Weekly Threat Intelligence Briefing — Monday, July 13, 2026

Weekly Threat Intelligence Briefing — July 13, 2026

July 13, 2026

Weekly Threat Intelligence Briefing · Monday, July 13, 2026


Nineteen agencies co-signed one advisory this week — and it is about routers. Add an AI orchestration platform landing on the KEV list and ransomware reaching maritime and aviation supply chains, and the week's theme is the infrastructure underneath the inventory.

FSB Center 16 router campaign — July 9 joint advisory from NSA, CISA, FBI, DC3, and fifteen international partners. Russia's FSB Center 16 (Berserk Bear / Static Tundra) is exploiting end-of-life and misconfigured network devices — SNMP configuration exfiltration and Cisco Smart Install abuse (CVE-2018-0171, a 2018 flaw still delivering access). The Defense Industrial Base is a named target sector; the DC3 co-seal makes that explicit.

DIB implication: if edge routers and serial gateways are not in your SSP inventory, the adversary is enumerating assets your attestation does not describe.

CVE-2026-55255 — Langflow authorization bypass — CVSS 9.9. Added to CISA's KEV catalog July 7 with a July 10 federal remediation deadline — that window has closed. Exploitation enables cross-tenant credential theft, and related Langflow flaws have fed JadePuffer ransomware deployments. Fixed in 1.9.2.

DIB implication: LLM orchestration is now a KEV-listed attack surface. If your teams run it, it is a governed asset.

📌 Watch — maritime and aviation supply chains. Qilin claimed the Shipping Association of New York & New Jersey. KRYBIT posted Taiwanese avionics manufacturer AeroVision. The Gentlemen posted Indra Group — the Spanish defense electronics firm in NATO's cyber coalition — which confirms a subsidiary incident it describes as limited to a non-critical environment. And a date: July 16 marks one year since the USCG Cybersecurity in the Marine Transportation System rule took effect. The Cyber Assessment, Cyber Plan, and CySO deadline lands July 16, 2027.

Practitioner takeaway: Disable Smart Install, move device management to SNMPv3, and schedule end-of-life router replacement — the advisory's checklist maps cleanly to the CM and SC control families. Patch Langflow to 1.9.2 or take it off the network. Maritime operators: you are twelve months from the Cyber Plan deadline, and the assessment work starts now, not next June.

PSYber360: This week's actor and campaign records — the FSB Center 16 router campaign, The Gentlemen's first-half victim volume, and KRYBIT's first tracked claim — are updated in our threat intelligence tracker.

Which end-of-life network device in your environment would you least want nineteen agencies asking about?

Back to Blog