🛡️ CISO Intel — Friday, 19-06-2026
Blog generation failed — API error. Presenting Discord briefing as fallback.
Friday. Most dangerous day in cybersecurity — everyone’s mentally checked out by 3pm. Eyes open.
🔴 Critical Threats & Active Exploitation
- Fortinet FortiSandbox —
CVE-2026-39813,CVE-2026-39808,CVE-2026-25089(CVSS 9.1) — Threat actors are actively exploiting multiple high-severity vulnerabilities in Fortinet FortiSandbox. These flaws allow unauthenticated remote attackers to execute arbitrary commands or escalate privileges via crafted HTTP requests. Patch immediately. 📌Source: Rod's Blog — direct link unavailable - Mastra AI Framework — Supply Chain Attack — An attacker compromised the
@mastranpm organization and injected a malicious typosquat dependency,easy-day-js, into over 140 packages. This delivered a two-stage infostealer. If you installed any@mastrapackage on June 17, 2026, treat your environment as compromised and downgrade tomastra@1.13.0explicitly using lockfiles. 📌Source: BankInfoSecurity · StepSecurity — [URL unavailable] · [URL unavailable] - Microsoft Defender —
CVE-2026-50656(CVSS 7.8) — Microsoft has confirmed a privilege escalation zero-day, publicly known as “RoguePlanet,” in the Microsoft Malware Protection Engine. While a patch is in development, a public PoC exploiting a race condition to gain SYSTEM-level privileges exists. 📌Source: SecurityWeek · The Hacker News — [URL unavailable] · [URL unavailable]
🛡️ CVEs Worth Your Attention
CVE-2026-47647| Microsoft Dynamics 365 | CVSS 9.9 | Elevation of Privilege | PoC: Unknown (recently published) 📌Source: CVE Tools — [URL unavailable]CVE-2026-54130| Microsoft 365 Copilot | CVSS 9.8 | Information Disclosure | PoC: Unknown (recently published) 📌Source: CVE Tools — [URL unavailable]CVE-2026-49257| mcp-pinot | CVSS 10.0 | Unauthenticated tool invocation via defaultoauth_enabled=False+ host0.0.0.0bind | PoC: Unknown (recently published) 📌Source: CVE Tools — [URL unavailable]CVE-2026-49454| Relyra SAML | CVSS 9.1 | SignatureValue not cryptographically verified -> authentication bypass | PoC: Unknown (recently published) 📌Source: CVE Tools — [URL unavailable]CVE-2026-49252| deepstream | CVSS 9.9 | Prototype Pollution | PoC: Unknown (recently published) 📌Source: CVE Tools — [URL unavailable]
⚡ New TTPs & Attack Research
- SocGholish Takedown — International law enforcement has disrupted the SocGholish operation, taking down 106 servers and cleaning nearly 15,000 compromised websites. This group (TA569, linked to Evil Corp) uses fake software updates to deliver malware, often via obfuscated JavaScript injected into legitimate WordPress sites.
- MITRE ATT&CK: T1189 (Drive-by Compromise), T1204.001 (User Execution: Malicious Link), T1071.001 (Application Layer Protocol: Web Protocols)
📌
Source: Help Net Security — [URL unavailable]
- MITRE ATT&CK: T1189 (Drive-by Compromise), T1204.001 (User Execution: Malicious Link), T1071.001 (Application Layer Protocol: Web Protocols)
📌
- “Fast16” Malware — Cybersecurity researchers recently uncovered a sophisticated cyber weapon, dubbed “Fast16,” dating back to the mid-2000s. This malware was designed to subtly alter high-precision mathematical calculations in specific physics software, likely aimed at disrupting Iran’s nuclear program. This is a fascinating example of highly targeted, stealthy sabotage.
- MITRE ATT&CK: T1560.001 (Archive Collected Data: Archive via Utility), T1059.006 (Command and Scripting Interpreter: Python), T1548.002 (Abuse Elevation Control Mechanism: Bypass User Account Control) (Inferred from sophisticated nature)
📌
Source: NPR · Utah Public Radio · WVXU — [URL unavailable]
- MITRE ATT&CK: T1560.001 (Archive Collected Data: Archive via Utility), T1059.006 (Command and Scripting Interpreter: Python), T1548.002 (Abuse Elevation Control Mechanism: Bypass User Account Control) (Inferred from sophisticated nature)
📌
🏗️ DevSecOps & Cloud Security
- Mastra AI Framework Supply Chain Attack — As noted in Critical Threats, a typosquatting attack on the
@mastranpm organization led to widespread compromise of AI framework packages. This highlights the critical need for strict access controls and account hygiene for package maintainers, as a single compromised account can affect an entire ecosystem.- Mitigations include disabling lifecycle scripts (
npm config set ignore-scripts true), using exact dependency versions, committing lockfiles, and verifying package provenance vianpm audit signatures. 📌Source: BankInfoSecurity · StepSecurity — [URL unavailable] · [URL unavailable]
- Mitigations include disabling lifecycle scripts (
- Arch Linux AUR Supply Chain Attack — Attackers compromised over 400 (potentially up to 1,500) orphaned or abandoned packages in the Arch User Repository (AUR). Malicious
PKGBUILDscripts installed a Rust-based credential stealer and, in some cases, an eBPF rootkit. This campaign, “Atomic Arch,” primarily affects users building from AUR. 📌Source: Rod's Blog — direct link unavailable
🔧 Patches & Vendor Releases
- Microsoft Defender —
CVE-2026-50656(RoguePlanet) — Microsoft is actively working on a high-quality security update for this privilege escalation zero-day. Status: 🟡 partial/workaround needed (patch pending). 📌Source: SecurityWeek · The Hacker News — [URL unavailable] · [URL unavailable]
🧪 Threat Intel & Malware
- GodDamn Ransomware — Researchers identified a new ransomware variant, “GodDamn,” which encrypts files and appends a
.God8Damnextension. It drops aREADME.TXTransom note. This is another one to add to the growing list. 📌Source: CYFIRMA — [URL unavailable] - VexxStealer — Identified as an information-stealing threat, VexxStealer is distributed through seemingly legitimate software installers. It conducts extensive reconnaissance, targets sensitive user data (credentials, personal info), and uses stealthy techniques to evade detection and maintain prolonged access.
📌
Source: CYFIRMA — [URL unavailable] - Ransomware Activity — Ransom-DB reports 40 new ransomware attacks in the last 24 hours across 18 countries. Genesis and SafePay are among the active threat groups.
📌
Source: Ransom-DB — [URL unavailable]
🌐 Industry, Brand & Internet Security
- Typosquatting Trends — A scan of 24 well-known brands found 591 live typosquatting domains, with 48% having email-sending capability. This underlines the persistent threat of phishing and brand impersonation. 20 domains were registered in the last 90 days, showing active threat actor investment.
📌
Source: Hard2bit — [URL unavailable] - BGP Hijacking Concerns — Telegram CEO Pavel Durov claimed BGP hijacking was used to compromise access to the app for users outside India, calling it a “competitive war” tactic. This highlights BGP’s continued vulnerability for traffic misdirection and interception.
📌
Source: The Indian Express — [URL unavailable]
🤖 AI & LLM Security
- AI Security Agent Launches — Ex-Tesla hacker Yoni Ramon launched “Pi,” a $100M AI security agent focused on automated patching. Cisco also unveiled its own agentic platform for critical IT infrastructure defense. This signals a growing industry investment in AI-driven security automation.
📌
Source: Forbes — [URL unavailable] - Meta AI Support Bot Exploitation — Hackers exploited a Meta AI support bot to take over Instagram accounts. This is a direct example of AI agent systems being targeted and abused for account compromise.
📌
Source: Forbes — [URL unavailable] - Orphaned AI Agents & Identity Sprawl — Companies are struggling with AI’s “identity sprawl,” with three-quarters of organizations not fully overseeing user accounts for AI agents. This creates significant entry points for attackers and unmonitored access risks.
📌
Source: The Hacker News · Cybersecurity Dive — [URL unavailable] · [URL unavailable]
📋 Compliance & Regulatory
- MeitY (India) Deepfake Takedown SOP — The Ministry of Electronics and Information Technology (MeitY) released a Standard Operating Procedure (SOP) requiring prompt removal of non-consensual intimate imagery (NCII) from internet platforms within 24 hours. This is India’s first victim-focused framework against deepfakes and revenge porn.
📌
Source: News4Hackers — [URL unavailable]
💡 Marcus’s Take
Another Friday, another reminder that the fundamentals are still what bite us. Today’s news screams “supply chain and identity.” The Mastra AI framework compromise is a perfect storm: typosquatting, credential compromise, and broad publishing access in npm. It’s not a movie villain; it’s an attacker maximizing ROI on a single, well-placed account.
Teams need to double down on package provenance, lockfiles, and least privilege for every automated system, especially in cloud-native and AI development. And that Microsoft Defender zero-day? Patch Tuesday survivorship bias in action. The patches that get skipped are always the ones that bite you. Don’t let your guard down just because it’s Friday.