EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 15, 20263 min read

Security Briefing | June 15, 2026 - PAN-OS VPN Exploited, FBI Dismantles $1.9B Phishing Ring, WordPress Supply-Chain Attack

Active exploitation of a PAN-OS GlobalProtect VPN authentication bypass flaw puts organizations at immediate risk. The FBI, Google, and Black Lotus Labs dismantled a Chinese AI-powered phishing-as-a-service platform responsible for $1.9 billion in losses. Meanwhile, WordPress plugins PushEngage, OptinMonster, and TrustPulse were backdoored via tampered JavaScript files.

By EACA Summit Content Team

Security Briefing | June 15, 2026 - PAN-OS VPN Exploited, FBI Dismantles $1.9B Phishing Ring, WordPress Supply-Chain Attack

1. Palo Alto Networks Confirms Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks reported active exploitation of CVE-2026-0257, an authentication bypass vulnerability affecting PAN-OS GlobalProtect portals and gateways. The flaw, with a CVSS score of 7.8, allows unauthorized access. The vendor has observed exploitation by an unknown threat actor and urges immediate patching.

Verified Facts

  • CVE-2026-0257 is an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway components
  • Palo Alto Networks confirmed active exploitation by an unknown threat actor
  • The vulnerability has a CVSS score of 7.8

Evidence

  • CVE-2026-0257
  • Palo Alto Networks advisory

Impact

Organizations using PAN-OS GlobalProtect VPNs are at immediate risk of unauthorized access. Defenders should prioritize patching and monitor for signs of compromise.

Confidence Level: High

The Hacker News | BleepingComputer

2. FBI, Google, and Black Lotus Labs Dismantle Chinese Phishing-as-a-Service 'Outsider Enterprise'

A fishing hook piercing a red email symbol over a dark digital circuit background representing an AI-powered phishing-as-a-service operation.

A coordinated operation by the FBI, Google, and Black Lotus Labs disrupted a massive Chinese phishing-as-a-service operation called 'Outsider Enterprise', which operated over 9,000 phishing sites, stole nearly 4 million credit cards, and caused approximately $1.9 billion in losses. The service used AI to generate phishing URLs at scale.

Verified Facts

  • The platform used over 9,000 phishing sites and stole nearly 4 million credit cards
  • Estimated losses are approximately $1.9 billion
  • The takedown involved the FBI, Google, and Black Lotus Labs
  • The service used AI to generate phishing URLs at scale

Evidence

  • FBI press release
  • Google Threat Analysis Group report

Impact

This takedown significantly disrupts a major credential theft operation. Defenders should remain vigilant against AI-generated phishing campaigns and review indicators of compromise shared by law enforcement.

Confidence Level: High

BleepingComputer | SecurityWeek

3. WordPress Plugins PushEngage, OptinMonster, and TrustPulse Backdoored via Tampered Scripts

Attackers tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, creating hidden admin accounts and installing backdoor plugins when site administrators were logged in. The attack did not affect ordinary visitors, making it particularly stealthy. The scope of compromise is under investigation.

Verified Facts

  • JavaScript files for PushEngage, OptinMonster, and TrustPulse were tampered with
  • The attack created hidden admin accounts and installed backdoor plugins when admins were logged in
  • Ordinary visitors were not affected
  • The scope of compromise is under investigation

Evidence

  • The Hacker News report
  • Plugin vendor advisories (pending)

Impact

WordPress site administrators using these plugins should immediately audit user accounts, check for unauthorized admin accounts, and review plugin integrity. This supply-chain attack highlights the risk of third-party scripts.

Confidence Level: Medium

The Hacker News | BleepingComputer

Also Noted

  • ShinyHunters claimed breaches of Infinite Campus and the Council of Europe. Verification of the scope and authenticity of the claims is ongoing.
  • A Ukrainian national pleaded guilty to charges related to the Conti ransomware operation.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings