CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are exploiting CVE-2026-65400 in macOS Screen Sharing to gain root access on internet-exposed Macs and install Monero miners. Apple has issued emergency security fixes, making systems that expose Screen Sharing the immediate priority.
Documented attacks reached Macs listening on TCP port 5900 and ended with privileged compromise and miner deployment. Organizations should identify externally reachable Macs, apply Apple’s fixes and remove unnecessary Screen Sharing exposure.
Editorial: Recommended Actions
01
PRIORITY
Install Apple’s emergency fixes on Macs immediately, then remove unnecessary internet exposure for Screen Sharing on TCP port 5900. Attackers are actively exploiting CVE-2026-65400 against exposed systems, gaining root access and deploying Monero miners.
02
PRIORITY
Apply SAP’s fix for CVE-2026-58231 to affected SAP Commerce Cloud Data Hub Adapter deployments immediately and restrict unauthenticated access until remediation is complete. The CVSS 10.0 flaw permits unauthenticated remote code execution, and exploitation attempts began three days after patch availability.
03
PRIORITY
Move assets from Coldcard wallets whose seeds were generated with Coinkite firmware released in March 2021, replacing those seeds before reuse. Attackers exploited insufficient seed entropy to drain at least 1,778.84 BTC—about $112.7 million—from more than 8,600 addresses.
04
PRIORITY
Inventory and patch internet-facing routers, cameras, NAS devices, firewalls, gateways, application servers, PHP-CGI systems, and Kubernetes ingress-nginx deployments targeted by Evooo1Bot; remove unnecessary exposure. The Mirai-based malware exploits known vulnerabilities, persists, and turns compromised devices into proxies, credential stealers, access infrastructure, or DDoS nodes.
05
PRIORITY
Prioritize Windows AFD.sys risk review and recruiter-lure defenses at defense and aerospace organizations, particularly in Brazil, France, Germany, and India. Lazarus Group exploited an AFD.sys zero-day in Operation Dream Job and used recruiter-themed lures to deploy the Troy in-memory backdoor.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages24mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_