Threat Intelligence Brief - Friday, September 25, 2026

Operational threat reporting for defenders who need signal, not noise.

By DevSecOpsDad

Threat Radar

  • North Korea’s Lazarus Group executed a $351.6M heist against Bitget via backend compromise — one of the largest state-linked crypto thefts on record. Financial services and digital asset custodians face elevated targeting risk.

  • CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail (CVSS 8.1), is actively exploited in the wild with a patch available. Any exposed instance should be treated as potentially compromised.

  • Three “SalesBleed” vulnerabilities in Salesforce Agentforce enabled zero-click data exfiltration and AI agent hijacking. Agentforce deployments require immediate configuration review and application of Salesforce mitigations.

  • Russia is intensifying hybrid operations against European nations, combining cyber sabotage, disinformation, and drone attacks. Government and critical infrastructure operators with European exposure should reassess resilience posture now.

  • This brief covers three operationally urgent and distinct response tracks — state-sponsored financial crime, actively exploited webmail infrastructure, and emerging AI agent attack surfaces — alongside a sustained hybrid threat requiring ongoing monitoring.



Immediate Action Required

  • Roundcube Webmail — CVE-2026-48842: Apply the available patch immediately. This pre-auth SQL injection requires no credentials to exploit and is confirmed actively exploited in the wild. Treat any unpatched, internet-exposed instance as a priority remediation. Review mail server logs for anomalous query activity against the virtuser_query plugin.

  • Bitget / Lazarus Group — Crypto Exchange Breach: Audit hot and warm wallet access controls and review backend authentication posture. Validate lateral movement exposure (T1021). Assess third-party exchange relationships and custodial arrangements for inherited risk.

  • Salesforce Agentforce — SalesBleed: Review Agentforce agent permission scopes and data access boundaries. Apply available Salesforce mitigations. CRM owners and IAM teams should determine what sensitive data is accessible to Agentforce agents and whether phishing-capable trust relationships exist.



High-Impact Developments

Lazarus Group Steals $351.6M from Bitget in State-Linked Crypto Heist

  • What happened: Cryptocurrency exchange Bitget disclosed that suspected Lazarus Group actors compromised its backend systems and executed unauthorized transfers totaling $351.6 million from hot and warm wallets. The breach was detected at 18:31 UTC on September 24, 2026.

  • Why it matters: This is a large-scale, state-sponsored financial theft targeting a major exchange’s operational wallet infrastructure. Lazarus has a documented pattern of targeting crypto platforms to fund North Korean state programs. The backend compromise vector (T1190, T1021) indicates the attackers achieved privileged access before initiating transfers — not a phishing incident.

  • Who should care: CISOs at cryptocurrency exchanges, digital asset custodians, fintech platforms, and any organization holding or transacting in digital assets. Financial services firms with crypto exposure should treat this as a sector-wide threat signal.

  • Recommended action: Audit hot and warm wallet access controls and privileged backend access. Review remote access paths (T1021) for anomalous activity. Confirm whether your exchange or custodial partners have disclosed any related exposure. Engage incident response if any unexplained wallet activity is detected.

  • Confidence: High — confirmed by Bitget disclosure, corroborated by multiple credible sources.

  • Search metadata: T1190, T1021, Lazarus, Bitget, cryptocurrency, financial theft

Intelligence Context



CVE-2026-48842: Roundcube Webmail Pre-Auth SQL Injection Under Active Exploitation

  • What happened: CVE-2026-48842, a pre-authentication SQL injection vulnerability (CVSS 8.1) in the virtuser_query plugin of Roundcube Webmail, is being actively exploited in the wild. The Canadian Centre for Cyber Security issued a public warning. A patch is available.

  • Why it matters: Pre-authentication exploitation means attackers need no valid credentials to compromise exposed instances. Roundcube is widely deployed across government, academic, and enterprise environments. Successful exploitation can yield unauthorized mailbox access and sensitive email data exposure at scale.

  • Who should care: Vulnerability management leads, IT operations, and email security teams running any version of Roundcube Webmail with the virtuser_query plugin enabled. SOC teams should treat unpatched instances as actively targeted.

  • Recommended action: Apply the patch for CVE-2026-48842 immediately. Identify all internet-exposed Roundcube instances in your environment. Review mail server access logs for anomalous pre-authentication activity. If patching cannot be completed immediately, restrict external access to Roundcube interfaces in the interim.

  • Confidence: High — active exploitation confirmed, government advisory issued, patch available.

  • Search metadata: CVE-2026-48842, T1190, Roundcube Webmail, SQL injection

Intelligence Context



SalesBleed: Zero-Click Agent Hijacking and Data Exfiltration in Salesforce Agentforce

  • What happened: Researchers disclosed three vulnerabilities collectively dubbed “SalesBleed” in Salesforce Agentforce. The flaws allowed attackers to hijack trusted AI agents, exfiltrate sensitive business data, and launch phishing attacks without requiring user interaction. Mitigations are available from Salesforce.

  • Why it matters: AI agent platforms operate with elevated trust and broad data access by design. Hijacking these agents without user interaction (T1020, T1566.002) bypasses user-awareness controls entirely. At enterprise scale, a compromised Agentforce agent could silently exfiltrate CRM data or deliver credible phishing from a trusted system identity — and do so without generating the signals defenders typically look for.

  • Who should care: Security architects, cloud security teams, CRM owners, and IAM leads at any organization running Salesforce Agentforce. This is also a signal for any organization deploying AI agents with broad SaaS data access — the attack surface class is not unique to Salesforce.

  • Recommended action: Review Agentforce agent permission scopes and data access boundaries. Apply available Salesforce mitigations. Determine what sensitive data is reachable by Agentforce agents and whether agent-to-user trust relationships could be weaponized for phishing. Engage Salesforce account teams for remediation guidance.

  • Confidence: High — vulnerabilities confirmed by SecurityWeek reporting; broader campaign scope not confirmed.

  • Search metadata: T1566.002, T1020, Salesforce Agentforce, SalesBleed, data exfiltration, agent hijacking

Intelligence Context



Monitor Only

  • Russia’s escalating hybrid operations — combining cyber sabotage (T1561, T1561.002), disinformation, and drone attacks — against European nations supporting Ukraine represent a sustained and broadening threat to government and critical infrastructure operators; European organizations should reassess resilience and physical security posture now. Source: Russia’s Hybrid Cyber-Physical War in Europe Heats Up — Dark Reading — https://www.darkreading.com/physical-security/russia-hybrid-cyber-physical-war-europe



Analyst Observation

Today’s brief reflects three distinct but operationally urgent threat tracks running in parallel. The Bitget breach is a reminder that Lazarus doesn’t need novel malware — backend access and privileged lateral movement are sufficient to move hundreds of millions in minutes. The Roundcube exploitation is a textbook case of why pre-auth vulnerabilities in internet-facing mail infrastructure demand same-day patching decisions, not next-cycle scheduling. The SalesBleed findings deserve more attention than they’ll likely receive: AI agent platforms are being deployed faster than security teams are evaluating their trust boundaries, and zero-click exfiltration from a system users inherently trust is a difficult problem to detect after the fact. The Russian hybrid operations story is real but diffuse — it matters most to organizations with European critical infrastructure exposure, where the physical and cyber threat surfaces are now genuinely converged.





Generated by DevSecOpsDadAttack cyber threat intelligence.

Share: X (Twitter) LinkedIn