~/greenteam/nerd

Thursday, June 18, 2026

Daily digest

The FortiBleed credential leak (73,000+ devices) and associated active exploitation campaign dominate today's threat landscape — if Fortinet devices exist anywhere in your environment or supply chain, treat this as urgent.

cybersec BleepingComputer

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000+ Devices

A data leak dubbed 'FortiBleed' has exposed VPN credentials for 73,932 FortiGate firewall URLs at organizations worldwide. A separate but related active attack campaign has already compromised over 30,000 devices across nearly 200 countries, with attackers compiling working credential lists. F5 also issued out-of-band emergency patches today, suggesting broad network infrastructure is under heightened attack pressure.

Why it matters: If any Fortinet devices sit at your perimeter or in your supply chain partners' environments, credentials may already be in attacker hands — rotate VPN credentials and audit FortiGate access logs immediately, as CMMC L2 boundary protection controls (AC.1.001, SC.3.177) depend on the integrity of those devices.

cybersec BleepingComputer

F5 Issues Out-of-Band Patches for Critical NGINX Vulnerabilities

F5 released emergency out-of-band security updates addressing multiple NGINX vulnerabilities, including two critical-severity flaws that enable remote code execution on affected systems. The patches were released outside the normal update cycle, indicating active or imminent exploitation risk.

Why it matters: If NGINX is running as a reverse proxy or load balancer in your AWS GovCloud environment or on any internal service — including containerized workloads — patch immediately; RCE on an internet-facing NGINX instance could be a direct path into CUI-handling systems.

cybersec The Hacker News

Microsoft Confirms RoguePlanet Defender Zero-Day (CVE-2026-50656), Patch in Development

Microsoft has formally disclosed a privilege escalation zero-day in the Microsoft Malware Protection Engine within Microsoft Defender, tracked as CVE-2026-50656 with a CVSS score of 7.8. The vulnerability is confirmed and a patch is in development but not yet available. Microsoft has not disclosed whether active exploitation is occurring.

Why it matters: Defender is your primary endpoint protection layer across your Intune-managed Windows 11 fleet — a local privilege escalation in the Malware Protection Engine means a low-privileged attacker or malware already on a machine could gain SYSTEM. Monitor Microsoft's security update channel closely and apply the patch the moment it drops.

cmmc BleepingComputer

CISA Orders Federal Agencies to Patch Max-Severity Joomla Plugin Flaw by Friday

CISA added a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin to its Known Exploited Vulnerabilities catalog and ordered all federal agencies to patch by end of week. The flaw is being actively exploited in the wild. This is a binding operational directive applicable to federal civilian executive branch agencies.

Why it matters: If any public-facing or internal sites in your environment run Joomla with the JCE plugin, this KEV addition requires immediate action; for CMMC L2, active KEV items should be treated as priority remediation under your vulnerability management process (CA.2.158, SI.1.210).

cmmc Federal News Network

Senate NDAA Proposes CMMC Grant Program and New Post-Quantum Cryptography Deadlines

The Senate Armed Services Committee's FY2027 NDAA bill includes a provision to establish a CMMC grant program, likely aimed at helping smaller defense contractors achieve compliance. The bill also introduces new mandatory deadlines for post-quantum cryptography migration and adds insider threat reporting requirements for AI companies.

Why it matters: The PQC deadline provisions are directly relevant to your environment — if your organization hasn't started a cryptographic inventory against NIST's post-quantum standards (FIPS 203/204/205), a legislative deadline in the NDAA could accelerate the timeline for your M365 GCC High and AWS GovCloud encryption configurations.

cybersec The Hacker News

Junior Attacker Used Tailscale and OpenSSH to Maintain Persistent Access After C2 Went Offline

A French-speaking attacker compromised a small business, deployed a keylogger, and — before his Havoc C2 server went dark — installed OpenSSH and Tailscale on the victim machine to create a persistent backdoor independent of the C2 infrastructure. The technique allowed continued access even after the primary command-and-control channel was disrupted.

Why it matters: Tailscale creates encrypted mesh VPN tunnels that can bypass traditional network egress controls — if your Windows 11 fleet doesn't have Intune or Defender policies blocking unauthorized VPN client installation, this technique could be used to maintain persistence in your environment without triggering C2 detection rules.

cybersec Microsoft Security Blog

Mastra npm Supply Chain Compromise: Postinstall Payload Hit 140+ Projects

Microsoft's threat intelligence team detailed a supply chain attack targeting the Mastra npm package, where a poisoned version delivered a hidden postinstall payload that infected over 140 downstream projects. The report includes detection guidance using Microsoft Defender and threat hunting queries.

Why it matters: If your Ansible automation workflows, CI/CD pipelines, or self-hosted AI stack pull from npm registries, review your dependency trees for Mastra or transitive dependencies; CMMC L2 supply chain risk management (SR.3.169) requires you to address risks introduced through third-party software components.

cybersec The Hacker News

Malicious JetBrains Marketplace Plugins Steal AI API Keys; Chrome Extensions Capture Chatbot Sessions

Researchers identified 15 malicious plugins on the JetBrains Marketplace posing as AI coding assistants built on DeepSeek and other LLMs, designed to exfiltrate AI API keys. A coordinated separate campaign used malicious Chrome extensions to capture chatbot conversation data from developer sessions.

Why it matters: If developers in your environment use JetBrains IDEs or any AI-assisted coding tools, audit installed plugins immediately — stolen API keys for your self-hosted or cloud AI stack could expose CUI if those keys have access to sensitive data pipelines or internal tooling.

cybersec Schneier on Security

Spyware Authors Embedding Policy-Violating Text to Block AI-Assisted Malware Analysis

At least one malware developer is embedding fake system instructions referencing nuclear and biological weapons topics inside JavaScript comment blocks within their spyware payload. The content doesn't affect code execution but is designed to trigger AI safety filters and prevent automated analysis tools from processing the malware.

Why it matters: If your SOC or incident response workflow relies on AI-assisted tools (including Copilot for Security or similar) for triage and malware analysis, this evasion technique means AI-flagged 'unable to analyze' results on a sample should themselves be treated as a potential indicator of malicious intent rather than a dead end.

infrastructure BleepingComputer

Microsoft Fixes Windows Server 2016 June 2026 Security Update Failures

Microsoft resolved a known issue where the June 2026 security updates failed to install on Windows Server 2016 systems that were not fully current on prior patches. Affected systems would silently fail the update without applying the security fixes.

Why it matters: Any Windows Server 2016 instances in your environment — including those running under Nutanix AHV — may have silently missed June's security patches; verify patch compliance in Intune or your patch management tooling before your next CMMC assessment evidence collection cycle.

infrastructure BleepingComputer

Microsoft Confirms Office App Launch Issues After June Updates

Microsoft is investigating a bug introduced by June 2026 Windows updates that prevents third-party applications from launching Microsoft Office apps or opening Office documents programmatically via OLE dependencies. The issue affects fully up-to-date Windows systems.

Why it matters: This could surface as a user-impacting incident across your M365 GCC High / Intune-managed fleet if any line-of-business apps or automation scripts launch Office documents programmatically — worth a targeted test before wide deployment of the June cumulative update.

cmmc Federal News Network

DoD $9.7B Microsoft Products Contract Derailed by Protest

Minburn Technology Group has filed a protest challenging the DoD's $9.7 billion Microsoft products contract award, alleging the department changed solicitation terms without notifying bidders, violating the Competition in Contracting Act. The protest will likely pause contract execution pending GAO review.

Why it matters: A sustained protest could delay DoD-wide Microsoft licensing renewals and affect availability or terms for M365 GCC High and related services your environment depends on — worth flagging to procurement and tracking through GAO's 100-day review window.