- Backdoor.TurnGo-based backdoor used by DragonForce for C&C via Microsoft Teams TURN relay infrastructure
- DragonForce ransomwareRansomware deployed for data encryption and exfiltration; active since 2023
ThreatNoir Afternoon Brief — June 17
Afternoon Review in IT Security — June 17, 2026
The cybersecurity landscape continues to face escalating threats across multiple vectors this afternoon, with attackers targeting cloud infrastructure, open-source platforms, and developer tools. From ransomware operations exploiting legitimate Microsoft services to coordinated supply-chain campaigns infiltrating development environments, organizations face urgent patching deadlines and emerging zero-day vulnerabilities requiring immediate attention.
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
Threat actors have deployed a sophisticated attack leveraging Microsoft Teams relay servers as a command-and-control infrastructure for ransomware operations. The campaign utilizes a new Go-based backdoor tracked as Backdoor.Turn, which communicates through Microsoft Teams servers to evade traditional network detection mechanisms. This approach allows attackers to hide malicious traffic within legitimate cloud service communications, making detection significantly more challenging for defenders relying on standard network monitoring.
The DragonForce ransomware group's use of Microsoft Teams infrastructure represents a notable shift in operational security tactics, exploiting the trust placed in mainstream cloud services. Source: Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
CISA Orders Federal Agencies to Patch Critical Joomla Plugin Flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandatory patching directive for federal agencies addressing a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin. Tracked as CVE-2026-48907, this flaw is currently experiencing active exploitation in the wild, placing government systems at immediate risk. The compressed timeline for remediation underscores the severity of the vulnerability and the urgency with which federal infrastructure must be secured.
Organizations running Joomla installations with the JCE plugin should prioritize patching efforts to prevent compromise. Source: CISA orders feds to patch max severity Joomla plugin flaw by Friday
Microsoft Working on Patch for 'RoguePlanet' Zero-Day
A newly disclosed zero-day vulnerability in Microsoft Defender, designated CVE-2026-50656, exploits a race condition to enable privilege escalation. Public proof-of-concept code demonstrates the ability to spawn a command prompt with System-level privileges, providing attackers with complete control over affected systems. Microsoft is actively developing a patch to address this critical flaw, which impacts the security posture of systems relying on Defender as their primary protection mechanism.
The availability of public exploit code accelerates the timeline for potential widespread exploitation, making patching efforts critical for organizations running vulnerable Microsoft Defender instances. Source: Microsoft Working on Patch for 'RoguePlanet' Zero-Day
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Cybersecurity researchers have identified a coordinated malware campaign distributing at least fifteen malicious plugins across the JetBrains Marketplace. These plugins masquerade as AI coding assistants built on DeepSeek and other large language models, offering functionality such as chat, commit message generation, code review, bug detection, and unit test creation. The campaign specifically targets developer credentials, exfiltrating artificial intelligence provider API keys that grant access to premium AI services and proprietary models.
The threat extends beyond the JetBrains ecosystem, with malicious Chrome extensions simultaneously capturing chatbot interactions and conversation data. This multi-platform supply-chain attack demonstrates sophisticated social engineering tactics designed to compromise developer environments and extract valuable authentication credentials. Source: Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Closing Summary
Today's threat landscape reflects attackers' evolving sophistication in exploiting trusted infrastructure, developer tools, and cloud services. Organizations must prioritize urgent patching for CVE-2026-48907 and CVE-2026-50656, implement enhanced monitoring for Teams-based command-and-control activity, and conduct security audits of installed browser extensions and IDE plugins. The convergence of ransomware operations, zero-day exploits, and supply-chain attacks demands immediate and comprehensive defensive action.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical improper access control vulnerability in Joomla JCE plugin allowing unauthenticated code execution
- RoguePlanet zero-day vulnerability in Microsoft Defender
39.107.60.51IP address of the server controlling the attacker's plugins