Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
2026-06-28T08:51:46Z•e9d6cc077bca7ef8d1e6c42f07723b7856910d148fb52164a36c638f2bfcd08c
AkritesCVE-2025-15660CVE-2026-13135CVE-2026-13136Cisco Unified CMFortibleed campaignHTML smugglingMFA bypassMirage2FASIM swappingSharkLoaderStrikeSharkSynology MailPlusZeroTier Quantumidentity and authorizationlaw enforcementmalwareopen-source securitypatchphishingpost-quantum cryptographyransomwaresupply-chain riskvulnerabilitiesx401 protocol
What happened
Weekly roundup of security developments: active exploitation of a Cisco Unified CM vulnerability and the Fortibleed campaign’s organizational impact; Synology released a critical MailPlus Server patch fixing CVE-2026-13136, CVE-2026-13135 and CVE-2025-15660; Fortra researchers disclosed the Mirage2FA phishing kit that uses HTML smuggling and obfuscated JavaScript to harvest Microsoft 365 credentials during MFA prompts; Kaspersky uncovered a novel SharkLoader dropper (StrikeShark) targeting governments and software developers; ransomware against European orgs is rising with third-party/supply‑‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- e9d6cc077bca7ef8d1e6c42f07723b7856910d148fb52164a36c638f2bfcd08c
- Enrichment time
- 2026-06-28T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.