# Threat Intel Brief — August 25, 2026

TL;DR

  • Critical authentication bypass vulnerabilities in Keycloak (CVE-2026-18963) and miniOrange WordPress plugin (CVE-2026-61979, CVE-2026-15981) are under active exploitation, enabling unauthenticated account takeover.
  • CISA emergency directive mandates three-day patching of actively exploited Zimbra RCE flaw (CVE-2026-73570) affecting federal agencies and global government infrastructure.
  • Unpatched Calix router vulnerability (CVE-2026-75501) exposes U.S. broadband customers to NAT bypass attacks; vendor unresponsive since June 2026.
  • China-nexus espionage operations target Myanmar government with QUICAgent backdoor, while UAT-10147 deploys AI-assisted attacks and SPECTRE malware globally.
  • Mobile and gaming threats escalate with ToxicPanda 2.0 Android banking malware and Weedhack campaigns targeting Minecraft players via SEO poisoning.

---

Critical Threats

Keycloak Password Reset Flaw Enables Account Takeover

What happened: Red Hat disclosed CVE-2026-18963, a critical vulnerability (CVSS 9.1) in Keycloak identity and access management servers allowing unauthenticated attackers to reset any user's password without email token validation. Affected versions include upstream Keycloak prior to 26.7.2 and Red Hat builds 26.4 (prior to 26.4.15) and 26.6 (prior to 26.6.6). All realms with "Forgot password" functionality enabled are vulnerable.

Impact: Attackers can achieve complete account takeover—including administrative accounts—by sending crafted requests to the reset-credentials endpoint. Organizations using Keycloak as SSO/IAM face cascading compromise across all downstream applications. While no active exploitation has been confirmed as of August 24, proof-of-concept details are publicly available.

Recommendations:

  • Update to Keycloak 26.7.2 (upstream) or apply Red Hat patches 26.4.15-1 / 26.6.6-1 immediately.
  • If patching is delayed, disable "Forgot password" functionality via Realm settings > Login in the administration console.
  • Review authentication logs for suspicious password reset activity targeting high-privilege accounts.
  • Re-enable forgotten password features only after patching and implement monitoring for anomalous reset-credentials endpoint activity.

---

Zimbra RCE Under Active Exploitation — CISA Orders Emergency Patching

What happened: CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog on August 21, requiring federal agencies to patch within three days. The flaw affects Zimbra Collaboration Suite versions prior to 10.1.20, enabling unauthenticated remote code execution via command injection in SNMP monitoring components. CERT Polska flagged active exploitation on August 18; Shadowserver confirmed over 270 compromised instances globally.

Impact: Attackers execute arbitrary OS commands as the Zimbra user by sending crafted SMTP requests. Zimbra's widespread deployment in government and enterprise environments—combined with historical targeting by APT28, APT29, and Winter Vivern—makes this a high-priority intelligence collection vector. Over 12,000 Zimbra servers remain exposed online.

Recommendations:

  • Upgrade all Zimbra instances to version 10.1.20 or later immediately (patched July 20, 2026).
  • If immediate patching is impossible, disable SNMP notifications as a temporary mitigation.
  • Audit /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ directories for files created by user 'zimbra' in the last 30 days.
  • Assume breach if suspicious artifacts are found; initiate incident response and forensic investigation.
  • Restrict network access to Zimbra servers to trusted IP ranges.

---

miniOrange WordPress Plugin Exploited for Admin Takeover

What happened: Attackers are actively exploiting CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. All seven editions are affected, with vulnerable versions spanning Free (<5.4.5), Premium single-site (<13.0.4), and multiple enterprise tiers. Exploitation began August 16 from six IP addresses across Europe, Africa, and the United States.

Impact: Successful exploitation grants full WordPress administrator control, enabling malware installation, data theft, defacement, or pivot to connected identity platforms (Entra ID, Okta, Google Workspace). Paid edition users likely remain unpatched due to incomplete vendor advisory in July 2026—no update warnings appeared in WordPress dashboards for paid versions.

Recommendations:

  • Immediately identify all WordPress sites using miniOrange SAML SSO via asset inventory or web application scanning.
  • Manually upgrade to patched versions: Free 5.4.5+, Premium single-site 13.0.4+, Standard 17.06+, multisite editions 20.2.8+, Enterprise/All-Inclusive single-site 26.0.3+, VIP editions 32.0.8+ (single-site) / 35.0.7+ (multisite).
  • Review WordPress administrator accounts created since July 2026 for unauthorized entries.
  • Audit SAML authentication logs from identity providers for suspicious login attempts or signature validation anomalies.
  • Block known attacker IPs and monitor for SAML response tampering attempts.

---

Unpatched Calix Router Flaw Exposes U.S. Broadband Customers

What happened: CVE-2026-75501 in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create persistent port-forwarding rules via exposed MiniUPnPd SOAP service on WAN TCP port 5000. Affected devices run EXOS/6.6.47 firmware and are deployed by Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. Calix has not responded to disclosure attempts since June 2026; no patch is available.

Impact: Attackers remotely expose internal devices (cameras, NAS, IoT, admin interfaces) to the public internet without authentication. Port mappings persist across reboots. Proof-of-concept code is publicly available, making exploitation trivial.

Recommendations:

  • Disable UPnP on affected routers via Advanced → Security → UPnP in the administrative interface.
  • If UPnP settings are ISP-locked, contact providers immediately to request WAN-side UPnP deactivation.
  • Audit existing port-forwarding rules for unauthorized mappings; delete unexpected entries.
  • Monitor firewall logs and external port scans targeting TCP 5000.
  • Consider replacing affected routers if vendor does not release a patch within 30 days.

---

Threat Actor Activity

Operation QUICSILVER: China-Nexus Espionage Targets Myanmar

A China-nexus threat actor is conducting cyber espionage against Myanmar's government and IT sectors using QUICAgent, a custom Go-based backdoor. The campaign employs spearphishing attachments (VHD files containing malicious LNK shortcuts) themed around official government communications, including graduation ceremony invitations from the Information Technology and Cyber Security Department. QUICAgent implements sandbox evasion via random delays and resource-intensive SHA-256 hashing, establishes C2 over QUIC protocol (UDP 443) using Cloudflare Workers infrastructure, and achieves persistence through Windows Startup folder LNK files. The campaign coincides with Mustang Panda deploying enhanced COOLCLIENT backdoor with kernel-mode driver capabilities across Myanmar, Mongolia, Pakistan, and Russia.

Defensive priorities: Monitor for VHD attachments and LNK files masquerading as PDFs; detect ftp.exe -s abuse; identify QUIC traffic over UDP 443 to unusual domains; audit Windows Startup folder for unauthorized LNK files.

---

UAT-10147: AI-Assisted Attacks Target Global Web Servers

Chinese-speaking cybercrime group UAT-10147 is conducting large-scale automated attacks against Windows and Linux web servers using AI-powered tools including PentestGPT and DeepAudit. The group exploits known vulnerabilities (CVE-2022-27925, CVE-2021-23758, CVE-2019-18935, CVE-2021-29441, CVE-2021-29442) for initial access, deploys web shells, and escalates privileges using EfsPotato and Linux exploits (CVE-2022-0995, CVE-2021-3156, CVE-2022-0847, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904). The actor deploys SPECTRE malware with EDR bypass and Linux rootkit capabilities alongside Quasar RAT, Gh0stCringe, BadIIS, Noodle RAT, and Meterpreter. Victims concentrate in Brazil, Bolivia, China, Canada, and Vietnam across education, media, technology, and gaming sectors. The group maintains target lists of approximately 170,000 URLs.

Defensive priorities: Patch listed CVEs immediately; monitor certutil.exe downloading executables; detect web shell deployment via file integrity monitoring; alert on suspicious scheduled task creation; block IP 139.180.197[.]150 and domain adminapi.tippusoni[.]in.

---

ShinyHunters Targets ReliaQuest in Failed Social Engineering Attack

ShinyHunters attempted to breach ReliaQuest through vishing (voice phishing) impersonating security personnel, using lookalike domain reliaquest.claims hosting a fake Okta SSO page. An employee entered credentials and approved an MFA push notification, granting temporary access to ReliaQuest's identity dashboard. Device-trust controls blocked pivot attempts to additional applications, preventing data theft. The attack demonstrates ShinyHunters' systematic campaign using .claims TLD domains to impersonate help desks across multiple organizations.

Defensive priorities: Implement phishing-resistant MFA (FIDO2/WebAuthn); deploy device trust and conditional access controls; conduct vishing awareness training; monitor for lookalike domains under new TLDs; enable real-time alerting for SSO attempts from unusual geolocations or new devices.

---

Geopolitical Context

U.S. Telecommunications Supply Chain Vulnerabilities

The unpatched Calix router flaw (CVE-2026-75501) highlights systemic risks in U.S. telecommunications infrastructure, where a single vendor's failure affects multiple major broadband providers. The vendor's non-response to responsible disclosure spanning June through August 2026 may trigger regulatory scrutiny from CISA or the FCC under critical infrastructure protection authorities. The vulnerability's trivial exploitation requirements lower barriers for both opportunistic cybercriminals and state-aligned actors seeking persistent access to residential networks—a counterintelligence concern for remote workers in government and defense sectors.

