EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 16, 20263 min read

Security Briefing | June 16, 2026 - Fortinet FortiSandbox Exploited, China Expands SprySOCKS to Windows, CISA Flags LiteSpeed Flaw

Threat actors are actively exploiting three Fortinet FortiSandbox vulnerabilities including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1). China-linked espionage groups have expanded the SprySOCKS backdoor to Windows, targeting government organizations in at least four countries. CISA has added a LiteSpeed cPanel privilege escalation flaw to its KEV catalog with a patching deadline of June 18, 2026.

By EACA Summit Content Team

Security Briefing | June 16, 2026 - Fortinet FortiSandbox Exploited, China Expands SprySOCKS to Windows, CISA Flags LiteSpeed Flaw

1. Fortinet FortiSandbox Flaws Exploited in Attacks

Threat actors are actively exploiting three vulnerabilities in Fortinet FortiSandbox, including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1). The exploitation was observed by Defused Cyber and reported by multiple sources. Patches are available for some of the flaws.

Verified Facts

  • CVE-2026-39813 is a path traversal vulnerability in FortiSandbox JRPC API with CVSS 9.1
  • CVE-2026-39808 and CVE-2026-25089 are also being exploited
  • Exploitation observed by Defused Cyber within the past 24 hours

Evidence

  • CVE-2026-39813
  • CVE-2026-39808
  • CVE-2026-25089

Impact

Organizations using FortiSandbox should immediately apply available patches and monitor for signs of compromise. These flaws could allow remote code execution or unauthorized access.

Confidence Level: High

The Hacker News | BleepingComputer

2. China-Linked SprySOCKS Backdoor Expands to Windows

Two hooded figures operating a computer displaying a global targeting map and exploitation tools representing a China-linked state-sponsored cyber espionage campaign.

ESET has discovered two Windows variants of the previously Linux-only SprySOCKS backdoor, used in attacks against government organizations in at least four countries. The variants, WIN_DRV and WIN_PLUS, include driver-based stealth capabilities and hard-coded C2 configurations.

Verified Facts

  • Two Windows variants of SprySOCKS discovered: WIN_DRV and WIN_PLUS
  • Used in attacks targeting government organizations in at least four countries
  • Variants support TCP, UDP, and include driver-based stealth

Evidence

  • ESET report shared with The Hacker News
  • BleepingComputer reporting

Impact

Defenders should monitor for SprySOCKS indicators on Windows systems, particularly in government and research networks. The driver-based stealth makes detection more challenging.

Confidence Level: High

The Hacker News | BleepingComputer

3. CISA Flags LiteSpeed cPanel Plugin Flaw Exploited in Attacks

CISA has added CVE-2026-54420, a privilege escalation vulnerability in the LiteSpeed cPanel plugin, to its Known Exploited Vulnerabilities catalog. Federal agencies are required to patch by June 18, 2026. The flaw allows root privilege escalation.

Verified Facts

  • CVE-2026-54420 is a privilege escalation vulnerability in LiteSpeed cPanel plugin with CVSS 8.5
  • Added to CISA KEV catalog on June 16, 2026
  • FCEB agencies must patch by June 18, 2026

Evidence

  • CVE-2026-54420
  • CISA KEV catalog entry

Impact

Organizations using LiteSpeed cPanel plugin should prioritize patching. This vulnerability is actively exploited and could lead to full server compromise.

Confidence Level: High

The Hacker News | BleepingComputer

Also Noted

China-linked espionage groups have also been observed abusing Google Workspace rules for data exfiltration. Organizations using Google Workspace should review mail filter rules and forwarding configurations for unauthorized changes.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings