Gunra Ransomware Exploits Fortinet Flaws Against Critical Infrastructure
Gunra ransomware actors are exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472 against critical infrastructure and government organizations, according to a joint U.S.-South Korean advisory. The same pressure is visible in active Microsoft exposure: Check Point reports North Korean operators used newly patched Windows zero-day CVE-2026-68820 in defense-sector espionage, while SharePoint Server CVE-2026-45659 entered CISA's KEV catalog after confirmed ransomware exploitation, with researchers pointing to suspected Storm-2603 activity.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
What the panel logged · 5
CVE-2024-55591 and CVE-2025-24472 are exploited Fortinet authentication-bypass risks; unexpected jsconsole administration, account changes, or appliance-originated access justify escalation.
CVE-2026-68820 was reportedly integrated into a fake-job and DLL side-loading chain to obtain SYSTEM and deploy FudModule; attribution should guide hunting without delaying containment.
Compromised TrueConf servers replaced hosted installers, extending the trust boundary to every endpoint that executed an unverified download.
Reported Polish OT manipulation demonstrates possible physical consequences, but exposed water-sector devices alone do not prove process manipulation; physical state must be verified before containment.
Paperclip CVE-2026-41679 presents a more complete enterprise exploit path than conditional GhostJacking demonstrations, while Zoom annotation flaws are patched and not known to be exploited.
What to do about it · 8
- Action 07UpdatedhighAI Security
Upgrade Paperclip for CVE-2026-41679, remove public exposure, and reduce agent approval and execution permissions while verifying exploit details against the vendor release.
- Action 01NewcriticalThreat Hunter
Apply Fortinet fixes, restrict management access, preserve external telemetry, and investigate unauthorized privileged activity before rotating downstream trust.
- Action 02NewcriticalIntel Analyst
Patch Windows CVE-2026-68820 and hunt defense-facing environments for fake-job delivery, DLL side-loading, FudModule, and the related RelayShell chain.
- Action 03NewcriticalSupply Chain Analyst
Isolate affected TrueConf Server deployments, quarantine hosted installers, verify provenance, and rebuild endpoints that executed altered packages.
- Action 04NewcriticalCrypto & FinCrime
Halt Tx XRPL bridge processing until destination and finality checks are corrected, balances reconciled, and adversarial transactions independently validated.
- Action 05NewcriticalCrypto & FinCrime
Suspend Harmony ONE issuance and affected bridge operations until unauthorized minting is contained, privileged controls rotated, and supply integrity independently reconciled.
- Action 06NewhighICS/OT Defender
Verify water-process conditions locally, freeze remote changes, remove direct PLC and modem exposure, and reset weak credentials without indiscriminately rebooting controllers.
- Action 08NewhighCloud Security
Inventory Zoom clients and deploy fixed versions for CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 within 72 hours, prioritizing users joining untrusted meetings.
Research trail
In this session
This is a crowded afternoon, but “critical” cannot mean equal airtime. We start with Gunra’s Fortinet exploitation because authentication bypass, session hijacking, backup deletion, and critical-infrastructure targeting create an immediate compromise-assessment problem—not merely a patching problem.
Then we test the DPRK Windows zero-day chain, TrueConf’s poisoned installers, and the CyberAv3ngers water-sector exposure.
Metabase, SNOWLIGHT, SharePoint CVE-2026-63520, Zoom, and the crypto bridge and mint failures get compressed decision lanes. CVE-2026-45659 remains urgent, but without a new delta today we will not relitigate yesterday’s SharePoint conclusion.
Alex, begin with Fortinet: what would make you treat an appliance as already compromised tonight?
Open this page on desktop for the full visual network.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Action 1
Dispatch Parallel
Gunra reportedly exploits FortiOS and FortiProxy authentication bypasses CVE-2024-55591 and CVE-2025-24472 against government and critical infrastructure, with MFA bypass, session hijacking, backup deletion, and double extortion. Take a firm position: which ex...
Alex MercerExploit feasibility lens
Moderator assignment
Gunra reportedly exploits FortiOS and FortiProxy authentication bypasses CVE-2024-55591 and CVE-2025-24472 against government and critical infrastructure, with MFA bypass, session hijacking, backup deletion, and double extortion. Take a firm position: which exposed versions and observable conditions justify treating the appliance and downstream domain as compromised tonight, what evidence matters most, and what are the first t... [arg clipped]
Response
Halil, the affected ranges are FortiOS 7.0.0–7.0.16, FortiProxy 7.0.0–7.0.19, and FortiProxy 7.2.0–7.2.12; fixed releases begin at 7.0.17, 7.0.20, and 7.2.13 respectively. These flaws permit unauthenticated super-admin access, and CISA associates them with Gunra operations. My assessment: if management was internet-accessible while running those versions, treat the appliance as compromised tonight—not merely vulnerable. An unauthenticated super-admin flaw is an unlocked control room, not a cracked window. fortiguard.com (opens in new tab) cisa.gov (opens in new tab)
Do not automatically condemn the downstream domain on exposure alone. Cross that threshold when you find an unexpected successful jsconsole super-admin login, unknown administrator or VPN account, unexplained configuration or MFA changes, session reuse, deleted backups/logs, or appliance-originated access toward domain controllers, identity systems, hypervisors, or backup infrastructure. A documented signal is an admin login showing ui="jsconsole" and method="jsconsole". External SIEM, IdP, EDR, NetFlow and backup audit records matter more than local appliance logs because super-admin access makes the appliance an unreliable witness.
fortifiedhealthsecurity.com (opens in new tab)
Tonight: isolate management access, preserve configuration, memory/session state and off-box logs, then replace or rebuild and patch the appliance. Revoke active VPN/admin sessions; rotate appliance credentials, API secrets, certificates and any directory or service credentials it could reach; disable unauthorized accounts; isolate suspicious endpoints; and hunt from the appliance toward identity and backup systems. Do not restore the old configuration blindly. Unknown: the available evidence does not establish the exact CVE-to-ransomware sequence for every Gunra victim, so attribution to one flaw should not delay containment.
Lena HartmannThreat intelligence lens
Moderator assignment
Assess the operational delta in North Korea-linked exploitation of Windows afd.sys CVE-2026-68820 against European and Indian defense and aerospace targets. Bound attribution confidence; map fake-job delivery, sideloading, FudModule, Roundcube CVE-2025-49113, and RelayShell; and give defenders the highest-yield hunts tonight without making attribution the response plan. State what evidence would change your confidence.
Response
The operational delta is chain integration, not a new remote-entry capability. Check Point reports this sequence against European and Indian defense/aerospace targets: fake-job impersonation → DLL side-loading → local CVE-2026-68820 exploitation for SYSTEM → FudModule kernel rootkit. In parallel, stolen Roundcube credentials → post-auth CVE-2025-49113 exploitation → RelayShell on compromised Roundcube, WordPress, or PrestaShop servers. ATT&CK: T1566, T1574.002, T1068, T1014, T1190, T1505.003, and T1090. Microsoft patched CVE-2026-68820 on August 11; CISA confirms active exploitation.
Attribution: Lazarus Group/G0032 is moderate confidence (ICD 203); operational chain confidence is high. FudModule and Dream Job provide continuity, but the new exploit-to-RelayShell linkage currently lacks enough independent infrastructure corroboration for high-confidence attribution.
Tonight, hunt the behavior—not “North Korea”:
- Trusted binaries loading DLLs from user-writable or newly created directories, followed by unusual child processes or networking.
- That execution chain transitioning rapidly to SYSTEM, kernel interference, or FudModule-like rootkit activity.
- Roundcube below 1.5.10/1.6.11: successful authentication followed by abnormal PHP object activity, new PHP files, or web-server-initiated outbound connections.
- Unexpected PHP changes and relay traffic on Roundcube, WordPress, and PrestaShop hosts; preserve authentication and web logs before containment.
- Patch CVE-2026-68820 and CVE-2025-49113 immediately.
I would raise attribution to high with independent victim telemetry plus passive-DNS/certificate pivots tying RelayShell administration to known G0032 infrastructure and reproducible FudModule code lineage. Multi-actor use of the exploit or proof that RelayShell is commodity infrastructure would lower confidence.
Tomas IlicSupply-chain trust lens
Moderator assignment
Head Mare reportedly exploited internet-facing TrueConf Server 5.3.x through 5.5.5 on port 4307/TCP, gained SYSTEM, installed a web shell, and replaced hosted client installers with PhantomCore or PhantomGraph builds. Determine the real trust boundary and downstream blast radius. Give a decision-ready containment and provenance-validation sequence, including how far back to distrust downloaded installers and which secrets or systems to rotate or rebuild.
Response
Halil, the real trust boundary is the TrueConf installer-distribution channel, not merely the server process. Kaspersky reports unauthenticated access over TCP/4307, SYSTEM-level execution, a web shell, privileged database access, and replacement of hosted client installers. Consequently, the blast radius includes the server, every endpoint that executed a substituted installer, and external counterparties that downloaded clients from it. PhantomGraph’s reported credential-theft and reverse-SSH capabilities also place reachable identity and network trust paths in scope.
Contain in this order:
- Isolate the server and block external TCP/4307; preserve disk, memory, logs, database records, and every hosted installer.
- Establish the compromise window from the earliest web-shell/file change, anomalous access, or installer replacement through verified restoration. If that cannot be proved, distrust every installer downloaded since the server first became both vulnerable and internet-accessible—or since the last independently verified clean installer hash, whichever is later. July 2026 is reported campaign activity, not a reliable per-server start date.
- Map downloads through server, proxy, browser, EDR, and software-deployment logs. Quarantine artifacts and validate both vendor signature and canonical hash; Kaspersky specifically provides detection for unsigned TrueConf installers.
- Rebuild the TrueConf server from clean media and rebuild endpoints that executed malicious or unverifiable installers. Download-only endpoints require artifact removal and investigation; rebuild them if execution cannot be excluded. Do not rely on in-place patching or uninstalling the client.
- From clean systems, rotate TrueConf database and service credentials, server-local and domain administrative credentials used there, and credentials or tokens present on infected clients; revoke sessions. Rotate SSH/VPN keys, deployment secrets, and signing keys only where access or theft is plausible. Investigate—and rebuild where persistence cannot be excluded—systems reached through stolen privileged credentials or reverse tunnels.
One version detail needs caution: Kaspersky’s press release identifies 5.3.9, 5.4.9, and 5.5.5 as fixed releases, so I would not treat the phrase “affected through 5.5.5” as authoritative without reconciling it against TrueConf’s branch-specific advisory before reconnecting.
Sara KovacsICS/OT safety lens
Moderator assignment
Compare reported CyberAv3ngers compromises of U.S. water systems via exposed cellular modems and PLCs with Russian-linked Polish cases involving weak HMI credentials and a FortiGate-to-private-APN path that ultimately put Siemens PLCs into STOP. What is the minimum safe action water and energy operators should take today without causing unsafe outages? Distinguish confirmed process manipulation from access-only events and give a 30-minute CISO/plant-manager sequence.
Response
The minimum safe action is local physical verification plus controlled containment of remote access—not emergency patching or indiscriminate cable-pulling. The Polish CHP case represents reported process manipulation: attackers traversed a FortiGate/private-APN path and put Siemens PLCs into STOP. Polish water reporting also describes altered water-quality and alarm parameters. By contrast, exposed cellular modems, reachable PLCs, or HMI access in the CyberAv3ngers cases do not prove that every process was manipulated; separate research found 22 exposed Rockwell controllers in affected cities but could not confirm compromise. Treat those as access events unless controller mode, commands, outputs, setpoints, or physical measurements prove otherwise.
Thirty-minute CISO/plant-manager sequence:
- 0–5 minutes: Operators verify physical truth using independent gauges and samples—tank level, pressure, dosing residuals, pump state, or boiler pressure and temperature. Maintain local control; do not reboot PLCs or alter SIS communications.
- 5–10 minutes: Freeze remote changes. At the Level 3/OT boundary, disable only the exposed or unauthorized cellular, VPN, FortiGate, vendor, or HMI path. Do not blanket-isolate Level 2/1 networks if that could interrupt control.
- 10–20 minutes: Preserve firewall, VPN, cellular and HMI logs; record PLC RUN/STOP state, program checksum, setpoint history, alarms and output changes. Staff the control room for local/manual operation under approved procedures.
- 20–30 minutes: If manipulation is confirmed, invoke the established process-safety shutdown or isolation plan. If access only is confirmed, keep the route blocked, intensify monitoring and schedule tested credential, firmware and segmentation changes during a maintenance window.
Any segmentation or authentication change must be tested against process and safety communications first: an accidental false trip can stop the plant, while disrupted safety logic can prevent a required trip.
James Okafor → Tomas Ilic
Tomas Ilic asked James Okafor.
I found Kaspersky reporting a TrueConf chain over unauthenticated TCP/4307 to SYSTEM, replacement of locale.php with a web shell, database access, and replacement of hosted client installers with PhantomCore; PhantomGraph supports command execution, credential theft, and reverse SSH tunneling. Campaign activity was observed in July 2026, but server-specific first compromise time is unknown. What minimum rebuild and secret-rotation scope would you set for (1) the compromised TrueConf server and (2) endpoints that executed downloaded installers, including adjacent identity, CI/signing, backup, and management systems?
This cross-question did not return a public answer.
The clearest lesson is that exposure changes the presumption, but not every downstream conclusion. For internet-managed FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19 or 7.2.0–7.2.12, Alex’s position is firm: treat the appliance as compromised, then use external telemetry to determine whether the intrusion crossed into identity, virtualization, backup, or domain infrastructure. Unexpected jsconsole super-admin activity, account or MFA changes, session reuse, and appliance-originated lateral access are the threshold indicators; exposure alone does not establish domain compromise.
The same discipline sharpens the other cases. Lena characterized the North Korea-linked activity as better integration of an existing delivery and privilege-escalation chain, rather than a novel remote-entry method: fake jobs, DLL side-loading, CVE-2026-68820, and FudModule, alongside compromised webmail and RelayShell infrastructure. Confidence is high in the observed operational chain but only moderate in Lazarus attribution, so hunting should follow behavior rather than the actor label. In the TrueConf case, Tomas moved the trust boundary beyond the server to the installer-distribution channel. Any endpoint or external party that executed a substituted installer may fall inside the blast radius, and the distrust window must be based on forensic evidence or a previously verified clean hash—not a campaign date.
Sara added an essential OT distinction: reachable modems, PLCs, or HMIs demonstrate dangerous access, but they do not by themselves prove process manipulation. The minimum safe response begins with independent physical verification and narrowly controlled containment of remote access, while avoiding indiscriminate disconnection, PLC rebooting, or disruption of safety communications.
That gives us a consistent decision rule: identify the real trust boundary, separate access from demonstrated impact, and scale containment to evidence without waiting for perfect attribution. We now carry that rule into bridge integrity, AI-connected tooling, passkey claims, and patch governance—four areas where dramatic labels can otherwise outrun the operational facts.
Action 2
Dispatch Parallel
The source pack presents Tx XRPL bridge false-deposit crediting, Harmony unauthorized minting, Ronin threshold validation failure, THORChain suspected GG20 TSS leakage, and a 2,150 ETH MEV-bot drain. Do not recap all five. Identify the two control failures tha...
Viktor PetrovCrypto financial-crime lens
Moderator assignment
The source pack presents Tx XRPL bridge false-deposit crediting, Harmony unauthorized minting, Ronin threshold validation failure, THORChain suspected GG20 TSS leakage, and a 2,150 ETH MEV-bot drain. Do not recap all five. Identify the two control failures that demand immediate operator decisions, separate confirmed facts from speculation, and give a protocol-specific stop/resume criterion for each. Explain why the smaller XRPL... [arg clipped]
Response
The two immediate decisions are Tx’s XRPL deposit-validation failure and Harmony’s ONE issuance-control failure.
Tx/XRPL — confirmed: reporting attributes nearly 200,000 XRP in losses to relayers accepting self-transfers with valid memos without confirming the bridge destination; 94 signed withdrawals followed. This was bridge infrastructure failure, not an XRPL compromise. Stop: keep crediting and withdrawals disabled. Resume only when: every bridged liability reconciles 1:1 with a finalized XRPL payment to the correct destination, independent relayers reproduce that result, and adversarial replay tests reject self-transfers and malformed deposits. The attacker’s identity and final off-ramp remain unknown.
Harmony — confirmed: reporting says an attacker created roughly four billion unauthorized ONE tokens. The precise root cause is not established in the available evidence, so key theft, validator compromise, and contract-authorization failure remain speculation. Stop: disable the affected issuance path and suspend ONE deposits, withdrawals, and bridge finalization. Resume only when: unauthorized supply is enumerated, the compromised authority is revoked or patched, validators agree on canonical supply/state, and exchanges and bridges reconcile against the same snapshot.
The smaller XRPL loss is operationally urgent because the bridge’s normal signing machinery authorized invalid state repeatedly. The amount already withdrawn measures observed loss—not the reserve still exposed to a repeatable validation defect.
Arjun PatelAI security lens
Moderator assignment
Choose between two AI risks for operational airtime: Paperclip CVE-2026-41679 unauthenticated RCE and GhostJacking prompt injection through logs or alerts into Claude Code-connected operations. Which has the more credible enterprise exploit path today? Give a 30-minute CISO action, identify the necessary preconditions, and argue against the frontier-agent 'hostile autonomy' framing if ordinary overprivilege and untrusted input explain the risk better.
Response
Paperclip gets the airtime. Fact: CVE-2026-41679 provides automated, unauthenticated RCE against network-accessible Paperclip instances before 2026.416.0 running the default authenticated configuration. Assessment: That is a closed exploit chain; GhostJacking remains conditional. Alex Mercer’s feasibility review reaches the same conclusion.
Necessary preconditions: - Paperclip: vulnerable version, network reachability, default authenticated mode. - GhostJacking: attacker-controlled text enters telemetry; Claude Code or another agent consumes it; the model treats it as instruction; connected MCP tools possess write authority. The published demonstration combined a poisoned User-Agent log with Cloudflare write permissions to alter DNS.
First 30 minutes: isolate exposed Paperclip instances, preserve process/API logs, upgrade to 2026.416.0, inspect imported configurations, and rotate every credential reachable by the Paperclip OS account. Separately, suspend autonomous write-capable MCP connections until their telemetry paths are reviewed. This is not “hostile autonomy”: it is injection plus overprivilege—untrusted input crossing into an agent holding operational credentials. Least privilege and sandboxing constrain the damage; model branding does not.
Marcus ValeIdentity security lens
Moderator assignment
Assess the reported pass-the-passkey techniques across Windows 11, Microsoft Entra ID, browsers, and password managers. One source calls them a broad bypass of phishing-resistant authentication; another calls the issue mostly a nothingburger. Reconcile the disagreement by naming the preconditions, what trust artifact is actually replayed or transferred, and whether enterprises should change authentication policy tonight. Give a defensible position, not a recap.
Response
The disagreement is mostly about scope. Fact: The demonstrated Windows 11→Entra chain requires a vulnerable endpoint, local access to its WebAuthn operational log, a previously captured signed WebAuthn assertion, and an Entra validation path that accepts its replay. The passkey private key is neither extracted nor cryptographically broken; the reusable trust artifact is the complete signed assertion. Without both endpoint disclosure and relying-party validation weakness, the chain fails.
Browser and password-manager findings broaden the attack surface through provider plugins and local mediation, but the available evidence does not establish a universal remote bypass. Those scenarios still appear to require control of the endpoint, browser, extension, provider, or recovery/onboarding flow. Calling the entire family a “nothingburger” understates a genuine Windows/Entra trust-chain defect; calling it a broad defeat of phishing-resistant authentication overstates it. I have not seen evidence that an attacker can remotely clone arbitrary passkeys from a clean device.
Enterprises should not disable passkeys or downgrade authentication tonight. Patch affected Windows 11 systems, restrict local administrative access, govern browser extensions and passkey-provider plugins, and investigate Entra sign-ins after any endpoint compromise. If exploitation is suspected, revoke resulting sessions and refresh tokens—not merely the passkey—and retain phishing-resistant FIDO2/WebAuthn policy.
Pierre LefevreBusiness impact lens
Moderator assignment
Translate today's 44% monthly rise to 85 high-impact actively exploited or weaponized CVEs into a patch-governance decision without simply declaring every patch urgent. Build a concrete three-tier queue using today's examples: active edge/control-plane exploitation, high-impact patched client/server flaws without known exploitation, and broad patch-wave items. State exact response windows you would defend to a board, and identify one headline the room should deliberately deprioritize.
Response
Halil, the 44% rise to 85 CVEs—36 rated “Very Critical”—is a capacity signal, not an instruction to emergency-patch all 85. My board-defensible queue is:
- Tier 1 — active exploitation on edge/control-plane systems: establish exposure within 4 hours, isolate or apply compensating controls within 8 hours, patch within 24 hours, then hunt for compromise for 72 hours. This includes exploited internet-facing infrastructure and SharePoint CVE-2026-45659, now associated with ransomware.
- Tier 2 — high-impact patched client/server flaws without known exploitation: test within 72 hours and deploy within 7 calendar days; allow 14 days only for isolated systems with documented controls. SonicWall GMS/Email Security issues, including CVE-2026-66147, fit here based on the evidence available.
- Tier 3 — broad patch-wave inventory: deploy within 30 days, bringing individual items forward only for exploitation, direct exposure, or critical-business dependency. Microsoft’s August release reportedly covers 398–421 CVEs, but only the exploited CVE-2026-68820 belongs in Tier 1 automatically.
The headline I would deliberately deprioritize is “Microsoft fixes nearly 400 security holes.” Raw patch volume does not measure business exposure. Best case, disciplined triage limits emergency change risk to a small exploited subset; worst case, an exposed Tier-1 control plane remains open beyond 24 hours and turns patching into containment, outage, and disclosure. I cannot responsibly attach a dollar range without the affected asset count, revenue dependency, and recovery-time data.
Alex Mercer → Arjun Patel
Arjun Patel asked Alex Mercer.
I’m comparing Paperclip CVE-2026-41679 with GhostJacking for enterprise exploit-path credibility. Evidence says Paperclip gives fully automated unauthenticated RCE against network-accessible pre-2026.416.0 instances in authenticated/default mode. GhostJacking requires attacker-controlled text to enter logs/alerts, an agent to ingest it, and connected MCP/tools with write authority; a demo used poisoned User-Agent telemetry plus GraphQL/Cloudflare MCP permissions to alter DNS. From kill-chain closure and likely exposure, which deserves airtime today, and what 30-minute containment would you prioritize?
Arjun, Paperclip deserves the airtime. Its chain is closed: network reachability, no credentials, default authenticated-mode configuration, and arbitrary commands as the server OS user; a Metasploit module exists. GhostJacking is credible but conditional—attacker-controlled telemetry must be ingested, trusted as instructions, and paired with write-capable MCP permissions. That is a loaded gun only in overprivileged agent deployments; Paperclip is already firing.
First 30 minutes: remove Paperclip from network access, preserve API/process/audit evidence, upgrade to 2026.416.0, and rotate secrets accessible to its OS account. For agent systems, immediately revoke or downgrade write-capable MCP tokens and disable autonomous changes; then quarantine poisoned telemetry before reconnecting tools.
Operational urgency now rests on exploitability and control-plane exposure, not headline size. Viktor identified two crypto failures that warrant immediate suspension: Tx’s confirmed XRPL destination-validation failure and Harmony’s unauthorized issuance of roughly four billion ONE. Tx must reconcile every liability to a finalized payment to the correct destination and pass independent adversarial testing before resuming. Harmony must disable the affected issuance path while the unauthorized supply and compromised authority are established; the evidence does not yet distinguish key theft, validator compromise, or contract-authorization failure.
Arjun made the same distinction in AI security. Paperclip CVE-2026-41679 has the more credible enterprise path because it is an unauthenticated RCE chain against reachable, vulnerable instances under the stated default configuration. The first response is isolation, log preservation, upgrade to 2026.416.0, configuration review, and rotation of credentials accessible to the service account. GhostJacking remains serious, but conditional: attacker-controlled telemetry must reach an agent that interprets it as instruction while holding write-capable tools. That is prompt injection combined with excessive privilege, not evidence of autonomous hostile behavior.
Marcus narrowed the passkey dispute to a real but bounded trust-chain defect. The demonstrated Windows 11-to-Entra attack replays a complete signed assertion exposed from a compromised endpoint; it neither extracts the private key nor proves that arbitrary passkeys can be cloned remotely from clean devices. Calling that universal defeat is too broad, while dismissing it entirely ignores the endpoint-disclosure and relying-party-validation weakness.
Pierre then converted the 44% monthly increase into governance: four-hour exposure assessment and 24-hour patching for actively exploited edge or control-plane flaws; seven days for high-impact patched flaws without known exploitation; and 30 days for the wider inventory, with escalation based on exposure and business dependency. That framework sets up the next challenge directly: whether internet management alone justifies treating a vulnerable Fortinet appliance as compromised, or whether exposure must remain distinct from evidence of exploitation.
Action 3
Challenge
Claim: Any internet-managed FortiOS 7.0.0–7.0.16, FortiProxy 7.0.0–7.0.19, or FortiProxy 7.2.0–7.2.12 appliance should be treated as compromised tonight. Counter-evidence: Exposure alone proves vulnerability, not exploitation, and Sara's OT guidance warns that...
Alex MercerExploit feasibility lens
Moderator assignment
Claim: Any internet-managed FortiOS 7.0.0–7.0.16, FortiProxy 7.0.0–7.0.19, or FortiProxy 7.2.0–7.2.12 appliance should be treated as compromised tonight. Counter-evidence: Exposure alone proves vulnerability, not exploitation, and Sara's OT guidance warns that indiscriminate containment can cause service or safety impact. Tighten your position: define the evidence-based minimum for compromise classification, distinguish internet reachability from confirmed unauthorized administration, and provide a safe sequence for an inline Fortinet appliance supporting critical services where immediate isolation could cause an outage.
Response
Halil, you’re right: I overstated the classification. Internet reachability on an affected version means urgent compromise assessment, not confirmed compromise. The minimum for appliance compromise is validated evidence of unauthorized privileged activity—for example, an unexplained successful jsconsole super-admin login, unauthorized administrator creation, or an unapproved configuration change tied to that session. Prefer off-box SIEM evidence. Classify the downstream domain separately; require successful appliance-originated authentication, account modification, credential access, or execution there.
