Cybersecurity Intelligence Report — 17 June 2026

Written by

in

Cybersecurity Intelligence Report — 17 June 2026

Executive signal: Today’s collection produced 65 new unique items, including 2 critical signals, 1 CISA Known Exploited Vulnerability update and 1 ransomware DLS victim entries. Prioritise remote access tooling, exploited web-management flaws and exposed identity paths.

1. Critical section

[12] SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) (HelpNetSecurity)

A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Maliciously “forged” Technician account (Source: Horizon3.ai) The vulnerability CVE-2026-48558 is an authentication bypass flaw affecting…


CVEs: CVE-2026-48558

[11] Software supply chains are heading for a transparency test (HelpNetSecurity)

Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. Level of SBOM adoption based on organisation size (Source: ENISA) SBOMs move from best…

2. CISA KEV section

CVEVendor/ProductScoreRequired action
CVE-2026-48907CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability – Widget Factory Joomla Content Editor 6Widget Factory Joomla Content Editor Improper Access Control Vulnerability – Widget Factory Joomla Content Editor . Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in…

3. Ransomware victims (DLS monitoring)

shinyhunters: Service Notice: Scheduled Maintenance and Infrastructure Upgrades

4. News section

[7] CISA warns of another cPanel plugin flaw exploited in attacks (BleepingComputer)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. CVEs: CVE-2026-54420.

[7] Ransomware gang abuses Microsoft Teams relays to hide malicious traffic (BleepingComputer)
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.

[7] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw (TheHackerNews)
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to… CVEs: CVE-2026-20262.

[7] Attackers are exploiting FortiSandbox vulnerabilities (HelpNetSecurity)
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of… CVEs: CVE-2026-39808, CVE-2026-25089, CVE-2026-39813.

[7] Cybercriminals mask malicious communications through Microsoft Teams relays (HelpNetSecurity)
The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation that has been active since 2023. The group provides affiliates with ransomware tools and supporting…

[5] CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation (TheHackerNews)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case… CVEs: CVE-2026-54420.

[5] iRhythm Confirms Data Stolen in Hack (SecurityWeek)
The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek

5. Summary

Total new items: 65. Critical count: 2. Active ransomware groups observed: 1. Top CVEs to patch urgently: CVE-2026-54420, CVE-2026-20262, CVE-2026-39808, CVE-2026-25089, CVE-2026-39813, CVE-2026-48558, CVE-2026-48907.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Companion dashboard: open the CSSLTD HTML intelligence dashboard.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *