CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2025-5777, CVE-2026-25089, CVE-2026-33825, CVE-2026-39808, CVE-2026-39813, CVE-2026-41091, CVE-2026-45498, CVE-2026-48854, CVE-2026-48907, CVE-2026-50656
IP Addresses:
2.9.99.6
Get tomorrow's brief in your inbox
June 18, 2026
Today: FortiBleed exposes 73,000 Fortinet VPN credentials to a Russian-speaking threat group targeting global enterprises including Chevron, Samsung, and NATO contractors. INC ransomware claims 800+ victims by exploiting proven vulnerabilities including four CISA KEV entries with EPSS scores above 95%. CISA orders federal agencies to patch a maximum-severity Joomla plugin flaw by Friday as active exploitation continues with public exploit code. Microsoft confirms a fourth Windows Defender zero-day codenamed RoguePlanet, granting SYSTEM-level privileges through a race condition. DragonForce ransomware deploys custom backdoor hiding command-and-control traffic as legitimate Microsoft Teams communications. An npm supply chain attack poisons 140+ Mastra packages through a compromised maintainer account, executing malicious code during installation on developer workstations and CI/CD pipelines.
Joomla Content Editor Plugin Zero-Day (CVE-2026-48907)
CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog on Tuesday, requiring federal agencies to patch by Friday. The vulnerability affects Widget Factory Joomla Content Editor (JCE) plugin and carries a maximum CVSS severity score of 10.0. Attackers exploit this improper access control flaw to upload and execute PHP code by creating new editor profiles for unauthenticated users. The JCE security team released version 2.9.99.6 in early June and warns that working exploit code is public, attacks are automated, and sites without public registration are not safe. The vulnerability has an EPSS score of 0.047 (91st percentile), indicating elevated exploitation probability. Critically, updating closes the entry point but does not remove what attackers left behind.
FortiBleed: 73,000 Fortinet VPN Credentials Exposed
Security researcher Bob Diachenko discovered a server containing valid Fortinet VPN credentials for 73,932 firewall URLs across 194 countries and 21,632 unique domains. The exposed database includes usernames, email addresses, and plaintext passwords for organizations including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, and a Turkish NATO defense contractor. Diachenko's investigation reveals a Russian-speaking multi-operator threat group conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 Microsoft SQL Server systems. The attackers intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used recovered credentials for lateral movement into internal Active Directory environments. Hudson Rock analysis confirms this is one of the largest known troves of compromised Fortinet credentials, with the highest impact in India, United States, Taiwan, Mexico, and Turkey. The most affected sectors are telecommunications, IT services, financial services, government, healthcare, education, and manufacturing. Security researcher Kevin Beaumont notes many exposed credentials were long complex passwords that would ordinarily be difficult to crack, suggesting they were extracted from Fortinet configuration files rather than brute-forced.
Fortinet FortiSandbox Vulnerabilities Under Active Exploitation
Attackers are exploiting three critical Fortinet FortiSandbox vulnerabilities disclosed in April and June, targeting the security product customers use to identify and defend against network threats. CVE-2026-39808 (OS command injection, EPSS 0.662/99th percentile) and CVE-2026-39813 (path traversal, EPSS 0.180/97th percentile) were disclosed in April but now face active exploitation. Defused observed 49 exploitation events from 11 distinct IPs across six days starting June 9, with activity originating from China, South Korea, Taiwan, India, Singapore, Germany, Netherlands, Canada, and Bulgaria. Attackers are also targeting CVE-2026-25089 (EPSS 0.027/84th percentile), patched June 9. Post-exploitation activity includes verification and reconnaissance, which typically precedes heavier attack waves. Researchers warn FortiSandbox is a high-value target because it ingests from and connects to other Fortinet devices and represents a trusted system in enterprise security architecture. A compromise provides elevated access within security-sensitive environments and could undermine broader detection workflows.
