FortiSandbox, Arch Linux, and Teams: A Week of Diverse Security Threats
A roundup of recent security incidents: FortiSandbox vulnerabilities under active exploit, a massive Arch Linux AUR supply chain attack, and a novel malware campaign using Microsoft Teams for command-and-control.
Security teams faced a barrage of threats this week as attackers exploited vulnerabilities in Fortinet's FortiSandbox, hijacked over 1,500 packages in the Arch User Repository, and deployed malware that hides command-and-control traffic inside Microsoft Teams. The incidents highlight the expanding attack surface across enterprise and open-source ecosystems.
On Monday, threat intelligence firm Defused warned that attackers are actively exploiting three vulnerabilities in FortiSandbox: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. FortiSandbox is a critical platform that other Fortinet security products rely on for threat verdicts, making it a high-value target. Defused noted that the exploit for one of the flaws appears to be "vibecoded" and likely faulty, suggesting AI-assisted development may be lowering the barrier for attackers.
Arch Linux AUR Supply Chain Attack
In a separate incident, the Arch User Repository (AUR) spent a weekend cleaning up after attackers seized control of more than 1,500 packages. The campaign did not require breaking into any systems; instead, attackers used compromised maintainer accounts to push malicious updates designed to steal developer credentials and secrets. The scale of the attack makes it one of the largest supply chain compromises targeting a Linux distribution.
- Over 1,500 AUR packages were hijacked in the campaign.
- Attackers targeted developer secrets, including SSH keys and API tokens.
- No infrastructure breach was needed; the attack relied on compromised maintainer accounts.
- Arch Linux maintainers have since revoked access and are auditing affected packages.
Microsoft Teams as a C2 Channel
Researchers also uncovered a novel malware campaign that uses Microsoft Teams to hide command-and-control (C2) traffic. Custom malware routes communications through legitimate Microsoft services, making malicious activity appear as routine corporate collaboration. The technique allows attackers to bypass network security controls that trust Microsoft's domains. The campaign may be linked to the ransomware and data extortion group Vice Society, according to Dark Reading.
Meanwhile, digital health company iRhythm confirmed on June 8 that attackers stole data in a breach and demanded a ransom. The company did not disclose the number of affected patients but said it is working with law enforcement.
These incidents underscore a broader trend: attackers are increasingly targeting trusted platforms and supply chains. The FortiSandbox exploits, the AUR hijack, and the Teams C2 technique all rely on abusing legitimate systems rather than breaking into them directly. As AI tools accelerate exploit development, defenders must expect more such attacks. Organizations should prioritize patching FortiSandbox, audit their use of community package repositories, and monitor for anomalous traffic to trusted cloud services.
Fact check
-
Attackers are actively exploiting three vulnerabilities in FortiSandbox: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089.
reported · source
-
Attackers hijacked over 1,500 packages in the Arch User Repository.
reported · source
-
Custom malware routes C2 communications through Microsoft Teams, making traffic appear as routine collaboration.
reported · source
-
The Teams C2 campaign may be linked to Vice Society.
reported · source
-
iRhythm confirmed a data breach on June 8 and received a ransom demand.
reported · source
Source reporting (11)
- Help Net Security · Attackers are exploiting FortiSandbox vulnerabilities
- The Next Web · Attackers hijacked over 1,500 Arch Linux packages to steal developers’ secrets, no hacking required
- Dark Reading · 'Lorem Ipsum' Malware Pivots to ClickFix Delivery
- SecurityWeek · iRhythm Confirms Data Stolen in Hack
- The Register · Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
- Help Net Security · Cybercriminals mask malicious communications through Microsoft Teams relays
- BleepingComputer · GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
- Help Net Security · TekStream launches Proactive Cyber Defense to counter AI-driven threats
- TechCrunch · SpaceX passes Amazon as valuation balloons to $2.7T
- SecurityWeek · Magnitude Emerges From Stealth Mode With $10 Million in Funding
- Help Net Security · SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)
Join the conversation
You need to be registered and logged in to comment on blog articles.
0 Comments
No comments yet
Be the first to share your thoughts on this article.