Security Roundup: Cisco SD-WAN Zero-Day, DragonForce Teams Relay Backdoor, JetBrains AI Key Theft, Mastra npm RAT, FortiBleed — Week of June 19, 2026
A week defined by a novel ransomware C2 technique abusing Microsoft's own relay infrastructure, the sixth Cisco SD-WAN zero-day of the year, a coordinated campaign stealing AI API keys from 70,000 developer IDE installs, a supply chain attack backdooring 144 npm packages via a stale contributor account, and a massive credential extraction campaign compromising 73,000 Fortinet firewalls. Here is everything you need to know and act on.
1. CVE-2026-20262 — Cisco SD-WAN Manager Zero-Day: Path Traversal to Root (CVSS 6.5, CISA KEV)
Cisco patched and disclosed CVE-2026-20262, the sixth Cisco SD-WAN zero-day to be actively exploited in 2026, on June 15–16. CISA immediately added it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 29, 2026.
CVSS: 6.5 Medium | CVE: CVE-2026-20262 | CISA KEV: June 15, 2026
The flaw is an arbitrary file-write via path traversal (CWE-22) in Cisco Catalyst SD-WAN Manager's file upload API. While a CVSS of 6.5 is medium-severity, the exploitation chain elevates its real-world risk significantly: an authenticated attacker with minimal (write-access) credentials can craft a traversal request, upload a malicious WAR file to WildFly's deployment directory, auto-trigger deployment, and then call the resulting JSP web shell through the vManage service proxy to achieve root code execution.
Attack chain summary: Authenticate (low-privilege) → POST crafted filename to upload API → write WAR to WildFly deployments/ → WildFly auto-deploys WAR → GET JSP shell via service proxy → root command execution.
Detection: Inspect /var/log/nms/vmanage-server.log, vmanage-appserver.log, and serviceproxy-access.log for unexpected .war uploads and JSP access. No workarounds — upgrade to 20.12.4, 20.13.3, or 20.14.1.
Remediation: Upgrade immediately. Restrict SD-WAN Manager management interface to trusted admin IP ranges via firewall rules. Enforce MFA on all SD-WAN Manager accounts.
2. DragonForce Backdoor.Turn — First Malware to Abuse Microsoft Teams TURN Relay for C2
Broadcom's Symantec and Carbon Black teams disclosed Backdoor.Turn, a novel Go-based backdoor deployed by DragonForce ransomware in an attack on a US services firm that maintained a dwell time of approximately two months. It is the first known malware to abuse Microsoft Teams' TURN relay infrastructure for command-and-control communications.
How it works: Backdoor.Turn obtains an anonymous Teams visitor token from Microsoft's Skype-backed identity services (no Teams account required), establishes a TURN relay session via a legitimate Microsoft relay server, and then tunnels a QUIC session to the attacker's real C2 through that relay. To network monitoring tools, the C2 traffic appears to originate from *.teams.microsoft.com infrastructure — virtually invisible to most enterprise security stacks.
BYOVD component: DragonForce used a multi-vector Bring Your Own Vulnerable Driver strategy, exploiting signed-but-vulnerable drivers from Huawei, Topaz Antifraud, Tower of Fantasy, and K7 Security to achieve kernel-level privileges and disable EDR tools before deploying the backdoor.
IOCs: QUIC traffic (UDP/443) from non-Teams processes to Microsoft relay IP ranges; DLL sideloading from non-standard directories; loading of the above BYOVD drivers outside their parent applications. Dwell time of 2 months before ransomware detonation.
Remediation: Monitor for QUIC to Teams relay ranges from unexpected processes; audit kernel driver loads for known BYOVD targets; isolate and harden internet-facing SQL/database servers.
3. JetBrains Marketplace AI Key Theft — 15 Plugins, ~70,000 Installs, TLS Bypass
JetBrains and Aikido Security disclosed a coordinated malware campaign on June 16, 2026: 15 malicious plugins on JetBrains Marketplace had been silently stealing AI provider API keys from developers since October 2025. Combined install count: approximately 70,000. Targeted keys: OpenAI, Anthropic (Claude), DeepSeek, Mistral, Cohere.
Mechanism: Each plugin masqueraded as a legitimate AI IDE utility. When a developer entered their AI API key and clicked Apply, the plugin registered a JVM-wide X509TrustManager that silently disabled TLS certificate validation, then POSTed the key as plaintext JSON to the hardcoded C2 at 39.107.60[.]51. The exfiltration ran in a background thread with no UI indication.
IOC: C2 IP 39.107.60[.]51; JVM-wide TLS validation bypass at plugin load; plaintext HTTP POST immediately following plugin settings save.
Remediation: Rotate all AI provider API keys immediately if any AI-related JetBrains plugin was installed between October 2025 and June 16, 2026. Audit plugin list, remove unverified AI plugins, check provider billing for unexpected usage.
4. Mastra npm Supply Chain: easy-day-js Typosquat Delivers Cross-Platform RAT to 144 Packages
On June 17, 2026, an attacker compromised the @mastra npm organization via a stale contributor account and mass-published 144 backdoored package versions in an 88-minute window, affecting the Mastra AI agent framework with 1.1M+ weekly downloads.
Attack mechanics: The attacker hijacked the dormant ehindero contributor account (scope access never revoked), then injected a typosquatted dependency — easy-day-js — a near-perfect clone of the legitimate dayjs library. The first published version (1.11.21) was clean, establishing package history. The second (1.11.22) contained an obfuscated postinstall dropper. Mastra packages were pinned to ^1.11.21, meaning every fresh npm install automatically resolved to the malicious 1.11.22.
Payload: A cross-platform Node.js RAT that installs OS-level persistence (Windows/macOS/Linux), inventories 166 cryptocurrency wallet browser extensions, harvests browser credentials from Chrome/Brave/Edge, and exfiltrates CI/CD secrets and .env files.
Remediation: Update all @mastra/* packages. Any environment that ran npm install between June 17 01:01–02:29 UTC should be treated as compromised: rotate all secrets, audit persistence mechanisms, check crypto wallet extensions.
5. FortiBleed — 73,932 Fortinet Firewalls Compromised, Credentials Cracked Across 194 Countries
Security researchers at Hudson Rock and Arctic Wolf published findings on the FortiBleed campaign, documenting the extraction and offline cracking of administrator credentials from 73,932 FortiGate firewall instances across 194 countries. The campaign is not a single zero-day — it is a convergence of multiple known, unpatched Fortinet CVEs (primarily CVE-2026-24858), SHA-256 password hashes crackable via GPU, and infostealer credential recycling.
Impact: Verified working admin credentials for an estimated 30,000–75,000 devices; 21,632 affected domains. Sectors include critical infrastructure, healthcare, financial services, and government.
Detection: Audit admin last-login timestamps; check FortiGate logs for unauthorized config exports; monitor for logins from unexpected geographies. Hudson Rock's published indicator list can be checked against your firewall's public IP.
Remediation: Immediately rotate all FortiGate admin passwords; apply all pending Fortinet patches (FortiOS 7.4.5+, 7.2.10+, 7.0.17+); restrict management interface access with trusted-host ACLs; enable MFA for all admin accounts; verify password hashing is bcrypt (FortiOS 7.2+).
Deep Dives
For full technical analysis, attack chain breakdowns, IOCs, and remediation commands, see the individual deep-dive posts:
- CVE-2026-20262: Cisco SD-WAN Manager Zero-Day — Path Traversal to Root + CISA KEV
- DragonForce Backdoor.Turn — Microsoft Teams TURN Relay C2: Attack Chain & Detection
- JetBrains Marketplace AI Key Theft — 15 Malicious Plugins, 70K Installs, TLS Bypass
- Mastra npm Supply Chain: easy-day-js Typosquat Delivers Cross-Platform RAT to 144 Packages
- FortiBleed: 73,932 Fortinet Firewalls Compromised — Credential Extraction Campaign Analysis