CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Bitget’s backend wallet compromise reportedly enabled $351.6 million in unauthorized transfers, while KelpDAO says a forged cross-chain message released 116,500 rsETH worth about $292 million. Separate intrusions show attackers pairing automation with exposed infrastructure: one operator allegedly used Strix, Cairn and Hermes agents to breach at least 27 organizations, and CARBONATO is targeting unauthenticated Docker APIs.
The Bitget incident reportedly began with a compromised backend component that triggered authorized signing without exposing private keys. Reports attributed a $387 million compromise to Lazarus Group; exploitation of Limit Break payment contracts and a roughly $1.8 million Payy bridge loss added separate pressure on cryptocurrency platforms.
CISA added CVE-2026-5430 and CVE-2026-71362, affecting WSO2 and Adobe Commerce or Magento, to its KEV catalog and set a September 27 remediation deadline for federal agencies. Internet-facing systems also demand scrutiny: CARBONATO scans port 2375 for exposed Docker APIs, while the AI-assisted retail campaign targeted 105 organizations in five days and compromised 27.
Editorial: Recommended Actions
01
PRIORITY
Patch Adobe Commerce, Adobe Commerce B2B, Magento, and Magento Open Source using Adobe’s supplied fixes, and prioritize forensic triage and mitigations for affected WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway deployments. CISA added CVE-2026-5430 and CVE-2026-71362 to KEV, with CVE-2026-5430 exploited in real-world attacks; federal agencies must complete the required work by September 27, 2026.
02
PRIORITY
Upgrade WordPress Core to 7.1.2 or a patched backport immediately, then inspect affected sites for attacker-controlled PHP files associated with pearcmd.php abuse. CVE-2026-87902 is actively exploited against WordPress Core 4.7.0 through 7.1.1 and can let attackers write malicious PHP files and potentially execute code; CISA has added the flaw to KEV.
03
PRIORITY
Inspect Oracle PeopleSoft Environment Management Hub and Windows PeopleSoft servers for web shells and the SIDEEYE backdoor, and do not treat existing WAF rules as sufficient protection. ShinyHunters, tracked as UNC6240, modified exploitation of CVE-2026-35273 to bypass temporary WAF mitigations; Google found web shells on dozens of systems and warned more than 100 organizations about renewed exploitation.
04
PRIORITY
Remove unauthenticated Docker APIs from public reach, focusing first on services exposed over TCP port 2375, and examine Linux hosts for privileged containers, reverse SSH tunnels, attacker-installed keys, and persistence mechanisms. CARBONATO is actively scanning for exposed Docker daemons, launching containers with host-filesystem access, and stealing credentials and API keys.
05
PRIORITY
Disable or remove Request a Quote for WooCommerce through version 2.9.2 until a fix is available, and investigate affected WordPress sites for unauthorized PHP uploads. The unauthenticated upload handler does not validate file extensions or MIME types, enabling remote code execution and complete site compromise; the flaw carries a CVSS score of 9.8 and had no patch at publication time.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages37mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_