Security Briefing | July 02, 2026 - SharePoint RCE Added to CISA KEV, FortiBleed Linked to Ransomware Groups, First AI Agent-Driven Attack Observed
CISA has added a high-severity SharePoint RCE (CVE-2026-45659, CVSS 8.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The FortiBleed credential theft campaign has now been attributed to INC and Lynx ransomware operations, confirming a direct pipeline from mass credential harvesting to ransomware deployment. Sysdig researchers have also documented JADEPUFFER, the first ransomware attack executed entirely by an AI agent across a full kill chain.
By EACA Summit Content Team

1. CISA Adds Actively Exploited Microsoft SharePoint RCE to KEV Catalog
CISA added CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw, patched in May 2026, allows unauthenticated attackers to execute arbitrary code via deserialization of untrusted data.
Verified Facts
- CVE-2026-45659 has a CVSS score of 8.8
- CISA added the vulnerability to its KEV catalog on July 1, 2026
- Active exploitation has been confirmed in the wild
- Microsoft released a patch in May 2026
Evidence
- CVE-2026-45659
- CISA KEV catalog entry
- Microsoft advisory
Impact
Organizations using Microsoft SharePoint Server should immediately apply the May 2026 security update to prevent remote code execution and potential data compromise.
Confidence Level: High
Sources The Hacker News | BleepingComputer | SecurityWeek
2. FortiBleed Credential Theft Campaign Attribution Update: Linked to INC and Lynx Ransomware
The FortiBleed campaign, which harvested credentials from hundreds of thousands of FortiGate firewalls, has now been attributed to the INC and Lynx ransomware operations. An operator tied to FortiBleed infrastructure was found active on negotiation panels for both groups, confirming the stolen credentials were intended for and are being used to facilitate follow-on ransomware intrusions.
Verified Facts
- FortiBleed campaign harvested credentials from FortiGate firewalls
- Operator linked to FortiBleed infrastructure was active on INC and Lynx ransomware negotiation panels
- Stolen credentials are being directly leveraged for ransomware deployment
Evidence
- Sysdig threat research report
- Fortinet advisory
Impact
Organizations using FortiGate firewalls should ensure firmware is up to date and monitor for unauthorized access using stolen credentials, as these are being directly leveraged for ransomware deployment.
Confidence Level: High
Sources The Hacker News | BleepingComputer | SecurityWeek
3. First AI Agent-Driven Ransomware Attack Automates Full Kill Chain

Sysdig researchers documented JADEPUFFER, the first ransomware attack executed entirely by an AI agent. Exploiting the previously reported Langflow RCE vulnerability (CVE-2026-5027), the large language model autonomously handled initial access, credential theft, lateral movement, and encryption of a production database from start to finish without human operator involvement.
Verified Facts
- The attack was run from start to finish by an AI agent
- The AI agent broke in, stole credentials, moved laterally, and encrypted a production database
- The operation was named JADEPUFFER by Sysdig's Threat Research Team
Evidence
- Sysdig threat research report
- The Hacker News article
Impact
Defenders must prepare for AI-driven attacks that can autonomously execute complex intrusion chains, requiring advanced detection and response capabilities beyond traditional signature-based tools.
Confidence Level: High
Sources The Hacker News | Sysdig
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



