DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch

DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch

•

Episode description

DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch

Three active threats demand immediate attention from UK small and medium businesses. Symantec researchers have documented DragonForce ransomware concealing command-and-control infrastructure inside Microsoft Teams relay servers using a custom backdoor that exploits anonymous visitor tokens. The intrusion evaded detection for over two weeks by routing malicious traffic through legitimate Microsoft infrastructure. CISA has added a maximum-severity Joomla Content Editor vulnerability (CVE-2024-43233) to its Known Exploited Vulnerabilities catalogue, confirming active exploitation of an unauthenticated remote code execution flaw widely present in UK business websites. A publicly disclosed privilege escalation zero-day in Microsoft Defender, named RoguePlanet, remains unpatched while attackers actively deploy footholds through phishing and social engineering campaigns. Mauven examines why perimeter defences cannot catch infrastructure-layer threats, what behavioural anomaly monitoring actually means in practice, and why patch management discipline should not depend on regulatory deadlines. This briefing provides specific technical actions for Joomla users, questions to ask managed security providers, and interim controls for the Defender zero-day.

Chapters

  • DragonForce Conceals Command Infrastructure Inside Microsoft Teams Symantec documents a two-week ransomware intrusion using custom malware to route attacks through Microsoft Teams relay servers, evading perimeter defences by hiding inside legitimate traffic. The technique exploits TURN servers and anonymous visitor tokens, requiring behavioural anomaly monitoring rather than edge security to detect.
  • CISA Adds Maximum-Severity Joomla Vulnerability to Exploitation Catalogue CVE-2024-43233, a CVSS 10.0 unauthenticated remote code execution flaw in the Joomla Content Editor plugin, is under active exploitation. The vulnerability affects a widely deployed extension common in UK small business websites. CISA has set a Friday patch deadline for federal agencies.
  • RoguePlanet Privilege Escalation Zero-Day in Microsoft Defender Remains Unpatched A publicly disclosed privilege escalation vulnerability in Microsoft Defender, part of the Nightmare Eclipse research chain, has no available patch. Microsoft has confirmed work is underway. The flaw enables attackers who gain initial access through phishing or social engineering to escalate to full system control on Windows endpoints.
  • Priority Actions and Patch Management Discipline Immediate actions include checking and patching Joomla JCE installations, asking managed security providers about internal anomaly monitoring capabilities, and applying least privilege controls while awaiting the Defender patch. A brief note covers an updated Cisco SD-WAN advisory affecting additional device models.

Links