Threat Brief — 2026-07-03 — Exploitation Escalation Across SharePoint, Fortinet, and Citrix
Executive Summary
The most urgent development is active exploitation of a Microsoft SharePoint RCE (CVE-2026-45659KEV), now in CISA's KEV catalog. Cisco has also confirmed in-the-wild exploitation of a patched Unified Communications Manager flaw. Ransomware operators are rotating quickly between perimeter appliance vulnerabilities — FortiBleed credentials are now directly feeding INC and Lynx ransomware, while Anubis affiliates are leveraging Citrix Bleed 2 (CVE-2025-5777KEV·R). Separately, a new attack pattern has emerged where AI agents are being used to autonomously execute ransomware end-to-end via Langflow RCE, marking a notable escalation in adversary automation.
Top items
- SharePoint RCE (CVE-2026-45659KEV) — actively exploited. High-severity remote code execution in Microsoft SharePoint Server, patched in May and added to CISA KEV this week after confirmed active exploitation. Prioritise patching and exposure checks immediately. Source
- Cisco Unified CM flaw — confirmed exploitation. Cisco acknowledged attackers are now exploiting a Unified Communications Manager vulnerability that was patched in early June. Organisations running Unified CM should verify patch status and check for indicators of compromise. Source
- FortiBleed linked to INC and Lynx ransomware. Stolen Fortinet firewall credentials from the FortiBleed campaign are being monetised by INC and Lynx ransomware affiliates for follow-on intrusions. Attackers are also leveraging a Nextcloud zero-day. Any unpatched Fortinet perimeter devices should be treated as potentially compromised. Source
- Anubis ransomware exploiting Citrix Bleed 2. Threat actors associated with the Anubis ransomware operation are using CVE-2025-5777KEV·R (Citrix Bleed 2) for initial access, combined with BYOVD techniques and supply-chain credentials. Source
- ChocoPoC RAT targeting vulnerability researchers. A new data-stealing trojan dubbed ChocoPoC is being distributed through fake Python proof-of-concept exploit repositories on GitHub, aimed specifically at vulnerability researchers. Security and research teams should validate the provenance of any PoC code before execution. Source
- AI agent executes autonomous ransomware via Langflow RCE. Sysdig reports the first observed end-to-end ransomware attack orchestrated by an AI agent (tracked as JADEPUFFER), exploiting a Langflow RCE to automate the full attack chain including database encryption. This signals a shift toward LLM-driven attack automation. Source
- ConsentFix / ClickFix attacks hijack M365 tokens in seconds. Fake OAuth consent prompts and ClickFix-style social engineering are being used to steal Microsoft 365 access tokens, bypassing MFA. Users should be trained on OAuth consent phishing and conditional access policies reviewed. Source
- ToddyCat-linked Umbrij malware abuses OAuth for Gmail access. The ToddyCat threat actor is deploying a new malware called Umbrij that uses the Google API and OAuth abuse to silently access victim email, enabling persistent espionage without traditional credential theft. Source
- Microsoft July CVE batch — five elevation-of-privilege flaws. New CVEs across Exchange Online (CVE-2026-54998), M365 Copilot (CVE-2026-41106, open redirect), Azure Synapse (CVE-2026-26145), Azure OpenAI (CVE-2026-45499, SSRF), and Entra Provisioning Service (CVE-2026-57100, SSRF). All enable network-based privilege escalation by authorised or unauthorised attackers. MSRC
- Microsoft Edge RCE (CVE-2026-50521). A remote code execution vulnerability in Chromium-based Edge; supported versions should be updated promptly. Source
- NetNut residential proxy network disrupted. The FBI and Google's Threat Intelligence Group have seized NetNut infrastructure, degrading a residential proxy service spanning ~2 million home devices. This reduces adversary ability to rotate residential IPs for credential stuffing, scraping, and evasion. Source
Themes
Microsoft cloud and identity attack surface — a broad target. Five new Microsoft elevation-of-privilege CVEs land alongside active exploitation of SharePoint RCE, a Copilot Outlook bug, and ConsentFix/ClickFix M365 token-theft campaigns. The concentration suggests adversaries are intensively targeting Microsoft identity, email, and collaboration infrastructure. Prioritise Microsoft patching, review OAuth consent grants, and audit Exchange/SharePoint exposure.
Ransomware diversifying initial-access vectors. INC, Lynx, and Anubis ransomware affiliates are simultaneously exploiting FortiBleed, Citrix Bleed 2, and supply-chain credentials. The pattern emphasises that perimeter appliance hygiene — especially Fortinet and Citrix — remains the critical first gate for ransomware prevention.
Adversarial AI moves from concept to observed use. The JADEPUFFER autonomous ransomware agent and the targeting of AI infrastructure (Langflow RCE, Azure OpenAI SSRF) indicate threat actors are operationalising AI agents for full attack-chain automation. Security teams should inventory exposed AI/ML services and treat them as internet-facing attack surface.
