EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 14, 20263 min read

Security Briefing | July 14, 2026 - US and Allies Warn of Russian Router Attacks on Critical Infrastructure, Forg365 PhaaS Targets Microsoft 365, Jscrambler Supply Chain Attack Scope Expands

US and allied cybersecurity agencies issued a joint advisory warning of Russian APT groups actively compromising poorly secured routers in critical infrastructure networks. A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 using device code phishing and adversary-in-the-middle techniques, sold on Telegram for $400 per month. Additional versions of Jscrambler npm packages have been confirmed compromised in the supply chain attack first reported July 12.

By EACA Summit Content Team

Security Briefing | July 14, 2026 - US and Allies Warn of Russian Router Attacks on Critical Infrastructure, Forg365 PhaaS Targets Microsoft 365, Jscrambler Supply Chain Attack Scope Expands

1. US and Allies Warn of Russian State-Sponsored Attacks on Critical Infrastructure Routers

Multiple Russian state-sponsored advanced persistent threat groups are actively compromising poorly secured routers in critical infrastructure networks, according to a joint advisory from US and allied cybersecurity agencies. The campaign targets devices with weak credentials and unpatched vulnerabilities to establish persistent access.

Verified Facts

  • US and allied agencies issued a joint advisory on Russian APT attacks targeting critical infrastructure routers
  • The attacks exploit poorly secured devices with weak passwords and unpatched vulnerabilities
  • Multiple APT groups are involved in the campaign

Evidence

  • SecurityWeek article: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

Impact

Critical infrastructure operators must immediately audit router configurations, enforce strong authentication, and apply patches to prevent initial access by state-sponsored threat actors.

Confidence Level: High

Sources SecurityWeek

Diagram illustrating an adversary-in-the-middle phishing attack intercepting Microsoft 365 authentication traffic to capture user credentials and authenticated session cookies.

2. Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service platform called Forg365 is being sold on Telegram for $400 per month or $3,800 per year, using device code phishing and adversary-in-the-middle techniques to steal Microsoft 365 sessions. The service includes AI-assisted lure creation and post-compromise mailbox operations.

Verified Facts

  • Forg365 is a PhaaS platform targeting Microsoft 365 accounts
  • It uses device code phishing and adversary-in-the-middle (AitM) techniques
  • The service costs $400 per month or $3,800 per year and is distributed via Telegram
  • It includes AI-assisted lure creation and post-compromise mailbox operations

Evidence

  • The Hacker News article: Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Impact

Organizations using Microsoft 365 should enforce conditional access policies, block device code authentication where possible, and educate users about phishing risks to defend against this emerging threat.

Confidence Level: High

Sources The Hacker News

3. Jscrambler Supply Chain Attack Update: Multiple Package Versions Confirmed Compromised

Additional reporting confirms that multiple versions of Jscrambler npm packages beyond the 8.14.0 release first reported July 12 were compromised in the supply chain attack, dropping a cross-platform credential stealer. Organizations using any recent Jscrambler packages should review their dependencies and rotate exposed credentials.

Verified Facts

  • Multiple Jscrambler npm package versions were compromised in a supply chain attack
  • The attack dropped a cross-platform credential stealer
  • The expanded scope was reported by SecurityWeek

Evidence

  • SecurityWeek article: Multiple Jscrambler Packages Impacted by Supply Chain Attack

Impact

Organizations using Jscrambler packages should immediately review their dependencies, rotate any credentials that may have been exposed, and monitor for signs of compromise.

Confidence Level: High

Sources SecurityWeek

Also Noted

CISA released a postmortem on a GitHub credential leak. The US sanctioned a VPN service for enabling ransomware operations.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings