CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are actively exploiting CVE-2026-64849 in MLflow, reaching internal services and cloud metadata that may expose credentials. More than 200 DeFi exploits also caused an estimated $840 million to $1.3 billion in losses during the first half of 2026.
MLflow’s vulnerable webhook test endpoint can follow redirects and re-resolve hostnames after validation. Organizations running versions before 3.15.0 should upgrade and investigate potential credential exposure, particularly in cloud-hosted deployments.
Bridge validation failures remain costly. An attacker paired a forged CCTP message with an Aave flash loan to take about $190,000 from Allbridge, while another minted roughly 14.9 billion unbacked SAND tokens through The Sandbox bridges on Base and BNB Smart Chain.
Editorial: Recommended Actions
01
PRIORITY
Upgrade every MLflow instance to version 3.15.0 immediately, then investigate whether CVE-2026-64849 exposed credentials through internal services or cloud metadata endpoints. Organizations running cloud-hosted MLflow versions before 3.15.0 face active exploitation of the webhook test endpoint’s redirect and hostname-resolution behavior.
02
PRIORITY
Update Coldcard Mk4 and Mk5 devices to firmware 5.6.1 or later and Coldcard Q devices to 1.5.1Q or later, then generate new seeds and transfer funds to the new wallets. Firmware updates cannot protect seeds created by vulnerable firmware, whose private keys may be reconstructed through button-press analysis.
03
PRIORITY
Stop trading SAND on Base and BNB Smart Chain while The Sandbox’s affected bridges remain shut down. An attacker minted about 14.9 billion unbacked SAND tokens and extracted legitimate SAND through the cross-chain infrastructure, putting holders and liquidity providers on those networks at immediate risk.
04
PRIORITY
Allbridge and other CCTP bridge operators should verify sender, recipient, minting and balance-increase conditions before accepting transfer messages. Allbridge’s insufficient message validation allowed an attacker to combine a forged one-million-USDC transfer claim with an approximately 809,000 USDC Aave flash loan, causing roughly $190,000 in losses.
05
PRIORITY
Upgrade affected Grafana OSS deployments to 11.6.14, 12.2.8, 12.3.6, 12.4.3 or 13.0.1, according to the deployed branch. CVE-2026-42129 allows remote directory traversal to administrative Loki endpoints and sensitive backend information; Check Point customers should also install current IPS updates and deploy the protection policy.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents18Messages30mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_