CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA has confirmed active exploitation of CVE-2026-21962, an unauthenticated flaw affecting Oracle HTTP Server and the WebLogic Server Proxy Plug-In. The campaign reportedly reached government and commercial networks in more than 100 countries, while attackers are also exploiting self-hosted Gitea servers and exposed enterprise AI workloads.
Oracle’s flaw permits remote access to protected WebLogic resources without authentication, and public proof-of-concept code is available. Organizations running affected Oracle HTTP Server and WebLogic proxy plug-in versions should apply Oracle’s latest security updates immediately.
Exposed LiteLLM, RAGFlow and Kestra workloads enabled credential theft, persistence, data access and cryptomining; compromised Gitea servers ran shell commands and deployed miners. DOJ and FBI action against QScan and QTRouter also highlights how infected IoT devices can conceal traffic aimed at government and critical-infrastructure networks.
Editorial: Recommended Actions
01
PRIORITY
Install Oracle’s latest security updates immediately on affected Oracle HTTP Server and WebLogic Server Proxy Plug-In deployments. CVE-2026-21962 is remotely exploitable without authentication, permits access to protected WebLogic resources, and is already being exploited against government and commercial networks worldwide; public proof-of-concept code further raises the risk.
02
PRIORITY
Prioritize remediation of internet-exposed, self-hosted Gitea servers affected by CVE-2026-60004 and investigate them for unauthorized shell commands or cryptocurrency miners. Attackers are actively exploiting the flaw to execute commands as the Gitea service account and deploy mining malware, and CISA has added it to the KEV catalog.
03
PRIORITY
Restrict exposure of LiteLLM, RAGFlow, and Kestra workloads and investigate exposed instances for credential theft, persistence, unauthorized data access, and XMRig. Microsoft observed attackers compromising these enterprise AI workloads, with the LiteLLM intrusion likely relying on a chain involving CVE-2026-42271 and CVE-2026-48710.
04
PRIORITY
Apply Microsoft’s SharePoint Server patches and hardening guidance for CVE-2026-55040 and CVE-2026-63520, then examine exposed servers for attempted exploitation. Attackers are probing systems with the two-vulnerability chain, public proof-of-concept exploits are available, and CISA has urged organizations to secure affected servers, although successful code execution has not been confirmed.
05
PRIORITY
Remove PLCs, HMIs, and other OT assets from direct internet or cellular exposure, replace default credentials, and route remote administration through controlled access mechanisms. Attackers accessed cellular-connected PLCs at more than 100 U.S. water and wastewater systems, changed network settings and passwords, and in some cases disabled safety mechanisms and alarms.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents13Messages17mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_