Threat actors are exploiting three FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), two patched in April and one last week, shrinking defenders’ patching window. FortiSandbox underpins verdicting for other Fortinet products, raising the blast radius if compromised. Organizations should patch immediately, validate integrations that trust FortiSandbox outputs, and hunt for suspicious admin/API activity.
Source: Help Net Security
Cisco discloses another exploited Catalyst SD-WAN Manager zero‑day (CVE-2026-20262)
Cisco confirmed active exploitation of CVE-2026-20262 in Catalyst SD‑WAN Manager, the second exploited SD‑WAN flaw in as many weeks. The bug enables arbitrary file writes via the web UI against the SD‑WAN management plane. Prioritize emergency updates, restrict management exposure, and review change logs and file integrity on the SD‑WAN Manager host.
Source: Help Net Security
Ransomware operation hides C2 inside Microsoft Teams relays
Symantec reported DragonForce affiliates using a custom Go backdoor (Backdoor.Turn) that tunnels command‑and‑control traffic through Microsoft Teams TURN relay infrastructure. By acquiring anonymous Teams visitor tokens, the actors blend malicious traffic with legitimate collaboration flows, complicating detection. SOCs should add detections for atypical Teams/TURN egress patterns, tighten egress controls, and monitor OAuth/token activity.
Source: Help Net Security
Researchers: GitHub dismissed reports tied to supply‑chain worm now infecting hundreds
According to researchers, GitHub rejected two design‑flaw reports that are now being leveraged by variants of the Shai‑Hulud supply‑chain worm to compromise hundreds of packages and developer accounts. The incident underscores platform‑level weaknesses in package and maintainer protections. Developers should enforce MFA, rotate tokens, review package ownership and release workflows, and monitor for anomalous publish activity.
Source: The Record
ESET finds Windows variants of SprySOCKS with kernel‑level stealth
ESET uncovered Windows versions of the FishMonger APT’s SprySOCKS backdoor, including a build that weaponizes a kernel driver for advanced stealth. The malware retains its encrypted C2 channels and modular command set, expanding targeting beyond Linux and raising persistence and detection challenges. Organizations with government and research footprints should harden driver loading policies, enable kernel telemetry, and review EDR coverage for kernel‑mode indicators.
Source: ESET Blog
Critical SimpleHelp RMM flaw allows unauthenticated creation of privileged technician accounts
CVE-2026-48558 in SimpleHelp RMM enables an authentication bypass in OpenID Connect setups, letting unauthenticated attackers forge a “Technician” account even when MFA is enforced. Successful exploitation grants remote access to managed endpoints, script execution, and lateral movement opportunities. Update immediately, audit technician accounts and OIDC trust settings, and review endpoint access logs for anomalous sessions.
Source: Help Net Security
Chrome and Firefox ship fixes for critical/high‑severity flaws—patch now
Google and Mozilla released updates addressing multiple memory‑safety and other high‑severity bugs that could lead to remote code execution. Given browser ubiquity and rapid exploit weaponization, enterprises should expedite updates via managed channels and verify version coverage across Windows, macOS, and Linux fleets.
Source: SecurityWeek
You May Also Be Be Interested In...
Microsoft open-sources AntiSSRF library to help block server-side request forgery
144 Mastra npm packages compromised via hijacked contributor account
Bug in FIFA World Cup internal system gave anyone ability to modify TV stream