DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months

2026-06-17T20:51:45Z7bb3865119107dbe75927887bcca2c6435d6a79d00be53ef9fe2a7798bcedd18
active-exploitationandroid-malwareaptbanking-trojancisa-kevcovert-channelscve-2026-20262cve-2026-48907data-theftdragonforceedtech-targetingextortionfishmongerfortinetfortisandboxhealthcare-breachkernel-rootkitmicrosoft-teamsransomwarerokarollasprysocksthreat-actoruefi-bootkit

What happened

Multiple high-risk incidents and active exploits reported across enterprise, cloud and mobile environments. DragonForce ransomware operators covertly routed C2 through Microsoft Teams relay servers to evade detection for 1–2 months. CISA added the Widget Factory Joomla Content Editor flaw (CVE-2026-48907, CVSS 10.0) to its Known Exploited Vulnerabilities catalog; Cisco confirmed active exploitation of CVE-2026-20262 (Catalyst SD‑WAN Manager arbitrary file write). Defused Cyber observed active exploitation of three critical FortiSandbox vulnerabilities. Additional notable threats include the Ro

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7bb3865119107dbe75927887bcca2c6435d6a79d00be53ef9fe2a7798bcedd18
Enrichment time
2026-06-17T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.