Tuesday, June 16, 2026
Daily digest
Today's feed is dominated by active exploitation stories — three Fortinet FortiSandbox CVEs, a Cisco SD-WAN zero-day, and a Microsoft 365 Copilot exfiltration chain are all seeing real-world attacks. Patch queues should be prioritized accordingly.
Attackers Actively Exploiting Three Critical Fortinet FortiSandbox Flaws
Threat intelligence firm Defused Cyber confirmed active in-the-wild exploitation of three FortiSandbox vulnerabilities: CVE-2026-39813 (CVSS 9.1, path traversal in JRPC API), CVE-2026-39808, and CVE-2026-25089. One of the flaws was patched only last week, meaning exploitation followed patching within days. Fortinet customers should treat these as emergency patches.
Why it matters: If FortiSandbox is part of your perimeter or email sandboxing stack, these are being actively hit now — verify your version and patch status immediately. Even if you don't run FortiSandbox directly, confirm your MSSP or upstream security vendors don't expose it on your behalf.
Cisco Catalyst SD-WAN Manager Zero-Day (CVE-2026-20262) Patched After Active Exploitation
Cisco released a fix for CVE-2026-20262 (CVSS 6.5), a directory traversal flaw in Catalyst SD-WAN Manager's web UI that allows an authenticated remote attacker to create arbitrary files, and which has been exploited as a zero-day. CISA added it to the KEV catalog with a federal remediation deadline. This is the second Catalyst SD-WAN Manager vulnerability exploited in attacks this month.
Why it matters: CISA's KEV listing creates a binding remediation obligation for federal contractors operating under CMMC/NIST 800-171 expectations. If Cisco SD-WAN is part of your WAN edge or branch connectivity, patch now and audit for indicators of compromise given the zero-day window.
Microsoft 365 Copilot 'SearchLeak' Flaw Allowed One-Click Email, File, and MFA Code Theft
Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click attack called SearchLeak, capable of exfiltrating emails, calendar data, indexed files, and MFA codes. The attack used a legitimate microsoft.com domain link, bypassing standard URL filtering and anti-phishing tools. Microsoft has patched the vulnerability.
Why it matters: M365 GCC High tenants running Copilot should confirm Microsoft's patch has been applied to their environment — GCC High rollouts sometimes lag commercial. This attack chain is particularly dangerous in a CUI-handling environment because it bypasses email security controls entirely and requires only a single user click.
DragonForce Ransomware Abuses Microsoft Teams Relay Infrastructure to Cloak C2 Traffic
The DragonForce ransomware group deployed custom malware dubbed 'Backdoor.Turn' that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, making the malicious traffic appear as legitimate Teams traffic. The technique is designed to evade network-based detection tools that allowlist Microsoft endpoints. Full technical details were published by the discovering researchers.
Why it matters: This directly affects Teams-heavy environments like GCC High deployments — perimeter rules that blanket-trust Microsoft relay IP ranges will not block this C2 channel. Review whether your EDR and SIEM have behavioral detections for Teams relay abuse, and consider whether your network segmentation assumptions need revisiting.
China-Linked Espionage Group Lurked in Medical and Military Research Networks for Over a Year via REDCap Backdoor
A China-nexus threat actor compromised REDCap research database servers at North American medical, academic, and military research institutions, stealing credentials and maintaining access for more than a year undetected. The attackers manipulated victims' own Google Workspace mail-routing rules to silently copy and exfiltrate emails containing sensitive research and defense information. Google discovered and disrupted the campaign.
Why it matters: The tradecraft here — abusing legitimate mail-forwarding rules rather than exfiltrating via external tools — would evade most DLP policies and CASB alerting tuned to outbound data transfers. Audit mail flow rules and transport rules in your M365/GCC High tenant for any unexpected forwarding configurations.
Windows Variants of SprySOCKS Backdoor Target Government Organizations in Four Countries
ESET researchers identified two previously undocumented Windows variants of the SprySOCKS backdoor — previously believed to be Linux-only — being used in attacks against government organizations in at least four countries. The variants (WIN_DRV and WIN_PLUS) use driver-based stealth techniques and hard-coded C2 configurations communicating over TCP and UDP. The malware is attributed to a China-linked threat group.
Why it matters: Government-sector targeting with a kernel-level Windows driver component means standard userspace EDR detections may miss this. Verify your Intune-managed Windows 11 fleet has driver-signing enforcement and Secure Boot enabled, and confirm your EDR vendor has updated signatures for SprySOCKS Windows variants.
Trump White House Memo Sets Aggressive Timelines to Secure Sensitive Military and Intelligence Systems
A new White House national security memorandum establishes accelerated timelines for securing classified, military, and intelligence systems against advanced threats, with explicit concern about AI-driven cyberattacks. The memo targets both government agencies and their supporting contractors. Specific technical requirements and deadlines are detailed in the classified annex, with an unclassified summary released publicly.
Why it matters: Memos of this type historically cascade into updated DFARS/CMMC guidance and contract requirements within 12–18 months. Defense contractors operating at CMMC Level 2 should monitor for forthcoming DAR Council rule changes and ensure POA&M items are being actively closed, not just documented.
LiteLLM Vulnerability Chain Allows Low-Privilege Users to Achieve Full Server Takeover
Obsidian Security disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway, that allows a low-privilege authenticated user to escalate to full admin and execute arbitrary code on the server. A successful exploit exposes all provider API keys brokered through the gateway. LiteLLM is used to proxy calls to over 100 AI model providers behind a single OpenAI-compatible interface.
Why it matters: If your self-hosted AI stack uses LiteLLM as a model gateway — common in on-prem or AWS GovCloud AI deployments — this is a critical patch. A compromise exposes every AI provider key in the system, potentially including keys to sensitive or controlled-data model endpoints. Update immediately and rotate all provider credentials as a precaution.
North Korean APT37 (ScarCruft) Deploying NarwhalRAT via Fake Microsoft Security Alerts
North Korean state-sponsored group ScarCruft (APT37) is running spear-phishing campaigns using emails that impersonate Microsoft Account security notifications to deliver a new Remote Access Trojan called NarwhalRAT. The lures are designed to create urgency around account compromise, prompting targets to open malicious attachments or links. Genians Security Center published the full technical report.
Why it matters: Impersonation of Microsoft account alerts is highly effective in M365 GCC High environments where users are conditioned to respond to legitimate Microsoft security notifications. Ensure your security awareness training includes examples of this specific lure format, and verify that Defender for Office 365 anti-spoofing and impersonation policies are enforced in your tenant.
CISA Adds LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-54420) to KEV Catalog
CISA added CVE-2026-54420 (CVSS 8.5), a symlink-following privilege escalation vulnerability in the LiteSpeed cPanel plugin, to its Known Exploited Vulnerabilities catalog. Federal agencies under FCEB were given a three-day remediation deadline of June 18, 2026. The flaw allows an attacker to escalate to root on affected servers.
Why it matters: If any internet-facing web infrastructure in your environment runs cPanel with the LiteSpeed plugin, this is an actively exploited root escalation with a federal patch deadline — treat it as emergency remediation regardless of your FCEB status.
AWS Wins $2.6B DHS-Wide Cumulus Cloud Contract
AWS secured the first announced award under DHS's Cumulus cloud initiative, a rolling multi-vendor contract vehicle that will also include Oracle, Google Cloud, and Microsoft. The $2.6 billion DHS-wide contract is intended to consolidate and modernize cloud services across the department. Additional awards to other vendors are expected to follow on a rolling schedule.
Why it matters: For contractors supporting DHS components, Cumulus will likely become the mandated procurement pathway for cloud services, which could affect how AWS GovCloud workloads are contracted and governed. Watch for DHS-issued migration timelines that may require SOW or ATO updates.
SimpleHelp Remote Management Software Flaw Lets Unauthenticated Attackers Create Privileged Accounts
A vulnerability in SimpleHelp remote management and support software allows unauthenticated attackers to create privileged technician accounts on servers using OpenID Connect authentication. The flaw requires no credentials to exploit and results in full administrative access to the remote support platform. A patch is available from SimpleHelp.
Why it matters: Remote support and RMM tools are a persistent supply-chain attack vector and a high-value target under CMMC access control requirements (AC.2.006). If SimpleHelp is used for helpdesk or remote administration in your environment, patch immediately and audit for unauthorized technician accounts.