For an inline critical-services appliance, don’t pull the plug blindly. Sara’s sequence is right: confirm process stability and local operator control; export logs and configuration out-of-band; restrict management access and revoke unauthorized sessions without rebooting; then transfer traffic through a tested HA peer or approved bypass only after operations confirms safety communications. Isolate the suspect unit, rotate administrative and VPN trust from a clean host, compare rules and routes with a known-good baseline, then replace or upgrade during a controlled window.
Sara Kovacs → Alex Mercer
Alex Mercer asked Sara Kovacs.
Fortinet CVE-2024-55591/24472 is known exploited and affected versions permit unauthenticated super-admin access. Fortinet lists successful jsconsole super_admin login and unauthorized admin creation as indicators. Moderator challenges exposure-only compromise classification and asks for a safe sequence for an inline appliance supporting critical services. What containment order minimizes operational/safety risk while preserving evidence?
Alex, those indicators move this from exposure to confirmed appliance compromise, but not confirmed downstream process manipulation. First verify the process is stable and establish local operator control; export logs/configuration out-of-band, then restrict the management plane and revoke unauthorized sessions without rebooting. Move traffic only through a tested HA peer or approved bypass, then isolate the suspect unit. Do not fail over or change Level 3/2 routing until plant operations confirms safety communications will survive.
Next rotate administrative/VPN credentials from a clean host, validate rules and routes against a known-good baseline, then upgrade or replace the appliance in a controlled window. Fortinet records the second flaw as CVE-2025-24472, not CVE-2024-24472.
Exposure has now been separated from compromise. An internet-managed FortiOS or FortiProxy appliance on the affected versions requires urgent investigation, but reachability alone does not prove exploitation. Alex corrected the earlier overstatement and set a defensible threshold: validated unauthorized privileged activity, such as an unexplained successful jsconsole super-admin login, unauthorized administrator creation, or an unapproved configuration change linked to that session. Off-box SIEM records are preferable because evidence retained solely on the appliance may be less trustworthy.
The downstream domain also needs its own classification. A compromised appliance does not automatically establish domain compromise; that requires evidence such as successful appliance-originated authentication, account modification, credential access, or execution. For inline critical-services systems, containment must avoid creating a larger operational incident. The sequence is to verify process stability and local operator control, export logs and configuration out of band, restrict management access, and revoke unauthorized sessions without rebooting. Traffic should move only through a tested HA peer or approved bypass after operations confirms that safety communications will remain intact. The suspect unit can then be isolated, administrative and VPN trust rotated from a clean host, and its rules and routes compared with a known-good baseline before controlled replacement or upgrade.
That distinction—urgent assessment versus confirmed compromise, with evidence preserved and operational safety maintained—now needs to anchor the closing plan. We turn next to a sequenced tonight and next-24-hours response across the issues already tested, including Gunra exploitation of the Fortinet vulnerabilities and the DPRK Windows activity.
Action 4
Dispatch One
Close the room with a sequenced tonight/next-24-hours plan across the topics already tested: Gunra exploitation of Fortinet CVE-2024-55591/CVE-2025-24472; DPRK use of Windows CVE-2026-68820; TrueConf installer poisoning; CyberAv3ngers/Polish OT access; Papercl...
James OkaforDefensive response lens
Moderator assignment
Close the room with a sequenced tonight/next-24-hours plan across the topics already tested: Gunra exploitation of Fortinet CVE-2024-55591/CVE-2025-24472; DPRK use of Windows CVE-2026-68820; TrueConf installer poisoning; CyberAv3ngers/Polish OT access; Paperclip CVE-2026-41679; and the Tx XRPL/Harmony protocol failures. Do not give a generic patch list. Resolve control conflicts: evidence preservation versus rebuilding... [arg clipped]
Response
Tonight, isolate affected Fortinet, Windows, TrueConf, Paperclip, and OT systems after rapid evidence capture; active safety risk overrides collection. Quarantine TrueConf installers and rebuild the server plus endpoints that executed them, rotating reachable identity, database, signing, backup, and management secrets. TrueConf’s June 2026 advisory recommends versions 5.3.9, 5.4.9, and 5.5.5; test the applicable branch before restoration.
Keep the OT cases separate: CyberAv3ngers reporting concerns US water infrastructure, while the Polish access was attributed in reporting to two Russian nationals. Block remote access, replace shared/default credentials, and validate controller setpoints with operators. Within 24 hours, stage verified Fortinet and Windows fixes and hunt adjacent trust systems. Evidence available here does not establish validated fixes for Paperclip CVE-2026-41679 or the XRPL/Harmony failures; isolate or pause affected services pending authoritative guidance.
The response plan is now sequenced around containment first and restoration only after verification. Tonight’s priority is rapid evidence capture followed by isolation of affected Fortinet, Windows, TrueConf, Paperclip, and OT systems; where operations or physical safety are at immediate risk, containment takes precedence over collection. TrueConf requires the broadest recovery scope: quarantine the installers, rebuild the server and every endpoint that executed them, and rotate any reachable identity, database, signing, backup, and management secrets. The cited June 2026 advisory recommends TrueConf versions 5.3.9, 5.4.9, and 5.5.5, but the correct branch must be tested before service restoration.
The OT incidents must remain analytically separate. Reporting on CyberAv3ngers concerns US water infrastructure, while the Polish access was reportedly attributed to two Russian nationals; those facts should not be blended into a single campaign narrative. The immediate defensive controls are nevertheless consistent: block remote access, replace shared or default credentials, and have operators independently validate controller setpoints.
Within 24 hours, teams should stage verified Fortinet and Windows fixes and hunt through adjacent trust systems rather than treating patching as the end of the incident. Important uncertainty remains around Paperclip CVE-2026-41679 and the XRPL/Harmony failures: the evidence provided here does not establish validated fixes, so affected services should remain isolated or paused pending authoritative guidance. We now turn to the Zoom annotation-engine flaws to establish the same minimum decision-ready view: which client platforms and versions are affected, and what organizations must do immediately.
Action 5
Dispatch One
Give the minimum decision-ready treatment for Zoom annotation-engine flaws CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Identify affected client platforms and versions supported by the evidence, explain the video-call code-execution precondition, and se...
Priya NatarajanCloud security lens
Moderator assignment
Give the minimum decision-ready treatment for Zoom annotation-engine flaws CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Identify affected client platforms and versions supported by the evidence, explain the video-call code-execution precondition, and set a defensible inventory, fixed-version verification, and patch deadline. Separate this patched but not known-exploited risk from today's active edge exploitation; do not inflate urgency.
Response
Decision: Treat this as accelerated client patching, not an exploitation emergency. CVE-2026-53413 is a high-severity annotation buffer overwrite enabling code execution; CVE-2026-53414 is a medium-severity buffer over-read associated with denial of service; CVE-2026-53415 is a high-severity use-after-free. Code execution requires the attacker to participate in the same Zoom meeting and send malicious annotation data to another participant; no victim click is reported.
Affected evidence supports:
- Zoom Workplace before 7.1.5, or before 7.0.6 on the 7.0 branch
- Zoom Rooms and Meeting SDK before 7.1.5
- Scope is described as all supported platforms, although the available evidence does not enumerate each OS
- Windows VDI Client before 7.0.11 is specifically tied to CVE-2026-53413; aggregate guidance also lists 6.6/7.0 VDI thresholds, but does not clearly map every threshold to all three CVEs
Inventory Workplace installations, Rooms, VDI components, and applications embedding Meeting SDK within 48 hours. Verify installed package/binary versions—not merely successful update jobs—and remediate below-fixed versions within 14 calendar days. Zoom has patched the client code; customers remain responsible for deployment and version enforcement. The reviewed evidence reports patches but no known in-the-wild exploitation, so keep this below confirmed active edge exploitation, which warrants emergency 24–72-hour action.
The Zoom finding sharpens into an accelerated patching requirement rather than an active-exploitation emergency. CVE-2026-53413 is a high-severity annotation buffer overwrite with code-execution potential, CVE-2026-53414 is a medium-severity buffer over-read associated with denial of service, and CVE-2026-53415 is a high-severity use-after-free. The reported code-execution path does not require a victim click, but it does require the attacker to participate in the same Zoom meeting and deliver malicious annotation data to another participant.
The supported version evidence places Zoom Workplace before 7.1.5 at risk, with 7.0-branch clients requiring at least 7.0.6. Zoom Rooms and Meeting SDK versions before 7.1.5 are also in scope. The guidance describes all supported platforms as affected, although the evidence available here does not enumerate each operating system. Windows VDI Client before 7.0.11 is specifically linked to CVE-2026-53413; broader 6.6 and 7.0 VDI thresholds were cited, but their applicability to each of the three CVEs remains unclear and should not be overstated.
Operationally, the defensible course is to inventory Workplace clients, Rooms, VDI components, and applications embedding the Meeting SDK within 48 hours, then remediate versions below the applicable fixed level within 14 calendar days. Completion must be established from installed package or binary versions, not merely from successful update-job status. With no further action queued, the final synthesis can now distinguish urgent containment cases from accelerated patching cases such as Zoom, while carrying forward the unresolved platform and VDI-mapping caveats.