CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. Adobe and Microsoft also fixed 172 and 996 CVEs respectively, including flaws reportedly under active exploitation, while CISA listed a maximum-severity GitLab vulnerability after attacks surfaced.
The new KEV entries carry immediate compromise risk: attackers can gain administrative privileges and deploy backdoors, CVE-2026-84869 has fueled worm-like attacks, and multiple Artifactory flaws are reportedly under coordinated exploitation. ConnectWise has released a patch, and exposed systems warrant rapid remediation and compromise checks.
Hacking Cat allegedly used Microsoft Exchange flaws to deliver ransomware and a wiper against Russian organizations, while a Symbiosis BridgeV2 exploit enabled the minting of 46.1 billion unbacked syBTC. Internet-facing administration and development systems, persistent access, and credential exposure remain the clearest priorities for attention.
Editorial: Recommended Actions
01
PRIORITY
Remediate CISA-listed flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS immediately, applying ConnectWise’s released patch and investigating affected systems for administrative compromise or backdoors. Managed service providers and operators of these products face active exploitation, including worm-like attacks involving CVE-2026-84869 and coordinated exploitation of critical Artifactory vulnerabilities.
02
PRIORITY
Upgrade vulnerable self-managed GitLab CE and EE deployments, restrict public access, and investigate for compromise. Attackers are exploiting CVE-2026-85706 to obtain arbitrary files without authentication; affected releases include 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1 across omnibus, Helm, and source-code deployments.
03
PRIORITY
Update Marimo installations through version 0.20.4 to version 0.23.0 and investigate them for cloud-credential and SSH-key theft. A human operator exploited pre-authentication RCE vulnerability CVE-2026-39987 to rapidly extract cloud credentials and an SSH private key, and CISA has added the flaw to its KEV catalog.
04
PRIORITY
Identify internet-facing Gitea instances and investigate them for exploitation of CVE-2026-60004, repository theft, stolen credentials, persistence, lateral movement, and root-level access. Red Heron automated attacks with public proof-of-concept code, scanned 1,386 instances, and compromised 13 organizations across government, defense, energy, aerospace, election, public-safety, and research sectors.
05
PRIORITY
Apply Adobe’s hotfix for CVE-2026-75650 to Adobe Commerce and Magento Open Source, rotate keys and credentials, and investigate for persistence. The CVSS 10.0 flaw is under active exploitation, with attacks observed installing persistent Linux and Rust backdoors; CISA gave federal agencies two weeks to patch.
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_