Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites

DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites

Jun 16, 2026 • 10min 54s

Episode description

DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites

Three critical threats demand immediate attention from UK small businesses today. DragonForce ransomware has deployed a custom backdoor that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, exploiting implicit trust in cloud services. Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are being actively exploited in the wild, raising serious questions for businesses relying on managed security providers. Meanwhile, over 1.2 million WordPress sites have been compromised through a supply chain attack targeting OptinMonster, TrustPulse, and PushEngage plugins. CISA has also added a critical LiteSpeed cPanel vulnerability to its Known Exploited Vulnerabilities catalogue, affecting countless UK websites on shared hosting. Mauven MacLeod walks through the behavioural and operational gaps these threats expose, and provides four concrete actions businesses can take today: checking FortiSandbox patch status with managed security providers, verifying LiteSpeed plugin updates with hosting providers, auditing WordPress admin accounts, and reviewing Microsoft Teams external tenant access configurations. None of these actions require large budgets, but all require the willingness to ask direct questions of service providers.

Chapters

  • DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites Mauven introduces three urgent threats: a sophisticated backdoor exploiting Microsoft Teams infrastructure, critical Fortinet vulnerabilities being actively exploited, and a WordPress supply chain attack compromising over a million sites. She explains why DragonForce’s Backdoor.Turn tool exploits implicit trust in Microsoft Teams relay traffic, details the pattern of Fortinet security product vulnerabilities, covers CISA’s urgent warning on LiteSpeed cPanel flaws, and reveals a supply chain attack through Awesome Motive’s CDN affecting OptinMonster, TrustPulse, and PushEngage plugins. The briefing concludes with four immediate actions: checking FortiSandbox patch status, verifying LiteSpeed updates, auditing WordPress admin accounts, and reviewing Teams external access settings.

Links

  • https://www.ncsc.gov.uk/collection/cloud-security
  • https://defused.com/
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://sansec.io/
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Jun 16, 2026
10:54 DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites
Jun 16, 2026
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons