Isometric network nodes highlighting critical software vulnerabilities and cyber threats.

Daily Cybersecurity News - June 17, 2026

CISA orders feds to patch Joomla flaw

CISA told federal agencies to patch a max-severity flaw in the JCE Joomla plugin by Friday. The bug lets unauthenticated attackers upload and run PHP code.

CVE-2026-48907 is an improper access control issue in Widget Factory's JCE editor. It carries maximum severity and sits on CISA's actively exploited list with public exploit code already circulating.

Affects any Joomla site running the JCE plugin before version 2.9.99.5. Federal civilian agencies face the Friday deadline under binding directive.

JCE team released the fix in early June after seeing automated attacks hit sites without public registration.

Microsoft Working On Defender Patch For RoguePlanet

Microsoft is patching a zero-day in Windows Defender that attackers already exploit.

RoguePlanet bypasses signature detection in real-time protection. zero-day status means no patch yet.

Windows users running Microsoft Defender stay exposed until the update lands.

Disclosed one week ago.

FortiBleed Leak Exposes Fortinet VPN Credentials

A data leak called FortiBleed dumped Fortinet VPN credentials for nearly 74,000 devices across the world.

Researcher Bob Diachenko found the exposed server holding usernames, emails, and plaintext passwords. The set covers 73,932 firewall URLs and big names like Chevron and Samsung.

Attackers ran a massive brute force campaign, cracked hashes on a GPU cluster, then logged the results with target details for follow-on access.

Many devices still sit online with management interfaces exposed to the internet.

Malicious JetBrains Plugins Steal AI Keys

Malicious plugins slipped into the JetBrains Marketplace and stole AI API keys from developers using popular IDEs.

Fifteen plugins published under seven accounts posed as coding assistants and Git tools. They worked as advertised but sent keys entered in settings to attacker servers. The plugins racked up nearly 70,000 installs since October 2025.

This stands out because credential theft via official marketplace plugins remains uncommon compared to npm or PyPI abuse. The operators also ran a paid tier that supplied harvested keys back to subscribers.

Some plugins stayed live on the marketplace even after researchers flagged the credential exfiltration code.

Steam Workshop Abused To Spread Malware Via Wallpaper Engine

Threat actors are abusing Steam Workshop to push malware hidden inside wallpaper packages for the Wallpaper Engine app.

They upload malicious application-type wallpapers that execute on install, dropping backdoors like DarkKomet or infostealers such as Lumma and Vidar. Victims get tricked into subscribing through the Workshop, with some packages downloaded thousands of times since late 2025.

This reuses the old trick of hiding payloads in user-generated content, but targets a popular Steam app with built-in execution features that bypass normal scrutiny.

Dozens of malicious wallpapers were found, each already downloaded thousands or tens of thousands of times before removal.

Fileless Phantom Stealer Targets Browser Credentials

A new phishing campaign delivers Phantom Stealer, a fileless credential stealer aimed at banks and high-value targets.

Attackers send malicious business documents that drop an obfuscated batch file. This launches a multistage chain injecting the malware directly into the Windows Explorer process for in-memory execution.

The dropper stands out with layered obfuscation using Base64, XOR, and Donut to hide its payload from analysts. Phantom Stealer itself is sold as malware-as-a-service with broad browser theft capabilities.

Researchers at Group-IB tracked earlier Phantom Stealer activity against European logistics and manufacturing firms from late 2025 into early 2026.

Source: Dark Reading

SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection

FishMonger expanded its SprySOCKS backdoor with a Windows version that leans on malicious kernel drivers for stealth against government targets.

The group hit organizations in Honduras, Taiwan, Thailand, and Pakistan. The WIN_DRV variant loads two custom drivers. One acts as a loader while the other hooks system calls to hide processes and files from security tools.

This marks a shift from their prior Linux-only focus. The drivers are fully malicious rather than abused legitimate ones, though they rely on an exposed certificate that works mainly on older systems.

ESET first spotted the Windows samples on VirusTotal with in-the-wild use dating back to 2023.

Source: Dark Reading