# Threat Intel Brief — August 27, 2026
TL;DR
- Critical Oracle WebLogic flaw (CVE-2026-21962, CVSS 10.0) under active exploitation; CISA orders federal agencies to patch within 48 hours.
- FBI disrupts Chinese state-sponsored QTFY infrastructure targeting U.S. critical infrastructure including NASA, Federal Reserve, and DoJ.
- Ubiquiti patches three maximum-severity RCE vulnerabilities affecting UniFi Protect, Talk, and OS products; over 100,000 instances potentially exposed.
- Unpatched Kaltura mwEmbed flaws (CVE-2026-19912, CVE-2026-19913) enable unauthenticated file read and remote code execution; vendor unresponsive.
- Iranian APT Nimbus Manticore expands toolset with TWOSTROKE-like backdoor; identified as among most active Iranian groups in 2026.
---
Critical Threats
Oracle WebLogic Server Under Active Exploitation
What happened: CISA added CVE-2026-21962 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog on August 26, 2026, following confirmed exploitation attempts against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The improper access control flaw allows unauthenticated attackers with network access via HTTP to access, create, delete, or modify critical data. Exploitation activity was first observed in February 2026 from IP 193.24.123[.]42, with attackers chaining this vulnerability alongside legacy WebLogic flaws dating to 2017–2020.
Impact: Complete compromise of accessible data on vulnerable WebLogic instances. Federal agencies under Binding Operational Directive 26-04 must remediate by August 28, 2026. Organizations running internet-facing WebLogic deployments face immediate risk of unauthorized data access, credential theft, and potential ransomware deployment. The vulnerability's maximum severity and unauthenticated exploitation vector make it attractive for both cybercriminal and state-sponsored operations.
Recommendations:
- Apply Oracle Critical Patch Update from January 2026 immediately to all Oracle HTTP Server and WebLogic Server Proxy Plug-in instances.
- Block or restrict HTTP access to WebLogic from untrusted networks at firewall/WAF level until patching is complete.
- Review access logs since February 2026 for indicators of compromise, particularly connections from IP 193.24.123[.]42.
- Monitor for HTTP requests to WebLogic console paths and proxy plug-in endpoints from suspicious sources.
---
Gitea Remote Code Execution Exploited in Wild
What happened: CISA confirmed active exploitation of CVE-2026-60004, a critical remote code execution vulnerability in Gitea self-hosted Git service versions prior to 1.27.1. Attackers with repository write access can execute arbitrary shell commands via the diffpatch API endpoint. Default configurations allowing self-registration enable unauthenticated attackers to create accounts and exploit the flaw. Cryptocurrency mining malware has been deployed on compromised servers.
Impact: Approximately 5,000 Gitea instances are exposed online. Successful exploitation grants attackers OS-level command execution as the Gitea service account, enabling data exfiltration, lateral movement, and persistent access. Federal agencies must patch by August 28, 2026 under BOD 26-04.
Recommendations:
- Upgrade all Gitea instances to version 1.27.1 or later immediately.
- Disable self-registration in Gitea configuration if immediate patching is not possible.
- Audit existing user accounts and repositories for suspicious registrations since July 2026.
- Monitor Gitea service processes for unexpected child processes, cryptocurrency miners, or outbound connections to mining pools.
- Restrict network access to Gitea instances using firewall rules or VPN-only access.
---
Ubiquiti Maximum-Severity Vulnerabilities Patched
What happened: Ubiquiti released patches for three maximum-severity (CVSS 10.0) vulnerabilities affecting UniFi Protect Application (CVE-2026-77537), UniFi OS Server (CVE-2026-77550), and UniFi Talk Application (CVE-2026-77554). All three flaws allow unauthenticated remote code execution without user interaction. Over 100,000 UniFi OS instances are potentially exposed online.
Impact: Unauthenticated attackers can achieve full device compromise of UniFi video surveillance, VoIP, and OS management platforms. Historical targeting of Ubiquiti products by state-sponsored groups (including GRU operations) and recent CISA emergency directives for similar UniFi OS flaws underscore the strategic value of these devices for botnet recruitment and espionage infrastructure.
Recommendations:
- Update UniFi Protect Application to version 7.2.105 or later immediately.
- Update UniFi Talk Application to version 5.3.2 or later immediately.
- Update UniFi OS Server to version 5.1.22 or later (versions 5.1.21 and earlier affected).
- Audit network exposure of all UniFi OS instances and restrict management interfaces from internet access.
- Review device logs for unauthorized access attempts or configuration changes between initial disclosure and patching.
---
Unpatched Kaltura mwEmbed Vulnerabilities Enable RCE
What happened: CERT/CC disclosed two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 video player library. CVE-2026-19913 allows remote unauthenticated attackers to read arbitrary server files including configuration files containing database credentials, admin passwords, and API keys. CVE-2026-19912 enables remote code execution via unsafe deserialization combined with path traversal. Both flaws affect Kaltura mwEmbed library v2.45, v2.103, and earlier v2.x releases. The vendor has been unresponsive to coordination attempts.
Impact: Multi-tenant environments face cross-customer risk due to shared CDN infrastructure. Attackers can exfiltrate sensitive credentials and execute code as the web server user. The vulnerable code has been present since at least March 2014 through the current release (West-23.5.0, August 2026). No patch is available.
Recommendations:
- Block or remove the mwEmbedLoader.php endpoint at WAF, reverse proxy, or CDN if legacy mwEmbed players are not actively served.
- Implement strict allow-list for the ServiceUrl parameter permitting only the deployment's own API host.
- Reject uiconf_id parameter values containing directory traversal sequences at the application or WAF layer.
- Deny PHP execution in Kaltura cache directories via web server configuration.
- Rotate all credentials in /opt/kaltura/app/configurations/local.ini if the endpoint has been externally accessible.
---
Threat Actor Activity
FBI Disrupts Chinese State-Sponsored QTFY Infrastructure
The U.S. Department of Justice disrupted QScan and QTRouter platforms operated by Chinese state-sponsored threat actor QTFY, employed by Nanjing Xinjiuwei Network Technology Company. Court documents reveal the company received payments from China's Ministry of State Security (MSS) and includes former People's Liberation Army (PLA) members. QTFY functioned as a digital quartermaster providing reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations.
Targets: Confirmed victims include NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and U.S. Senate. The group demonstrated strong preference for academia and research communities, exploiting collaborative environments to access cutting-edge research and government operations.
TTPs: QTFY exploited zero-day and N-day vulnerabilities across multiple platforms including Ivanti CSA (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380), Fortinet SSL-VPN (CVE-2018-13379), Citrix ADC (CVE-2019-19781), Microsoft Exchange (CVE-2021-26855), F5 BIG-IP (CVE-2020-5902), Apache Log4j (CVE-2021-44228), Atlassian Confluence (CVE-2023-22515), Check Point Quantum Gateway (CVE-2024-24919), and others. The group used QScan for reconnaissance and automated IoT device compromise, building botnets for the QTRouter obfuscation network. Traffic was routed through compromised IoT devices and commercial proxy services to evade IP-based defenses.
Defensive actions: Prioritize patching of vulnerabilities exploited by QTFY. Monitor for anomalous traffic patterns from geographically proximate IoT devices and commercial proxy services. Implement network segmentation and zero-trust architecture to limit lateral movement. Harden IoT devices and edge infrastructure against compromise.
---
Iranian APT Nimbus Manticore Expands Capabilities
Cybersecurity researchers discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, UNC1549), an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). The group is identified as among the most active Iranian APT groups in 2026.
Toolset: The expanded arsenal includes a C++ backdoor sharing similarities with TWOSTROKE, capable of system information collection, DLL loading, file manipulation, and persistence establishment. The backdoor masquerades as Windows terminal server SDK DLL (wtsapi32.dll) and uses hard-coded C2 servers for HTTPS-based command execution. A reverse SSH tunneling tool establishes connections to operator infrastructure on port 443 (172.86.98[.]113).
Targets: Historically targeted defense, aerospace, IT service providers, and military organizations primarily in the Middle East and the United States. Recent infrastructure discoveries suggest expanded targeting profile focusing on Middle Eastern countries alongside European nations.
Defensive actions: Monitor for suspicious processes masquerading as legitimate Windows DLLs, particularly wtsapi32.dll. Implement network monitoring for unusual SSH connections on non-standard ports. Deploy behavioral detection for HTTPS C2 communications with hard-coded server destinations. Enhance email security controls targeting job opportunity-themed social engineering lures associated with Dream Job campaigns.
---
West African Cybercrime Networks Disrupted
INTERPOL Operation Jackal IV, an eight-month coordinated international operation involving 22 countries across six continents, resulted in the arrest of 58 suspects and identification of 263 others involved in cyber fraud and organized crime. The operation targeted West African criminal networks including Black Axe and similar groups engaged in global cyber fraud activities including romance scams, cryptocurrency fraud, business email compromise (BEC), and sextortion.
Scale: South African operations seized $2.67 million and blocked 257 bank accounts. Romanian operations identified €143 million in losses from a single call center operation. The operation identified 196 individuals linked to a major Crime-as-a-Service network in Argentina.
Defensive actions: Implement enhanced email authentication controls (SPF, DKIM, DMARC) and anomaly detection for BEC attempts. Deploy behavioral analytics on financial systems to detect unusual wire transfer patterns and cryptocurrency transactions. Establish user awareness training addressing romance scams, cryptocurrency investment fraud, and sextortion tactics.
