Back to Weekly Roundups
2026-W25 Classification: PUBLIC

WEEKLY INTELLIGENCE BRIEFING

2026-06-15 to 2026-06-21 80 articles

Articles scanned
80
Top IOCs
15
When your trusted tools become the attack vector

Tagline

When your trusted tools become the attack vector

Executive Summary

The week in one line

Credential exposure, supply chain poisoning, and AI agent exploitation converged to make third-party trust the defining security problem of the week.

What happened

Three distinct waves hit defenders simultaneously: a mass credential leak across Fortinet infrastructure, a coordinated takedown of the SocGholish botnet, and a cluster of supply chain attacks spanning npm packages, WordPress build pipelines, and SaaS OAuth integrations. Regulators added pressure with CISA emergency directives and European DPA enforcement actions.

  • FortiBleed exposed credentials for 86,000+ Fortinet firewalls and VPN gateways; CISA issued an urgent hardening advisory
  • Operation Endgame dismantled 106 SocGholish C2 servers and cleaned nearly 15,000 compromised WordPress sites tied to Evil Corp
  • Icarus group abused stolen OAuth tokens from Klue to exfiltrate Salesforce data from multiple organizations including Huntress and Recorded Future
  • North Korean Sapphire Sleet poisoned 140+ Mastra AI npm packages with a cross-platform information stealer
  • CISA added CVE-2026-20253 (Splunk Enterprise) to the KEV catalog and mandated federal patching by June 21
  • F5 issued out-of-band critical patches for two NGINX RCE vulnerabilities rated CVSS 9.2

Why it matters for defenders and leaders

This week's incidents are not isolated: they share a common thread of attackers targeting trusted intermediaries - plugin vendors, market intelligence platforms, open-source maintainers, and AI agent frameworks - rather than attacking organizations directly. Detection and response controls built around perimeter threats and known malware signatures are structurally blind to these vectors.

  • Third-party OAuth integrations are now a primary exfiltration channel, not a theoretical risk
  • EDR evasion has industrialized: Gentlemen RaaS silences 400+ security processes before encryption begins
  • AI coding agents and browsing agents are executing attacker instructions with inherited developer-level credentials and no security review
  • Fortinet credential exposure creates a wide initial-access opportunity for ransomware operators in the weeks ahead

What to do this week

  • Patch NGINX (CVE-2026-42530 and CVE-2026-42055) and Splunk Enterprise (CVE-2026-20253) on all internet-facing instances before any other vulnerability work
  • Rotate all Fortinet VPN and administrative credentials, terminate active sessions, enable phishing-resistant MFA, and review logs for Active Directory lateral movement
  • Audit every third-party OAuth integration connected to Salesforce or CRM platforms; revoke tokens for any unverified vendor
  • Inventory all AI agent deployments, review the credentials and permissions they inherit, and block unauthenticated localhost access from browser-based agents
  • Review npm and open-source dependencies updated in the past 30 days against the TeamPCP and Sapphire Sleet IOC sets; pin critical package versions in CI/CD pipelines
TLDR
  • πŸ”₯ FortiBleed exposes 86,000+ Fortinet credentials as CISA issues urgent hardening guidance for internet-facing devices.
  • πŸ•ΈοΈ Operation Endgame dismantles Evil Corp's SocGholish botnet, cleaning nearly 15,000 compromised WordPress sites across 106 servers.
  • πŸ”‘ Icarus threat group abuses stolen OAuth tokens to pillage Salesforce CRM data via the Klue third-party integration, hitting cybersecurity vendors Huntress and Recorded Future.
  • βš™οΈ F5 issues emergency out-of-band patches for two critical NGINX RCE flaws rated CVSS 9.2, while CISA orders federal agencies to patch Splunk CVE-2026-20253 by Sunday.
  • πŸ€– AI agent attack surface explodes: AutoJack enables RCE via a single malicious webpage, and Agentjacking weaponizes fake Sentry bug reports against coding agents.
  • πŸ—οΈ Supply chain trust erodes further: North Korean Sapphire Sleet poisons Mastra AI npm packages, TeamPCP compromises 1,000+ open-source packages, and ShapedPlugin's build pipeline is hijacked.
  • 🦾 Gentlemen RaaS deploys GentleKiller to silence 400+ security processes across 48 vendors, signaling a new bar for EDR evasion sophistication.

