← Carolina Clear Tech

Cyber Threat Brief

2026-06-20

Listen to this brief (28:58)

Download MP3
Show Notes

Show Notes - 2026-06-20

Stories Covered

CVEs Referenced

CVE-2026-12439, CVE-2026-12446, CVE-2026-12447, CVE-2026-12453, CVE-2026-12454, CVE-2026-12458, CVE-2026-12459, CVE-2026-12460, CVE-2026-20253, CVE-2026-25592, CVE-2026-26030, CVE-2026-4020, CVE-2026-8713

Indicators of Compromise

IP Addresses: 0.4.2.2

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Threat Brief - June 20, 2026

Today: CISA orders federal agencies to patch Splunk Enterprise by Sunday as active exploitation confirmed. FortiBleed campaign hits 86,000 Fortinet devices with verified credentials as Russian threat actors run 1.16 billion password attempts. DragonForce ransomware abuses Microsoft Teams TURN relays to hide C2 traffic behind trusted infrastructure.

Critical Alerts

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday (CVE-2026-20253)

CISA added CVE-2026-20253 to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 21. The critical flaw affects Splunk Enterprise versions 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6, allowing unauthenticated remote attackers to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint with no authentication. WatchTowr published proof-of-concept exploit code on June 12, and Splunk confirmed limited in-the-wild exploitation on June 18. Shadowserver tracks over 1,400 Internet-exposed Splunk instances, with most in North America and Europe. The vulnerability carries an EPSS score of 0.100 (95th percentile), indicating high likelihood of exploitation.

FortiBleed: 86,000 Fortinet Device Credentials Compromised

Russian-speaking threat actors compiled a verified database of 86,644 working administrative and VPN credentials for FortiGate firewalls across 194 countries. The campaign combined 1.16 billion credential attempts against 320,000 FortiGate targets and 2.1 billion attempts against 163,000 MSSQL servers. Threat actors exploited legacy SHA-256 credential hashing in older FortiOS versions and extracted credentials from configuration files, then used a 45-GPU cluster managed through Hashtopolis for offline cracking. The campaign is self-sustaining: attackers spray known passwords, intercept SSL VPN traffic on compromised devices to harvest additional credentials, and add verified logins back to their attack database. Generic admin accounts (35%) and built-in Fortinet system accounts (28.3%) comprise most compromised credentials, indicating widespread failure to rename default accounts or rotate factory credentials. Confirmed targets include government entities, critical infrastructure providers, and a Turkish NATO defense contractor from which classified documents were exfiltrated.

Ransomware & Extortion

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service operation maintains a mature portfolio of EDR killers centered around the GentleKiller framework, with eight variants targeting 400 processes from 48 security vendors. ESET reports the group can operationalize newly disclosed bring-your-own-vulnerable-driver (BYOVD) proof-of-concepts within days of public release. Each GentleKiller variant mimics a different legitimate security product (Kaspersky, FACEIT Anti-Cheat, Valorant, Javelin, WatchDog, Network Blocker, Cleaner, G11) and abuses a different vulnerable driver for EDR termination. The group also incorporates third-party tools including HexKiller (googleApiUtil64.sys, previously exclusive to Warlock ransomware), ThrottleBlood (used by MedusaLocker and DragonForce affiliates), and HavocKiller (havoc.sys). All tools share standardized defense-evasion layers with fake version information, copied legitimate certificates, icons, and binary protection using Enigma or Themida. The Gentlemen has claimed 504 victims since March 2025, primarily in Southeast Asia, South America, and Western Europe, and is led by Russian national Alexander Andreevich Yapaev.

