DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
2026-06-17T20:51:45Z•7bb3865119107dbe75927887bcca2c6435d6a79d00be53ef9fe2a7798bcedd18
active-exploitationandroid-malwareaptbanking-trojancisa-kevcovert-channelscve-2026-20262cve-2026-48907data-theftdragonforceedtech-targetingextortionfishmongerfortinetfortisandboxhealthcare-breachkernel-rootkitmicrosoft-teamsransomwarerokarollasprysocksthreat-actoruefi-bootkit
What happened
Multiple high-risk incidents and active exploits reported across enterprise, cloud and mobile environments. DragonForce ransomware operators covertly routed C2 through Microsoft Teams relay servers to evade detection for 1–2 months. CISA added the Widget Factory Joomla Content Editor flaw (CVE-2026-48907, CVSS 10.0) to its Known Exploited Vulnerabilities catalog; Cisco confirmed active exploitation of CVE-2026-20262 (Catalyst SD‑WAN Manager arbitrary file write). Defused Cyber observed active exploitation of three critical FortiSandbox vulnerabilities. Additional notable threats include the Ro
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 7bb3865119107dbe75927887bcca2c6435d6a79d00be53ef9fe2a7798bcedd18
- Enrichment time
- 2026-06-17T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.