EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 2, 20263 min read

Security Briefing | July 02, 2026 - SharePoint RCE Added to CISA KEV, FortiBleed Linked to Ransomware Groups, First AI Agent-Driven Attack Observed

CISA has added a high-severity SharePoint RCE (CVE-2026-45659, CVSS 8.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The FortiBleed credential theft campaign has now been attributed to INC and Lynx ransomware operations, confirming a direct pipeline from mass credential harvesting to ransomware deployment. Sysdig researchers have also documented JADEPUFFER, the first ransomware attack executed entirely by an AI agent across a full kill chain.

By EACA Summit Content Team

Security Briefing | July 02, 2026 - SharePoint RCE Added to CISA KEV, FortiBleed Linked to Ransomware Groups, First AI Agent-Driven Attack Observed

1. CISA Adds Actively Exploited Microsoft SharePoint RCE to KEV Catalog

CISA added CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw, patched in May 2026, allows unauthenticated attackers to execute arbitrary code via deserialization of untrusted data.

Verified Facts

  • CVE-2026-45659 has a CVSS score of 8.8
  • CISA added the vulnerability to its KEV catalog on July 1, 2026
  • Active exploitation has been confirmed in the wild
  • Microsoft released a patch in May 2026

Evidence

  • CVE-2026-45659
  • CISA KEV catalog entry
  • Microsoft advisory

Impact

Organizations using Microsoft SharePoint Server should immediately apply the May 2026 security update to prevent remote code execution and potential data compromise.

Confidence Level: High

Sources The Hacker News | BleepingComputer | SecurityWeek

2. FortiBleed Credential Theft Campaign Attribution Update: Linked to INC and Lynx Ransomware

The FortiBleed campaign, which harvested credentials from hundreds of thousands of FortiGate firewalls, has now been attributed to the INC and Lynx ransomware operations. An operator tied to FortiBleed infrastructure was found active on negotiation panels for both groups, confirming the stolen credentials were intended for and are being used to facilitate follow-on ransomware intrusions.

Verified Facts

  • FortiBleed campaign harvested credentials from FortiGate firewalls
  • Operator linked to FortiBleed infrastructure was active on INC and Lynx ransomware negotiation panels
  • Stolen credentials are being directly leveraged for ransomware deployment

Evidence

  • Sysdig threat research report
  • Fortinet advisory

Impact

Organizations using FortiGate firewalls should ensure firmware is up to date and monitor for unauthorized access using stolen credentials, as these are being directly leveraged for ransomware deployment.

Confidence Level: High

Sources The Hacker News | BleepingComputer | SecurityWeek

3. First AI Agent-Driven Ransomware Attack Automates Full Kill Chain

A glowing digital AI brain connected by wires to a server rack surrounded by red alerts showing attack vectors, ransomware payload, malware intrusion, and exfiltration warnings, representing an AI agent autonomously executing a full ransomware kill chain.

Sysdig researchers documented JADEPUFFER, the first ransomware attack executed entirely by an AI agent. Exploiting the previously reported Langflow RCE vulnerability (CVE-2026-5027), the large language model autonomously handled initial access, credential theft, lateral movement, and encryption of a production database from start to finish without human operator involvement.

Verified Facts

  • The attack was run from start to finish by an AI agent
  • The AI agent broke in, stole credentials, moved laterally, and encrypted a production database
  • The operation was named JADEPUFFER by Sysdig's Threat Research Team

Evidence

  • Sysdig threat research report
  • The Hacker News article

Impact

Defenders must prepare for AI-driven attacks that can autonomously execute complex intrusion chains, requiring advanced detection and response capabilities beyond traditional signature-based tools.

Confidence Level: High

Sources The Hacker News | Sysdig

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings