Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


What happened
FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.
The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.
What to do
What happened
Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.
The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.
What to do
What happened
CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.
What to do
Stay safe and share this with your team.
Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.
We protect your on-premise/cloud/OT environments - 24x7x365