The Lyceum: Cyber Intelligence Daily — Jun 17, 2026
Photo: lyceumnews.com
Past 3 Days — June 17, 2026
The Big Picture
This is a week about the infrastructure you trust most being turned against you. Ransomware operators hid inside Microsoft Teams' own relay servers for two months. A Russian-speaking crew compiled working VPN logins for 73,000 Fortinet firewalls. CISA flagged a perfect-10 Joomla flaw as actively exploited with a Friday deadline, and Oracle's PeopleSoft bug graduated from "bad" to ransomware's preferred front door. If you run Fortinet, Joomla, Teams, or PeopleSoft, this issue is about you specifically.
What Just Dropped
- CVE-2026-48907 — Widget Factory Joomla Content Editor (1.0.0–2.9.99.4): actively exploited, added to CISA KEV. Maturity: operational. Unauthenticated attackers can upload and run PHP code via crafted editor profiles. Fixed in 2.9.99.5+.
- CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62: actively exploited, ransomware-linked, in KEV. Maturity: commoditized. Unauthenticated remote code execution.
- CVE-2026-54420 — LiteSpeed cPanel Plugin: actively exploited, in KEV. Maturity: operational. Symlink-following flaw exploitable by users with FTP access.
- CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: actively exploited, in KEV. Maturity: operational. Path traversal in the web management interface.
- CVE-2026-10520 — Ivanti Sentry (≤10.7.0): actively exploited and confirmed backdoored in the wild, in KEV. Maturity: operational. Unauthenticated OS command injection yielding root.
This Week's Stories
Your Fortinet VPN Credentials May Already Be in a Criminal Database
If your organization runs a Fortinet firewall — and tens of thousands do — your VPN login may be sitting in an attacker's verified database right now.
A leak dubbed "FortiBleed," discovered by researcher Volodymyr "Bob" Diachenko, exposed Fortinet and FortiGate VPN credentials for 73,932 firewall URLs worldwide — usernames, emails, and plaintext passwords. Diachenko's screenshots show entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, and Toyota.
The crucial nuance: despite the name, this isn't a new vulnerability. It's a pile of credentials harvested in earlier Fortinet breaches, fired back at organizations that never rotated them — many of them generic admin accounts or built-in system accounts. Researchers at Dark Reading describe the broader operation as a Russian-speaking multi-operator group processing 1.16 billion credential attempts against more than 320,000 FortiGate targets. Separately, exploitation attempts have hit three FortiSandbox flaws — CVE-2026-39813 (authentication bypass) and CVE-2026-39808 (OS command injection), both critical and patched in April.
If your device appears in the dataset, treat it as fully compromised. Rotating passwords isn't enough if an attacker already planted a backdoor. Hudson Rock has published a free FortiBleed lookup tool. The signal to watch: if Fortinet traces the credential sources to a single unpatched CVE, the remediation story shifts from "rotate" to "patch and rotate" — and the affected universe grows well beyond 73,000.
DragonForce Hid Inside Microsoft Teams for Two Months — And Nobody Noticed
The most dangerous intrusions look exactly like your normal workday. DragonForce ransomware operators hid inside a major U.S. services firm for up to two months by routing their command-and-control traffic through Microsoft Teams' own relay servers.
Symantec and Carbon Black revealed on June 16 what they describe as the first documented in-the-wild abuse of Teams' TURN relay infrastructure for malware C2. TURN — the protocol Teams uses to relay messages when a direct connection isn't possible — became the perfect hiding place. A custom Go-based backdoor, tracked as Backdoor.Turn, grabbed an anonymous Teams visitor token from Microsoft's identity services, then tunneled through Microsoft's TURN relay to reach the attacker's real C2. To defenders, the only visible traffic was outbound connections to Microsoft Teams — which almost every network whitelists by default.
The group entered through an unpatched SQL Server flaw, then spent weeks loading legitimate-but-vulnerable drivers (a technique called BYOVD) to blind endpoint detection tools before establishing persistence. DragonForce has claimed 579 victims since its 2023 launch, with activity accelerating after RansomHub's collapse sent affiliates shopping for new platforms.
What changes: every network tool that treats Teams traffic as inherently trustworthy just became less reliable. Watch for whether Microsoft issues guidance restricting anonymous visitor tokens — the specific mechanism this abused. If it doesn't, the technique is reusable by anyone.
Joomla's Most Popular Editor Has a Perfect-10 Flaw — Patch by Friday
Someone may already be running code on your Joomla server. CISA added CVE-2026-48907 (CVSS 10.0) in the Widget Factory Joomla Content Editor to its Known Exploited Vulnerabilities catalog, citing active exploitation. JCE is the most popular third-party editor for Joomla — think of it as the text-formatting toolbar admins use to write content. The flaw is a chained design failure in the JCE profile import workflow: missing authorization plus weak file validation plus disabled upload safety controls, together letting unauthenticated attackers upload and run arbitrary PHP through the /tmp directory.
Joomla's own warning is blunt: "the vulnerability is being actively exploited, working exploit code is public, and the attacks are automated, so a site with no public registration is not safe."
Update JCE to 2.9.99.5 or later immediately. The fix shipped June 6; CISA has ordered federal agencies to patch by June 19, a Friday deadline that signals exploitation is automated and running right now. The observable signal: if scanning telemetry spikes over the weekend, the attack tooling has moved from targeted to mass-scanning, and every unpatched Joomla site should be treated as compromised regardless of traffic.
Oracle's PeopleSoft Hole Is Now Officially an Exploited, Ransomware-Linked Problem
The PeopleSoft story has moved from "bad vulnerability" to "known front door for extortion crews," and that distinction matters. Oracle's June 10 alert says CVE-2026-35273 affects PeopleSoft Enterprise PeopleTools 8.61 and 8.62, is remotely exploitable without authentication, and leads to remote code execution at CVSS 9.8.
CISA placed it in the KEV catalog and marked it as used in ransomware campaigns. BleepingComputer reported last week that ShinyHunters has been abusing exposed PeopleSoft servers in data-theft attacks. That makes this more than a theoretical enterprise-software headache: PeopleSoft sits where HR, payroll, student, and government workflow data lives — the digital filing cabinet nobody wants to find hanging open.
Oracle is urging immediate patching; admins who can't move fast should check whether the exposed environment-management components are even needed. This is the patch-your-boring-systems story of the week, because attackers love boring systems when those systems hold everybody's records. Watch for more named victims in education and government — this flaw keeps paying off long after the first headlines fade.
⚡ What Most People Missed
144 AI developer packages were poisoned in a supply chain attack. Up to 144 npm packages in the Mastra namespace — a popular framework for building AI applications — were compromised via a hijacked contributor account, with a malicious dependency (easy-day-js) that runs on install. Separately, 15 malicious JetBrains plugins have been stealing AI API keys, two of them with 25,000+ downloads. The pattern is clear: AI developer tooling is now a high-value target.
ShinyHunters confirmed a Kodak breach — 2.2 million records. Kodak acknowledged unauthorized access to company data after ShinyHunters claimed to have stolen over 2.2 million customer PII and internal records, first observed June 15. Given the group's habit of publishing after deadlines lapse — as it did with Charter's 42 million records — expect these to surface if no settlement is reached.
Microsoft Defender has an unpatched zero-day called "RoguePlanet." Microsoft confirmed it's working on a patch for a Defender flaw disclosed a week ago. A zero-day in the security software running on virtually every Windows machine is uncomfortable precisely because it's the tool you'd use to detect the attack. No fix yet.
A space-mission control stack just got a critical auth bug with public exploit code. YAMCS — open-source mission-control software for satellites — has an LDAP injection flaw (CVE-2026-42568) where the username drops straight into an LDAP query without escaping, enabling auth bypass. Exploit-DB now carries working code; fixed in 5.12.7 and 5.13.0. Critical-infrastructure operators patch slowly, so treat this as pre-incident work.
Notepad++ 8.9.6 has a public arbitrary-code-execution exploit. Exploit-DB surfaced a PoC for one of the most widely installed Windows text editors. Open a crafted file and the editor session can be hijacked. It's PoC-level for now — but Notepad++ is a default on developer and admin workstations, which puts it in the same "everyday file becomes an entry point" category as Office macros.
From the Foreign Press
A "SearchLeak" flaw in Microsoft Copilot let attackers steal two-factor codes
Russian-language outlet Xakep reported that researchers found a vulnerability dubbed SearchLeak in Microsoft Copilot that could expose a victim's email contents and one-time confirmation codes after the victim clicked a specially crafted link. The issue stems from how Copilot handled certain search and integration features following a link follow-through, letting an attacker siphon sensitive content from the victim's Microsoft account context. Microsoft has patched it. For Western defenders, the takeaway is stark: AI assistants wired into corporate email are now a credential-theft surface, and 2FA codes leaking through an "AI helper" defeats the very control they're meant to protect. Worth watching for a formal CVE and technical writeup.
Source: Xakep.ru — Russian. No English-language coverage confirmed at time of publication.
OpenClaw is vulnerable to phishing attacks and can disclose data
Xakep also reported that OpenClaw — an AI agent platform — is susceptible to phishing-style manipulation that can cause it to leak data it should be protecting. The report dovetails with fresh academic work suggesting tool-using LLM agents quietly spill more sensitive data than most policies assume: credentials, internal URLs, and private snippets surfacing in logs and prompts during ordinary troubleshooting. For anyone wiring AI agents into SOC runbooks or ticketing systems, adopt the model of "chatty junior analyst with copy-paste access to everything" — not "black box that respects data boundaries." The risk lives in the glue code, not the model weights.
Source: Xakep.ru — Russian. No English-language coverage confirmed at time of publication.
📅 What to Watch
- If Fortinet names a specific CVE behind the FortiBleed credential dump, the fix shifts from password rotation to patching — and the scope balloons well past 73,000 devices.
- If Microsoft restricts anonymous Teams visitor tokens, it's an admission that Backdoor.Turn's vector is structural — and every Teams shop needs to revisit network egress rules, because "Teams traffic is safe" stops being true.
- If Drupal issues an SA-CORE advisory matching the new 10.5.5 SQL injection PoC, organizations that diligently patched the May CVE-2026-9082 wave are not actually protected — a distinct flaw in a patched release.
- If ShinyHunters' Council of Europe deadline (expires June 17) produces a 297 GB dump, the resulting phishing against European policy staff will be indistinguishable from real HR correspondence — and tells you whether the Council quietly negotiated.
- If the RoguePlanet Defender zero-day gets a public PoC before Microsoft ships a fix, every Windows endpoint becomes temporarily less defended by its own security software — heading into a weekend, no less.
The Closer
This week: ransomware hitching a ride on Microsoft Teams like a stowaway in a delivery truck, 73,000 Fortinet firewalls handing out their house keys to anyone holding a leaked guest list, and a satellite mission-control system felled by an LDAP bug a junior dev would catch in code review. Somewhere a SOC analyst is whitelisting Teams traffic, sleeping soundly, while an AI assistant cheerfully reads someone's 2FA codes aloud to a stranger who clicked the right link.
Stay patched, stay paranoid, and assume the boring system is the one they want.
Forward this to the colleague who still thinks "it's just a text editor."
⚡ EDGE Signals
The following signals appeared in the adversarial edge sweep but were not carried forward in the primary synthesis:
- [8] [webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection
URL: https://www.socdefenders.ai/item/ad34f919-9b42-4e06-ab01-bb66298d6af5
Snippet: Key Points: - CVE-2026-42568** is a critical LDAP injection vulnerability in YAMCS yamcs-core versions prior to 5.12.7, ...
- [14] Must Read - Security Affairs
URL: https://securityaffairs.com/must-read
Snippet: ... June 16, 2026. Fortinet Warned as Three Critical FortiSandbox Bugs Come Under Attack. Three FortiSandbox flaws, including one patched last week, are being ...
- [16] BlackBerry Secure Communications Blog
URL:
Snippet: Jun 16, 2026·Articles flaws in messaging apps expose critical communication vulnerabilities. not AI itself. The FBI is warning that end-to-end encryption ...