QScan and QTRouter seized: DOJ and FBI dismantle China-state platforms sold to Ministry of State Security and PLA, victims include NASA, Federal Reserve, DOE, DOJ, NIH, and US Senate      CISA AA26-237A: same attack tradecraft against two critical infrastructure organizations, one SOC detected and contained everything, one detected nothing until CISA told them      Kaltura CVE-2026-19913 and CVE-2026-19912: two unpatched RCE and file-read flaws on the CDN shared by all Kaltura tenants, CERT/CC could not reach the vendor to coordinate      QScan and QTRouter seized: DOJ and FBI dismantle China-state platforms sold to Ministry of State Security and PLA, victims include NASA, Federal Reserve, DOE, DOJ, NIH, and US Senate      CISA AA26-237A: same attack tradecraft against two critical infrastructure organizations, one SOC detected and contained everything, one detected nothing until CISA told them      Kaltura CVE-2026-19913 and CVE-2026-19912: two unpatched RCE and file-read flaws on the CDN shared by all Kaltura tenants, CERT/CC could not reach the vendor to coordinate     
CyberSipTM
Intelligence without the noise
Issue No. 118
August 27, 2026
3 items · past 24h
<5 min read
Today's picture

The DOJ and FBI seized the three domains hard-coded into QScan and QTRouter, two complementary hacking platforms built and sold by QTFY, a China-state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company that provided intrusion services to China's Ministry of State Security and the People's Liberation Army, with confirmed victims that include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, HHS, NIH, and the US Senate. CISA published advisory AA26-237A, titled A Tale of Two SOCs, documenting two simultaneous red team assessments of critical infrastructure organizations using identical attack tradecraft where the Government Services organization never detected the complete domain compromise and the Water and Wastewater organization detected, isolated, and contained the intrusion at first contact. CERT/CC disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow an unauthenticated remote attacker to read arbitrary files from the server and execute code, with no patch available, no response from Kaltura to CERT/CC's coordinated disclosure attempts, and the vulnerable endpoint exposed on Kaltura's shared multi-tenant CDN meaning every tenant served by those hosts is in scope.

Today's intelligence
3 items
01 CriticalQTFY / QScan / QTRouterDOJ Seizure
The DOJ and FBI seized the platforms China used to hit NASA, the Federal Reserve, and the US Senate, rendering both inoperable
QScan scanned the internet and infected thousands of IoT devices automatically. QTRouter used those compromised devices to route attack traffic through legitimate-looking IP addresses and hide its Chinese origin. QTFY sold both as a service to the Ministry of State Security and the PLA. The seized domains were hard-coded for authentication and C2, so the court orders made both platforms immediately inoperable.
PlatformsQScan (scanner)
QTRouter (obfuscation)
OperatorQTFY
Nanjing Xinjiuwei
Network Technology
CustomersMinistry of State
Security (MSS)
People's Liberation
Army (PLA)
VictimsNASA, Federal Reserve
DOE, DOJ, HHS
NIH, US Senate
Seized domainsqtproxy[.]xyz
qt-proxy[.]org
qt-team[.]com
The Department of Justice and FBI announced court-authorized domain seizures on August 26, 2026, targeting three domains hard-coded into the QScan and QTRouter malware platforms. Court documents unsealed in the Southern District of California describe QTFY as a People's Republic of China state-sponsored group whose members are employed by Nanjing Xinjiuwei Network Technology Company and who built and operated the two platforms as a commercial hacking service sold to China's Ministry of State Security, the People's Liberation Army, and other customers. QScan is a scanning and exploitation tool designed to automatically identify vulnerable internet-of-things devices and compromise them at scale. The court affidavit notes QScan processed more than two million scanning and exploitation tasks on a single day in 2024. Compromised devices were then folded into QTRouter, an obfuscation network composed of compromised IoT devices, commercial proxy services, and leased virtual private servers. QTRouter's purpose was to route QTFY and customer attack traffic through systems outside China, including devices located on networks adjacent to or within target organizations, making the traffic appear to originate from legitimate systems rather than from Chinese infrastructure. The DOJ confirmed that QTFY's victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The three seized domains, qtproxy.xyz, qt-proxy.org, and qt-team.com, were hard-coded into both QScan and QTRouter and used for essential functions including authentication and command-and-control communication. Because those functions depended on the seized domains, the court-authorized seizures rendered QScan and QTRouter immediately inoperable. This is the latest in a series of US government operations against China-linked cyber infrastructure following the 2025 PlugX takedown that removed the malware from more than 4,000 US computers and the prior Flax Typhoon IoT botnet disruption.
The QScan and QTRouter seizure disrupts an active operational capability that was generating revenue for a China-state-linked company by selling hacking services to Chinese intelligence and military agencies. The victim list is not the result of a broad campaign that happened to reach those organizations. The DOJ affidavit treats NASA, the Federal Reserve, DOE, and the US Senate as specific targets, not collateral exposure. QTRouter's design, routing traffic through compromised IoT devices local to target networks, was specifically intended to defeat attribution and network-based blocking by making the attacker's traffic indistinguishable from trusted internal or local network traffic. Organizations with critical infrastructure may have seen QTRouter-routed traffic appear as originating from their own networks or from trusted adjacent systems and treated it as legitimate. The seizure disrupts current campaigns but does not retroactively close any access QTFY or its customers had already established through these platforms.
The DOJ's description of QTRouter as routing traffic through devices on networks local to the target deserves specific attention for threat hunters. An organization that was targeted through QTRouter may have logs showing internal-looking or geographically local traffic associated with reconnaissance, lateral movement, or data exfiltration that did not trigger external threat detection because the source appeared to be a nearby or internal address. The three seized domains, qtproxy.xyz, qt-proxy.org, and qt-team.com, should be searched across historical DNS and network logs as indicators of QScan and QTRouter activity. Any historical outbound DNS queries or connections to those domains from internal systems indicate potential compromise of those systems by QScan or contact with QTRouter infrastructure. The FBI has not published a comprehensive indicator-of-compromise list accompanying this seizure, but the seized domains are the most specific indicator available from the public court documents.
  • Search historical DNS query logs and network flow data for any connections to qtproxy.xyz, qt-proxy.org, and qt-team.com originating from systems in your environment. These three domains were hard-coded into QScan and QTRouter for authentication and C2. Internal systems connecting to these domains were either compromised by QScan or were in contact with QTRouter infrastructure. Any such connections warrant incident investigation regardless of when they occurred.
  • Review historical network traffic for anomalous activity appearing to originate from IoT devices, home routers, or other edge devices on networks local to your environment, particularly for traffic destined at sensitive internal systems. QTRouter's design specifically used compromised local-network devices to route attack traffic, meaning successful QTRouter-routed intrusions would appear in logs as coming from network-adjacent addresses rather than from external Chinese infrastructure.
QScan compromised thousands of IoT devices automatically. QTRouter routed attack traffic through devices local to the target, so it looked like it came from inside. The DOJ seized the three hard-coded domains and both platforms stopped working immediately. Check your DNS and network logs for those three domains. Any hits warrant investigation.
02 HighCISA AA26-237AA Tale of Two SOCs
CISA used identical attack tradecraft against two critical infrastructure organizations and found that one SOC detected nothing while the other stopped every stage
The Government Services organization never detected the red team. The Water and Wastewater organization caught and isolated the first intrusion attempt within minutes. CISA published both attack chains with full MITRE ATT&CK mapping and identified the specific AD and cloud misconfigurations that determined each outcome. The difference between the two organizations was not funding or tooling. It was configuration and human response.
AdvisoryAA26-237A
August 25, 2026
Organization AGov't Services sector
Full compromise
undetected
Organization BWater / Wastewater
Detected + contained
at first contact
Entry methodDefault credentials
on web application
+ spearphishing
Escalation viaAD Machine Account
Quota + ADCS ESC1
misconfiguration
CISA published advisory AA26-237A, titled A Tale of Two SOCs, on August 25, 2026, documenting two simultaneous red team assessments of critical infrastructure organizations that had requested the evaluations. The assessments used nearly identical attack tradecraft but produced starkly different defensive outcomes. Organization A is a Government Services and Facilities Sector entity. The red team gained initial access after finding a web application with default credentials on built-in accounts, which allowed them to send spearphishing emails from an internal address. Those emails landed on four workstations. The red team then escalated domain privileges by abusing two specific Active Directory misconfigurations: an unrestricted Machine Account Quota, which by default allows any authenticated user to add up to ten machine accounts to the domain, and an Active Directory Certificate Services template vulnerable to the ESC1 attack class, which allows any authenticated user to request a certificate usable for domain controller authentication. With those credentials, the red team reached sensitive business systems and cloud resources, read SOC staff emails, deployed a keylogger, and extracted data. The Organization A SOC never detected any of this activity. Organization B is a Water and Wastewater Systems Sector entity. When the red team gained initial access using the same approach, the Organization B SOC detected the intrusion and quarantined the affected systems within minutes. The red team shifted to an assumed-breach approach, attempting to move laterally from a position already inside the network. The SOC detected and contained multiple subsequent lateral movement attempts. The full advisory maps every technique to its MITRE ATT&CK identifier, compares the detection rates between the two organizations at each attack stage, and names the specific misconfigurations and monitoring gaps responsible for each outcome. CISA recommends fixing the specific AD misconfigurations, enforcing credential hygiene, implementing Conditional Access for workload identities, and reducing alert noise that causes analysts to miss genuine intrusion signals.
The advisory's central finding is that both organizations had security teams, security tooling, and operational security operations centers. The difference in outcomes was not one of investment or technology. It was configuration discipline and analyst effectiveness. Organization A's SOC had the same category of tools as Organization B's but could not detect an intrusion that reached full domain compromise, cloud access, SOC staff email reading, and keylogger deployment. The specific factors CISA identified as responsible for Organization A's failure include too many alerts that analysts had stopped treating as meaningful, cloud identity misconfigurations that allowed service accounts to be used in unexpected contexts without triggering alerts, and the two Active Directory misconfigurations that the red team exploited for privilege escalation. The ESC1 ADCS misconfigurations that were present in Organization A are the same class of certificate-template abuse that has been documented in multiple Chinese state-sponsored campaigns this year, including techniques associated with the Volt Typhoon and Silk Typhoon actor clusters.
CISA's advisory includes a specific list of hardening steps ordered by the impact they would have had on the attack chain. The highest-priority items are: set the Machine Account Quota (ms-DS-MachineAccountQuota) to zero or to a small value matching only known service accounts, which prevents an attacker with any domain authentication from adding machine accounts used for privilege escalation; audit all Active Directory Certificate Services templates for ESC1 and ESC2 misconfiguration using tools such as Certify or Certipy, and restrict enrollment rights to only the accounts and groups that legitimately need them; remove default or unchanged credentials from all built-in application accounts; and reduce SOC alert volume by removing or raising the threshold for low-fidelity rules that analysts have learned to ignore. The last point is counterintuitive but operationally important: an SOC that receives more alerts than analysts can meaningfully review is functionally equivalent to an SOC that receives none, because genuine intrusion signals are buried in noise and treated the same way as the noise.
  • Audit and set the Active Directory Machine Account Quota attribute on the domain's Default-First-Site-Name. Set ms-DS-MachineAccountQuota to zero to prevent non-administrator accounts from creating machine accounts, or to a small specific value if legitimate service accounts require it. The CISA advisory describes this as the specific misuse pathway the red team used to escalate privileges at Organization A.
  • Run an Active Directory Certificate Services audit using Certify, Certipy, or Locksmith to identify templates with ESC1 misconfiguration, where enrollment is open to broad groups and Subject Alternative Names can be supplied by the requester. Restrict enrollment rights on any such templates to specific service accounts or privileged groups that have a documented business need for those certificates.
  • Review all web application accounts for unchanged default credentials. The red team's initial access to Organization A was through a web application with default built-in account passwords. Rotate all built-in application account credentials and verify that credential management processes cover internal-facing applications and administrative panels, not only public-facing web applications.
Same attack. One organization detected and contained it at every stage. The other did not detect it at all until CISA told them after the assessment was complete. The difference was configuration and analyst response, not budget. Set the Machine Account Quota to zero. Audit the ADCS templates for ESC1. Remove the default credentials. Then tune the alert rules until analysts can actually see the signals.
03 HighKalturaNo Patch / No Vendor Response
Kaltura has two unpatched RCE and file-read flaws on its shared CDN, with CERT/CC unable to reach the vendor to coordinate a fix
CVE-2026-19913 and CVE-2026-19912 both stem from the same unsafe PHP deserialization in the mwEmbedLoader.php endpoint. No authentication needed, no session token needed. File read lets an attacker extract database credentials and API keys from the server. Code execution lets them plant persistence and move laterally. Because the endpoint is on Kaltura's shared CDN, every tenant served by those hosts is in scope even if they do not self-host.
CVEsCVE-2026-19913
(file read)
CVE-2026-19912
(code execution)
EndpointmwEmbedLoader.php
mwEmbed / html5lib
RequiresNetwork access
to endpoint only
No authentication
PatchNot available
Vendor contactCERT/CC unable
to reach Kaltura
CERT/CC published vulnerability note VU#308749 on August 25, 2026, disclosing two vulnerabilities in the Kaltura HTML5 video player library distributed as mwEmbed and html5lib. Kaltura is a video platform providing tools for video management, publishing, playback, and integration into web applications, used by universities, media companies, enterprises, and healthcare organizations. The affected library exposes the mwEmbedLoader.php endpoint, which accepts a user-controlled ServiceUrl parameter as the target URL for backend API requests. The KalturaClientBase PHP client library fetches data from this URL and automatically deserializes the response using PHP's unserialize() function without validating the source, scheme, or content of the data returned. CVE-2026-19913 exploits this by supplying a file:// path as the ServiceUrl. The server fetches a local file at that path rather than an API response and attempts to deserialize it. The deserialization fails, but the raw bytes of the local file appear in the resulting error message, reflecting the contents of that file back to the requester. This arbitrary file read can extract database credentials, administrative secrets, API keys, partner secrets, and any other sensitive data present in local files accessible to the web server process. CVE-2026-19912 exploits the same deserialization path for remote code execution: by supplying a URL pointing to an attacker-controlled server, the client fetches and deserializes a malicious PHP serialized payload, executing attacker-controlled code in the context of the Kaltura server. No authentication and no Kaltura session token are required for either flaw. The affected endpoint is also exposed on Kaltura's shared multi-tenant CDN infrastructure, meaning that the vulnerability is present not only on self-hosted customer installations but on Kaltura's own CDN hosts that serve content for all tenants. CERT/CC states it was unable to reach Kaltura to coordinate these vulnerabilities before disclosure. No patch is available. Affected versions include html5lib v2.45, v2.103, and earlier v2.x releases that expose the vulnerable endpoint.
The shared CDN exposure is the most significant operational detail in this disclosure. Self-hosted Kaltura deployments that maintain their own infrastructure can mitigate immediately by restricting or removing access to the mwEmbedLoader.php endpoint. Tenants served by Kaltura's shared CDN infrastructure have no equivalent control: they do not manage the CDN hosts, cannot configure the CDN endpoints, and cannot apply any mitigation that depends on server-side configuration. Their exposure depends entirely on Kaltura applying a server-side fix to its CDN, which requires a patch that does not yet exist and a vendor that CERT/CC has not been able to reach. Any organization whose Kaltura video content is served through Kaltura's shared CDN should assume the vulnerable endpoint exists on their content delivery infrastructure until Kaltura confirms otherwise, because the endpoint is present on the CDN by design and the flaw is in the library that runs on that CDN.
CERT/CC's VU#308749 includes a specific set of interim mitigations applicable to organizations that run self-hosted Kaltura. Block or remove the mwEmbedLoader.php endpoint at the WAF, reverse proxy, or CDN layer where legacy mwEmbed players are not actively being served; implement a strict allowlist for the ServiceUrl parameter that permits only the specific API host for the deployment and rejects all non-HTTP and non-HTTPS schemes; reject uiconf_id values containing path traversal sequences; deny PHP execution in cache directories; and restrict outbound network access from the application server, which the code execution path needs to fetch a remote payload. Organizations that have stored sensitive credentials, API keys, or secrets in files accessible to the Kaltura web server process should rotate those credentials even before a patch is available, because CVE-2026-19913's file read can already expose them to any attacker who reaches the endpoint.
  • If you operate a self-hosted Kaltura deployment, immediately restrict or block external access to the mwEmbedLoader.php endpoint at the WAF, reverse proxy, or server configuration level. This endpoint is the entire attack surface for both CVE-2026-19913 and CVE-2026-19912. Blocking unauthenticated access to it eliminates the exploitation path without requiring a software update.
  • If your Kaltura video content is served through Kaltura's shared CDN, monitor Kaltura's security advisories for any patch release or server-side mitigation. Because CERT/CC was unable to reach Kaltura to coordinate the disclosure, the vendor may not be aware of the vulnerabilities through that channel. Check whether your Kaltura account team or enterprise support contact can escalate the CERT/CC advisory to Kaltura's security team directly and confirm whether the CDN endpoints have been mitigated.
  • Rotate database credentials, administrative passwords, API keys, and partner secrets that are stored in files accessible to the Kaltura web server process on any self-hosted Kaltura installation that has had external access to the mwEmbedLoader.php endpoint. CVE-2026-19913's file read path can retrieve those credentials without any authentication, and no log entry associated with a failed deserialization would indicate the file's contents were exfiltrated.
No authentication. No session token. File read extracts database credentials from the server. Code execution from a crafted serialized payload is one HTTP request away. No patch. CERT/CC could not reach the vendor. The endpoint is on Kaltura's own CDN, so every tenant is in scope even if they do not self-host. Restrict or block mwEmbedLoader.php on self-hosted instances now, and rotate the credentials it could already have read.
Cross-source standouts
01
QTRouter and the attribution problem: when attack traffic appears to come from inside the building
The most operationally significant detail in the QScan and QTRouter affidavit is not the victim list. It is the sentence that describes QTRouter as an obfuscation network that allows malicious communications to appear to originate from computers local to the targeted networks. QTRouter infected IoT devices, home routers, and other edge systems through QScan. Those infected devices were then used to relay attack traffic toward targets in a way that made the traffic appear to originate from devices physically or logically adjacent to the target. For a targeted organization, this means that reconnaissance traffic, lateral movement, or data exfiltration routed through QTRouter would appear in network logs as originating from a nearby or internal-seeming address, not from a Chinese IP range. IP-based blocking, geoblocking, and threat intelligence feeds built around Chinese IP address ranges would not catch this traffic, because the traffic was not originating from those ranges by the time it reached the target. Network detection tools that flag unusual traffic from external sources would similarly miss it, because the traffic appeared to come from expected sources. The takedown disrupts the C2 infrastructure and stops new campaigns that depend on the seized domains. It does not retroactively identify what activity was already conducted through QTRouter against organizations that were targeted before the seizure. Organizations that received security warnings from CISA, NSA, or sector-specific ISACs about Volt Typhoon, Silk Typhoon, or other China-linked actor campaigns between 2024 and today should add the three seized domains to their historical log searches, specifically because QTRouter was designed to leave traffic that looked legitimate at the network level.
02
A Tale of Two SOCs: the four specific misconfigurations that determined which organization was fully compromised undetected
CISA's advisory is notable because it names the specific misconfigurations responsible for Organization A's complete failure to detect a full domain compromise. This is unusual: most red team advisory disclosures describe the attack chain without naming the precise configuration errors on the victim side. AA26-237A names them. The four conditions that allowed the red team to compromise Organization A without detection were: a web application with default credentials that gave internal email access; an unrestricted Machine Account Quota that allowed any domain-authenticated user to create machine accounts used for privilege escalation; an Active Directory Certificate Services template with ESC1 misconfiguration that allowed any domain-authenticated user to request a certificate enabling domain controller impersonation; and an SOC alert environment with too much noise for analysts to distinguish genuine intrusion signals from background alerts. All four of these conditions are common across large enterprise environments, not because organizations are negligent but because they are the default state of an AD environment that has not been specifically hardened against post-exploitation privilege escalation. Machine Account Quota defaults to ten in standard Active Directory configurations. ADCS templates misconfigured for ESC1 are present in a significant fraction of organizations that have implemented certificate-based authentication, as documented by the SpecterOps research that produced the Certify tool. Default application credentials persist in environments where application-specific credential management was not enforced. Alert noise accumulates in SOC environments as detection rules are added over time without being regularly pruned for fidelity. The CISA advisory is the most actionable red team advisory this brief has covered this year because it tells you exactly what to check and why.
Still watching
Days 2–3
Gitea CVE-2026-60004 (Issue 117 · CISA KEV August 26, deadline August 28 — tomorrow) — update to 1.27.1. If update is not possible, disable open user registration immediately. Federal deadline is tomorrow. For internet-accessible instances on vulnerable versions, check for unexpected account registrations, repository creations, and mining process activity since July 27.
Day 2
ShieldBreak CVE-2026-69414 (Issue 113 · Defender patch bypass, patch in progress per August 21) — low privilege to SYSTEM on fully patched Windows 10, 11, and Server 2025. Monitor MSRC for patch release and apply the day it ships. Verify endpoint detection is current for CVE-2026-69414 specifically.
Day 7+
GeoServer zero-day (no CVE, no patch) (Issue 108 · active probing since August 12, jsonArrayContains SQL injection) — no patch as of August 27. Restrict public WFS endpoint access. Limit SQL Server backend permissions to block xp_cmdshell. Monitor logs for injection patterns.
Day 7+
M365 Copilot prompt injection (Issue 98 · Hakon Maloy, reported March 7, 2026) — no CVE, no complete patch, 173 days. Enterprise Copilot prompt injection path remains open. Scope Copilot connector access tightly. Treat Copilot memory as a potential persistence mechanism requiring periodic review.
Day 7+