Afternoon edition
Cyber Decisions, On The Record
Sealed — full session on the record
RoundtableScheduled · Afternoon

BeyondTrust Comes Offline: Remote Support Is Too Privileged To Patch Later

A remote-support auth bypass is not another appliance bug; it is the path admins use to touch everything else. BeyondTrust public reachability lost to the risk of handing attackers the help desk.

Panel aligned135 sources5 findings13 voices

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Key findings

What the panel logged · 12

Active exploitation should reorder response toward exposure validation and compromise checks for Oracle EBS, SharePoint, ColdFusion, NetScaler, and Gitea Docker rather than patch-ticket handling alone.

Containment should precede patching: isolate exposed systems, preserve logs, reset trust state, then patch or rebuild according to exposure and evidence.

These are not just password incidents; attacker-held trust state includes sessions, refresh tokens, OAuth grants, remembered devices, contractor access, and downstream app sessions.

JadePuffer reflects human-directed intrusion using agentic tooling as an automation layer, not fully autonomous ransomware.

Exposed AI workflow tooling such as Langflow should be governed like privileged automation or CI/CD because it can execute code, access secrets, and call cloud APIs.

Attribution confidence should remain segmented: UAT-7810/Ruckus ORB activity is high-confidence and actionable, while broader actor labeling around Roundcube and several state-linked stories remains less certain.

Roundcube compromises are urgent because session theft, MFA capture, webshells, and backdoors can persist after password resets.

A blanket engineering freeze is unwarranted; response should be scoped to package publishing paths, CI/CD jobs with secrets or write permissions, and dependency-promotion boundaries.

Crypto and fraud incidents share a common control failure: systems accepted formally valid instructions without validating economic intent or safety.

For OT exposure, the emergency action is reachability reduction upstream of controllers; do not reboot PLCs, change logic, or make unsafe segmentation changes during live operations.

Legal and notification triggers depend on confirmed unauthorized access, exfiltration, service disruption, regulated data impact, or payment decisions—not vulnerability headlines alone.

BeyondTrust RS/PRA authentication bypass should be treated as an identity-boundary failure with privileged credential and session blast radius beyond the appliance itself.

Recommended actions

What to do about it · 16

  1. Action 01criticalDefense Architect

    Remove public reachability or apply emergency mitigations for internet-facing Oracle E-Business Suite, then hunt for compromise before patching.

  2. Action 02criticalDefense Architect

    Remove public reachability for internet-facing SharePoint Server, preserve evidence, and treat exposed instances as hunt-as-compromised before patching.

  3. Action 03criticalDefense Architect

    Isolate or access-control internet-facing Adobe ColdFusion immediately, preserve logs, then patch and hunt.

  4. Action 04criticalDefense Architect

    Restrict external and management-plane exposure for NetScaler, preserve configuration and logs, and promote to assume-compromised if probes or anomalies are present.

  5. Action 07criticalICS/OT Defender

    Cut direct internet access to Rockwell/Allen-Bradley remote-access paths and allow only break-glass access via VPN or jump host with MFA and named approvals.

  6. Action 08criticalIdentity Architect

    Revoke trust state tied to affected platforms, including active sessions, refresh tokens, OAuth grants, device-code authorizations, remembered devices, contractor access, and third-party sessions.

  7. Action 09criticalIdentity Architect

    Remove BeyondTrust RS/PRA from direct internet exposure where possible, kill active appliance sessions, rotate related tokens and privileged credentials, and review federation bindings.

  8. Action 11highIntel Analyst

    Patch or reduce exposure on Ruckus edge devices and hunt routers for persistence associated with UAT-7810 ORB expansion tooling.

  9. Action 12highSupply Chain Analyst

    Freeze package publishing paths in affected dependency chains until maintainer accounts, registry tokens, release assets, tag history, and provenance are verified.

  10. Action 13highSupply Chain Analyst

    Freeze CI/CD workflows that accept external inputs and also hold secrets, id-token, package publish rights, or cloud credentials; review workflow composition flaws and credential exposure paths.

  11. Action 14highSupply Chain Analyst

    Pause promotion of new dependencies and version bumps until lockfiles, hashes, and artifact-proxy logs are reviewed; allow pinned builds using known-good cached artifacts to continue.

  12. Action 16highRegulatory

    Preserve authentication, application, cloud, EDR, asset inventory, patch-timestamp, attacker-IP, and admin-session evidence before making notification decisions; escalate immediately if unauthorized access, exfiltration, disruption, regulated data exposure, or ransom payment is confirmed.

  13. Action 05highAI Security

    Remove direct internet exposure from Langflow, rotate cloud/API credentials accessible from the environment, sandbox tool execution, and restrict agent permissions before restoration.

  14. Action 06highThreat Hunter

    Patch and restrict exposure for Gitea Docker while inspecting container logs and authentication events; do not assume compromise from probing alone.

  15. Action 10highIntel Analyst

    Hunt Roundcube environments for phishing-driven session theft, MFA capture, PHP webshells, Go backdoors, and persistence that survives password resets; invalidate sessions and strengthen phishing resistance.

  16. Action 15verifyCrypto & FinCrime

    Treat DAO governance capture, flash-loan valuation abuse, weak wallet entropy, and prompt-injected payment agents as board-level control failures; add timelocks, quorum and price-manipulation checks, transfer caps, out-of-band verification, and transaction-path review.

Research trail

Research trail

Who searched, who cited

Panel: 9 searches · 109 sources consulted · 38 cited

  • 3
    Arjun Patel
    2 searches22 consulted
  • 4
    Viktor Petrov
    0 searches0 consulted
  • 2
    James Okafor
    1 search19 consulted
  • 4
    Sara Kovacs
    3 searches24 consulted
  • 7
    Marcus Vale
    1 search15 consulted
  • 1
    Lena Hartmann
    0 searches0 consulted
  • 8
    Sofia Andersen
    2 searches29 consulted
  • 7
    Tomas Ilic
    0 searches0 consulted
  • 2
    Alex Mercer
    0 searches0 consulted

Per-expert queries and consulted sources are recorded on the session transcript

Sign in to preview the research trail detail (moves to Pro at launch).

