SAMURAI CYBER WATCH
Issue #11 — July 10, 2026
Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations
THIS WEEK'S BRIEFING
AI Infrastructure Under Attack — CISA Confirms Active Exploitation in Langflow, ColdFusion, and Joomla
The rapid proliferation of AI tooling is creating security blind spots. Academic institutions hit in the same week. Cloud PBX fraud strikes SMBs directly. This week's incidents share one thread: no environment is too new, too small, or too specialized to be targeted.
THE KEY DEVELOPMENT
VULNERABILITIES HIT AI INFRASTRUCTURE HARD: ACTIVE EXPLOITATION CONFIRMED IN ADOBE COLDFUSION, LANGFLOW, AND JOOMLA
The most critical development this week is the emergency alert issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 8. CISA confirmed that vulnerabilities in Adobe ColdFusion, Langflow, and a Joomla extension are being actively exploited in the wild, not merely as theoretical threats.
The vulnerability drawing my closest attention is CVE-2026-33017 in Langflow. Trend Micro has already confirmed this flaw is being weaponized in cryptocurrency mining attacks, and when viewed alongside the CISA alert, the attack picture comes into sharp focus. Langflow is an open-source framework that allows developers to build AI applications powered by large language models through a largely no-code, visual interface. It has seen rapid adoption across environments ranging from prototype builds to full production deployments. This incident is a stark reminder that the rapid proliferation of AI tooling is creating security blind spots even as it delivers convenience.
The same logic applies to ColdFusion. Despite being a recurring target for years, unpatched instances persist in legacy environments. With CISA designating active exploitation as confirmed, executives must treat patching as a task for today, not something to defer to next month's agenda.
JAPAN LENS: CONCENTRATED ATTACKS ON ACADEMIC INSTITUTIONS AND THE CHALLENGES OF JAPAN'S SECURITY CULTURE
Domestic incidents also demanded attention this week. Two academic institutions, Nihon University and Toyama Prefectural University, publicly disclosed unauthorized access incidents in the same week. In the former case, email accounts were compromised and abused as spam relay infrastructure. In the latter, Microsoft 365 accounts and a student organization website were breached.
With more than two decades in this industry, I can say that a concentration of attacks on academic institutions within the same period is not coincidental. In the weeks leading up to summer recess, security teams tend to be stretched thin, and universities carry large populations of hard-to-manage accounts belonging to current students and alumni. Attackers know this rhythm well.
A structural problem common to Japanese academic institutions is the weakness of IT security budgets and the near-universal absence of dedicated security personnel. Japan's Ministry of Education, Culture, Sports, Science and Technology has developed security guidelines for educational institutions in recent years, but a significant gap remains between the existence of guidelines and their actual implementation on the ground. Regarding the Microsoft 365 breach at Toyama Prefectural University, the evidence suggests that multi-factor authentication may not have been fully enforced following the institution's cloud migration. The misconception that simply adopting a cloud service equates to being secure appears to remain stubbornly persistent.
BEYOND THE EPICENTER: A DEFENSE ARGUMENT FOR SMB LEADERS IN AN ERA WHERE SIMPLY USING A TOOL MAKES YOU A TARGET
Looking across this week's incident list, it is clear that large enterprises are not the only targets. Plesk is server management software widely used by small and medium-sized businesses. The cloud PBX breach at CC Architect struck directly at SMB operational infrastructure. And the phishing campaign exploiting Makuake's platform cleverly targeted general consumers and small merchants who trusted the service.
My message to SMB leaders has been consistent: the era of being too small to be a target ended long ago. Attackers are no longer selecting victims by hand. They use automated scanning tools that sweep entire IP ranges for vulnerable systems. A Plesk server that has not been updated carries the same level of risk regardless of where in the world it is hosted.
The lesson from the cloud PBX breach is particularly important. Toll fraud results in direct financial losses for small businesses. I urge you to verify right now whether multi-factor authentication is configured on your administrative console. In this industry, it is far from unusual for a zero-cost countermeasure to prevent the most severe possible damage.
STATE ACTOR WATCH: INDICATORS OF STATE INVOLVEMENT AND APT GROUP EXPANSION ACROSS THE ASIA-PACIFIC
No incidents this week carry explicit state attribution, but critical context is worth noting. ESET's H1 2026 APT Activity Report documents the continued and expanding activity of APT groups including OceanLotus and FishMonger across the Asia-Pacific region.
Reinterpreting the Langflow attacks through this lens: the exploitation currently confirmed is attributed to cybercriminal groups motivated by cryptocurrency mining. However, once an initial foothold is established within an AI orchestration platform, the potential for repurposing that access for intelligence collection and reconnaissance is very real. LLM frameworks are increasingly connected to organizations' internal data and business processes, meaning the intelligence value of a successful breach is anything but low.
The same is true for the Adobe ColdFusion vulnerability. There are documented historical cases of state-sponsored groups exploiting it in targeted attacks. Organizations running ColdFusion in government agencies, defense-related companies, or research institutions should move beyond simply applying a patch and begin immediately reviewing logs for indicators of compromise reaching back before the patch was applied.
DEFEND WITHOUT CHOOSING SIDES
Practical defensive actions drawn from this week's incidents
① Patching Langflow and Adobe ColdFusion must be your top priority. CVE-2026-33017 has confirmed active exploitation in the wild. There is no time to spare. Alongside patching, restrict network access to servers running AI frameworks to the minimum necessary. If a development environment is directly exposed to the internet, impose access controls immediately.
② Deploy browser updates for Google Chrome and Firefox for iOS across all endpoints urgently. This round of Chrome fixes addresses critical vulnerabilities, and forced updates through endpoint management tooling are strongly recommended. Organizations operating a bring-your-own-device policy should consider formalizing a procedure for verifying browser versions on personally owned devices.
③ Conduct a full audit of MFA enrollment status across all Microsoft 365 accounts. As the Toyama Prefectural University incident demonstrates, cloud accounts continue to be left without MFA configured. The goal should be completing mandatory MFA enforcement for all users — not just administrators — before the end of this week.
④ Organizations operating Cisco ISE should apply available workarounds as directed in Cisco's security advisory while awaiting the patch release scheduled for July 15. Because ISE serves as an authentication backbone, a successful breach creates a launchpad for lateral movement across the entire organization. Strengthening monitoring of access logs in parallel is essential.
⑤ Using the Makuake phishing incident as a reference point, audit whether your own service's messaging and notification functions are being abused by attackers. Phishing sent from legitimate domains bypasses conventional filtering far more easily. Issue advisories to your users and consider implementing a warning display for any external URLs embedded in in-platform messages.
NEXT ISSUE
Next week, we continue tracking the evolving threat landscape — including any further developments on the Langflow and ColdFusion exploitation campaigns and ongoing APT activity across Asia-Pacific. See you Friday.
About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-armed state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.
Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.
© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.