EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 18, 20263 min read

Security Briefing | June 18, 2026 - Microsoft Defender Zero-Day, FortiBleed Leaks 73K VPN Credentials, ShapedPlugin WordPress Supply Chain Attack

Microsoft confirms an actively exploited privilege escalation zero-day in Microsoft Defender (CVE-2026-50656, CVSS 7.8) with no patch yet available. The FortiBleed leak exposes VPN credentials for over 73,000 Fortinet firewall devices worldwide. A supply chain attack against ShapedPlugin distributes malicious WordPress plugin updates through official channels to paying customers.

By EACA Summit Content Team

Security Briefing | June 18, 2026 - Microsoft Defender Zero-Day, FortiBleed Leaks 73K VPN Credentials, ShapedPlugin WordPress Supply Chain Attack

1. Microsoft Confirms RoguePlanet Defender Zero-Day (CVE-2026-50656)

Microsoft formally disclosed a privilege escalation zero-day vulnerability in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656 (CVSS 7.8). The flaw, codenamed RoguePlanet, affects Microsoft Defender and is being actively exploited. A patch is under development.

Verified Facts

  • CVE-2026-50656 is an elevation of privilege vulnerability in the Microsoft Malware Protection Engine
  • Microsoft confirmed the vulnerability and stated a patch is in development
  • The flaw has a CVSS score of 7.8

Evidence

  • CVE-2026-50656
  • Microsoft Security Response Center advisory

Impact

Defenders should monitor for exploitation attempts and apply the patch as soon as it is released. Until then, restrict access to Defender components and monitor for unusual privilege escalations.

Confidence Level: High

The Hacker News | BleepingComputer

2. FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

Hacker accessing stolen VPN credentials on a laptop with glowing red username and password login fields overlaid on screen

A data leak dubbed 'FortiBleed' exposed a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs worldwide. The leak poses a significant risk of unauthorized network access and lateral movement.

Verified Facts

  • FortiBleed leak exposed credentials for 73,932 Fortinet VPN devices
  • The leak includes firewall URLs and associated credentials
  • Organizations worldwide are affected

Evidence

  • FortiBleed leak report
  • BleepingComputer article

Impact

Organizations using Fortinet VPNs should immediately rotate credentials, enforce multi-factor authentication, and audit for unauthorized access. This leak enables direct network compromise.

Confidence Level: High

BleepingComputer | SecurityWeek

3. ShapedPlugin Supply Chain Attack Distributes Malicious WordPress Plugin Updates

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack. Malicious releases were distributed to paying customers via the vendor's official update system, potentially allowing full site compromise.

Verified Facts

  • ShapedPlugin's update flow was hacked to distribute infected plugin releases
  • The attack targeted paying customers via official update channels
  • Multiple plugins were affected

Evidence

  • BleepingComputer report
  • ShapedPlugin advisory (claimed but not confirmed)

Impact

WordPress site administrators using ShapedPlugin plugins should immediately check for unauthorized updates, verify plugin integrity, and rotate any credentials stored on affected sites.

Confidence Level: High

BleepingComputer | The Hacker News

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings