit activity, and related persistence. Check Point reported DPRK-linked Operation Dream Job activity using impersonation sites, SEO abuse, SecurityPDF, the Troy backdoor, Roundcube exploitation, and a Windows zero-day exploited before Microsoft patched it to gain SYSTEM privileges and evade EDR.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents17Messages35mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_