Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (17 June 2026)
Published: Loading…
At a Glance
- DragonForce ransomware deployed Backdoor.Turn to route C2 traffic through Microsoft Teams TURN relay infrastructure, evading detection for up to two months.
- Attackers are actively exploiting three critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) enabling unauthenticated remote code execution.
- CISA added CVE-2026-54420 in LiteSpeed cPanel Plugin and CVE-2026-20262 in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities catalog.
- Windows variants of SprySOCKS, used by FishMonger, targeted government organisations in Honduras, Taiwan, Thailand, and Pakistan using a kernel driver rootkit.
- Rokarolla, a new Android banking trojan, targets 217 banking and cryptocurrency apps using 137 commands including overlay attacks, SMS theft, and clipboard manipulation.
- iRhythm disclosed a data breach after attackers stole patient health information and demanded ransom for not publicly releasing the data.
Summary
DragonForce ransomware operators deployed a custom Go-based backdoor, Backdoor.Turn, routing command-and-control traffic through Microsoft Teams TURN relay servers using QUIC. The intrusion at a U.S. services company included SQL exploitation, VirtualBox DLL sideloading, and BYOVD driver abuse for defence evasion. Attackers maintained persistence for one to two months before deploying ransomware.
Three critical Fortinet FortiSandbox vulnerabilities—CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089—are under active exploitation, enabling unauthenticated remote code execution. The flaws carry CVSS scores of 9.1 and allow path traversal and OS command injection via HTTP requests. Fortinet patched two of the three flaws in April 2026 and the third only last week.
CISA added two CVEs to its Known Exploited Vulnerabilities catalog, mandating FCEB agency remediation by June 18. CVE-2026-54420 affects the LiteSpeed cPanel Plugin, enabling root privilege escalation. CVE-2026-20262 affects Cisco Catalyst SD-WAN Manager, where authenticated attackers can write or overwrite files to escalate privileges to root.
FishMonger-linked Windows variants of the SprySOCKS backdoor targeted government organisations in Honduras, Taiwan, Thailand, and Pakistan between 2023 and 2024. The WIN_DRV variant uses the RawWNPF kernel driver rootkit to conceal processes and network activity. Both variants support over 30 commands across TCP, UDP, and WebSocket channels with AES-encrypted messaging.
Rokarolla, a newly documented Android banking trojan, targets 217 banking and cryptocurrency applications using 137 remote commands and Accessibility Service abuse. The malware steals lock-screen PINs, intercepts SMS messages, manipulates clipboard data to redirect cryptocurrency payments, and disables Google Play Protect. Separately, iRhythm disclosed a breach in which attackers stole patient protected health information from third-party-hosted business applications and demanded a ransom payment.
The ErrTraffic ClickFix framework is distributing malware through compromised WordPress sites and fake AI platforms, using EtherHiding on the Polygon blockchain for C2 resolution. Two operational clusters deliver payloads including Vidar, Stealc, DanaBot, and HijackLoader via obfuscated JavaScript and encrypted API-driven delivery. A coordinated campaign of at least 15 malicious JetBrains Marketplace plugins was also identified, designed to exfiltrate AI provider API keys from developers.
Highlights of the Day
ErrTraffic ClickFix Framework Spreads Malware via WordPress Sites and Fake AI Pages
ErrTraffic ClickFix JavaScript framework injects compromised WordPress sites and impersonated AI platforms, using EtherHiding on the Polygon blockchain to resolve command and control infrastructure and deliver ClickFix lures through a traffic distribution system operated as Malware-as-a-Service across “Analytics” and “Beer” clusters. The “Analytics” cluster relies on a single smart contract and a PHP MU-plugin backdoor named session-manager.php to deploy the Vidar infostealer, while the “Beer” cluster uses multiple smart contracts to distribute Vidar, Stealc, Remus, Salat, DanaBot and HijackLoader through obfuscated JavaScript and encrypted API-driven payload delivery. Campaigns include credential theft from compromised WordPress administrator accounts and malvertising sites impersonating Google Antigravity and ChatGPT that execute PowerShell droppers retrieving payloads via /api/index.php and /cf.js endpoints.
CISA Adds Two Actively Exploited Vulnerabilities to KEV Catalog
CISA added two CVEs to KEV catalog due to active exploitation affecting Cisco Catalyst SD-WAN Manager directory/path traversal and LiteSpeed cPanel plugin symlink vulnerability. Binding Operational Directive 26-04 directs FCEB agencies to prioritise remediation of KEV-listed vulnerabilities on public-facing assets and verify pre-patch compromise. CISA continues expanding the KEV catalog and accepts nominations requiring CVE identifiers, exploitation evidence, and documented mitigation guidance for inclusion review process.
Cisco SD-WAN Manager File Write Flaw Enables File Overwrite
Cisco disclosed CVE-2026-20262 in Catalyst SD-WAN Manager, where authenticated attackers exploit file upload validation flaws to write or overwrite files, enabling privilege escalation to root. Cisco reports CVSS 6.5 CWE-22 and confirms impact across on-prem, cloud-managed and FedRAMP deployments, with limited exploitation observed and fixed software releases issued. Indicators include malicious WAR file upload and deployment logs with follow-on HTTP requests, while Cisco notes no workarounds and provides fixed release versions.
Fortinet FortiSandbox Vulnerabilities Exploited in Active Attacks
Threat actors are exploiting Fortinet FortiSandbox vulnerabilities CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089, enabling unauthenticated remote code execution via low-complexity command injection, according to Defused. Fortinet released security updates on 14 April for the flaws and also patched CVE-2026-26083, while CVE-2025-61624 was previously exploited in the wild. FortiClient Enterprise Management Server CVE-2026-21643 is tracked as actively exploited, with CISA ordering federal agencies to address exposure across Fortinet deployments.
DragonForce Abuses Microsoft Teams Relay for Stealth Ransomware C2
DragonForce ransomware operators deployed Backdoor.Turn, a Go-based backdoor, to route command-and-control traffic through Microsoft Teams TURN relay infrastructure using QUIC to external C2 servers. Initial access involved suspected SQL or MSSQL exploitation followed by VirtualBox DLL sideloading, persistence modifications, and BYOVD techniques abusing vulnerable drivers for defence evasion. The operation enabled DragonForce ransomware deployment alongside network reconnaissance, LDAP Active Directory mapping, credential theft, and long-term persistence spanning one to two months.
Windows SprySOCKS variants expand FishMonger espionage tools
ESET Research identified two Windows SprySOCKS variants used by FishMonger, targeting government organisations in Honduras, Taiwan, Thailand and Pakistan during 2023–2024. Both WIN_DRV and WIN_PLUS support TCP, UDP and WebSocket command and control, implement over 30 commands, and reuse HP-Socket-based communication and AES encrypted messaging. WIN_DRV uses RawWNPF kernel driver rootkit to hide processes and network activity via IOCTLs, with limited indications of UEFI bootkit CVE-2023-24932 involvement.
Rokarolla Android banker takes full device control
Zimperium researchers identified Rokarolla, an Android banking trojan distributed via fake websites impersonating popular apps, targeting over 200 banking and cryptocurrency applications. Malware uses 137 commands with Accessibility Service abuse, deploying overlays, keyloggers, SMS theft, call blocking, and disabling Google Play Protect on infected devices. Rokarolla communicates over HTTPS C2 infrastructure generating bot IDs, supports fallback domains, captures screenshots as PNG snapshots, and manipulates clipboard data for financial fraud.
Malicious JetBrains Plugins Steal AI API Keys from Developers
Security researchers identified at least 15 JetBrains IDE plugins across seven vendor accounts that exfiltrate AI provider API keys from developers. Collectively installed nearly 70,000 times, the plugins operate as AI coding assistants but transmit keys to a hardcoded attacker-controlled server. The campaign began in October 2025 and continues into June 2026, sending API keys in plaintext over HTTP to 39[.]107[.]60[.]51.
iRhythm Reports Patient Data Theft After Third-Party App Breach
iRhythm detected unauthorised activity on June 8 involving third-party-hosted business applications accessed through social engineering, with attackers claiming theft of patient protected health information. On June 9, attackers demanded ransom and claimed data exfiltration, while iRhythm confirmed some data was stolen but scope remains under investigation and systems unaffected. A June 10 SEC Form 8-K classified the incident as material, stating no impact to medical systems or financial reporting while investigations continue.
Daily Coverage