CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Bitget reported roughly $351.6 million in unauthorized transfers from its hot- and warm-wallet infrastructure, while an integer-underflow exploit in shared Cosmos EVM code drained six blockchain networks of an estimated $5.7 million. Operation Master also exploited Palo Alto Networks GlobalProtect, as attackers targeted newly disclosed WordPress and Check Point flaws.
Bitget suspended withdrawals after attackers allegedly compromised a core wallet backend and generated fraudulent transfer requests without stealing private keys. The company said its cold wallets and customer balances were unaffected, but the scale of the transfers makes the incident the most consequential financial loss reported.
Attackers exploited WordPress CVE-2026-87902 within hours of disclosure, while Check Point reported exploitation of two critical pre-authentication flaws affecting VPN gateways and management systems. Operation Master’s use of GlobalProtect CVE-2026-0257 to reach seven gateways in four countries further underscores the immediate exposure around internet-facing access infrastructure.
Editorial: Recommended Actions
01
PRIORITY
Patch WordPress immediately to 7.1.2, 7.0.6, 6.9.9, or 6.8.10, as appropriate, and investigate affected sites for suspicious PHP files under /tmp or /var/tmp. Attackers began exploiting CVE-2026-87902 within hours of disclosure, using pearcmd.php to write and execute attacker-controlled PHP on internet-exposed installations that meet the required theme and server conditions.
02
PRIORITY
Identify and remediate affected Check Point Security Gateways, Log Servers, and Multi-Domain Management systems as an emergency. CVE-2026-85102 can permit unauthenticated remote code execution during VPN negotiation, while CVE-2026-93616 can enable unauthenticated script upload and execution on management systems. Both flaws are actively exploited and appear in CISA’s Known Exploited Vulnerabilities catalog.
03
PRIORITY
Remediate the critical JetBrains TeamCity remote-code-execution flaw immediately and investigate exposed servers for compromise. Ransomware groups are exploiting the unauthenticated agent-polling vulnerability, and a breached TeamCity server could expose credentials, signing keys, cloud tokens, build artifacts, and downstream deployment infrastructure.
04
PRIORITY
Upgrade Roundcube Webmail to 1.6.16 or 1.7.1, or disable the virtuser_query plugin if an upgrade cannot be completed immediately. Review application, database, web, and authentication logs for exploitation attempts. Attackers are actively exploiting CVE-2026-48842, a pre-authentication SQL injection flaw affecting earlier Roundcube releases, including cPanel-hosted deployments.
05
PRIORITY
Move affected on-premises VeloCloud Orchestrator deployments to version 5.2.3.16 or 6.4.2.8 or later where those fixes apply, and urgently assess release trains that remain unpatched. Attackers are exploiting the input-validation flaw to use an Edge certificate, bypass the front end, and send requests to trusted internal services; affected versions include earlier 5.2.3, 6.1.3, 6.4.2, and 7.0.0 releases.
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_