Wednesday, June 17, 2026
Daily digest
Microsoft Defender's unpatched 'RoguePlanet' zero-day is the story to watch today — no fix is available yet for a vulnerability affecting every Windows endpoint in your fleet.
Microsoft Working on Defender Patch for RoguePlanet Zero-Day
Microsoft has confirmed it is developing a patch for a zero-day vulnerability in Microsoft Defender, publicly disclosed one week ago and tracked as 'RoguePlanet.' No patch is yet available. The vulnerability was disclosed externally before Microsoft had a fix ready.
Why it matters: Every Intune-managed Windows 11 endpoint in your environment runs Defender — this is an unpatched, publicly known vulnerability with no workaround yet announced. Monitor Microsoft's Security Update Guide and MSRC for emergency out-of-band patch release.
CISA Orders Feds to Patch Max-Severity Joomla JCE Plugin Flaw by Friday
CISA added CVE-2026-48907 (CVSS 10.0) — an improper access control flaw in the Widget Factory Joomla Content Editor plugin allowing arbitrary PHP code execution — to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate by end of week. Active exploitation has been confirmed in the wild. The flaw requires no authentication to exploit.
Why it matters: If any internet-facing Joomla instances exist in your environment or those of your subcontractors, this is a drop-everything patch. As a CMMC L2 contractor, KEV additions also carry compliance weight under NIST 800-171 SI.3 — document your patch status or risk exposure.
Attackers Exploit Three Critical Fortinet FortiSandbox Flaws
Active exploitation has been observed against three vulnerabilities in Fortinet FortiSandbox, including CVE-2026-39813 (CVSS 9.1), a path traversal flaw in the JRPC API, along with CVE-2026-39808 and CVE-2026-25089. One of the three was patched only last week. Patches are available for all three and Fortinet has urged immediate upgrade.
Why it matters: If FortiSandbox is part of your perimeter or email security stack, treat this as emergency patching — one CVE was dropped into active exploitation within days of its patch release, indicating rapid weaponization.
Microsoft Confirms Office Apps Launch Issues After June Updates
Microsoft has confirmed a bug introduced by June 2026 Windows updates that prevents third-party applications from launching Microsoft Office apps or opening Office documents via OLE on fully patched systems. The issue is under active investigation with no fix yet published. Affected systems are current on Windows updates.
Why it matters: This will likely surface across your Intune-managed Windows 11 fleet if any line-of-business apps invoke Office documents programmatically — check helpdesk tickets for 'Office won't open from [app]' reports and hold the June update on a ring if validation fails.
Malicious JetBrains Marketplace Plugins Steal AI API Keys from Developers
Researchers identified a coordinated campaign of at least 15 malicious plugins published to the JetBrains Marketplace, each posing as AI coding assistants built on DeepSeek and other LLMs. The plugins exfiltrate AI provider API keys from developer machines. A parallel campaign involving malicious Chrome extensions was also flagged, targeting chatbot conversation data.
Why it matters: If developers in your environment use JetBrains IDEs (IntelliJ, PyCharm, etc.) and have installed AI assistant plugins, audit installed plugins immediately. Exfiltrated API keys tied to internal AI infrastructure or self-hosted LLM services could expose proprietary code and CUI-adjacent data.
144 Mastra npm Packages Compromised via Hijacked Contributor Account
A supply chain attack dubbed 'easy-day-js' compromised 144 npm packages in the @mastra namespace — a popular JavaScript/TypeScript AI application framework — by hijacking a single contributor's npm account and mass-publishing malicious versions. Findings were corroborated independently by JFrog, SafeDep, Socket, and StepSecurity. The malicious packages have since been removed from the registry.
Why it matters: If your Ansible playbooks, CI/CD pipelines, or self-hosted AI stack pull @mastra/* dependencies via npm, verify your lockfiles and check build logs for any @mastra installs between the compromise window. A compromised AI framework package is a direct vector into your build environment.
China-Linked SprySOCKS Backdoor Expands to Windows with Kernel Driver-Based Stealth
ESET researchers discovered two previously undocumented Windows variants of the SprySOCKS backdoor, previously considered Linux-only, attributed to the China-nexus threat group FishMonger. The variants (WIN_DRV and WIN_PLUS) abuse kernel drivers to evade detection and support TCP, UDP, and other C2 communication protocols. Government targets in multiple countries have been hit.
Why it matters: FishMonger has explicitly targeted government entities — as a DIB contractor handling CUI in a CMMC L2 environment, your organization fits the targeting profile. Kernel driver-based evasion may bypass standard Defender detections; check your EDR telemetry for anomalous driver loads.
Crooks Hide Command-and-Control Traffic Inside Microsoft Teams
Researchers documented custom malware that routes C2 communications through legitimate Microsoft Teams infrastructure, making malicious traffic appear indistinguishable from normal corporate collaboration traffic. The technique exploits Teams' trusted status in enterprise network monitoring and firewall rules. The malware was purpose-built to blend into standard Teams API call patterns.
Why it matters: Your environment runs M365 GCC High with Teams as a primary collaboration platform. This technique could render network-based C2 detection ineffective since Teams traffic is almost certainly allow-listed — endpoint-level behavioral detection via Defender for Endpoint becomes your primary control here.
AWS Security Blog: Detecting and Preventing Subdomain Takeover
AWS published a detailed threat tactic spotlight on subdomain takeover, explaining how dangling DNS records pointing to deprovisioned AWS resources can be claimed by attackers to serve malicious content under a victim's domain. The post covers detection approaches using AWS services and mitigation strategies including Route 53 and resource cleanup practices.
Why it matters: In AWS GovCloud environments, deprovisioned S3 buckets, CloudFront distributions, or Elastic Beanstalk endpoints that still have DNS CNAMEs pointing at them are live subdomain takeover risks. Run an audit of your Route 53 records against active resources — this is a low-effort, high-impact hardening task.
What's New with Terraform + Ansible Integration
HashiCorp announced Terraform Ansible Collection 2.0, a new pyTFE Python library for interacting with Terraform Enterprise, and an enhanced Terraform GitHub Actions experience. The updates are designed to simplify infrastructure lifecycle management across both tools, with tighter integration between Terraform provisioning and Ansible configuration management workflows.
Why it matters: If your automation stack uses both Terraform and Ansible — common in AHV and AWS GovCloud provisioning workflows — Collection 2.0 may offer meaningful workflow consolidation. Review the changelog before upgrading existing playbooks, as major version bumps can introduce breaking changes.
Tesco Sprints to Quit VMware Despite Rapid Migration Risks
Tesco is aggressively accelerating its exit from VMware/Broadcom licensing, turning to third-party support providers as a court date is set for a licensing dispute with Broadcom. The migration is proceeding at a pace the company's own teams acknowledge carries operational risk. The case adds to a growing body of enterprise VMware exit stories following Broadcom's acquisition.
Why it matters: As a Nutanix AHV shop, you've likely already navigated or are navigating this transition. This story is worth monitoring for migration lessons and any legal outcomes from the Broadcom licensing dispute that could affect maintenance terms for organizations still running hybrid VMware/AHV environments.
Agentic AI Is Coming to Government Faster Than Its Guardrails
A former FBI cyber special agent argues that federal agencies are deploying agentic AI systems — AI that autonomously takes actions — faster than security and governance frameworks can be established to oversee them. The piece highlights gaps in incident response playbooks, access control models, and adversarial testing practices specific to autonomous AI agents in government contexts.
Why it matters: If your organization supports or is evaluating agentic AI tooling under government contracts, this is directly relevant to upcoming CMMC and NIST AI RMF compliance expectations. The absence of guardrails today may become a documented gap during your next CMMC assessment.