Weekly review

ThreatNoir Afternoon Brief — June 16

2026-06-16Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — June 16, 2026

The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities are actively exploited across government and enterprise infrastructure. Today's briefing covers urgent warnings from federal agencies, widespread attacks on security appliances, and sophisticated malware campaigns leveraging trusted communication platforms to evade detection.

CISA Warns of Another cPanel Plugin Flaw Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive to federal government agencies regarding an actively exploited vulnerability in the LiteSpeed cPanel user-end plugin. The flaw, identified as CVE-2026-54420, has been assigned a three-day remediation deadline for all U.S. government systems. Source: CISA warns of another cPanel plugin flaw exploited in attacks

This represents another critical security incident in the cPanel ecosystem, demonstrating the ongoing risk posed by widely deployed server management software. The compressed timeline for remediation underscores the severity of active exploitation and the immediate threat to government infrastructure.

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Threat intelligence firm Defused Cyber has documented active exploitation of multiple vulnerabilities in Fortinet FortiSandbox systems. The attacks target CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, with exploitation observed over the past 24 hours. CVE-2026-39813 carries a CVSS score of 9.1 and involves a path traversal vulnerability in the FortiSandbox JRPC API. Source: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

The rapid exploitation of these vulnerabilities, particularly one patched only recently, indicates that threat actors are actively monitoring security updates and developing exploits with minimal delay. Organizations deploying FortiSandbox should prioritize immediate patching to prevent compromise of their security infrastructure.

Ransomware Gang Abuses Microsoft Teams Relays to Hide Malicious Traffic

The DragonForce ransomware gang has deployed a custom backdoor named Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams relay infrastructure. This technique exploits the trust placed in legitimate Microsoft communications platforms to evade detection systems that typically monitor external network traffic. Source: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

The abuse of legitimate cloud services for malicious command-and-control represents a significant evolution in evasion tactics. By hiding communications within trusted platforms, attackers can bypass traditional network monitoring and maintain persistent access to compromised environments while reducing the likelihood of detection.

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

Security researchers have identified two previously undocumented Windows variants of the SprySOCKS backdoor, a tool previously believed to be limited to Linux systems. ESET researchers designated these variants as WIN_DRV and WIN_PLUS, both featuring hard-coded command-and-control configurations and support for TCP and UDP communication protocols. Source: China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

The expansion of SprySOCKS to Windows platforms with driver-based stealth capabilities indicates a sophisticated enhancement to this nation-state tool. The driver-level implementation provides deeper system access and increased resistance to detection, representing a significant escalation in the threat posed by this backdoor family.

The convergence of government-targeted vulnerabilities, supply chain risks, and advanced persistent threat activities underscores the critical need for immediate defensive action across all organizational tiers. Security teams should prioritize patching, network monitoring enhancements, and threat intelligence integration to counter these evolving threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
CVE4
  • OS command injection in FortiSandbox/Cloud/PaaS, CVSS 9.1, unauthenticated RCE, patched last week, AI-generated faulty exploit, actively exploited
  • Path traversal in FortiSandbox JRPC API, CVSS 9.1, unauthenticated authentication bypass, actively exploited
  • OS command injection in FortiSandbox, CVSS 9.1, unauthenticated RCE, patched April 2026, actively exploited
  • Critical flaw in FortiClient EMS, CVSS 9.1, exploited in the wild, patched April 2026
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Malware7
  • RedLeaves
    Backdoor with source code overlaps to Trochilus and shared traits with SprySOCKS
  • Trochilus
    Windows RAT that SprySOCKS is based on
  • SprySOCKS
    China-linked backdoor with Linux and Windows variants supporting TCP, UDP, and WebSocket protocols
  • DriverLoader
    Encrypted kernel driver (KX1B5206BDC1743DD.dat) responsible for loading RawWNPF
  • RawWNPF
    Kernel driver (KW1B5206BDC1743FP.dat) used by WIN_DRV for advanced stealth
  • WIN_PLUS
    Windows SprySOCKS variant leveraging Windows Print Spooler service
  • WIN_DRV
    Windows SprySOCKS variant using kernel driver RawWNPF for stealth