THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Attackers actively exploit three FortiSandbox flaws, impacting Fortinet ecosystems

Threat actors are exploiting three FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), two patched in April and one last week, shrinking defenders’ patching window. FortiSandbox underpins verdicting for other Fortinet products, raising the blast radius if compromised. Organizations should patch immediately, validate integrations that trust FortiSandbox outputs, and hunt for suspicious admin/API activity.

Source: Help Net Security


Cisco discloses another exploited Catalyst SD-WAN Manager zero‑day (CVE-2026-20262)

Cisco confirmed active exploitation of CVE-2026-20262 in Catalyst SD‑WAN Manager, the second exploited SD‑WAN flaw in as many weeks. The bug enables arbitrary file writes via the web UI against the SD‑WAN management plane. Prioritize emergency updates, restrict management exposure, and review change logs and file integrity on the SD‑WAN Manager host.

Source: Help Net Security


Ransomware operation hides C2 inside Microsoft Teams relays

Symantec reported DragonForce affiliates using a custom Go backdoor (Backdoor.Turn) that tunnels command‑and‑control traffic through Microsoft Teams TURN relay infrastructure. By acquiring anonymous Teams visitor tokens, the actors blend malicious traffic with legitimate collaboration flows, complicating detection. SOCs should add detections for atypical Teams/TURN egress patterns, tighten egress controls, and monitor OAuth/token activity.

Source: Help Net Security


Researchers: GitHub dismissed reports tied to supply‑chain worm now infecting hundreds

According to researchers, GitHub rejected two design‑flaw reports that are now being leveraged by variants of the Shai‑Hulud supply‑chain worm to compromise hundreds of packages and developer accounts. The incident underscores platform‑level weaknesses in package and maintainer protections. Developers should enforce MFA, rotate tokens, review package ownership and release workflows, and monitor for anomalous publish activity.

Source: The Record


ESET finds Windows variants of SprySOCKS with kernel‑level stealth

ESET uncovered Windows versions of the FishMonger APT’s SprySOCKS backdoor, including a build that weaponizes a kernel driver for advanced stealth. The malware retains its encrypted C2 channels and modular command set, expanding targeting beyond Linux and raising persistence and detection challenges. Organizations with government and research footprints should harden driver loading policies, enable kernel telemetry, and review EDR coverage for kernel‑mode indicators.

Source: ESET Blog


Critical SimpleHelp RMM flaw allows unauthenticated creation of privileged technician accounts

CVE-2026-48558 in SimpleHelp RMM enables an authentication bypass in OpenID Connect setups, letting unauthenticated attackers forge a “Technician” account even when MFA is enforced. Successful exploitation grants remote access to managed endpoints, script execution, and lateral movement opportunities. Update immediately, audit technician accounts and OIDC trust settings, and review endpoint access logs for anomalous sessions.

Source: Help Net Security


Chrome and Firefox ship fixes for critical/high‑severity flaws—patch now

Google and Mozilla released updates addressing multiple memory‑safety and other high‑severity bugs that could lead to remote code execution. Given browser ubiquity and rapid exploit weaponization, enterprises should expedite updates via managed channels and verify version coverage across Windows, macOS, and Linux fleets.

Source: SecurityWeek


You May Also Be Be Interested In...

Microsoft open-sources AntiSSRF library to help block server-side request forgery

144 Mastra npm packages compromised via hijacked contributor account

Bug in FIFA World Cup internal system gave anyone ability to modify TV stream

Cybersecurity — June 17, 2026 | Briefing24