# Threat Intel Brief — 22 May 2026
TL;DR
- Fortinet FortiCloud SSO bypass (CVE-2025-59718, CVE-2025-59719) actively exploited to extract LDAP credentials via static encryption key; immediate patching and credential rotation required.
- Microsoft Defender privilege escalation (CVE-2026-41091) under active exploitation; attackers gain SYSTEM-level access on Windows endpoints.
- SonicWall Gen6 SSL-VPN exploited via incomplete patching; threat actors bypass MFA and deploy ransomware tooling.
- Supply chain attacks compromise npm packages (@antv) and Grafana infrastructure; CI/CD credentials stolen across GitHub, AWS, Kubernetes, and Vault platforms.
- China-nexus actors target telecommunications with Linux/Windows malware (Showboat, JFMBackdoor); UK NCSC issues defensive guidance on covert device networks.
Critical Threats
Fortinet FortiCloud SSO Authentication Bypass
What happened: Threat actors are actively exploiting CVE-2025-59718 and CVE-2025-59719 to bypass FortiCloud SSO authentication on FortiGate appliances. The attack leverages a default static encryption key present on all FortiGate instances to decrypt configuration data, extracting LDAP credentials and private keys. CERT.at reports that initial patches were incomplete, and attackers are exporting configuration backups from vulnerable systems.
Impact: Organizations using FortiGate with FortiCloud SSO face immediate credential theft risk. Compromised LDAP passwords enable lateral movement into Active Directory environments. Extracted private keys may expose VPN and certificate-based authentication. The shared static encryption key represents a systemic supply chain weakness affecting all FortiGate deployments globally.
Recommendations:
- Disable FortiCloud SSO on all FortiGate appliances until patches are verified complete (0–24h)
- Apply latest Fortinet security updates for CVE-2025-59718 and CVE-2025-59719; confirm patch addresses full vulnerability scope (0–24h)
- Rotate all LDAP service account passwords and monitor Active Directory for suspicious authentication (0–24h)
- Review FortiGate logs for unauthorized configuration access or SSO authentication anomalies (24–72h)
- Audit and rotate private keys and certificates stored in FortiGate configurations (24–72h)
Microsoft Defender Privilege Escalation Under Active Exploit
What happened: Microsoft disclosed that CVE-2026-41091, a privilege escalation vulnerability in Defender, is being actively exploited in the wild. The flaw allows local attackers to gain SYSTEM privileges through improper link resolution handling. A second denial-of-service vulnerability in Defender is also under active exploitation.
Impact: High-severity local privilege escalation enables attackers with initial low-privilege access to gain full SYSTEM control on endpoints running Microsoft Defender. Active exploitation increases risk of ransomware deployment, lateral movement, and persistence establishment. Defender is deployed by default on most Windows systems, making exposure widespread.
Recommendations:
- Apply Microsoft security updates for Defender immediately via Windows Update or WSUS (0–24h)
- Verify Defender definition and platform updates are current using Update-MpSignature PowerShell cmdlet (0–24h)
- Review Windows Security Event Logs and Defender operational logs for suspicious privilege escalation attempts (24–72h)
- Audit local administrator group membership changes and new SYSTEM-level scheduled tasks created in past 30 days (24–72h)
- Deploy detection rules for abnormal Defender process behavior, particularly MsMpEng.exe spawning unexpected child processes with SYSTEM privileges (this week)
SonicWall SSL-VPN Exploited via Incomplete Patching
What happened: Threat actors exploited incomplete patching on SonicWall Gen6 SSL-VPN appliances to brute-force VPN credentials and bypass multi-factor authentication. Attackers subsequently deployed tools used in ransomware attacks. CVE identifier not yet publicly assigned.
Impact: Organizations with SonicWall Gen6 SSL-VPN appliances face critical risk of compromise. Successful exploitation grants attackers authenticated VPN access despite MFA, enabling lateral movement and ransomware deployment. The incomplete patching issue suggests potential zero-day or undisclosed vulnerability requiring immediate verification of patch status.
Recommendations:
- Verify all SonicWall Gen6 SSL-VPN appliances are fully patched to latest firmware version from SonicWall support portal (0–24h)
- Review VPN authentication logs for brute-force attempts, unusual login patterns, or MFA bypass indicators (0–24h)
- Enforce strong password policies and implement account lockout thresholds to mitigate brute-force attacks (24–72h)
- Enable additional network segmentation and monitoring for VPN-connected devices to detect lateral movement (24–72h)
- Contact SonicWall support to confirm patch applicability and obtain specific remediation guidance for Gen6 appliances (this week)
Supply Chain Attacks Target npm and CI/CD Infrastructure
What happened: Compromised @antv npm packages deployed Mini Shai-Hulud malware to steal CI/CD credentials from Linux-based automation environments. The malware executes during npm install and targets secrets across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. Separately, Grafana suffered a data breach caused by a GitHub workflow token that was not rotated following the TanStack npm supply-chain attack.
Impact: Critical impact to CI/CD security posture. Stolen credentials provide attackers with access to source code repositories, cloud infrastructure, secrets management systems, and deployment pipelines. Potential for lateral movement across entire development and production infrastructure. Organizations using affected packages must assume credential compromise and rotate all secrets accessible from build environments.
Recommendations:
- Immediately audit all CI/CD pipelines and development environments for @antv package usage and remove compromised versions (0–24h)
- Rotate all credentials accessible from affected build environments: GitHub tokens, AWS keys, Kubernetes service accounts, Vault tokens, npm tokens, and 1Password credentials (0–24h)
- Review npm audit logs and CI/CD execution logs for suspicious package installations and outbound network connections during build processes (24–72h)
- Implement package integrity verification using npm lock files and consider using private npm registries with package scanning (this week)
- Monitor for unauthorized access attempts using stolen credentials across GitHub, AWS, Kubernetes, and other targeted platforms (this week)
Threat Actor Activity
Chinese State-Sponsored Telecom Targeting
Chinese state-sponsored actors are conducting cyber-espionage operations against telecommunications providers using newly discovered Linux malware (Showboat) and Windows malware (JFMBackdoor). Showboat is a modular post-exploitation framework capable of spawning remote shells, transferring files, and functioning as a SOCKS5 proxy backdoor. The campaign has targeted at least one telecommunications provider in the Middle East since mid-2022.
Defensive priorities:
- Deploy enhanced monitoring for Linux systems in telecom infrastructure, focusing on anomalous process execution and network connections
- Implement network segmentation between IT and operational technology environments to limit lateral movement
- Establish baseline behavioral analytics for critical telecom management systems and alert on deviations
- Conduct threat hunting for indicators of Showboat and JFMBackdoor across both Linux and Windows estates
China-Nexus Covert Device Networks
The UK National Cyber Security Centre issued guidance on defending against China-nexus covert networks of compromised devices. International cyber agencies report a widespread shift in tactics toward networks of compromised infrastructure used by state-sponsored actors to conceal malicious cyber activity. Organizations are advised to map and baseline edge device traffic, particularly VPN and remote access connections, and implement dynamic threat feed filtering with known covert network indicators.
Cybercriminal Infrastructure Disruption
Law enforcement conducted a joint international operation to seize the "First VPN" service, which was being used by threat actors to facilitate ransomware attacks and data theft operations. Separately, Canadian authorities arrested a 23-year-old Ottawa man suspected of operating Kimwolf, an IoT botnet that infected millions of devices for DDoS attacks. The suspect faces criminal hacking charges in both Canada and the United States.
