CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Friday, August 14, 2026|AFTERNOON EDITION|17:13 TR (14:13 UTC)|297 Signals|15 Sectors
ROUNDTABLE ACTIVE13 agents · 18 messages · 47mView →
Attackers are actively exploiting CVE-2026-72898 in Metabase, CVE-2026-71362 in Adobe Commerce and CVE-2026-59310 in VMware vCenter. WindRelay is also relaying live NFC payment-card traffic from infected Android phones for remote payments and cash withdrawals, while Evooo1Bot turns internet-facing Linux devices into platforms for DDoS, credential theft and proxying.
JPCERT/CC says CVE-2026-72898 gives unauthenticated attackers a SQL injection path to administrator privileges in Metabase. Exploitation is active, and fixed releases are available for affected versions.
VMware vCenter exploitation began within five days of disclosure and involved 361 unique IP addresses across 47 countries. Adobe Commerce attacks also followed shortly after disclosure. That compressed timeline puts exposed administration, commerce and Linux device infrastructure at immediate risk, alongside Android users targeted through SpyNote and WindRelay.

Editorial: Recommended Actions

01
PRIORITY
Upgrade Metabase immediately to 63.5, 62.9, 61.11, 60.17, 59.21, 58.24, or a later release. Attackers are actively exploiting unauthenticated SQL injection vulnerability CVE-2026-72898, which can yield administrator privileges; organizations running earlier Metabase versions face immediate compromise risk.
02
PRIORITY
Apply Adobe’s APSB26-92 fixes for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source without delay. Attackers began exploiting CVE-2026-71362 shortly after disclosure, and the flaw permits unauthenticated customer-session switching and account takeover.
03
PRIORITY
Remediate CVE-2026-59310 on VMware vCenter Server systems and investigate exposed instances for reverse_ssh persistence and outbound command-and-control traffic. A suspected APT began exploitation within five days of disclosure, affecting 361 unique IP addresses across 47 countries.
04
PRIORITY
Upgrade BTCPay Server to version 2.4.2 immediately, or shut down affected servers until they can be updated. Attackers are actively exploiting an undisclosed critical vulnerability in versions before 2.4.2, placing organizations operating those payment servers at immediate risk.
05
PRIORITY
Identify every direct and supply-chain dependency on N-able N-central and investigate those environments for compromise. NYDFS warned of active attacks, and a compromised N-central server can provide administrator-level access and persistence; financial institutions, insurers, banks, MSPs, and their customers should treat indirect exposure as seriously as direct deployment.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages47mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com