CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers exploited a transaction-validation flaw in Liquid Network to drain about 4,000 BTC, a loss reported at roughly $320 million, while active MikroTik RouterOS exploitation and a million-person Mathspace breach added immediate remediation pressure. Microsoft also fixed at least 974 vulnerabilities, including two Windows privilege-escalation zero-days exploited in the wild.
The Liquid Network failure involved Elements’ range-proof verification cache: fraudulent assets passed validation, and approximately 3,996 BTC valued near $316 million left in about 44 minutes. About 3,400 BTC was returned, while roughly 598 BTC was retained.
MikroTik’s MikroTrick chain can grant unauthenticated administrator access to exposed RouterOS devices, and Mathspace was breached through CVE-2026-72898 before it installed an available Metabase update. OpenAI, meanwhile, decommissioned a shared JFrog Artifactory instance that researchers showed could carry hidden instructions between ChatGPT code-execution containers; no malicious exploitation was confirmed.
Editorial: Recommended Actions
01
PRIORITY
Upgrade MikroTik RouterOS 7 devices to 7.24.2 and RouterOS 6 devices to 6.49.21 immediately, prioritizing internet-exposed routers. CVE-2026-67276 and CVE-2026-86060 form the actively exploited MikroTrick chain, which can provide unauthenticated administrator access; review affected devices for unauthorized administrative access after updating.
02
PRIORITY
Isolate potentially compromised F5 BIG-IP APM systems and investigate them for the Linux rootkit, fileless PHP web shell, specially formatted requests, and use of the protected UNIX socket. Attackers likely delivered the implant through CVE-2025-53521, and the rootkit can persist across BIG-IP upgrade images, so upgrading alone should not be treated as eradication.
03
PRIORITY
Remove direct exposure from FortiGate devices running FortiOS 6.4 through 7.6.3 and inspect them for reverse shells and PivotC2 before restoring access. Attackers are exploiting CVE-2025-25249, a CVSS 9.8 heap-based buffer overflow, to obtain persistent remote access, tunnel traffic, steal credentials, and transfer files.
04
PRIORITY
Update N-able N-central versions before 2026.3.1.14 using the released 2026.3.1.14 and Hotfix 4 fixes, and ensure 2026.3 Hotfix 3 is applied for CVE-2026-86206 and CVE-2026-86207. CVE-2026-86218 permits unauthenticated remote code execution, while chaining the other two flaws can create an attacker-controlled System administrator account; review deployments for unauthorized administrator accounts after patching.
05
PRIORITY
Apply the available update for CVE-2026-72898 to every self-hosted Metabase instance and review database access for signs of exploitation. Attackers exploited the CVSS 10.0 SQL-injection vulnerability before Mathspace installed the update, exposing personal data belonging to 1,079,819 students, teachers, staff, and guardians.
ROUNDTABLE
Expert Panel Discussion
14 AI experts analyzed this briefing across 3 turns of structured debate
14Agents18Messages26mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_