---
Geopolitical Context
U.S. Sanctions Iranian Cyber Actors
The U.S. Department of the Treasury announced sanctions against Iranian cyber actors linked to critical infrastructure breaches as part of Operation Economic Outcast, an "unprecedented, whole-of-government, economic campaign" against Iran. The action designates nearly 60 entities across nuclear, missile, oil, cyber, and digital assets networks, with particular focus on secondary sanctions to isolate Iran financially.
Five individuals affiliated with Iran's Ministry of Intelligence and Security (MOIS) and the Mabna Institute were sanctioned and indicted for network compromises of U.S. critical infrastructure since late 2023, including energy companies, defense contractors, healthcare institutions, IT companies, financial institutions, and government offices. The Treasury also designated U.K.-based cryptocurrency exchanges Zedcex and Zedxion, which allegedly processed approximately $1 billion for the Islamic Revolutionary Guard Corps (IRGC). A $10 million Rewards for Justice bounty was announced.
Activity intensified following U.S. and Israeli airstrikes against Iran beginning February 2026, with summer 2024 breaches of government offices, 2025 Iranian telecom targeting, and recent 2026 attacks on over 30 water and wastewater utilities across at least 12 U.S. states.
---
Norway's Digital Government Infrastructure Under DDoS Attack
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since August 25, 2026, affecting services used by the public sector. This marks the third such incident in recent months (following attacks in June and early August). The attack targets Digitaliseringsdirektoratet (Digdir), which operates critical national services including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.
Norwegian media have speculated about potential Russian involvement, though no official attribution has been issued. Norway's strategic position as a NATO member, major energy exporter to Europe, and Arctic stakeholder places it within a contested geopolitical environment where cyber operations serve as tools of statecraft below the threshold of armed conflict.
---
Recommended Actions
Immediate (0–24 hours)
- Patch Oracle WebLogic Server to address CVE-2026-21962 (CVSS 10.0) under active exploitation.
- Upgrade Gitea to version 1.27.1 or later; disable self-registration if patching is delayed.
- Update Ubiquiti UniFi products to address three maximum-severity RCE vulnerabilities.
- Mitigate Kaltura mwEmbed exposure by blocking mwEmbedLoader.php endpoint or implementing strict input validation (no patch available).
- Rotate credentials for systems potentially exposed to Kaltura vulnerabilities or QTFY reconnaissance.
Within 24–72 hours
- Audit Gitea, Oracle WebLogic, and Ubiquiti deployments for indicators of compromise since February 2026.
- Implement network segmentation to restrict access to critical infrastructure management interfaces.
- Review authentication logs for anomalous patterns consistent with session hijacking or credential theft.
- Deploy behavioral detection for proxy-based C2 communications and commercial proxy service abuse.
This week
- Conduct threat hunting for QTFY infrastructure abuse, focusing on compromised IoT devices and commercial proxy traffic.
- Enhance email security controls to detect BEC attempts, phishing campaigns, and social engineering lures.
- Implement phishing-resistant authentication (FIDO2/WebAuthn) to mitigate adversary-in-the-middle attacks.
- Review and harden AI infrastructure against credential harvesting and cryptomining attacks targeting LiteLLM gateways and similar platforms.
- Establish incident response procedures for DDoS attacks against critical digital infrastructure.
---
Watch List
- Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520): Active exploitation confirmed; public PoCs available.
- Xecurify miniOrange SAML plugin (CVE-2026-61979, CVE-2026-15981): Unauthenticated authentication bypass enabling WordPress admin access; active scanning observed.
- Zimbra Collaboration Suite: Over 270 instances compromised via remote code execution attacks; CVE not yet publicly assigned.
- PostgreSQL RCE vulnerability: Proof-of-concept exploit available; CERT.BE advises immediate patching (CVE: see source).
- OAuth2 Proxy authentication bypass: Critical vulnerability disclosed by CERT.BE; CVE not yet assigned.
- Mirage2FA phishing campaign: Targeting 4,500+ US and EU organizations via Microsoft 365 AitM attacks; 48% potential compromise rate.
- NovaCookies PhaaS toolkit: $320/month subscription service abusing DocuSign notifications for Microsoft 365 session hijacking.
- AnonyMousKIT PhaaS platform: Voice AI agents automating iPhone passcode theft and Activation Lock bypass.
---
Sources
- CISA Known Exploited Vulnerabilities Catalog
- U.S. Department of Justice
- U.S. Department of the Treasury
- CERT/CC
- CERT.BE (Belgium)
- CERT.at (Austria)
- INTERPOL
- Microsoft Threat Intelligence
- BleepingComputer
- The Hacker News
- Proofpoint
- ANY.RUN
- Group-IB
- Kaspersky
- Wordfence
- Black Lotus Labs (Lumen)
- SOCRadar
- Oasis Security
