Clone Systems
We’re here to make security and compliance simple for your team.
CVE Alert: Critical NGINX Open Source Flaws
F5 has released security updates for two critical NGINX Open Source vulnerabilities that could allow remote code ex*****on on affected systems.
• CVE-2026-42530 | CVSS 9.2
• CVE-2026-42055 | CVSS 9.2
The flaws impact certain NGINX configurations involving HTTP/3 QUIC, HTTP/2 proxying, and gRPC traffic.
Affected organizations should update to the latest fixed versions immediately. F5 also recommends disabling HTTP/3 for CVE-2026-42530 and adjusting affected header configuration settings for CVE-2026-42055 where patching cannot be completed right away.
Although active exploitation has not been reported, critical NGINX vulnerabilities can move quickly from disclosure to attack activity.
Patch now. Validate configurations. Monitor exposed systems.
Threat Alert: DragonForce Abuses Microsoft Teams Relay Infrastructure
Threat actors linked to DragonForce ransomware have been observed using a custom Go-based RAT known as Backdoor.Turn to hide command-and-control traffic through Microsoft Teams relay infrastructure.
According to Symantec and Carbon Black, the malware used legitimate Microsoft TURN relay services so defenders would only see outbound traffic to Microsoft Teams servers.
Key details:
• Custom RAT: Backdoor.Turn
• Linked to DragonForce ransomware activity
• C2 traffic hidden through Microsoft Teams relay infrastructure
• Attackers reportedly remained in the environment for 1–2 months
• Capabilities include command ex*****on, network scanning, AD/LDAP search, lateral movement, and credential theft
• Activity also involved DLL side-loading and BYOVD techniques to evade security tools
This highlights a growing challenge for defenders: attackers are increasingly abusing trusted services to blend malicious traffic into normal business activity.
Organizations should review outbound traffic patterns, monitor for unusual Teams-related connections, investigate suspicious PowerShell activity, and validate endpoint controls against DLL side-loading and vulnerable driver abuse.
Trusted infrastructure does not always mean trusted activity.
06/17/2026
How often should your business run vulnerability scans?
Quarterly scanning is a good baseline, but it should not be treated as enough for every environment.
Public-facing systems, ecommerce websites, internal networks, and systems that change often may need monthly, after-change, or continuous scanning to stay ahead of risk.
A strong scanning schedule should include:
• Quarterly scans for baseline security and compliance
• Monthly scans for active public-facing environments
• Internal scans to identify risk inside the network
• Website scans after major updates
• Rescans after remediation to confirm fixes worked
Vulnerability scanning is not just about finding issues. It is about creating visibility, prioritizing risk, and fixing weaknesses before attackers can exploit them.
Read the full blog: https://www.clone-systems.com/how-often-should-you-run-vulnerability-scans/
CVE Alert: Fortinet FortiSandbox
Attackers are reportedly exploiting three Fortinet FortiSandbox vulnerabilities:
• CVE-2026-39813 | CVSS 9.1
• CVE-2026-39808 | CVSS 9.1
• CVE-2026-25089 | CVSS 9.1
The flaws include path traversal and OS command injection issues that could allow unauthenticated attackers to bypass authentication or execute unauthorized commands through crafted HTTP requests.
Two of the vulnerabilities were patched in April 2026, while CVE-2026-25089 was patched last week.
Organizations using FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS should apply the latest Fortinet updates immediately, review exposure, and monitor for suspicious activity.
Critical appliance vulnerabilities continue to be heavily targeted. Patch quickly and validate remediation.
Click here to claim your Sponsored Listing.