DragonForce Abuses Microsoft Teams Relays to Conceal Backdoor Traffic

DragonForce ransomware operators deployed a custom Go-based backdoor called Backdoor.Turn that conceals command-and-control traffic within legitimate Microsoft Teams relay infrastructure. Researchers observed an attack on a major U.S. services company where DragonForce obtained an anonymous Teams visitor token backed by Skype identity services, then leveraged Microsoft's Traversal Using Relays around NAT (TURN) protocol to establish a QUIC session with the attacker's C2 server. Network defenders only observed outbound traffic to trusted Microsoft servers, allowing attackers to remain undetected for up to two months. The intrusion began in December 2025 via SQL or MSSQL server exploitation, followed by PowerShell delivery of a fake technical support hotfix ZIP containing DLL side-loading sequences. Attackers employed BYOVD techniques with a Huawei audio driver and ABYSSWORKER payload masquerading as Palo Alto software to achieve kernel-level privileges and terminate security tools. This marks the first documented in-the-wild abuse of Microsoft Teams TURN relays for C2 communications.

Klue OAuth breach victim list grows as Icarus hackers claim attack

Market intelligence platform Klue confirmed a security incident on June 12 where attackers gained access through a compromised legacy credential associated with an integration service, then obtained OAuth tokens to connect Klue with Salesforce and other third-party platforms. Attackers used stolen OAuth credentials to access customer Salesforce environments and conduct large-scale data theft via Python scripts querying Salesforce's API for extended periods. The Icarus extortion operation publicly claimed responsibility and threatened to leak stolen data unless victims contact them via Session messaging platform. Affected organizations include Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Klue revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, and engaged CrowdStrike for incident response. Most victims report the incident was limited to Salesforce data exfiltration with no impact to their own platforms, infrastructure, payment information, or internal systems.

Business & Infrastructure Threats

Threat Brief: Mitigating Large-Scale Credential Attacks (FortiBleed)

Unit 42 warns of a large-scale password spraying and credential theft campaign targeting Fortinet devices, with reports of MSSQL and Sophos devices also affected. Threat actors use a curated password list developed through previous breaches and vulnerability exploitation to conduct internet-wide scanning and password spraying. Once credentials are obtained, attackers exploit privilege escalation vulnerabilities to extract device configuration files containing stored credentials, perform offline password cracking to add to their attack list, and establish persistent administrator access. An initial access broker on Russian-language forum Exploit.in claimed responsibility and offered harvested credentials for sale on June 16, 2026. SOCRadar provided initial reporting on FortiGate targeting.

CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

Microsoft warns of a Windows cryptocurrency clipper active since February 2026 that establishes a lightweight backdoor with data exfiltration and remote code execution capabilities. CryptoBandits deploys a portable Tor client on infected systems and routes traffic through a local SOCKS5 proxy to poll a hidden-service C2 server every 500 milliseconds. The malware is distributed through malicious shortcut (.lnk) payloads and deploys two components: a worm for USB propagation and a clipper/stealer for cryptocurrency wallet theft. The clipper uses Windows Script Host and ActiveX-driven logic, checks whether Task Manager is running as an anti-analysis defense, and achieves persistence through scheduled tasks. It can extract seed phrases and private keys from cryptocurrency wallets and replace cryptocurrency addresses in the clipboard with attacker-controlled addresses to hijack transactions. The malware employs multi-layered obfuscation, decrypts all components at runtime, and uses the Tor client to route communication over localhost:9050 to hide C2 location.

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Law enforcement from the Netherlands, Canada, Germany, and the U.S. disrupted 106 servers linked to SocGholish malware and cleaned infections from 14,971 WordPress websites as part of Operation Endgame, an international initiative targeting botnets associated with Russian cybercrime syndicate Evil Corp. SocGholish is a JavaScript-based downloader active since 2017 that hijacks legitimate websites to deceive visitors into installing malicious payloads disguised as browser updates. Upon installation, the malware establishes remote access enabling threat actors to deploy secondary malware and ransomware families including LockBit, RansomHub, Dridex, and Raspberry Robin. SocGholish operators (Gold Prelude, Mustard Tempest, Purple Vallhund, TA569, UNC1543) have been observed delivering loaders like Gholoader and MintsLoader, which deploy GhostWeaver, AsyncRAT, and NetSupport RAT. Authorities notified affected website owners to update CMS, change credentials, delete suspicious accounts, and implement multi-factor authentication.

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin (CVE-2026-4020)

Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in Gravity SMTP WordPress plugin, active on 100,000 sites. CVE-2026-4020 affects all versions from 2.1.4 and older and was fixed in version 2.1.5 released March 17. The flaw stems from an exposed REST API endpoint whose permission_callback always returns true, allowing unauthenticated GET requests to receive a comprehensive JSON system report containing API keys, secrets, OAuth tokens for email integrations (Amazon SES, Google, Mailjet, Resend, Zoho), WordPress configuration details, server and PHP environment information, and database configuration. Wordfence blocked over 17 million exploit attempts against protected customers, with exploitation activity spiking to 4 million requests on June 7.

1.2 million WordPress sites compromised in OptinMonster supply chain attack

Attackers injected malicious JavaScript into Awesome Motive's OptinMonster, TrustPulse, and PushEngage WordPress plugin CDN scripts. The payload activates for logged-in administrators, creating rogue administrator accounts and a hidden backdoor plugin. The breach stemmed from a compromised UpdraftPlus instance and CDN key. The supply chain attack affected more than 1.2 million WordPress sites.

Texas govt data breach exposes over 3 million driver's licenses

Texas Parks and Wildlife Department disclosed a data breach at its license system vendor affecting 3,087,721 Texas hunting and fishing license customers. Texas Cyber Command discovered the intrusion and confirmed that driver's license information, passport numbers, email addresses, phone numbers, and residential addresses were exposed. Social Security Numbers, dates of birth, and financial information were not impacted. TPWD is working with the vendor to implement new safeguards and enhanced monitoring, and is offering one year of free credit monitoring to affected individuals.

General Security News

Authorities Dismantle PhaaS Network & Clean Sites Infected with SocGholish

Coordinated FBI-led action dismantled Outsider Enterprise, a Chinese Phishing-as-a-Service operation running since 2023. The syndicate combined AI and distributed phishing kits to impersonate trusted brands across millions of fraudulent SMS messages sent from major U.S. telecom carriers. Investigators attribute $1.9 billion in financial losses and theft of roughly 3.8 million credit card records to the operation. Federal authorities seized multiple administrative servers, a Shopify storefront, a Telegram bot containing customer data, and approximately $100,000 in cryptocurrency. Google disabled thousands of associated domains and filed a civil lawsuit against the infrastructure operators, while coordinating with AT&T, T-Mobile, and Verizon to block fraudulent text messages.

MaXSS and Spyder flaws expose 10 million Chrome users to hacking

Critical vulnerabilities in SiderAI (Spyder) and MaxAI (MaXSS) agentic side-panel Chrome extensions allow malicious websites to trigger arbitrary extension actions, including hidden tab screenshots, AI memory dumps, and potential file access. With over 10 million combined installs and no vendor response, the issues enable full browser session compromise and account takeovers without user interaction.

10-year-old phpBB flaw enables session hijacking

Researchers uncovered a critical authentication bypass in phpBB versions up to 3.3.16 and 4.0.0-a2. A single unauthenticated HTTP request can impersonate any user, including admins, exposing private messages and forum content, and providing full administrative control. phpBB users should upgrade immediately to 3.3.17 or the latest master branch.

JetBrains Marketplace plugins steal developer AI keys

At least 15 malicious AI coding assistant plugins published in the JetBrains Marketplace exfiltrate OpenAI, DeepSeek, and similar API keys. The plugins have racked up nearly 70,000 installs while functioning as advertised. Keys are sent to attacker-controlled servers, enabling unauthorized use of developer AI service accounts and potential large-scale API abuse.