Microsoft Defender Zero-Day RoguePlanet (CVE-2026-50656)
Microsoft confirmed development of a patch for CVE-2026-50656 (CVSS 7.8), a privilege escalation vulnerability in the Microsoft Malware Protection Engine publicly disclosed as RoguePlanet. Security researcher Chaotic Eclipse released a proof-of-concept exploit demonstrating a race condition that grants attackers SYSTEM-level privileges. The researcher reports 100% success rates on some machines while others struggle, noting the exploit works regardless of whether real-time protection is enabled or disabled. The PoC even functions when Defender runs in passive mode. RoguePlanet is the fourth Defender vulnerability disclosed by Chaotic Eclipse after BlueHammer (CVE-2026-33825, CISA KEV, EPSS 0.062/93rd percentile), UnDefend (CVE-2026-45498, CISA KEV, EPSS 0.025/83rd percentile), and RedSun (CVE-2026-41091, CISA KEV, EPSS 0.012/63rd percentile), all of which Microsoft has patched. CVE-2026-50656 currently has an EPSS score of 0.004 (30th percentile), though this will likely rise as public exploit code circulates.
INC Ransomware Reaches 800+ Victims Through Basic Tactics
Acronis Threat Research Unit published analysis of INC ransomware, a group that emerged in 2023 and has claimed over 800 victims by mastering fundamental attack techniques. INC benefited from the shutdown of ALPHV/BlackCat and disruption of LockBit, gaining market share alongside other ascending groups like The Gentlemen. The group operates as ransomware-as-a-service with double extortion tactics (encryption plus data leaking) and targets manufacturing, legal services, healthcare, technology, construction, and education sectors. INC demonstrates preference for organizations with especially sensitive data to add extortion pressure, repeatedly targeting high-profile victims including Scottish healthcare organization NHS Dumfries and Galloway and Alder Hey Children's Hospital in Liverpool. Acronis attributes INC's growth to unusually aggressive victim selection, rapid affiliate scaling, and focus on proven intrusion methods rather than technical innovation. Intrusion methods include spear-phishing, valid account credentials from initial access brokers, and exploitation of tried-and-tested vulnerabilities including Citrix Bleed CVE-2025-5777 (CISA KEV, EPSS 0.999/100th percentile), SimpleHelp RMM bug CVE-2024-57727 (CISA KEV, EPSS 0.951/100th percentile), Citrix Netscaler CVE-2023-3519 (CISA KEV, EPSS 0.993/100th percentile), and Fortinet EMS CVE-2023-48788 (CISA KEV, EPSS 0.985/100th percentile). Post-compromise tactics include credential theft via base64 encoded scripts, living-off-the-land binaries for lateral movement, EDR killers for evasion, and commercial remote access tools for command and control. INC exfiltrates data by packaging into archives and uploading to attacker-controlled cloud storage. The malware, recently rewritten in Rust for both Windows and Linux/ESXi, has been sold to at least three parties. Ransomware actors Lynx and Sinobi use strains of INC malware.
DragonForce Ransomware Deploys Custom Backdoor Using Microsoft Teams Infrastructure
Symantec and Carbon Black threat hunters identified Backdoor.Turn, a sophisticated Go-based malware deployed by DragonForce ransomware operators that hides command-and-control communication as legitimate Microsoft Teams traffic. The backdoor obtains an anonymous Teams visitor token from Microsoft's Skype-backed identity services, uses a legitimate Microsoft TURN relay to establish connections, and runs a QUIC session to the attacker's real C2 server. This appears to be the first malware family to abuse TURN relay infrastructure in this manner. The custom backdoor was used in an attack on a US services firm, likely compromised through an unknown SQL or MSSQL server vulnerability. DragonForce operators accessed the victim network in December 2025 and relied on DLL sideloading to fetch additional malware. The hackers established persistence, conducted reconnaissance, employed bring-your-own-vulnerable-driver (BYOVD) strategies to exploit signed driver flaws for kernel-level access, and terminated security processes. DragonForce deployed ransomware for encryption and exfiltration while maintaining persistence through Backdoor.Turn after encryption. The backdoor enables command execution, process creation, network scanning, LDAP/AD mapping, lateral movement with stolen credentials, and credential exfiltration from browsers. Researchers note security products only see C2 traffic going to legitimate Teams servers, leaving defenders unaware of data exfiltration.
EdTech Sector Faces Escalating Ransomware and Data Breach Activity
Resecurity reports the education technology sector has become a prime target for cybercriminals as attacks against educational institutions and EdTech platforms continue to escalate. EdTech systems store sensitive data including student records, employee information, and payment data, making the sector appealing for financial gain and data exploitation. The targeting aligns with broader trends of attackers focusing on sectors where operational disruption creates immediate pressure to restore services and pay ransoms.
Mastra npm Supply Chain Attack Poisons 140+ Packages
Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 140+ packages across the mastra and @mastra scopes on the npm registry. The compromise originated from takeover of the ehindero npm maintainer account, which had publish rights across the Mastra ecosystem. The attacker used the compromised account to publish poisoned package versions introducing easy-day-js, a malicious typosquat of the popular dayjs library (57M+ weekly downloads). The malware triggered a postinstall hook executing an obfuscated dropper script that disabled TLS certificate verification, contacted attacker-controlled C2 infrastructure, downloaded a second-stage payload, and executed it as a detached hidden process. The attack followed a coordinated staged delivery pattern with a clean bait version published first, followed by weaponized versions and rapid publication of compromised Mastra packages. Because the payload executes during installation, any developer workstation or CI/CD pipeline running npm install or npm update after compromised versions were published faced potential exposure, regardless of whether the package was imported in application code. This created risk to credentials, tokens, build environments, and downstream software integrity. Microsoft Threat Intelligence detected the compromise through anomalous publishing patterns. All previous Mastra versions through v1.13.0 were published through GitHub Actions OIDC (legitimate CI/CD pipeline). Version 1.13.1 was manually published by ehindero using a Tutamail anonymous email address. The only change was addition of easy-day-js@^1.11.21 as a dependency with no corresponding code changes in the Mastra GitHub repository. Both the compromised publisher ([email protected]) and typosquat publisher ([email protected]) used Tutamail anonymous email. Microsoft shared findings with npm security, and compromised packages have been removed with attacker publish access revoked.
Account Takeover Attacks Rising Through Session Hijacking and MFA Bypass
Credential abuse remains one of the most reliable attack vectors, accounting for 22% of breaches in 2025 according to Verizon. While multi-factor authentication remains critical defense, attackers have adapted tactics to target the authentication process itself through MFA fatigue (prompt bombing) and session hijacking. MFA fatigue involves repeatedly triggering approval requests until users accept out of frustration. The 2022 Uber breach exemplified this tactic when attackers targeted an employee with repeated MFA prompts until one was approved, allowing privilege escalation and cloud infrastructure compromise. Attackers also use adversary-in-the-middle frameworks and session hijacking tools to bypass MFA entirely by stealing authenticated session tokens after login. Threat researchers at Outpost24 uncovered a phishing campaign employing a legitimate Cisco domain through multi-chain redirect attacks designed to evade detection and increase credibility. Compromised endpoints provide valuable routes into trusted environments, with infostealer malware harvesting credentials, browser-stored passwords, and authenticated session cookies directly from user devices. The expansion of BYOD and unmanaged devices accessing corporate applications creates limited visibility into whether employees connect using devices with missing security updates or malware infections.
CASB Blind Spot: QUIC Protocol Bypasses Web Traffic Inspection
A SANS Internet Storm Center guest diary by Varun Murdula identifies a critical gap in Cloud Access Security Broker (CASB) enforcement where Chrome and other browsers can reach blocked destinations without logging the traffic. The issue stems from QUIC, the UDP-based protocol powering HTTP/3, which most CASBs cannot inspect because they were designed to inspect TCP traffic. When a security team configures a CASB to block a website or cloud service, the assumption is the block applies across all browsers. Testing across five browsers on a managed endpoint with active CASB policy revealed real enforcement gaps. CASBs perform SSL/TLS inspection by intercepting connections, decrypting traffic, applying policy, re-encrypting, and forwarding. This requires browsers to trust CASB re-signed certificates through root CA certificates in the device's trusted certificate store. However, QUIC creates coverage gaps because it runs over UDP rather than TCP, bypassing traditional proxy-based inspection. The gap is documented by security vendors including Palo Alto Networks, Forcepoint, and Cloudflare, but many security teams have never tested for it. A block policy can appear completely effective in logs and dashboards while traffic to blocked destinations flows freely through browsers using QUIC on the same machine.
