TL;DR
FBI disrupted Chinese hacking infrastructure (QScan, QTRouter) targeting U.S. critical infrastructure. Kaltura video player has two unpatched RCE flaws. NovaCookies phishing kit abuses DocuSign to steal Microsoft 365 sessions; one CISA red team exercise went undetected by a critical infrastructure organization.
Executive Summary
- The U.S. Department of Justice disrupted two Chinese state-sponsored hacking platforms (QScan and QTRouter) that targeted critical infrastructure and sensitive U.S. networks.
- Two critical remote code execution vulnerabilities in Kaltura's mwEmbed video player remain unpatched and allow unauthenticated attackers to read files and execute code.
- The NovaCookies adversary-in-the-middle phishing toolkit abuses genuine DocuSign notifications to redirect and harvest Microsoft 365 authenticated sessions, sold as a service for $320/month.
- A CISA red team assessment of two critical infrastructure organizations using similar attack tradecraft produced sharply different results: one organization detected the compromise; the other did not.
- Microsoft released updates for approximately 398 security vulnerabilities, including one actively exploited weakness.
Top Threats Today
1. Chinese State-Sponsored Infrastructure Disruption
Severity: HIGH Affected: government
The U.S. Department of Justice announced the disruption of two hacking platforms named QScan and QTRouter, attributed to Chinese state-sponsored threat actors [1]. The platforms were used to target critical infrastructure and other sensitive networks in the United States [1][2]. Federal remediation due dates and specific victims have not been disclosed in available reporting [1][2].
Sources:[1] The Hacker News[2] The Record
Recommended Action
- Review network logs for indicators of compromise associated with QScan/QTRouter scanning activity
- Audit critical infrastructure systems for unauthorized access or lateral movement patterns
- Coordinate with sector-specific ISACs for additional IOC sharing and threat intelligence
2. Unpatched Kaltura mwEmbed Remote Code Execution
Severity: HIGH Affected: technology
The CERT Coordination Center has disclosed two unpatched vulnerabilities (CVE-2026-19913 and CVE-2026-19912) in Kaltura's HTML5 video player library mwEmbed [1]. Both flaws allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it [1]. No patch has been released as of the disclosure date [1].
Sources:[1] The Hacker News
Recommended Action
- Identify all instances of Kaltura mwEmbed deployed in production environments
- Isolate or restrict network access to systems hosting the vulnerable library until a patch is available
- Monitor vendor security advisories for patched versions and deploy immediately upon release
3. NovaCookies Phishing-as-a-Service Targeting Microsoft 365
Severity: HIGH Affected: technology
Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that abuses genuine DocuSign notifications to redirect Microsoft 365 sign-ins while capturing authenticated sessions [1][2]. The toolkit is sold as a service at $320 per month, lowering the barrier to entry for actors to conduct attacks ⚠[2]. The method captures more than user credentials, enabling session hijacking [1].
Sources:[1] The Hacker News[2] Dark Reading
Recommended Action
- Implement conditional access policies requiring re-authentication for sensitive operations in Microsoft 365
- Deploy advanced phishing detection and block DocuSign-spoofed domains and mail flows
- Conduct user awareness training focused on verifying authentication and notification sources
- Monitor for anomalous session activity and geographic sign-in patterns
4. Critical Infrastructure Detection Gap Exposed in CISA Red Team Exercise
Severity: HIGH Affected: government
The U.S. Cybersecurity and Infrastructure Security Agency conducted red team assessments against two critical infrastructure organizations using similar tradecraft [1]. One organization detected the compromise while the other did not, highlighting a significant gap in detection capability [1]. CISA published the results to underscore defensive effectiveness variability [1].
Sources:[1] The Hacker News
Recommended Action
- Conduct a defensive readiness assessment comparing your organization's detection posture to CISA red team findings
- Review logging and monitoring configurations for completeness across all network segments
- Engage threat hunting teams to validate detection coverage against common adversary tradecraft
5. Microsoft Patches 398 Vulnerabilities, One Actively Exploited
Severity: HIGH Affected: technology
Microsoft released updates to remedy at least 398 security vulnerabilities in Windows and supported software [1]. One of the patched weaknesses is already being actively exploited in the wild, and two others were publicly detailed prior to release [1].
Sources:[1] Krebs on Security
Recommended Action
- Prioritize deployment of the actively exploited vulnerability patch across all Windows systems
- Apply publicly disclosed patches on an expedited schedule
- Test patches in non-production environments before broad deployment
Today’s Action Checklist
- ☐ URGENT: Patch Microsoft actively exploited vulnerability and publicly disclosed flaws immediately
- ☐ HIGH: Identify and isolate Kaltura mwEmbed instances; review for unauthorized file access or code execution
- ☐ HIGH: Monitor for NovaCookies phishing campaigns targeting Microsoft 365 and block DocuSign-spoofed domains
- ☐ MEDIUM: Review detection logs for QScan/QTRouter indicators and assess critical infrastructure network segmentation
- ☐ MEDIUM: Validate red team findings apply to your organization and conduct a detection capability assessment