Geopolitical Context
European Critical Infrastructure Under Pressure
Multiple European national CERTs issued urgent warnings this week reflecting heightened threat activity against critical infrastructure. Belgium's CERT.BE warned of actively exploited vulnerabilities in PgBouncer, Portainer, nginx, Microsoft Exchange Server, Palo Alto Networks PAN-OS, Cisco Catalyst SD-WAN, and Sparx enterprise software. Latvia's CERT.LV reports that cyber threats remain at elevated levels with a steady upward trend in Q4 2025, driven by both financial and political motivations with geopolitical factors serving as a significant catalyst.
Baltic and Eastern European Threat Landscape
Slovenia faces multi-vector ransomware campaigns leveraging phishing, RDP exploitation, and vulnerability abuse. The country's position as a NATO and EU member state bordering the Balkans makes it an attractive target for both financially motivated cybercriminals and potentially state-aligned actors. Latvia's elevated threat posture reflects broader vulnerabilities across the Baltic region, where proximity to Russia and support for Ukraine have historically correlated with increased hostile cyber operations.
Five Eyes Coordination on China-Linked Activity
The UK NCSC's public release of defensive guidance on China-nexus covert networks signals coordinated intelligence-sharing among Five Eyes and allied nations. The advisory reflects growing concern regarding the operational security evolution of China-linked advanced persistent threat groups, particularly their shift toward leveraging compromised infrastructure rather than direct command-and-control channels to complicate attribution and evade detection.
Recommended Actions
Immediate (0–24 hours)
1. Fortinet users: Disable FortiCloud SSO and apply patches for CVE-2025-59718/CVE-2025-59719; rotate LDAP credentials
2. Windows environments: Apply Microsoft Defender updates addressing CVE-2026-41091
3. SonicWall deployments: Verify Gen6 SSL-VPN patch status and review authentication logs
4. Development teams: Audit CI/CD pipelines for compromised @antv npm packages; rotate all accessible credentials
5. All organizations: Review and patch critical vulnerabilities in PgBouncer, Portainer, nginx, Exchange Server, PAN-OS, and Cisco SD-WAN per vendor advisories
Short-term (24–72 hours)
1. Review FortiGate, Defender, and VPN logs for indicators of compromise
2. Implement enhanced monitoring for CI/CD environments and npm package installations
3. Audit local administrator group membership and scheduled tasks for unauthorized changes
4. Enable network segmentation and monitoring for VPN-connected devices
5. Conduct threat hunting for Showboat and JFMBackdoor indicators in telecom infrastructure
This week
1. Implement package integrity verification and private npm registries with scanning
2. Deploy detection rules for abnormal Defender process behavior and privilege escalation
3. Map and baseline edge device traffic, particularly VPN and remote access connections
4. Review and harden authentication mechanisms on network appliances and edge devices
5. Conduct security awareness training focused on phishing recognition and safe browsing practices
Watch List
- PostgreSQL version 14 EOL: Plan migration to version 15+ before end-of-life date
- Chromium zero-day: Monitor Google Chrome release channels for emergency patch addressing JavaScript persistence after browser close
- Ivanti products: Check vendor security advisories for product-specific patch releases
- MikroTik RouterOS: CVE-2025-42611 authentication bypass affecting OpenVPN, CAPsMAN, and 802.1X services
- Orca heat pumps: CVE-2026-25599 missing authentication and clear-text data transmission
- 3onedata Modbus gateways: CVE-2025-13605 OS command injection vulnerability
- Code Runner MCP Server: CVE-2026-5029 missing authentication on critical functions
Sources
This brief synthesizes intelligence from CERT.at, CERT.BE, CERT.LV, CERT.PL, SI-CERT, NCSC UK, BleepingComputer, The Hacker News, Krebs on Security, and Microsoft Security. Full source citations available in original reporting. Organizations should consult vendor security advisories for specific patch guidance and affected version information.
---
*This threat intelligence brief is current as of 22 May 2026. Threat landscapes evolve rapidly; organizations should maintain continuous monitoring and subscribe to vendor security advisories for updates.*
