- LiteSpeed cPanel user-end plugin flaw
- LiteSpeed cPanel user-end plugin flaw
ThreatNoir Afternoon Brief — June 16
Afternoon Review in IT Security — June 16, 2026
The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities are actively exploited across government and enterprise infrastructure. Today's briefing covers urgent warnings from federal agencies, widespread attacks on security appliances, and sophisticated malware campaigns leveraging trusted communication platforms to evade detection.
CISA Warns of Another cPanel Plugin Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive to federal government agencies regarding an actively exploited vulnerability in the LiteSpeed cPanel user-end plugin. The flaw, identified as CVE-2026-54420, has been assigned a three-day remediation deadline for all U.S. government systems. Source: CISA warns of another cPanel plugin flaw exploited in attacks
This represents another critical security incident in the cPanel ecosystem, demonstrating the ongoing risk posed by widely deployed server management software. The compressed timeline for remediation underscores the severity of active exploitation and the immediate threat to government infrastructure.
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Threat intelligence firm Defused Cyber has documented active exploitation of multiple vulnerabilities in Fortinet FortiSandbox systems. The attacks target CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, with exploitation observed over the past 24 hours. CVE-2026-39813 carries a CVSS score of 9.1 and involves a path traversal vulnerability in the FortiSandbox JRPC API. Source: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
The rapid exploitation of these vulnerabilities, particularly one patched only recently, indicates that threat actors are actively monitoring security updates and developing exploits with minimal delay. Organizations deploying FortiSandbox should prioritize immediate patching to prevent compromise of their security infrastructure.
Ransomware Gang Abuses Microsoft Teams Relays to Hide Malicious Traffic
The DragonForce ransomware gang has deployed a custom backdoor named Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams relay infrastructure. This technique exploits the trust placed in legitimate Microsoft communications platforms to evade detection systems that typically monitor external network traffic. Source: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
The abuse of legitimate cloud services for malicious command-and-control represents a significant evolution in evasion tactics. By hiding communications within trusted platforms, attackers can bypass traditional network monitoring and maintain persistent access to compromised environments while reducing the likelihood of detection.
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Security researchers have identified two previously undocumented Windows variants of the SprySOCKS backdoor, a tool previously believed to be limited to Linux systems. ESET researchers designated these variants as WIN_DRV and WIN_PLUS, both featuring hard-coded command-and-control configurations and support for TCP and UDP communication protocols. Source: China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
The expansion of SprySOCKS to Windows platforms with driver-based stealth capabilities indicates a sophisticated enhancement to this nation-state tool. The driver-level implementation provides deeper system access and increased resistance to detection, representing a significant escalation in the threat posed by this backdoor family.
The convergence of government-targeted vulnerabilities, supply chain risks, and advanced persistent threat activities underscores the critical need for immediate defensive action across all organizational tiers. Security teams should prioritize patching, network monitoring enhancements, and threat intelligence integration to counter these evolving threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- OS command injection in FortiSandbox/Cloud/PaaS, CVSS 9.1, unauthenticated RCE, patched last week, AI-generated faulty exploit, actively exploited
- Path traversal in FortiSandbox JRPC API, CVSS 9.1, unauthenticated authentication bypass, actively exploited
- OS command injection in FortiSandbox, CVSS 9.1, unauthenticated RCE, patched April 2026, actively exploited
- Critical flaw in FortiClient EMS, CVSS 9.1, exploited in the wild, patched April 2026
- Vulnerability in Topaz Antifraud wsftprm.sys driver used for BYOVD.
- Vulnerability in K7 Security K7RKScan.sys used for BYOVD.
- Vulnerability in Tower of Fantasy GameDriverx64.sys used for BYOVD.
- DragonForceRansomware gang active since at least 2023.
- Backdoor.TurnCustom malware used by DragonForce to hide C2 traffic.
- RedLeavesBackdoor with source code overlaps to Trochilus and shared traits with SprySOCKS
- TrochilusWindows RAT that SprySOCKS is based on
- SprySOCKSChina-linked backdoor with Linux and Windows variants supporting TCP, UDP, and WebSocket protocols
- DriverLoaderEncrypted kernel driver (KX1B5206BDC1743DD.dat) responsible for loading RawWNPF
- RawWNPFKernel driver (KW1B5206BDC1743FP.dat) used by WIN_DRV for advanced stealth
- WIN_PLUSWindows SprySOCKS variant leveraging Windows Print Spooler service
- WIN_DRVWindows SprySOCKS variant using kernel driver RawWNPF for stealth