Crypto Clipper Malware Uses Tor and Worm-Like Propagation
Microsoft Security Blog reports a cryptocurrency clipboard hijacker using Tor for command and control alongside worm-like propagation for persistence. The malware monitors clipboard contents for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, redirecting transactions. The campaign abuses fake GitHub stars, AI-generated narration, and VirusTotal comments to establish false legitimacy. Check Point Research confirms the threat actor uses fake reputation signals across multiple platforms to distribute the malware. The use of Tor for C2 communications complicates network-based detection while worm-like propagation ensures persistence across reboots and spreading to connected systems.
Office Apps Experiencing Launch Issues After June Updates
Microsoft confirmed Office applications are experiencing launch issues following June updates. Organizations are reporting problems opening Word, Excel, PowerPoint, and other Office applications after deploying monthly security updates. Microsoft is investigating the root cause and working on a fix.
Interpol: Cyber Offenses Account for One-Third of Crime in Asia-Pacific
Interpol's latest review shows cyber offenses now account for approximately one-third of all crime across Asia and South Pacific regions. Scams continue to dominate the threat landscape while AI-enabled attackers prove difficult to counter for cash-strapped regions. The data demonstrates the continued shift from traditional crime to cyber-enabled criminal activity, with scams representing the highest-volume threat category.
Junior Hacker Uses Tailscale and OpenSSH for Backup Persistence
A junior-level threat actor deployed Tailscale VPN and OpenSSH as backup persistence mechanisms after their primary command-and-control infrastructure went offline. The tactic demonstrates the commoditization of living-off-the-land techniques where attackers use legitimate remote access tools to maintain access when custom C2 infrastructure fails. Tailscale provides encrypted mesh VPN connectivity while OpenSSH offers encrypted remote shell access, both appearing as legitimate administrative tools in most environments.
CVE-2026-48854: Elixir gRPC Unbounded Request Body Memory Exhaustion
Microsoft Security Response Center published CVE-2026-48854 affecting elixir-grpc/grpc, an unbounded request body accumulation vulnerability causing memory exhaustion. Attackers can send specially crafted requests causing the server to accumulate unbounded request bodies in memory, leading to denial of service through resource exhaustion.
Coordinated SSH Brute Force Attacks Over Three Months
SANS Internet Storm Center guest diary documents coordinated SSH brute force attack behavior over the last three months, showing sustained automated credential guessing against internet-facing SSH services. The coordinated nature suggests botnet or distributed attack infrastructure targeting weak credentials across multiple organizations simultaneously.
Today's briefing reveals converging pressures on enterprise network perimeters and supply chain integrity. The FortiBleed credential leak affecting 73,000 devices demonstrates the scale at which state-aligned threat groups operate, combining massive brute force campaigns (1.16 billion attempts) with GPU-powered hash cracking and Active Directory lateral movement. This pairs with active exploitation of three FortiSandbox vulnerabilities, showing attackers target both the VPN perimeter and the security infrastructure behind it. The npm supply chain attack poisoning 140+ Mastra packages through a compromised maintainer account highlights the fragility of trust models in software distribution, particularly the risk of postinstall hooks executing malware during developer workflows and CI/CD builds. The CASB blind spot created by QUIC protocol adoption shows how architectural assumptions (TCP-based inspection) fail as protocols evolve, leaving enforcement gaps security teams have not tested for. INC ransomware's success exploiting four CISA KEV vulnerabilities with EPSS scores above 95% reinforces that attackers do not need novel techniques when organizations fail to patch proven attack vectors. The common thread is trust boundary failure: VPN credentials that should protect the perimeter are compromised at scale, package maintainer accounts that should guarantee code integrity are taken over, CASB policies that should block traffic fail against modern protocols, and vulnerabilities that should be patched remain exploitable months after disclosure.