Intelligence Breakdown

6 modules
Vulnerabilities & Exploits
VULNERABILITIES-AND-EXPLOITS
2026-W25

F5 Issues Out-of-Band Patches for Critical NGINX RCE Vulnerabilities. F5 released emergency fixes for two critical NGINX flaws: CVE-2026-42530 (use-after-free in ngx_http_v3_module) and CVE-2026-42055 (heap buffer overflow in proxy and gRPC modules), both scored CVSS 9.2 and enabling unauthenticated RCE when ASLR is disabled or bypassed. The out-of-band release signals F5 treated these as immediately dangerous; organizations running HTTP/3 or gRPC proxying should treat patching as a P1 incident this week. Learn more

CISA: Splunk Enterprise Flaw Actively Exploited - Patch by Sunday. CVE-2026-20253, the first Splunk vulnerability ever added to CISA's Known Exploited Vulnerabilities catalog, allows unauthenticated attackers to create or truncate arbitrary files via a PostgreSQL sidecar service, effectively enabling remote code execution. CISA's Binding Operational Directive 26-04 required federal agencies to patch by June 21; all organizations running Splunk Enterprise should treat this with equivalent urgency. Learn more

AutoJack: One Malicious Page Can RCE the Host Running Your AI Agent. Microsoft researchers detailed AutoJack, an exploit chain targeting AutoGen Studio that leverages localhost trust, missing authentication on MCP WebSocket connections, and unsafe parameter handling to achieve remote code execution on the host machine from a single malicious webpage. While patched before public release, the technique exposes a systemic design flaw in how AI agent frameworks handle local service communications and untrusted content.

Critical Cisco ISE Flaw Enables Root-Level Command Execution. CVE-2026-20181 (CVSS 9.1) in Cisco Identity Services Engine allows authenticated attackers to escalate to root via a crafted HTTP request, effectively surrendering complete control of a device that sits at the center of network access control. Learn more

Key Takeaway

Prioritize NGINX and Splunk patching this week ahead of all other vulnerability work; both have confirmed active exploitation and carry critical CVSS scores.


Ransomware & Breaches
RANSOMWARE-AND-BREACHES
2026-W25

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 Devices. A Russian-speaking threat group compiled credentials for over 86,000 FortiGate firewalls and VPN gateways using a mix of default credentials, previously breached accounts, and brute-force attacks - then leaked the dataset publicly in a campaign now called FortiBleed. CISA's guidance is explicit: terminate all active VPN sessions, rotate every administrative and VPN password immediately, enforce phishing-resistant MFA, and audit logs for lateral movement into Active Directory.

Gentlemen RaaS Uses GentleKiller to Disable 400+ Security Processes. The Gentlemen ransomware-as-a-service operation has built a dedicated EDR-killing framework, GentleKiller, with at least eight variants that use Bring Your Own Vulnerable Driver (BYOVD) techniques to gain kernel-level access and disable security products from 48 vendors before deploying encryption. The group supplements GentleKiller with third-party tools including HexKiller, ThrottleBlood, and HavocKiller for redundancy, representing one of the most industrialized EDR evasion arsenals observed to date.

DragonForce Abuses Microsoft Teams Relays to Mask Ransomware C2 Traffic. DragonForce operators deployed a custom Go-based remote access tool called Backdoor.Turn that routes its command-and-control traffic through legitimate Microsoft Teams relay infrastructure, blending malicious communications with normal enterprise traffic and evading network-based detection for one to two months in at least one confirmed victim. The group used DLL sideloading and BYOVD techniques post-access, highlighting how trusted cloud services are becoming preferred C2 channels. Learn more

New Prinz Eugen Ransomware Omits Ransom Notes to Reduce Forensic Footprint. Prinz Eugen is a newly observed ransomware that deliberately targets recently modified files for encryption rather than sweeping entire file systems, and it skips traditional ransom note drops in favor of out-of-band attacker communication - a tactic designed to reduce forensic artifacts and slow incident response attribution.

Key Takeaway

Rotate all Fortinet credentials immediately and audit your network visibility for Teams-relayed C2 traffic; conventional alert triggers will miss both FortiBleed follow-on attacks and DragonForce's tunneling technique.


Supply Chain
SUPPLY-CHAIN
2026-W25

Microsoft Links Mastra AI npm Supply Chain Attack to North Korean Sapphire Sleet. North Korea's Sapphire Sleet (BlueNoroff) compromised an npm maintainer account and published malicious updates across more than 140 packages, injecting a typosquatted dependency that deployed a cross-platform information stealer targeting cryptocurrency wallets with persistence mechanisms across Windows, Linux, and macOS. The targeting of AI framework packages amplifies blast radius as these dependencies propagate into pipelines and production environments rapidly.

TeamPCP Poisons 1,000+ Open-Source Packages in Four Months. TeamPCP, a threat actor likely based in South Africa, has injected malicious code into more than 1,000 open-source packages in under four months, exploiting the development community's reliance on automated dependency ingestion and CI/CD speed over security review. The campaign reveals how adversaries are outpacing the open-source ecosystem's trust model at industrial scale. Learn more

ShapedPlugin Build Pipeline Compromised to Deliver Credential-Stealing Malware. Attackers infiltrated ShapedPlugin's plugin build and distribution pipeline, injecting malware into paid releases of Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro that were pushed to paying customers through the vendor's official update mechanism. The malware deployed a hidden fake WooCommerce plugin to harvest credentials, 2FA secrets, database connection strings, and payment data - targeting customers who trusted the vendor's signed update channel explicitly. Learn more

Klue OAuth Breach Enables Icarus Group to Exfiltrate Salesforce CRM Data. The newly emerged Icarus extortion group compromised Klue's backend infrastructure and harvested OAuth tokens used by customers to connect their Salesforce environments, then used those tokens to query Salesforce's REST API and quietly exfiltrate business contacts, sales quotes, and competitive intelligence over extended periods. Salesforce has disabled the Klue Battlecards integration entirely; confirmed victims include cybersecurity vendors Huntress and Recorded Future. Learn more

Key Takeaway

Audit every third-party OAuth integration connected to your Salesforce or CRM environments this week; revoke tokens for any vendor you cannot immediately verify was unaffected.


APT & Nation-State
APT-AND-NATION-STATE
2026-W25

Operation Endgame Dismantles SocGholish / Evil Corp Infrastructure. A multinational law enforcement operation spanning the Netherlands, Canada, the US, and Germany took down 106 SocGholish command-and-control servers and remediated nearly 15,000 compromised WordPress sites used by Evil Corp's TA569 syndicate since 2017 to deliver ransomware including WastedLocker, Hades, and Phoenix CryptoLocker via fake browser update lures. The takedown is a significant disruption but not a permanent elimination; defenders should continue blocking SocGholish IOCs including the FakeUpdates delivery mechanism. Learn more

China-Linked UNC6508 Actively Targets Outdated REDCap Research Servers. The majority of internet-accessible REDCap servers - widely used in academic and clinical research - are running outdated software, and China-linked threat actor UNC6508 is actively exploiting them to deploy custom backdoors including InfiniteRed for credential harvesting and data exfiltration from research organizations. Healthcare and academic institutions running REDCap should treat upgrade as an urgent operational security matter.

Key Takeaway

Block SocGholish IOCs at the perimeter and verify REDCap version currency across any research or clinical environments in your portfolio.


AI & Emerging Threats
AI-AND-EMERGING-THREATS
2026-W25

Agentjacking: Fake Sentry Bug Reports Hijack AI Coding Agents. Researchers demonstrated that attackers with access to an exposed Sentry DSN can inject malicious instructions into fake error reports that AI coding assistants then act upon, triggering arbitrary command execution and exposing developer secrets without any indication that the actions were unauthorized. The attack bypasses conventional security controls because the agent interprets attacker input as legitimate operational context. Learn more

Rokarolla Android Banking Trojan Targets 200+ Financial and Crypto Apps. Zimperium identified Rokarolla, a new Android banking trojan distributed via malicious websites impersonating popular apps, that targets more than 217 financial and cryptocurrency applications using screen overlays, keylogging, SMS hijacking, clipboard manipulation, and screenshot exfiltration while hiding its icon and disabling Google Play Protect to evade detection. Learn more

Key Takeaway

Inventory all AI agent deployments and the credentials they inherit; treat exposed Sentry DSNs as a critical secret requiring immediate rotation.


References
REFERENCES
2026-W25

Regulatory Updates

Regulatory & Compliance
Action items and policy signal

PCI DSS v4.0.1 Mandates Script Inventory and Integrity Controls on Checkout Pages. New PCI DSS v4.0.1 requirements now obligate merchants to maintain a full inventory of all scripts loaded on payment pages, authorize each one explicitly, and implement tamper detection - directly targeting the web skimming attack vector where compromised third-party scripts silently exfiltrate cardholder data. Organizations that have not yet completed this inventory are out of compliance and exposed to enforcement action. Learn more

Emirates Fined 180,000 EUR for GDPR Health Data Transparency and Retention Failures. Italy's Garante fined Emirates 180,000 EUR for failing to adequately inform passengers with reduced mobility about health data processing via the MEDIF form and retaining that data for seven years without adequate justification - a case study in how health data obligations under GDPR apply to operational, non-digital-native processes. Learn more

CJEU Rules Supervisory Authorities Cannot Reject GDPR Complaints Citing Parallel Court Cases. The Court of Justice of the EU clarified that Article 77(1) GDPR provides an independent remedy that supervisory authorities must process regardless of whether parallel judicial proceedings on the same matter are underway, strengthening data subject enforcement rights across member states.

Key Takeaway

If your organization processes payments online, your PCI DSS v4.0.1 script inventory and integrity controls are due now; treat non-compliance as an active risk, not a future audit finding.