Threat Brief — 2026-08-17 — KEV pressure, dark-web AI, and firewall leaks
Executive summary. CISA added a Ray-Project RCE to its KEV catalog with confirmed active exploitation and a three-week patch deadline — the priority item for infrastructure teams today. On the threat-actor side, a subscription AI model ("MessiahGPT") launched on the dark web at $8/month, lowering the barrier to entry for automated attacks. Meanwhile, a DNS bug exposed the source code behind China's Great Firewall, and Brazilian police closed a three-year investigation with raids across seven cities tied to a €30M German banking fraud.
Top items
- [High] Ray-Project CVE-2025-62593KEV — actively exploited, now in CISA KEV. A code-injection vulnerability in the Ray AI compute engine allows RCE via browser-based CSRF combined with DNS rebinding, bypassing an insufficient User-Agent guard on the local developer dashboard. CISA added it to the KEV catalog today with a three-week remediation deadline. Active exploitation is confirmed; no public exploit URL was provided in the feeds, but KEV listing itself signals in-the-wild use. Affected product: Ray-Project (Ray dashboard). (src: CISA KEV / NVD)
- [Developing] Threema messaging DDoS — second crash in 17 hours. The Swiss encrypted-messaging service experienced 4 hours of total isolation after a flood of requests from floating IP addresses took it down for the second time in 17 hours. This extends the ongoing DDoS disruption first reported 2026-08-16 by BleepingComputer. The repeated outages suggest sustained, adaptive attacker infrastructure rather than a one-off event. (src: securitylab-ru)
- [Developing] Brazilian raids conclude €30M bank-fraud investigation. Raids across seven Brazilian cities have concluded a three-year investigation into a software-update flaw at a service provider that enabled €30M in fraudulent transfers from German Commerzbank customers. This is a new milestone in the ongoing case first reported 2026-08-14 by BleepingComputer. The scale of arrests underscores how a single flawed code update can cascade into multi-jurisdictional fraud. (src: securitylab-ru)
- [New] MessiahGPT — dark-web AI assistant for cyberattacks at $8/month. An underground neural-network service dubbed MessiahGPT has launched on the dark web, offering automated cyberattack capabilities on a subscription model. The low price point significantly lowers the technical barrier to entry for aspiring cybercriminals, potentially increasing the volume of low-sophistication attacks. (src: securitylab-ru)
- [New] Great Firewall of China source code leaked via DNS bug. Researchers discovered a DNS misconfiguration that exposed the source code behind China's censorship infrastructure, including roughly 500 repositories. The leak provides unprecedented visibility into the mechanics of the Great Firewall's filtering and blocking logic. (src: securitylab-ru)
- [Developing] Armored Likho expands espionage toolkit with Still Toolkit. Kaspersky analysts report a new campaign by Armored Likho (aka Eagle Werewolf) targeting Russian government structures, IT companies, educational organizations, and individual users, deploying Telegram espionage and audio-surveillance tools. This extends the group's activity first reported 2026-07-18 by Securelist, now with an expanded target set and new tooling. (src: xakep)
Themes
Democratisation of offensive capability. MessiahGPT's $8/month subscription model and the Ray-Project dashboard RCE both illustrate how sophisticated attack paths are becoming accessible to lower-skilled actors — one through commoditised AI, the other through a local developer-tool weakness requiring no advanced exploit chain.
Sustained infrastructure attacks. Threema's second outage in 17 hours and the ongoing botnet expansion of Evooo1Bot (first reported 2026-08-15) point to a pattern of persistent, adaptive pressure on communication and routing infrastructure rather than opportunistic hits.