Sign in to preview query and source lists.

Entities

In this session

Moderator framing

This afternoon is busy, but not random. The common thread is trusted platforms turning into attacker paths: Oracle E-Business Suite, SharePoint, ColdFusion, NetScaler, Gitea, Langflow, Roundcube, Ruckus routers, even DeFi governance and package maintainers.

I don’t want us hypnotized by the AI-agent ransomware headline and miss the simpler emergency: exposed enterprise systems are being exploited now, with patches available and measurable attack surface still online. JadePuffer matters because it may compress the intrusion timeline, but SharePoint, Oracle, NetScaler, ColdFusion, and Rockwell access are the decisions CISOs have to make before dinner.

So we’ll spend real airtime on four lanes: first, exploited internet-facing enterprise platforms; second, Langflow and what agentic automation actually changes in ransomware; third, China-linked Roundcube/Ruckus activity and developer supply-chain compromise; fourth, DeFi governance and identity abuse where money or tokens move fast. Deepfake fraud, mobile patches, policy updates, and the long advisory list stay in monitoring unless they change today’s action.

Alex, I’ll come to you first for exploitability and exposure realism.

Marcus and James, be ready to translate that into containment. Arjun, I want you sharp on what is real AI-enabled intrusion versus branding. And Lena — keep us honest on attribution.

— Moderator
How to read this record →
Mobile conversation map

Open this page on desktop for the full visual network.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Action 1

Dispatch Parallel

Alex, take the exposed-platform lane only. Using the source pack plus the CyberBrief corpus confirmation: Oracle E-Business Suite CVE-2026-46817 is under active exploitation against roughly 950 exposed instances, with prior reporting describing unauthenticated...

Alex MercerExploit feasibility lens

Moderator assignment

Alex, take the exposed-platform lane only. Using the source pack plus the CyberBrief corpus confirmation: Oracle E-Business Suite CVE-2026-46817 is under active exploitation against roughly 950 exposed instances, with prior reporting describing unauthenticated HTTP access to the Oracle Payments File Transmission/ibytransmit path on EBS 12.2.3–12.2.15; SharePoint Server CVE-2026-45659 is in CISA KEV; ColdFusion CVE-2026-48282 and NetScaler CVE-2026-8451 are being exploited or scanned; Gitea Docker CVE-2026-20896 is being probed. Give me a decision-ready exploitability ranking for the next 24 hours: which systems are 'assume compromised if exposed,' which are 'patch/isolate now,' and which are 'hunt but do not panic.' Do not recap CVSS — translate kill-chain closure into CISO action.

Response

Halil, my 24-hour ranking is blunt:

PriorityBucketSystem / CVECISO action
1Assume compromised if exposedOracle E-Business Suite CVE-2026-46817If internet-facing, isolate first, then patch. Treat as data-access/extortion exposure, not maintenance. Review access to /ibytransmit, Oracle Payments/File Transmission activity, new accounts, outbound staging, and exfil paths.
2Assume compromised if exposedSharePoint Server CVE-2026-45659KEV plus active exploitation closes the chain. Auth required does not save you if SharePoint is exposed and broad Site Member access exists. Patch, restrict access, and hunt for post-exploitation tooling and persistence.
3Patch/isolate nowAdobe ColdFusion CVE-2026-48282Active exploitation reported. Internet-facing ColdFusion should be isolated or access-controlled immediately, then patched. Hunt, but I rank it below Oracle/SharePoint because the exposed-count and post-exploitation detail are weaker in the evidence I have here.
4Patch/isolate nowNetScaler CVE-2026-8451Edge appliance plus exploitation/scanning means do not wait. Patch or pull from direct internet exposure. If logs show matching probes or anomalies, promote to assume-compromised.
5Hunt but do not panicGitea Docker CVE-2026-20896Probing is not the same as confirmed compromise. Patch, restrict admin/API exposure, inspect container logs and auth events, but do not burn the incident-response weekend unless you see exploit telemetry.

The kill-chain difference is the whole story. Oracle EBS is the worst: unauthenticated HTTP against a payments/file-transfer path on exposed ERP is like leaving the loading dock open next to the finance vault. SharePoint is next because KEV plus observed post-exploitation means attackers are already past “can this work?” ColdFusion and NetScaler are urgent edge cleanup. Gitea Docker is watch-and-harden unless probing turns into execution evidence.

James OkaforDefensive response lens

Moderator assignment

James, listen to the same exposed-platform evidence but answer as the defensive closer: if a CISO has 30 minutes and cannot patch everything at once, what exact sequence should they authorize tonight across Oracle EBS, SharePoint Server, ColdFusion, NetScaler, Gitea Docker, and Rockwell Allen-Bradley PLC remote access? Include isolation versus patching, identity/session resets, log sources to pull first, and where business outage is justified.

Response

If the CISO has 30 minutes, I would not start with patching. I’d authorize containment first, then evidence, then trust reset, then patching by exposure. We have visible evidence of active exploitation for Oracle E-Business Suite CVE-2026-46817 and SharePoint Server CVE-2026-45659, and a serious Rockwell/Allen-Bradley PLC remote-access exposure warning tied to nation-state targeting. For ColdFusion, NetScaler, and Gitea Docker, I do not have current advisory or patch evidence visible here, so tonight’s decision should be exposure reduction and log capture first, not blind patch claims.

Tonight’s authorization sequence:

1. Immediate isolation / outage justified - Rockwell Allen-Bradley PLC remote access: cut direct internet access now. Business outage is justified if remote engineering access depends on exposed PLC paths. Allow only break-glass access through VPN/jump host with MFA and named approvals. - Oracle EBS and SharePoint Server if internet-facing: remove public exposure or put behind VPN/WAF allowlist immediately. If that breaks external users, accept the outage tonight. - NetScaler if it fronts identity/VPN: do not power it off blindly, but restrict management plane and external access to known ranges; preserve config first. - ColdFusion and Gitea Docker: block public access unless there is a confirmed business-critical need; keep internal access only.

2. Pull logs before resets or patching - Oracle EBS: web/app access logs, EBS application logs, DB audit logs, SSO/IdP logs. - SharePoint: IIS logs, ULS logs, Windows Security logs, PowerShell logs, webshell/file-write locations. - ColdFusion: web server logs, ColdFusion application/exception logs, admin login logs. - NetScaler: ns.log, audit logs, VPN/AAA logs, configuration backup, management login history. - Gitea Docker: container logs, reverse proxy logs, Git over SSH/HTTP logs, Docker daemon logs, database audit if available. - Rockwell/OT: firewall/VPN logs, jump-host logs, engineering workstation Windows logs, Studio 5000/FactoryTalk activity where enabled, PLC change records if available.

3. Trust reset after containment - Reset privileged/admin sessions for Oracle EBS, SharePoint, ColdFusion admin, NetScaler admin/VPN, Gitea admin, and OT remote-access accounts. - Revoke active sessions/tokens where the platform supports it. - Rotate service credentials only after you have captured evidence, otherwise you lose timeline clarity.

Patch order after that: Oracle EBS and SharePoint first because active exploitation is visible in the evidence; Rockwell exposure remediation is equal priority but handled as isolation/remote-access shutdown, not normal IT patching. NetScaler, ColdFusion, and Gitea Docker go into the next maintenance wave unless the SOC finds compromise indicators tonight. The practical call: take the outage on exposed OT, public EBS, and public SharePoint; preserve logs everywhere; then patch only the confirmed exploited platforms first.

Marcus ValeIdentity security lens

Moderator assignment

Marcus, focus on the identity and trust-state failures cutting across the briefing: Microsoft Device Code Flow phishing stealing tokens, AdaptHealth's third-party cloud session compromise, Roundcube session/MFA harvesting, Oracle/SharePoint business app exposure, and Langflow/cloud credential theft. What are the identity actions that matter tonight beyond password resets — token/session revocation, OAuth/device-code controls, contractor access, service accounts, API keys, non-human identities — and where would teams most likely under-respond?

Response

Halil, the big identity point tonight is: don’t treat these as password incidents. The evidence I have solidly in front of me says the Microsoft item is Device Code Flow phishing stealing account tokens, and the AdaptHealth item involved social engineering against a third-party contractor session to access cloud business apps, patient management/document storage, and external EHR portals. That is attacker-held trust state: sessions, refresh tokens, app grants, remembered devices, contractor entitlements — not just passwords.

For tonight, I’d sequence actions like this: revoke active sessions and refresh tokens for affected users; disable or tightly scope OAuth Device Code Flow where it is not explicitly needed; review suspicious OAuth consent grants and app registrations; remove remembered MFA devices; invalidate contractor sessions; and re-evaluate third-party access with conditional access, device compliance, and least privilege. For AdaptHealth-style exposure, disabling the contractor account and resetting credentials is necessary, but incomplete unless cloud sessions, delegated app tokens, external portal access, and any downstream EHR/document-system sessions are also killed.

For Roundcube session/MFA harvesting, Oracle/SharePoint business app exposure, and Langflow/cloud credential theft, I don’t have enough confirmed detail here to assert mechanics beyond the briefing labels. But the under-response pattern is predictable: teams reset human passwords while leaving API keys, service accounts, OAuth tokens, SAML/OIDC sessions, app passwords, and cloud workload credentials alive. Langflow-type cloud credential theft especially needs a non-human identity sweep: rotate exposed cloud keys, replace static secrets with workload identity federation, inspect CI/CD and app environment variables, and hunt for newly created access keys or privilege changes.

Where teams will most likely under-respond: contractors, legacy auth paths, and non-human identities. They’ll fix the named user and miss the trust chain around them. My minimum bar tonight is phishing-resistant auth for high-risk users and contractors, device-code restrictions, short-lived tokens, continuous access evaluation where supported, and a forced inventory of OAuth apps, API keys, service accounts, and external business-app permissions.

Arjun PatelAI security lens

Moderator assignment

Arjun, separate signal from hype on the AI lane. Sysdig says JadePuffer exploited Langflow CVE-2025-3248 and used an LLM agent to automate reconnaissance, credential harvesting, lateral movement, privilege escalation, data theft, and encryption while a human supplied victim selection, infrastructure, and credentials. Zscaler also reports indirect prompt injection causing agent-driven crypto payments, and OpenAI Codex macOS has a prompt-injection data-leak path. What has actually changed for defenders this afternoon? Give me the minimum controls for exposed AI dev tooling and autonomous agents, and be explicit about what we should not overclaim.

Response

Halil, the change this afternoon is not “AI ransomware went autonomous.” The real shift is that agentic tooling is now part of the intrusion chain: Sysdig’s JADEPUFFER reporting frames the LLM agent as an automation layer over an already human-directed operation — victim selection, infrastructure, and credentials still came from the operator. That matters because defenders should treat AI agents like privileged automation systems, not like chatbots.

For exposed AI dev tooling, the minimum controls are: patch or remove internet-facing Langflow immediately, especially around CVE-2025-3248; require authentication and network isolation for workflow builders; strip secrets from agent runtimes; block direct cloud metadata and database access unless explicitly needed; and log every agent tool call, shell command, credential read, and outbound connection. If an AI workflow can run code, query databases, or call cloud APIs, it belongs behind the same controls as CI/CD and admin automation.

For autonomous agents, the minimum is: tool allowlists, egress allowlists, human approval for money movement/destructive actions, secret-scoped sessions, prompt/content provenance checks, and no rendering of remote content from model output by default. The Codex macOS issue is a clean example: NVD says indirect prompt injection could cause Codex to construct a remote image URL containing sensitive data from the session, including API keys or source code, with no known exploitation in the wild. That is not model sentience; it is classic data exfiltration through an unsafe rendering/tool boundary.

What we should not overclaim: we should not say JADEPUFFER proves self-directed malware, or that every LLM agent can autonomously ransomware a network. We can say the attacker work factor is dropping when agents sit on privileged tool boundaries. And Zscaler’s crypto-payment scenario reinforces the same point: the dangerous primitive is not “AI thinking,” it is untrusted instructions reaching an agent that can spend money, move data, or execute actions.

Peer consultations
James OkaforArjun Patel

Arjun Patel asked James Okafor.

James, I’ve got Sysdig evidence that JADEPUFFER exploited internet-facing Langflow via CVE-2025-3248, where NVD describes Langflow before 1.3.0 as missing auth/code execution and CISA KEV-listed, and Sysdig says the operator used an AI agent to run an automated database-extortion playbook. I also have NVD evidence for CVE-2026-14898 in OpenAI Codex macOS: indirect prompt injection could make the app render a remote image URL containing secrets from the Codex session, with no known exploitation in the wild. For a minimum defensible control set, what would you prioritize operationally for exposed AI dev tooling and agentic workflows—especially around network exposure, secret scope, egress, and agent permissions?

This cross-question did not return a public answer.

Checkpoint

What sharpened here is that the urgent picture is not one single “patch everything” story; it is an exposure-and-trust-state story. Alex put Oracle E-Business Suite CVE-2026-46817 and SharePoint Server CVE-2026-45659 at the top because the evidence points to active exploitation, and in Oracle’s case roughly 950 exposed instances. James reinforced the operational consequence: if those systems are internet-facing tonight, containment may matter more than orderly patch sequencing. Isolate or restrict first, preserve evidence, then patch by exposure and business risk.

The second thing the room learned is that the identity layer is carrying a lot of the blast radius. Marcus made the key distinction: these are not just password compromises. Device Code Flow phishing, contractor session compromise, cloud app access, external EHR/document portals, MFA/session harvesting, and broad business-application exposure all point to stolen or abused trust state. So the defensive move is not merely “reset credentials”; it is revoke sessions, kill refresh tokens, review OAuth grants, remove remembered MFA devices, constrain contractor access, and re-establish conditional access around verified devices and least privilege.

On the AI side, Arjun gave us a useful correction against hype. The reported Langflow/JadePuffer activity should not be framed as fully autonomous AI ransomware based on what we have here. The more defensible conclusion is that agentic tooling is being folded into intrusion operations as an automation layer while humans still provide victim selection, infrastructure, and credentials. That means defenders should govern exposed AI workflow builders like CI/CD or privileged admin automation: network isolation, authentication, secrets control, tool and egress allowlists, and detailed logging of agent actions.

There are also caveats. James explicitly did not confirm current advisory or patch evidence for every named platform in the prompt, especially ColdFusion, NetScaler, and Gitea Docker, so the safer recommendation there is exposure reduction and log capture until advisory details are verified. The next turn should widen the lens from emergency containment into campaign continuity: who is behind some of this activity, how developer trust and release pipelines are being abused, how governance attacks are turning into crypto theft, and what the OT implications are for exposed Rockwell/Allen-Bradley environments.

Action 2

Dispatch Parallel

Lena, take the attribution and campaign-continuity lane. We have likely China-linked Roundcube exploitation against U.S. and Canadian universities using phishing, stolen logins/cookies/MFA inputs, deserialization, PHP webshells and a Go backdoor; Cisco Talos r...

Lena HartmannThreat intelligence lens

Moderator assignment

Lena, take the attribution and campaign-continuity lane. We have likely China-linked Roundcube exploitation against U.S. and Canadian universities using phishing, stolen logins/cookies/MFA inputs, deserialization, PHP webshells and a Go backdoor; Cisco Talos reports China-nexus UAT-7810 expanding an ORB network through unpatched Ruckus routers with LONGLEASH, DOGLEASH and JARLEASH; the pack also includes DPRK maintainer/package compromise, Iranian-linked Rockwell targeting, Russian activity against Ukrainian media, and Cavern Manticore against Israeli networks. What should we treat as high-confidence, what is merely plausible, and what changes defender action today?

Response

Halil, I’d split it this way.

High confidence: UAT-7810 expanding an ORB through unpatched Ruckus routers — Cisco Talos is the anchor, and the handoff marks the evidence strong and active. Treat LONGLEASH, DOGLEASH, and JARLEASH as campaign infrastructure tooling, not just malware trivia; defender action today is patch/exposure reduction on Ruckus edge devices and hunting for persistence on routers. Also high confidence: DPRK-linked developer/package compromise is real and continuing; the package-ecosystem pattern aligns with reported North Korean PolinRider activity and Lazarus-linked npm impersonation of Rollup tooling.

Moderate confidence: the Roundcube university campaign is China-linked and active, but I would not collapse it into a named Chinese actor without more pivots — domains, passive DNS, certificates, and malware lineage. The tactics are clear enough for action: phishing, credential/session theft, MFA capture, deserialization, PHP webshells, and a Go backdoor mean universities should prioritize Roundcube patching, session invalidation, webshell hunts, and MFA-resistant phishing controls.

Low confidence from what I can verify here: Iranian-linked Rockwell targeting, Russian activity against Ukrainian media, and Cavern Manticore against Israeli networks. They may be valid stories, but I don’t have enough visible campaign evidence in front of me to make an attribution call. ATT&CK-wise, the actionable cluster today is credential theft/session hijacking, exploitation of public-facing apps, webshell persistence, and compromised network-edge infrastructure — attribution can wait; those controls cannot.

Tomas IlicSupply-chain trust lens

Moderator assignment

Tomas, focus only on developer and software-supply-chain trust. The pack shows DPRK-linked compromise of maintainer accounts and GitHub repos with 162 malicious release artifacts across 108 npm/Go packages using blockchain/public RPC payload retrieval for DEV#POPPER RAT and OmniStealer; stolen Trivy credentials allegedly uploaded trojanized LiteLLM packages to PyPI with about 47,000 downloads in 46 minutes; Shai-Hulud/Hades self-reinforcing npm/PyPI credential harvesting; Kaspersky and Novee reporting large-scale GitHub Actions/Cordyceps CI/CD misconfigurations; and Gitea Docker CVE-2026-20896 header spoofing/impersonation under active probing. What exact trust boundaries should engineering freeze or verify tonight without causing a blanket shutdown?

Response

Halil, I would not freeze all engineering. I would freeze only the boundaries that can execute untrusted code, read secrets, or publish artifacts.

Tonight’s freeze list:

  1. Package publishing paths — freeze npm, PyPI, Go module, container, and GitHub release publishing for repos in the affected dependency path. Verify maintainer accounts, registry tokens, release assets, tag history, and provenance before reopening. This is where the Trivy/LiteLLM chain matters: reported evidence says a Trivy CI/CD compromise led to malicious Trivy releases and then LiteLLM PyPI token abuse despite 2FA.
  1. CI/CD workflows with secrets or write permissions — freeze GitHub Actions jobs triggered by PRs, issue comments, workflow_run, pull_request_target, or external inputs if they also have secrets, id-token, package publish rights, or cloud credentials. Kaspersky’s scan found broad GitHub Actions misconfiguration patterns, and Cordyceps reporting points to workflow composition flaws enabling credential theft, artifact poisoning, and privilege escalation.
  1. New dependency promotion — pause promotion of new npm/PyPI/Go dependencies and version bumps until lockfiles, hashes, and artifact-proxy logs are reviewed. Do not stop existing pinned builds that use known-good cached artifacts. For the DPRK-linked package/release-artifact cluster described in the pack, the key boundary is not “developers coding”; it is “who can cause our build to fetch and execute a malicious release artifact.”
  1. Credential-bearing developer and CI environments — rotate secrets only where there is execution evidence: systems that installed or ran suspicious LiteLLM/Trivy-linked versions, Shai-Hulud/Hades packages, or the affected npm/Go package set. PyPA guidance cited in reporting says users who installed and ran the malicious LiteLLM versions should assume credential exposure and revoke/rotate credentials.

For Gitea Docker CVE-2026-20896, treat any internet-facing Gitea behind proxy headers as a source-control identity boundary: freeze releases/merges from that instance until header trust, proxy stripping, patch level, and audit logs are verified. What should stay open: local development, read-only CI, tests with no secrets, and builds pinned to verified cached artifacts.

Viktor PetrovCrypto financial-crime lens

Moderator assignment

Viktor, take the crypto financial-crime lane. BonkDAO reportedly lost nearly $20 million after an attacker bought roughly $4–4.4 million in BONK voting power and passed a malicious governance proposal; Summer.fi paused compromised contracts after a $65.4 million flash loan manipulated LazyVault accounting and drained about $6 million; Ill Bloom weak wallet recovery phrase generation enabled theft from 431 wallets worth about $3.1 million; and Zscaler's prompt-injection testing showed AI agents manipulated into payments. What is the common control failure, and what should DAOs, vault operators, wallets, and custodians do immediately?

Response

Halil, the common failure is money-moving authority accepted a formally valid instruction without proving economic intent or safety. BonkDAO’s governance path treated purchased voting power and low-turnout quorum as sufficient authorization; Summer.fi’s vault path treated manipulated short-window accounting as redeemable value. Ill Bloom and Zscaler fit the same pattern as reported examples: weak seed generation and prompt-injected payment agents show authority was technically valid, but the control layer failed to ask, “Should this value movement be allowed?”

For DAOs, the immediate fix is not just “better voting.” Put treasury transfers behind timelocks, minimum participation thresholds, vote-locking/snapshot rules, executable proposal simulation, transfer caps, and emergency guardian/multisig review for abnormal outflows. In BonkDAO’s case, reporting says roughly $20 million was drained after an attacker accumulated about $4 million in BONK voting power, used Solana Realms governance, and some funds began moving toward exchanges — that is a time-to-freeze issue. Exchanges, bridges, and law enforcement need wallet clustering and freeze requests before the funds are bridged or peeled out.

For vault operators, Summer.fi is the accounting version of the same failure. Reporting says a $65.4 million flash loan distorted valuation/accounting in Lazy Summer/Fleet Commander logic, enabling about $6 million in losses, with proceeds swapped into DAI and routed through Uniswap V3. The immediate controls are same-block/short-window manipulation guards, TWAP or multi-source valuation, redemption invariant checks, per-epoch withdrawal limits, flash-loan-resistant accounting, and narrow contract pauses rather than broad panic where possible.

For wallets and custodians, the priority is to remove silent authority paths. Wallets should force migration if seed generation is suspect, revoke approvals, publish reproducible entropy/keygen audits, and push users toward hardware-backed recovery. Custodians and AI-payment systems should not let an agent or prompt directly authorize value movement: use transaction allowlists, address-book controls, velocity limits, human dual approval, chain-risk screening, and policy engines that treat payment intent as separate from text input.

Sara KovacsICS/OT safety lens

Moderator assignment

Sara, take the OT lane. CISA warns nation-state-linked actors, including Iranian-linked activity, are targeting internet-exposed Rockwell Automation Allen-Bradley CompactLogix and Micro850 PLCs using legitimate engineering tools rather than zero-days; the pack also cites Kaspersky Q1 2026 data showing malicious objects blocked on 19.6% of ICS computers across 10,052 malware families. What is the emergency plant-side action tonight, what should not be changed during operations, and how should IT/security coordinate with control engineers without creating safety risk?

Response

Halil, the emergency action tonight is reachability reduction, not controller surgery. CISA says internet-connected OT devices, including Rockwell Automation/Allen-Bradley PLCs, are being exploited across critical infrastructure, with disruption tied to project-file interaction and HMI/SCADA display manipulation. Nozomi’s analysis says the actors accessed CompactLogix and Micro850 devices with Rockwell’s Studio 5000 Logix Designer, so the immediate question is: can anyone from the internet, a vendor path, cellular router, VPN, or jump host reach Level 1/2 controllers? If yes, disconnect that path upstream — firewall, NAT, router, remote-access gateway — without touching the PLC runtime.

What should not change during live operations: no PLC firmware flashes, no program downloads, no controller reboots, no mode changes, no “restore known good” unless the process is in a controlled safe state and the control engineer owns the step. Also do not make blind segmentation changes that might break HMI-to-controller, controller-to-I/O, or safety-system communications. A bad security change can become the incident — false trip on one side, missed trip on the other.

I checked with James, and we’re aligned: tonight is “isolate and watch.” Freeze engineering changes, revoke exposed/shared/vendor remote sessions, preserve VPN/firewall/cellular-router/jump-host/HMI/historian logs, and alert on new PLC sessions, project reads/writes, and HMI tag/display changes. Control engineers should validate running logic and HMI values against approved references, but IT/security should not drive changes directly on the plant floor. Kaspersky’s Q1 2026 figure — malicious objects blocked on 19.6% of ICS computers across 10,052 malware families — reinforces that this is not just one PLC campaign; Level 2/3 workstations and engineering stations need containment discipline too.

Peer consultations
James OkaforSara Kovacs

Sara Kovacs asked James Okafor.

James, I’m looking at CISA AA26-097A warning that Iranian-affiliated actors are exploiting internet-connected OT devices including Rockwell/Allen-Bradley PLCs across U.S. critical infrastructure, with disruptions from malicious interactions with project files and manipulation of HMI/SCADA displays. Rockwell also points operators to identify exposed assets and disconnect them from the public Internet. From a defensive sequencing perspective, what would you prioritize tonight that does not require rebooting controllers or changing control logic during operations?

Sara, tonight I’d authorize network isolation without touching controller runtime: remove PLCs from public Internet paths, shut down exposed cellular/router port-forwards, block inbound OT ports at the perimeter, and force any remote engineering through a VPN/jump host with MFA and named approval. If that breaks vendor remote support, take that outage — but do not reboot controllers or download new logic during operations.

Then preserve and restrict: freeze engineering changes, pull firewall/VPN/cellular router logs, jump-host and engineering-workstation Windows logs, HMI/SCADA/historian access logs, and any controller project upload/download/change records available. Disable shared/vendor remote accounts, revoke active VPN sessions, and alert on new PLC sessions, project reads/writes, and HMI tag/display changes. This is an “isolate and watch” night, not a “patch and reboot PLCs” night.

Checkpoint

The room now has four separate “control planes” in view, and they are not all solved by patching alone. Lena drew a useful confidence line: treat the Ruckus router ORB activity and DPRK-linked developer/package compromise as high-confidence, active problems; treat the Roundcube university campaign as actionable but not yet cleanly attributable to a named Chinese actor from the evidence here. That distinction matters. We can act on phishing, session theft, deserialization, webshells, Go backdoors, and exposed routers without overstating who is behind every piece.

Tomas then narrowed the software-supply-chain response in a way that should help engineering teams avoid panic. He is not saying “freeze development.” He is saying freeze the places where untrusted code can execute, secrets can be read, or artifacts can be published. That includes package publishing paths, risky CI/CD workflows with secrets or write permissions, and new dependency promotion until provenance, tokens, tags, release assets, lockfiles, and hashes are checked. The key caveat is that the exact affected repos and packages still need local validation, but the trust-boundary principle is immediately usable.

Viktor’s crypto lane gave us a broader pattern: formally valid authority can still be unsafe authority. In BonkDAO, the reported issue was governance power and process being enough to move value; in Summer.fi, manipulated accounting around a flash-loan path allegedly became redeemable value. The fix he emphasized is operational friction around abnormal value movement — timelocks, quorum quality, vote-locking, simulation, transfer caps, guardians, and rapid exchange or bridge coordination — not just better postmortems after funds move.

Sara’s OT guidance is the clearest “do no harm” message of this round. For internet-exposed Rockwell/Allen-Bradley environments, the emergency move is reachability reduction upstream, not live controller surgery. No blind firmware flashes, downloads, reboots, mode changes, or segmentation edits that could break process communications unless the control state and engineering ownership are clear. That leaves us with a practical handoff: James now needs to fold these lanes back into one defensible priority model, alongside the earlier Oracle EBS, SharePoint, ColdFusion, and NetScaler exposure findings.

Action 3

Follow Up

James, you are the closer now. Fold in the rest of the room: Alex ranked Oracle EBS exposed instances as assume-compromised first, with SharePoint/ColdFusion/NetScaler close behind; Marcus warned this is trust-state theft, not passwords; Arjun says JadePuffer...

James OkaforDefensive response lens

Moderator assignment

James, you are the closer now. Fold in the rest of the room: Alex ranked Oracle EBS exposed instances as assume-compromised first, with SharePoint/ColdFusion/NetScaler close behind; Marcus warned this is trust-state theft, not passwords; Arjun says JadePuffer is human-directed intrusion accelerated by agentic tooling, especially around exposed Langflow and cloud credentials; Lena separates high-confidence UAT-7810/Ruckus ORB activity from lower-confidence Roundcube attribution; Tomas wants a bounded freeze only on code-execution, secrets, and publish boundaries; Viktor says DeFi governance/vaults failed by accepting formally valid money-moving instructions without intent/safety checks; Sara says OT action is reachability reduction, not controller surgery. Give me the final CISO-ready 24-hour sequence: what gets isolated now, patched now, hunted as compromised, delegated to business owners, and kept to monitoring.

Response

Halil, the 24-hour call is: isolate first, patch the confirmed exploited edge systems second, reset trust state everywhere those systems touch. Now: remove public reachability for exposed Oracle EBS, SharePoint, NetScaler, Langflow, ColdFusion, Gitea Docker, and Rockwell/Allen-Bradley remote access. Outage is justified for public Oracle EBS, SharePoint, NetScaler VPN/ADC exposure, Langflow with cloud/database access, and any direct OT remote path. For Rockwell, follow Sara’s line: reduce reachability, do not reboot controllers or change logic during operations.

Patch now / hunt as compromised: treat exposed Oracle EBS CVE-2026-46817, SharePoint CVE-2026-45659, NetScaler CVE-2026-8451, and Langflow CVE-2025-3248/JadePuffer-style exposure as assume-compromised. Preserve web/app logs, IdP logs, session stores, VPN/AAA logs, reverse proxy logs, cloud audit logs, database access logs, container logs, and EDR telemetry before rebuilds where possible. Then patch or rebuild from clean images, revoke sessions, rotate tokens/API keys/service accounts, and invalidate SSO cookies — Marcus is right, this is trust-state theft, not just password theft. For ColdFusion and Gitea Docker, I do not have current visible advisory/patch evidence here, so tonight I would isolate, freeze only code-execution/secrets/publish paths, pull logs, and let business owners approve any outage beyond exposure removal.

Delegate and monitor: business owners must sign off on frozen publishing, disabled automation, vendor remote-access interruption, DeFi/governance money-moving pauses, and OT remote-support downtime. Keep lower-confidence Roundcube attribution and broader ORB activity in monitoring unless telemetry shows access to identity, mail, or command infrastructure; keep DeFi/vault controls in “human approval required” mode for formally valid but high-risk transactions. The SOC’s tonight dashboard should be small: new admin/session creation, unexpected outbound from AI/dev tools, token use after revocation, SharePoint/EBS webshell indicators, NetScaler session anomalies, cloud key use from new locations, and OT remote-session attempts.

Checkpoint

James has turned the scattered vulnerability map into an operational triage rule: tonight is not mainly a “patch everything in order” problem; it is an exposure and trust-reset problem. The sharpest point is that public-facing Oracle EBS, SharePoint, NetScaler, Langflow, ColdFusion, Gitea Docker, and Rockwell/Allen-Bradley remote access should be treated as systems whose reachability must be reduced immediately, with outages justified for the highest-risk internet-exposed business, identity, cloud, and OT access paths.

What changed here is the priority stack. Alex’s “assume-compromised first” framing for exposed Oracle EBS now carries through to SharePoint, NetScaler, and Langflow-style exposure. Marcus’s warning also becomes central: if these platforms were touched, responders should not stop at passwords. Sessions, API keys, service accounts, SSO cookies, VPN and AAA state, IdP records, reverse-proxy paths, cloud audit trails, database access, container evidence, and EDR telemetry all become part of the blast-radius question. James is also preserving Sara’s caveat on industrial environments: reduce Rockwell remote reachability, but do not casually reboot controllers or change logic during live operations.

There are still boundaries on certainty. We are not saying every exposed instance is proven compromised, and we are not assigning every case to a named actor. But for the confirmed exploited edge categories called out here — Oracle EBS CVE-2026-46817, SharePoint CVE-2026-45659, NetScaler CVE-2026-8451, and Langflow CVE-2025-3248/JadePuffer-style exposure — the room’s working posture is that evidence preservation, isolation, clean rebuild or patching, and trust invalidation should happen before anyone declares the environment safe.

That naturally brings us to Sofia’s lane. Once we decide systems may need to be isolated, logs preserved, tokens revoked, and outages accepted, the regulatory question is not abstract compliance. It changes timing, notification thresholds, evidence handling, and what leadership can or cannot say tonight, especially with active exploitation and healthcare-impacting incidents in the packet.

Action 4

Dispatch One

Sofia, give us the regulatory lens only where it changes tonight's decisions. The pack includes active exploitation of Oracle EBS/SharePoint/ColdFusion/NetScaler, AdaptHealth's material patient-data incident via a third-party contractor cloud session, European...

Sofia AndersenRegulatory obligation lens

Moderator assignment

Sofia, give us the regulatory lens only where it changes tonight's decisions. The pack includes active exploitation of Oracle EBS/SharePoint/ColdFusion/NetScaler, AdaptHealth's material patient-data incident via a third-party contractor cloud session, European Commission AWS/Europa data theft claims, CISA's expected September CIRCIA final rule with 72-hour substantial-incident and 24-hour ransomware-payment reporting, and Australia OAIC breach notification growth. What should CISOs and legal teams start preserving or deciding in the first 24 hours, and what items are monitor-only rather than immediate notification triggers?

Response

Halil, the first 24 hours should be evidence-preservation, not reflexive notification for every exploited product. For Oracle EBS, SharePoint, ColdFusion, and NetScaler, the legal trigger changes only once there is evidence of unauthorized access, data exfiltration, service disruption, or regulated-sector impact. CISOs should preserve: authentication logs, web/application logs, cloud access logs, EDR telemetry, affected asset lists, vulnerable-version inventories, patch timestamps, attacker IPs, admin-session history, and a clean chronology of “first detection” versus “confirmed impact.” That chronology matters because GDPR Article 33(1) requires notifying the supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach, unless risk to individuals is unlikely; Article 34(1) adds data-subject communication without undue delay where high risk is likely.

AdaptHealth is different: a patient-data incident through a third-party contractor cloud session is already in notification-preparation territory, not monitor-only. Legal should immediately preserve the contractor agreement, processor/subprocessor instructions, access logs, affected patient fields, data-export evidence, and decision records on whether identity, health, insurance, or payment data was involved. If EU personal data is implicated, GDPR controller/processor allocation and Article 33/34 analysis starts now. For any SEC filer, preserve the board/legal materiality record and business-impact inputs; I would want a current SEC source before restating exact timing here, but the decision process itself must be documented.

Monitor-only for tonight: the European Commission AWS/Europa theft claims unless your organization is a controller, processor, recipient, listed victim, or downstream data holder; OAIC breach-notification growth as a trend signal unless Australian personal information was actually accessed or lost; and CIRCIA for now as readiness planning, because the sources I have show the 72-hour covered-incident and 24-hour ransom-payment duties apply once the final rule is implemented. Do not wait for patch completion to start the file: preserve evidence, identify jurisdictions, map affected data, and decide within 24 hours whether you are in “breach assessment,” “regulator pre-notification,” or “monitor-only vulnerability response.”

Checkpoint

Sofia has narrowed the legal question in a useful way: active exploitation in the news does not automatically mean every organization has a notification clock running tonight. For Oracle EBS, SharePoint, ColdFusion, and NetScaler, the immediate regulatory decision point is evidence: unauthorized access, exfiltration, disruption, or impact in a regulated context. Until that is established, the strongest move is disciplined preservation — logs, telemetry, asset inventories, vulnerable-version records, patch times, attacker indicators, admin-session history, and a clear chronology separating first detection from confirmed impact.

The important caveat is that “preserve first” is not the same as “wait casually.” Sofia is telling us that the legal clock depends on when the organization becomes aware of a personal-data breach or other reportable impact, and that timeline must be defensible later. GDPR’s 72-hour supervisory authority window and high-risk data-subject communication standard were the concrete examples here. So the room should hear this as: security teams need to move fast operationally, but legal teams need clean facts before they turn widespread exploitation into formal breach notification.

AdaptHealth lands in a different bucket. Because the packet describes a material patient-data incident through a third-party contractor cloud session, Sofia treated that as already notification-preparation territory rather than a monitor-only scenario. That also reinforces a broader point for tonight: third-party remote or cloud access is not just an IT control issue; it changes the evidence package, contract review, processor/subprocessor questions, and potentially the notification posture.

That brings us naturally to the next quick lane: privileged remote access. If third-party sessions and administrative tooling can move an incident from exposure management into regulated-impact territory, then BeyondTrust Remote Support and Privileged Remote Access authentication-bypass flaws need very direct identity and access guidance before we close.

Action 5

Dispatch One

Marcus, targeted quick lane before we close: For BeyondTrust Remote Support and Privileged Remote Access CVE-2026-40138 and related critical authentication-bypass flaws, with patches available and no reported in-the-wild exploitation in the source pack, what s...

Marcus ValeIdentity security lens

Moderator assignment

Marcus, targeted quick lane before we close: For BeyondTrust Remote Support and Privileged Remote Access CVE-2026-40138 and related critical authentication-bypass flaws, with patches available and no reported in-the-wild exploitation in the source pack, what should CISOs do tonight beyond patching? Cover exposure isolation, session/token revocation, privileged credential rotation, and which logs or indicators would make you treat a system as compromised.

Response

Halil, I’d treat CVE-2026-40138 as an identity boundary failure, not just a software bug. BeyondTrust’s advisory says this is a critical pre-authentication vulnerability in the authentication subsystem of Remote Support and Privileged Remote Access, where improper authentication request processing could let an unauthenticated remote attacker bypass access controls and reach the appliance, including elevated accounts. So yes, patch tonight — but don’t stop there.

Beyond patching: remove RS/PRA from direct internet exposure where possible, restrict access to VPN/ZTNA or tight IP allowlists, and kill all active appliance sessions. Revoke or rotate API tokens/integrations tied to the appliance, disable suspicious local accounts, review SAML/OIDC/LDAP bindings, and rotate privileged credentials that could have been used through Jump Clients, Shell Jump, credential injection, or vault/check-out workflows. If this tool can broker access to domain controllers, cloud admin consoles, hypervisors, backup systems, or finance systems, those credentials are in the blast radius.

I’d treat the system as compromised if logs show successful admin/API access from unusual IPs, new local/elevated accounts, policy changes, new Jump Clients or Shell Jump entries, new API integrations/tokens, config export/backup activity, session recordings with command shell or file transfer, credential checkouts, logging gaps, or sessions that do not line up with IdP/SAML/MFA events. That last one matters: if the BeyondTrust appliance says “valid session” but your IdP has no matching authentication, that is a trust-chain break.

The under-response I expect is “patched, ticket closed.” Wrong. For privileged remote access infrastructure, patching only fixes tomorrow’s entry path; it does not invalidate yesterday’s stolen session, API token, appliance-local account, or privileged credential exposed through the platform.

Peer consultations
James OkaforMarcus Vale

Marcus Vale asked James Okafor.

James, I’m looking at BeyondTrust Remote Support/PRA CVE-2026-40138. The BeyondTrust advisory says it is a critical pre-auth authentication subsystem issue that can let an unauthenticated remote attacker bypass access controls and reach the appliance, including elevated accounts; source pack says patches are available and no reported in-the-wild exploitation. From a defensive response angle, what log patterns or IR triggers would make you treat a patched appliance as already compromised rather than merely exposed?

Marcus, for a patched BeyondTrust RS/PRA box, I’d flip from “exposed” to “assume compromised” if we see any trust-state change that cannot be tied to a normal ticket: successful appliance/admin/API access from unusual IPs, local/elevated account creation or policy changes, new Jump Clients or Shell Jump entries, new API integrations/tokens, config backup/export activity, or sessions that lack a matching IdP/SAML/MFA event. BeyondTrust’s own docs show the platform can expose API-driven report/config operations and Jump Client/endpoint automation, so I’d treat unexplained use of those features as materially worse than a failed login storm.

The hard IR triggers are: command shell recordings, file transfers, credential injection/checkouts, or privileged sessions into domain controllers, cloud admin workstations, hypervisors, backup servers, or finance systems; syslog gaps or logging/config changes around the suspicious window; and any active session that survived patching. If any of those hit, isolate the appliance, export syslog/session recordings/config, revoke all active sessions/API keys, rotate credentials reachable through RS/PRA, and rebuild or restore from a known-good image — don’t just patch and declare victory.

Checkpoint

BeyondTrust changes the conversation from “patch a remote-access product” to “protect an identity control plane.” Marcus’s point is that Remote Support and Privileged Remote Access are not ordinary edge applications; they can broker privileged sessions into domain controllers, cloud consoles, hypervisors, backup platforms, finance systems, and other crown-jewel environments. So a critical pre-authentication bypass in that layer deserves urgency even if the source pack does not report in-the-wild exploitation.

The room’s practical takeaway is clear: patch immediately, but assume patching is only the first containment step. CISOs should reduce exposure by taking RS/PRA off the open internet where possible, putting access behind VPN or ZTNA, using tight IP allowlists, and terminating active appliance sessions. Marcus also widened the remediation set to include identity hygiene: rotate or revoke API tokens and integrations, review SAML/OIDC/LDAP bindings, disable suspicious local accounts, and consider privileged credentials at risk if they were accessible through Jump Clients, Shell Jump, credential injection, vaulting, or checkout workflows.

The important caveat is that we are not saying exploitation has been confirmed here. The source material, as framed, does not establish active exploitation. But absence of reported exploitation does not make this low risk, because pre-auth bypass on a privileged remote access appliance creates a short path from perimeter access to administrative reach. The evidence threshold for declaring compromise still depends on logs and telemetry: unusual successful admin or API access, unexpected source IPs, suspicious account activity, and signs that privileged workflows were used in ways the organization cannot explain.

With that, we have enough to synthesize the roundtable’s broader pattern: across these cases, the response is not just “patch the named CVE.” It is exposure reduction, evidence preservation, identity review, credential containment, and a legally disciplined assessment of whether unauthorized access or regulated impact actually occurred.

Unified Search

Search the public record.