CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (3 July 2026)

Published: Loading…

At a Glance

  • The FortiBleed campaign harvested over 110 million credentials from 430,000 FortiGate firewalls, fueling INC and Lynx ransomware operations.
  • CISA added SharePoint flaw CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of the deserialization bug.
  • Cisco confirmed active exploitation of Unified Communications Manager vulnerability CVE-2026-20230, enabling server-side request forgery and potential root escalation.
  • Google and the FBI disrupted the NetNut residential proxy network, also known as Popa, spanning roughly two million compromised devices.
  • Medtronic notified patients that a corporate network intrusion between April 13 and 19 exposed names, Social Security numbers and health data.
  • An AI agent dubbed JadePuffer exploited Langflow flaw CVE-2025-3248 to run a fully automated ransomware attack on a production database.

Summary

The FortiBleed campaign harvested over 110 million credentials from more than 430,000 internet-facing FortiGate firewalls. Attackers exploited CVE-2026-35616 to deploy sniffing tools and compromise 354 domains. Researchers linked the stolen credentials directly to the INC Ransom and Lynx ransomware operations.

CISA added Microsoft SharePoint flaw CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. Cisco separately confirmed in-the-wild exploitation of a Unified Communications Manager vulnerability, CVE-2026-20230, which enables server-side request forgery. Attackers also began exploiting Oracle E-Business Suite flaw CVE-2026-46817 before public proof-of-concept code existed.

Google and the FBI disrupted the NetNut residential proxy network, also tracked as Popa, which controlled roughly two million compromised home devices. The action followed Google's earlier takedown of the IPIDEA proxy network in January 2026. Investigators found 316 threat clusters used NetNut exit nodes for password spraying in a single week.

Medtronic notified patients that intruders accessed corporate systems between April 13 and 19, exposing names, Social Security numbers and health information. A suspected Scattered Spider member was extradited to the United States over a jewelry retailer breach involving an $8 million ransom demand. Attackers also impersonated GitHub pages belonging to Arctic Wolf, Malwarebytes and Bitdefender to distribute information-stealing malware.

Security firm Sysdig documented an agentic ransomware attack it named JadePuffer, in which an AI system exploited Langflow flaw CVE-2025-3248 to autonomously breach, move laterally through, and encrypt a production database. Separately, 25 npm packages published under the @marketfront scope used a dependency-confusion lure to harvest SSH keys and cloud credentials, while the Vect and TeamPCP groups combined supply-chain compromise with ransomware deployment.

Highlights of the Day

FortiBleed Campaign Harvests 110 Million Credentials from FortiGate Devices

Researchers uncovered the FortiBleed campaign targeting more than 430,000 internet-facing FortiGate firewalls, where attackers deployed the FortigateSniffer tool on around 12,000 devices, harvested over 110 million RADIUS, NTLM and Kerberos credentials, and compromised 354 domains. The campaign has been linked to the INC Ransom and Lynx ransomware groups, while CVE-2026-35616, a critical unauthenticated access control flaw affecting FortiClient EMS 7.4.5 and 7.4.6, has been actively exploited to distribute the EKZ Stealer malware and was added to CISA's Known Exploited Vulnerabilities catalogue.

Alleged Scattered Spider Member Extradited to Face US Cybercrime Charges

US authorities extradited Peter Stokes, a 19-year-old dual US and Estonian citizen, from Finland after charging him with conspiracy, computer intrusion and fraud for his alleged role in the Scattered Spider cybercrime group. Prosecutors allege Scattered Spider has conducted more than 100 network intrusions generating over $100 million in ransom payments, including a May 2025 attack against a luxury jewellery retailer involving an $8 million cryptocurrency ransom demand that caused at least $2 million in losses despite no payment being made.

FBI and Google Disrupt NetNut Residential Proxy Network

The FBI, supported by Google, Lumen and other partners, seized hundreds of domains linked to the NetNut residential proxy network, also known as Popa, which researchers estimate controlled at least two million compromised devices, including smart TVs and streaming boxes. Google disabled NetNut command-and-control accounts and applications containing its SDKs, while reporting that 316 distinct cybercriminal and espionage threat clusters used suspected NetNut exit nodes during a single week in June 2026 to conceal malicious activity including password spraying.

CISA Flags Active Exploitation of Microsoft SharePoint Server Flaw

CISA has added CVE-2026-45659, a high-severity deserialisation vulnerability affecting Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalogue after confirming active exploitation of the flaw. Patched by Microsoft in May, the vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016 and SharePoint Enterprise Server 2016, allowing authenticated attackers with Site Member permissions to execute arbitrary code.

Fake GitHub Pages Deliver Information-Stealing Malware Campaign

Arctic Wolf researchers identified a malicious GitHub page impersonating the company that directed users to download a ZIP archive containing a trojanised executable Arctic-Wolf-3.9.7.exe which deployed the BoryptGrab Stealer via DLL sideloading using a disguised libcurl.dll. The campaign, linked to nearly 300 similar repositories impersonating vendors such as Malwarebytes and Bitdefender, used fake “official” links and SEO manipulation to distribute information-stealing malware through GitHub-hosted content and external redirects.

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco has confirmed in-the-wild exploitation of CVE-2026-20230, an improper HTTP request validation vulnerability affecting Unified Communications Manager and Unified CM Session Management Edition, which enables server-side request forgery attacks. The flaw, rated CVSS 8.6, affects systems with the WebDialer service enabled and can lead to arbitrary file placement on the underlying operating system and potential escalation to root privileges after successful exploitation.

npm Marketfront Campaign Uses Dependency Confusion to Steal Credentials

Security researchers identified a dependency confusion campaign in which 25 npm packages under the @marketfront scope were batch-published at version 7.0.0, each containing a postinstall hook that executed a credential-harvesting script targeting SSH keys, cloud credentials, and developer secrets. The packages reused a known “Internal package — Platform Engineering Team” README lure seen in earlier campaigns, while the payload executed gzip-compressed exfiltration via HTTPS POST requests with an X-Secret header to a /api/v1/events endpoint.

Source: SafeDep

Vect and TeamPCP Align in Supply Chain Ransomware Campaign

Sophos CTU researchers identified a partnership between ransomware group Vect and threat actor TeamPCP, combining credential harvesting, supply chain compromise and ransomware deployment in coordinated attacks across development environments and enterprise systems. TeamPCP previously exploited CVE-2025-55182 in React Server Components and compromised tools such as Trivy and LiteLLM, enabling credential theft, worm propagation and exfiltration of large-scale secrets used in downstream ransomware operations attributed to Vect.

Source: Sophos

Phishing Campaign Delivers AsyncRAT and Remcos via Multi-Stage Payloads

LevelBlue SpiderLabs identified a global phishing campaign using malicious spreadsheet attachments to deliver multi-stage infection chains that deploy AsyncRAT and Remcos across organisations in manufacturing, media, agriculture, and professional services. The attack chain uses macro-enabled Excel files, obfuscated HTA scripts, and PowerShell-based staging to retrieve payloads from rotating infrastructure including Cloudflare Workers and URL-shortened links, with final execution achieved through fileless DLL loading via AppDomain methods.

Medtronic Discloses Patient Data Exposure After Network Intrusion

Medtronic has notified patients that attackers accessed corporate systems between April 13 and April 19 following detection of unusual activity on April 15, exposing personal and health-related information held for regulatory and service purposes. The compromised data includes names, contact details, dates of birth, Social Security numbers and medical information, with the company stating there is no evidence of public release or impact on device functionality. The incident has been linked to a broader extortion campaign involving the ShinyHunters group, which previously claimed access to millions of records before removing its listing.

AI Agent Automates Ransomware via Langflow Exploit in Sysdig Case

Sysdig documented JADEPUFFER using CVE-2025-3248 Langflow RCE for initial access and LLM-driven automation across the intrusion chain. It performed reconnaissance, MinIO enumeration, and credential harvesting, then pivoted to a MySQL-backed Nacos environment using root database credentials. It encrypted 1,342 configuration items using MySQL AES_ENCRYPT, dropped core tables, and generated a ransom note with an ephemeral key preventing recovery.

Daily Coverage

Developments
Fortibleed CampaignSharepoint Rce KevCisco Unified Cm FlawNetnut Proxy Disruption
Vulnerabilities
CVE-2026-45659Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)CVE-2026-46817Oracle Payments 12.2.3 (Critical)CVE-2025-3248Langflow (Critical)CVE-2026-35616Forticlientems 7.4.5 (Critical)CVE-2026-14191Winrar (High)CVE-2025-5777Netscaler_Application_Delivery_Controller 12.1-55.328 (Critical)CVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2026-20230Cisco Unified Communications Manager N/ACVE-2026-48282Coldfusion (Critical)CVE-2026-8451Adc 14.1 (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.INC RansomINC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.ToddyCatToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multistage infection chains against government and military targets across Europe and Asia.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.