CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (24 June 2026)

Published: Loading…

At a Glance

  • Executive Order 14409 mandates federal agencies transition high-value systems to post-quantum cryptography by December 31, 2030.
  • A Russian initial access broker's FortiBleed campaign captured over 110 million credentials from more than 430,000 FortiGate firewalls globally since February 2026.
  • Scattered Spider members Thalha Jubair and Owen Flowers pleaded guilty to the 2024 Transport for London cyberattack, costing £29 million in losses.
  • Malicious npm packages impersonating PostCSS tools delivered a multi-stage Windows RAT with HTTP C2, registry persistence, and Chrome credential theft.
  • A 29-year-old memory leak dubbed Squidbleed in Squid proxy server silently exposed plaintext HTTP requests and credentials for nearly three decades.
  • CVE-2026-28496 in FOSSBilling chains an auth bypass with Twig SSTI to enable unauthenticated remote code execution on default installs.

Summary

Executive Order 14409, signed June 22, 2026, mandates that federal agencies transition high-value systems to post-quantum cryptography by December 31, 2030, and complete post-quantum digital signature migration by December 31, 2031. The order also directs compliance from federal contractors and extends support to critical infrastructure operators. A Commerce Department pilot programme is required by end of 2027 to assist agencies in addressing harvest-now-decrypt-later risks.

A Russian-speaking financially motivated initial access broker is assessed to be behind the FortiBleed campaign, which has targeted more than 430,000 FortiGate firewalls worldwide since February 2026. Attackers deployed a Golang-based tool called FortigateSniffer, abusing a FortiOS diagnostic command to capture authentication traffic across 24 protocols. The operation has identified over 110 million credentials and confirmed the compromise of at least one NATO-aligned defence contractor.

Software supply chain threats continued across multiple ecosystems. Malicious npm packages impersonating PostCSS tooling delivered a multi-stage Windows remote access trojan with AES-GCM encoded payloads, PowerShell downloaders, and Chrome credential theft. Unit 42 separately identified malicious skills on the OpenClaw ClawHub marketplace using Base64-encoded droppers and paste-site redirection to deliver macOS infostealers and conduct agentic financial fraud.

Scattered Spider members Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in the United Kingdom to charges stemming from the August 2024 cyberattack on Transport for London. The attack caused £29 million in losses and disrupted public transport services for months. U.S. prosecutors also allege Jubair participated in 120 separate network intrusions generating at least $115 million in ransom payments between 2022 and 2025.

Multiple significant vulnerabilities were disclosed across widely deployed software. A 29-year-old memory leak in Squid proxy server, dubbed Squidbleed, silently exposed plaintext HTTP requests, credentials, and session tokens for decades before being patched. CVE-2026-28496 in FOSSBilling chains an authentication bypass with an unsandboxed Twig server-side template injection, enabling unauthenticated remote code execution on versions 0.5.4 through 0.7.2. An eight-year-old use-after-free flaw in Samsung KNOX also exposed Galaxy devices from the S9 through S25 to kernel-level attacks.

Tata Electronics confirmed a cybersecurity incident affecting parts of its IT infrastructure after the World Leaks extortion group claimed to have published stolen data including alleged Apple supplier specifications and Tesla manufacturing documents. The Xsolis healthcare technology firm separately disclosed a data breach affecting 1.4 million individuals following a phishing attack. A vendor breach affecting the Texas Parks and Wildlife Department exposed passport numbers, driver's licence data, and personal information belonging to more than 3 million Texans.

Highlights of the Day

Trump Orders Faster Federal Shift to Quantum-Safe Encryption

President Donald Trump signed an executive order directing the Department of Commerce, NSA and DHS to provide guidance accelerating federal adoption of post-quantum cryptography. The order requires agencies to appoint officials overseeing migration efforts and upgrade critical systems to quantum-resistant encryption by 2030 or 2031, depending on system type. It also mandates a Commerce Department pilot programme by the end of 2027 to help agencies prepare for quantum-era threats, including “harvest now, decrypt later” risks.

Scattered Spider Members Admit Roles in TfL Cyberattack

Scattered Spider members Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in the United Kingdom to offences linked to the August 2024 cyberattack on Transport for London, including conspiring to commit unauthorised acts against computer systems and causing risk of serious damage to human welfare. U.S. prosecutors allege Jubair participated in 120 network intrusions affecting 47 organisations between 2022 and 2025 that generated at least $115 million in ransom payments, while also helping run a SIM-swapping operation and an SMS phishing campaign that compromised more than 130 organisations.

FortiBleed Campaign Harvests Credentials from FortiGate Firewalls

SOCRadar researchers reported the FortiBleed operation, an active credential-harvesting campaign targeting more than 430,000 FortiGate firewalls worldwide since at least February 2026, with attackers deploying 659 collection pipelines and identifying over 110 million credentials. The campaign uses a Golang-based tool called FortigateSniffer, which abuses the FortiOS diagnose sniffer packet command to capture authentication traffic across 24 protocols, including cleartext credentials and password hashes. Investigators linked the activity to a financially motivated initial access broker, confirmed the compromise of a NATO-aligned defence contractor, and observed credential reuse, Active Directory targeting, Kerberos hash cracking and data exfiltration from compromised environments.

Source: SOCRadar

Tata Electronics Confirms Breach After Data Leak Claims

Tata Electronics confirmed a cybersecurity incident affecting some of its systems, weeks after the World Leaks extortion group claimed to have stolen and published confidential company data. Researchers reviewing leaked samples reported the files appeared to include Apple supplier specifications and Tesla-related manufacturing documents, although the authenticity of the material has not been independently verified. World Leaks, a cybercriminal operation that emerged from the Hunters International ransomware group in 2025, primarily conducts data theft and extortion campaigns without deploying file-encrypting ransomware.

Malicious npm Packages Deliver Windows RAT via PostCSS Impersonation

JFrog researchers identified multiple npm packages impersonating PostCSS tooling, including postcss-minify-selector-parser, postcss-minify-selector, and aes-decode-runner-pro, which ultimately deliver a Windows remote access trojan through a multi-stage infection chain. The packages depend on legitimate postcss-selector-parser and conceal AES-GCM encoded JavaScript payloads that deploy a PowerShell downloader retrieving a Windows archive from nvidiadriver[.]net and executing a VBS bootstrapper. The final payload contains a bundled Python runtime with Nuitka-compiled modules enabling HTTP C2 communication, persistence via registry keys, and credential theft from Chrome browsers, with infrastructure tied to an IP-based command-and-control server at 95[.]216[.]92[.]207:8080.

FOSSBilling Chain Enables Unauthenticated RCE via Twig SSTI

VulnCheck disclosed CVE-2026-28496 in FOSSBilling, combining an authentication bypass in API role validation with an unsandboxed Twig server-side template injection that allows unauthenticated remote code execution in versions 0.5.4 through 0.7.2. The flaw originates from a missing throw statement in isRoleAllowed(), which permits unauthenticated access to /api/system/ endpoints, including string_render, exposing the full dependency container via guest.getDi() and enabling access to services such as PDO, cache, and password hashing. Chained exploitation allows SQL execution, administrator account creation, cache poisoning of extension metadata, and deployment of malicious modules that can execute arbitrary system commands via /api/guest//.

Source: VulnCheck

Malicious OpenClaw Skills Exploit AI Agent Supply Chain

Unit 42 researchers analysed OpenClaw’s ClawHub marketplace and identified multiple malicious AI skills abusing the agentic execution model to deliver macOS infostealers, credential exfiltration, and financial fraud techniques across third-party “skills”. The campaigns used Base64-encoded curl-pipe-bash droppers, paste-site redirection, and inflated file padding to evade scanning, with payloads connecting to command-and-control infrastructure including 91[.]92[.]242[.]30 and 2.26.75[.]16. Additional findings showed runtime affiliate injection via externally controlled product feeds and agent-driven front-running schemes leveraging blockchain transactions to manipulate meme token launches.

Daily Coverage

Developments
Fortibleed CampaignScattered Spider Guilty PleasPostcss Npm RatSquidbleed Disclosure
Vulnerabilities
CVE-2026-28496Fossbilling < 0.8.0CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-20230Cisco Unified Communications Manager N/A
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.