CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are actively hijacking internet-exposed MikroTik routers with the MikroTrick chain, combining CVE-2026-67276 and CVE-2026-86060. A public proof of concept now shows how an alleged RouterOS RSA verification weakness can provide unauthenticated SSH access, increasing the urgency for operators to identify exposed and potentially compromised devices.
The proof of concept shows that an attacker may forge an RSA signature using exponent e=1 under stated prerequisites. A related flaw, CVE-2026-67277, can leak kernel memory or remotely crash routers, adding another route to disruption or information exposure.
RouterOS operators should patch and investigate immediately, rebuilding compromised devices where necessary. Active exploitation combined with public exploit code leaves little room for delayed remediation, particularly for routers exposed directly to the internet.
Editorial: Recommended Actions
01
PRIORITY
Patch internet-exposed MikroTik RouterOS devices immediately, investigate them for compromise, and rebuild affected routers where necessary. Attackers are actively exploiting CVE-2026-67276 and CVE-2026-86060 to hijack exposed routers, and public proof-of-concept code exists for CVE-2026-67276. CVE-2026-67277 can also leak kernel memory or remotely crash devices.
02
PRIORITY
Upgrade JetBrains TeamCity On-Premises installations affected by CVE-2026-63077 to 2025.11.7 or 2026.1.3 and later, as applicable, then review exposed backups and rotate associated AWS credentials and tokens. Attackers used an unpatched TeamCity server to breach JetBrains Cadence and access IAM credentials, secrets, source code, user information, configuration files, and S3 data; CISA has added the flaw to its KEV catalog.
03
PRIORITY
Prioritize remediation of internet-facing SonicWall SMA 6210, SMA 7210, SMA 8200v, and Central Management Server deployments for CVE-2026-83548 and CVE-2026-83549, and investigate affected appliances for broader compromise. Both flaws were exploited as zero-days and added to CISA’s KEV catalog; CVE-2026-83548 is a pre-authentication SSRF rated CVSS 10.0, and the vulnerabilities were reportedly chained.
04
PRIORITY
Investigate Adobe Commerce and Magento Open Source stores for persistent implants associated with StyleSmuggler, and prepare to apply Adobe’s remediation as soon as it becomes available. The actively exploited chain enables unauthenticated remote code execution and implant installation, while Adobe had not released a patch or official workaround; a second implant variant appeared on September 6, 2026.
05
PRIORITY
Push the Google Chrome update addressing CVE-2026-85046 to managed endpoints without delay and verify deployment. Google says the zero-day is being exploited in the wild, and a malicious HTML page may trigger crashes, code execution, or data theft; technical details remain restricted while users deploy the update.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents13Messages27mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_