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution (CVE-2026-25592, CVE-2026-26030)

Microsoft researchers detailed an exploit chain named AutoJack that turns an AI browsing agent into a delivery vehicle for remote code execution. The flaw sits in AutoGen Studio, the open-source prototyping interface for Microsoft Research's AutoGen multi-agent framework. The vulnerability was present in two pre-release PyPI builds (0.4.3.dev1 and 0.4.3.dev2) that included an unauthenticated MCP WebSocket route accepting commands directly from request parameters. The socket trusted localhost connections, skipped authentication on MCP paths, and ran attacker-supplied commands under the AutoGen Studio process account. A web page rendered by a local browsing agent could execute arbitrary commands on the host. Microsoft reported the behavior to MSRC and maintainers hardened the main branch in commit b047730, but no patched PyPI release exists yet.

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers published a working exploit dubbed usbliter8 that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. The code is burned into silicon at manufacture and cannot be patched via software update. The exploit requires physical possession of the device in DFU mode and connection via USB to a dedicated RP2350-based microcontroller board, completing in under two seconds. Affected devices include iPhone XS, XS Max, XR, iPhone 11 series, iPhone SE (2nd gen), iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen, Apple Watch Series 4 and 5, Watch SE (1st gen), and HomePod mini. The root issue is a hardware flaw in the Synopsys DWC2 USB controller that creates a repeatable buffer underflow, stepping the write pointer backwards through memory 12 bytes at a time. On A12 and A13, the USB DART (IOMMU) runs in bypass mode, allowing DMA pointer to reach and overwrite arbitrary SRAM. Post-exploitation injects a custom USB request handler and can temporarily demote SoC production mode or boot unsigned iBoot images outside Apple's chain of trust. A11 is not affected; A14 and later appear to configure DART correctly.

Patch Priority

Vulnerability Disclosures

Avada Builder WordPress plugin (CVE-2026-8713)

Critical unauthenticated arbitrary file-deletion flaw affects Avada Builder WordPress plugin used on one million sites. Attackers can delete arbitrary files on the server through a path traversal flaw, provided a published Avada form is configured to save submissions to the database. Deleting critical files such as wp-config.php can revert the site to its initial setup state, leading to full site takeover and remote code execution. Fixed in version 3.15.4. No active exploitation observed yet.

Microsoft: June 2026 Windows updates break Recycle Bin prompts

Microsoft confirmed a bug in June 2026 Windows updates that causes different filenames to appear in the confirmation dialog when permanently deleting a file from the Recycle Bin. The dialog displays the internal Recycle Bin filename (for example, $Rxxxxx.ext) instead of the original filename. The issue affects all supported Windows client and server platforms. Microsoft is working on a fix for a future Windows update, with a temporary workaround available for businesses through Microsoft's Support for business.

Chromium CVEs (CVE-2026-12446, CVE-2026-12458, CVE-2026-12439, CVE-2026-12447, CVE-2026-12453, CVE-2026-12459, CVE-2026-12460, CVE-2026-12454)

Microsoft Security Response Center published corrected CVE titles for multiple Chromium vulnerabilities including insufficient data validation in Passwords (CVE-2026-12446), incorrect security UI in Passwords (CVE-2026-12458), use after free in Digital Credentials (CVE-2026-12439), heap buffer overflow in WebRTC (CVE-2026-12447), insufficient validation of untrusted input in Input (CVE-2026-12453), inappropriate implementation in Serial (CVE-2026-12459), insufficient policy enforcement in File System Access (CVE-2026-12460), and race in Safe Browsing (CVE-2026-12454). All are informational changes only with EPSS scores ranging from 0.001 to 0.004 (4th to 32nd percentile).

Trends & Context

The FortiBleed campaign demonstrates a self-sustaining attack model where credential theft and network interception create a feedback loop enabling continued expansion. This pattern, combined with The Gentlemen's rapid operationalization of public BYOVD exploits and DragonForce's abuse of trusted Microsoft Teams infrastructure, shows threat actors optimizing for stealth and persistence by exploiting legitimate services and weak credential practices. The high volume of WordPress plugin supply chain attacks and authentication bypass flaws highlights the persistent risk in third-party integrations and the immediate need for strict authentication controls on all API endpoints.