CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
CISA added CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities catalog after attackers chained the Zammad flaws in a data-stealing compromise of the Dutch Institute for Vulnerability Disclosure. Citrix NetScaler systems also face worldwide exploitation of two flaws that can independently enable remote code execution, while Apple patched a CoreGraphics vulnerability used in highly targeted attacks.
The Zammad case gives the exploitation warning unusual weight: the victim was a vulnerability-disclosure organization, and CVE-2026-102489 can enable session hijacking and remote command execution in affected versions. Organizations operating Zammad should treat CISA's action as evidence of demonstrated attacker capability, not a theoretical exposure.
China-linked Warlock operators likewise turned unpatched SharePoint servers into ransomware access, disabling endpoint defenses on at least 40 systems in one intrusion and encrypting at least 33. Separately, attackers allegedly stole $387.5 million from Bitget by exploiting third-party security products and obtaining credentials that enabled forged withdrawals across 12 blockchains.
Editorial: Recommended Actions
01
PRIORITY
Patch affected Zammad deployments immediately and investigate them for session hijacking, remote command execution, and data theft. CVE-2026-102489 and CVE-2026-102490 affect Zammad 1.5.0 through 7.1.3, have been added to CISA’s Known Exploited Vulnerabilities catalog, and were chained in the compromise of the Dutch Institute for Vulnerability Disclosure.
02
PRIORITY
Update customer-managed Citrix NetScaler appliances against CVE-2026-88771 and CVE-2026-88772 without delay, then review exposed systems for attempted remote code execution. Both flaws independently enable remote code execution, both are listed in CISA’s Known Exploited Vulnerabilities catalog, and GreyNoise observed worldwide scanning and exploitation attempts around Citrix’s security update release.
03
PRIORITY
Apply Fortinet’s fixed FortiMail releases or temporary mitigations immediately and conduct compromise hunting on affected appliances. Attackers are exploiting a critical zero-day capable of unauthenticated arbitrary file writes and possible code execution across listed FortiMail 7.2, 7.4, 7.6, and 8.0 releases; CISA added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to address it within three days.
04
PRIORITY
Remediate the actively exploited Cisco Catalyst SD-WAN Manager authentication bypass and restrict exposure of its administrative interfaces while remediation proceeds. Attackers can encode the letter “j” in the j_security_check path to bypass authentication and obtain unauthenticated administrative API access; CISA added the flaw to its exploited-vulnerability catalog and set an October 3, 2026 remediation deadline.
05
PRIORITY
Patch internet-facing Microsoft SharePoint Server systems against the ToolShell vulnerability chain and investigate unpatched servers for follow-on activity. China-linked Warlock operators are exploiting SharePoint flaws for initial access, using a vulnerable signed driver affected by CVE-2025-1055 to disable antivirus and EDR, and deploying ransomware; one intrusion disabled defenses on at least 40 systems and encrypted at least 33.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents18Messages39mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_