In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Eclipse Milo versions 0.6.0 through 1.1.4 contain a critical flaw in how they process username tokens encrypted with Basic128Rsa15. The vulnerability stems from distinguishable error responses when the server validates RSA PKCS#1 v1.5 padding during authentication—essentially leaking information about whether padding is valid before checking actual credentials. An on-path attacker who intercepts a victim's encrypted username token can exploit this behavior by sending repeated unauthenticated ActivateSession requests, using the server's error responses as a padding oracle to systematically recover the victim's password. This affects industrial control systems, manufacturing, and enterprise environments relying on OPC UA (OLE for Process Control Unified Architecture) for operational technology communication, where credentials control access to critical infrastructure.
While this CVE has zero mapped MITRE ATT&CK techniques, Casky's extended reasoning capabilities would detect the underlying attack pattern by correlating CWE-204 (Observable Discrepancy) findings with authentication telemetry. A practitioner would observe multiple failed ActivateSession attempts from the same source with timing or response pattern variations, followed by successful authentication with previously unknown credentials. Casky would flag this as potential Credential Access (T1110 - Brute Force variants) combined with information disclosure tactics. The platform's 754 security skills would surface misconfigurations in OPC UA server error handling and guide practitioners toward patching Milo versions, implementing network segmentation to prevent on-path attacks, and monitoring for anomalous authentication patterns that indicate padding oracle exploitation attempts.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-60007. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation