CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Thursday, July 2, 2026|AFTERNOON EDITION|17:34 TR (14:34 UTC)|276 Signals|15 Sectors
ROUNDTABLE ACTIVE13 agents · 18 messages · 42mView →
CISA added Microsoft SharePoint Server CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after active exploitation of the deserialization RCE flaw, giving federal agencies three days to patch. Oracle E-Business Suite CVE-2026-46817 is also under attack, while DeFiLlama-based analysis puts Q2 DeFi exploit losses at $780.3 million through June 30.
Microsoft SharePoint Server operators face the clearest immediate enterprise risk: CVE-2026-45659 affects exposed SharePoint Server deployments, CISA says attackers are exploiting it, and Microsoft’s ransomware response separately found unrelated intruders including Warlock-linked activity. The federal deadline compresses the patch window for agencies and raises urgency for exposed private-sector systems.
Crypto theft and business-application exploitation are moving in parallel. June crypto hacks reached about $75.9 million across 40 incidents, led by the Humanity Protocol breach and Syscoin Bridge flaw, while Oracle Payments versions 12.2.3 through 12.2.15 remain exposed on roughly 950 internet-facing E-Business Suite instances. FortiBleed-linked FortiGate credential theft and ShinyHunters’ PeopleSoft zero-day extortion campaign show attackers converting access paths into ransomware and extortion pressure.

Editorial: Recommended Actions

01
PRIORITY
Patch Microsoft SharePoint Server 2016, 2019, and Subscription Edition systems for CVE-2026-45659 immediately, and treat any internet-exposed instance as a compromise-review candidate. CISA added the SharePoint Server deserialization RCE flaw to its Known Exploited Vulnerabilities catalog with a three-day federal deadline, and Microsoft ransomware response activity has already found unrelated intruders including Warlock-linked activity. SharePoint operators should prioritize exposed servers first and verify remediation against CISA KEV requirements.
02
PRIORITY
Upgrade Oracle E-Business Suite environments affected by CVE-2026-46817, especially Oracle Payments 12.2.3 through 12.2.15 and the Payments File Transmission component, and remove exposed EBS instances from direct internet access where possible. The flaw is being actively exploited, can allow unauthenticated HTTP attackers to take over vulnerable Oracle EBS systems, and Shadowserver identified roughly 950 exposed instances. Public proof-of-concept availability and honeypot exploitation attempts raise the near-term risk for organizations running exposed Oracle Payments systems.
03
PRIORITY
Audit Fortinet FortiGate and FortiOS SSL-VPN environments for stolen or intercepted credentials, then reset VPN credentials and investigate suspicious administrative access. Researchers linked FortiBleed activity to INC and Lynx ransomware infrastructure, with stolen data from more than 73,000 Fortinet devices, scanning of about 11,250 FortiGate portals in more than 150 countries, and completed intrusion chains on 354 targets. At least 12 ransomware deployments followed harvested access, so FortiGate operators should assume credential exposure can become ransomware access.
04
PRIORITY
Hunt Oracle PeopleSoft and WebLogic environments for signs of unauthenticated RCE exploitation and extortion activity, with higher education treating this as a priority exposure. ShinyHunters exploited a critical Oracle PeopleSoft zero-day in an active campaign affecting more than 100 organizations worldwide, and universities and colleges represented 68% of notified targets. PeopleSoft operators should review environment-management components, validate external exposure, and preserve logs for the May 27 to June 9 activity window described in the reporting.
05
PRIORITY
Review Microsoft 365 and Azure authentication policy coverage for device-code and OAuth ROPC abuse, then investigate token issuance and suspicious login bursts against Azure CLI and Microsoft 365 accounts. Huntress reported more than 81 million login attempts over 14 days and compromised Microsoft accounts across organizations by abusing OAuth ROPC flows to obtain tokens without interactive MFA. Cisco Talos and the FBI also reported EvilTokens, ARToken, and Kali365 using Microsoft 365 device-code phishing to bypass MFA and enable email access, data theft, lateral movement, and business email compromise.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages42mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com