CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Thursday, August 13, 2026|MORNING EDITION|08:49 TR (05:49 UTC)|347 Signals|15 Sectors
Gunra ransomware operators are exploiting FortiOS and FortiProxy CVE-2024-55591 and CVE-2025-24472 against government and critical infrastructure targets, while Lazarus used Windows zero-day CVE-2026-68820 against defense, aerospace, and aviation organizations. CISA also moved exploited Metabase and SharePoint flaws into the center of the patch queue as attackers hit exposed business applications.
Lazarus’ Operation Dream Job remains the sharpest state-linked item: North Korean hackers used recruiter lures, malicious PDFs or trojanized PDF viewers, DLL sideloading, the Troy backdoor, FudModule, and compromised Roundcube infrastructure to turn a Windows AFD.sys zero-day into access against high-value sectors. CISA added CVE-2026-68820 to KEV and gave U.S. federal agencies two weeks to patch.
The pressure is not limited to endpoints. Metabase CVE-2026-72898 has been used to compromise five companies and expose connected database credentials; attackers used a Rapid7 proof of concept against live SharePoint systems within a day; and Britain’s ACRO Criminal Records Office suffered repeated intrusions after an outdated Kentico CMS portal stayed unpatched.

Editorial: Recommended Actions

01
PRIORITY
Patch Windows systems for CVE-2026-68820 immediately and prioritize defense, aerospace, and aviation environments, especially endpoints used by job applicants and recruiting staff. Lazarus is actively exploiting the Windows AFD.sys zero-day in Operation Dream Job after phishing footholds, recruiter lures, malicious PDFs or trojanized PDF viewers, DLL sideloading, and the Troy backdoor; CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal agencies two weeks to patch.
02
PRIORITY
Upgrade and restrict internet-facing Metabase deployments affected by CVE-2026-72898, then review exposed dashboards, shared cards, application-database access, and stored database credentials. The CVSS 10.0 SQL injection flaw is actively exploited, has compromised five companies, and can let attackers read the Metabase application database or reach connected databases, data warehouses, and credential stores; CISA added it to KEV with a reported August 14, 2026 remediation deadline.
03
PRIORITY
Secure exposed Microsoft SharePoint Server 2016 and 2019 systems against CVE-2026-55040 now, following CISA hardening guidance and reducing unauthenticated internet access where possible. Attackers used Rapid7 proof-of-concept code against live SharePoint systems within a day, honeypots are seeing activity, and CVE-2026-63520 may be chainable with CVE-2026-55040 even though exploitation of the second flaw has not been indicated.
04
PRIORITY
Patch and inspect exposed VMware vCenter systems for exploitation of CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310, with particular attention to /sdk/ and /websso probing and unexpected cron jobs. Incident responders observed active exploitation leading to code execution and persistent remote access, including reverse_ssh persistence, with activity spanning 361 victim IPs in 47 countries; CVE-2026-59309 is a critical vmdir authentication bypass rated CVSS 9.8.
05
PRIORITY
Patch FortiOS and FortiProxy for CVE-2024-55591 and CVE-2025-24472 and hunt for unauthorized admin-style accounts, deleted logs, staged cloud exfiltration, and double-extortion indicators. U.S. and South Korean authorities warned that Gunra ransomware operators are exploiting these Fortinet flaws worldwide, including against government and critical infrastructure targets, then attacking Windows and Linux systems as part of a ransomware-as-a-service operation derived from leaked Conti source code.

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com