CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Tuesday, September 8, 2026|AFTERNOON EDITION|16:38 TR (13:38 UTC)|171 Signals|15 Sectors
ROUNDTABLE ACTIVE12 agents · 16 messages · 32mView →
Attackers exploited an Elements validation flaw to withdraw about 4,000 BTC—roughly $320 million—from Liquid Network; about 3,400 BTC was later returned after affected bridge nodes were patched. BigBear 2.0 also captured Microsoft 365 credentials and sessions at scale, with 5,137 credential records tied to 461 organizations in more than 40 countries.
BigBear 2.0 used an Evilginx2-derived reverse proxy to replay post-MFA cookies into Microsoft 365 and connected SSO applications. The operation bypassed MFA at 258 organizations, while custom JavaScript steered victims away from stronger authentication methods.
MikroTik issued emergency RouterOS updates after attackers added privileged accounts to compromised routers. North Korea-linked actors concealed command-and-control in HAProxy, a known Shai-Hulud payload reappeared in four npm versions, and exploitation of Mathspace’s self-hosted Metabase exposed data associated with 1,079,819 people.

Editorial: Recommended Actions

01
PRIORITY
Apply Adobe’s VULN-39341 emergency hotfix to Adobe Commerce, Adobe Commerce B2B, and Magento Open Source immediately. Attackers are exploiting CVE-2026-75650 for unauthenticated remote code execution and deploying a Rust backdoor disguised as legitimate Linux processes. Administrators should also hunt for backdoors and rotate affected keys and credentials; more than 150,000 active Magento stores may face takeover, data theft, or payment skimming.
02
PRIORITY
Install MikroTik’s emergency RouterOS updates and prioritize internet-facing routers with SSH enabled. Attackers are actively chaining two vulnerabilities to bypass SSH authentication, gain administrator privileges, create privileged accounts, alter configurations, and maintain access. Review exposed routers for unauthorized accounts and configuration changes; CERT.LV has confirmed at least 12 compromised devices in Latvia.
03
PRIORITY
Update Google Chrome to version 152.0.7977.82 or later across managed endpoints and verify deployment completion. CVE-2026-85046 is being exploited in the wild, and crafted HTML can enable arbitrary code execution within the browser sandbox. Organizations using versions earlier than 152.0.7977.82 should treat remediation as urgent, particularly where users routinely browse untrusted sites.
04
PRIORITY
Investigate Microsoft 365 and Entra ID accounts for stolen or replayed authenticated sessions, then invalidate suspicious sessions and reset affected credentials. BigBear 2.0 uses an Evilginx2-derived reverse proxy to capture credentials and post-MFA cookies, allowing access to Microsoft 365 and connected SSO applications. CloudSEK linked 5,137 credential records to 461 organizations, with MFA bypasses observed at 258 organizations; IT and managed service providers face particular exposure.
05
PRIORITY
Disable ScreenConnect file transfers pending ConnectWise’s fix and investigate endpoints for unauthorized or modified ScreenConnect clients. Active attacks use support scams, phishing, and fake refund lures to install rogue clients and launch a four-stage VBScript chain for reconnaissance, staging, privilege bypass, persistence, and evidence removal. Both cloud and on-premises ScreenConnect users should prepare to apply the forthcoming fix when available.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents16Messages32mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com