China-Myanmar Cyber Espionage Dynamics

Operation QUICSILVER and concurrent Mustang Panda activity reflect sustained Chinese intelligence collection priorities against Myanmar's government and critical infrastructure. The parallel targeting by multiple China-nexus actors suggests coordinated regional operations spanning the Indo-Pacific. Myanmar's strategic location, natural resources, and complex political dynamics make it a persistent priority for Chinese cyber espionage. The use of Cloudflare Workers for C2 infrastructure demonstrates operational security awareness and abuse of legitimate cloud services across jurisdictions.

European Government Email Infrastructure at Risk

The actively exploited Zimbra vulnerability (CVE-2026-73570) poses acute risk to European government agencies, many deploying Zimbra as primary email infrastructure. Historical exploitation by APT28 (targeting Ukrainian government servers) and APT29 (credential harvesting campaigns) underscores the platform's strategic value for intelligence collection. Poland's CERT taking the lead in threat detection reflects Central European states' elevated threat awareness amid the Russia-Ukraine conflict. The three-day U.S. federal patching deadline should inform European government response timelines for agencies handling classified or sensitive diplomatic communications.

---

Recommended Actions

Immediate (0-24 hours)

  • Patch Keycloak to version 26.7.2 or apply Red Hat updates; disable "Forgot password" if patching is delayed (CVE-2026-18963).
  • Upgrade Zimbra to version 10.1.20; disable SNMP notifications if immediate patching is impossible (CVE-2026-73570).
  • Update miniOrange WordPress plugin across all editions; review administrator accounts created since July 2026 (CVE-2026-61979, CVE-2026-15981).
  • Disable UPnP on Calix GS7 XGS routers; contact ISPs if settings are locked (CVE-2026-75501).
  • Block UAT-10147 infrastructure: IP 139.180.197[.]150, domain adminapi.tippusoni[.]in.

Within 24-72 hours

  • Audit Zimbra servers for indicators of compromise in /opt/zimbra/ directories; assume breach if suspicious artifacts found.
  • Review SAML authentication logs from identity providers for anomalies between July-August 2026.
  • Inventory WordPress sites using miniOrange SAML SSO; prioritize paid editions lacking automatic update notifications.
  • Deploy mobile threat defense policies to block ToxicPanda 2.0 IoCs; disable Developer Options and Wireless ADB on corporate Android devices.
  • Monitor for VHD attachments and LNK files in email; detect ftp.exe -s abuse via command-line logging.

This week

  • Patch UAT-10147 target vulnerabilities: CVE-2022-27925, CVE-2021-23758, CVE-2019-18935, CVE-2021-29441, CVE-2021-29442, CVE-2022-0995, CVE-2021-3156, CVE-2022-0847, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904.
  • Implement phishing-resistant MFA (FIDO2/WebAuthn) to mitigate credential harvesting attacks.
  • Deploy web shell detection via file integrity monitoring on web server directories.
  • Conduct vishing awareness training emphasizing out-of-band verification of caller identity.
  • Review .NET Framework August 2026 updates for WPF printing/PDF export issues; apply AppContext switch workaround only to mission-critical applications if necessary.

---

Watch List

  • Calix patch timeline: Monitor for vendor response or regulatory intervention by CISA/FCC regarding CVE-2026-75501.
  • Zimbra exploitation attribution: Watch for coordinated advisories from U.S., Polish, or EU cyber authorities linking CVE-2026-73570 to state-aligned actors.
  • UAT-10147 tooling proliferation: Track adoption of AI-assisted exploitation frameworks (PentestGPT, DeepAudit) by additional Chinese-speaking cybercrime groups.
  • ToxicPanda 2.0 distribution: Monitor for expanded targeting beyond current 349 financial apps and 16 countries.
  • WordlistLoader/SynkLoader campaigns: Watch for evolution of ClickFix social engineering and Microsoft Teams phishing tactics.
  • South Korean key management incident: Track regulatory response and potential audit of government-backed digital platforms.

---

Sources

  • BleepingComputer: [Unpatched Calix flaw lets hackers bypass NAT to expose internal devices](https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/)
  • BleepingComputer: [Hackers target WordPress sites in miniOrange auth bypass attacks](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/)
  • BleepingComputer: [CISA orders urgent patching of actively exploited Zimbra flaw](https://www.bleepingcomputer.com/news/security/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw/)
  • BleepingComputer: [ReliaQuest confirms failed data-theft attack after ShinyHunters breach](https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/)
  • BleepingComputer: [South Korean startup platform breach exposes key management failures](https://www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/)
  • BleepingComputer: [Microsoft: August updates break printing, PDF export in WPF apps](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-updates-break-printing-pdf-export-in-wpf-apps/)
  • BleepingComputer: [ToxicPanda Android malware uses VPN permissions to block Google Play](https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/)
  • The Hacker News: [Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account](https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html)
  • The Hacker News: [Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor](https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html)
  • The Hacker News: [UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit](https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html)
  • The Hacker News: [Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html)
  • The Hacker News: [WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords](https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html)