What Business Owners Need to Know This Week

Week 26 (14–21 June 2026) was quiet on fresh SA ransomware claims but operationally heavy on global exposure events that hit South African infrastructure directly. FortiBleed: roughly 74,000 internet-facing Fortinet FortiGate firewalls — about 50% of all internet-exposed FortiGates globally, spanning 194 countries — have valid usernames and plaintext passwords circulating on an attacker-controlled server; CISA issued an emergency alert on 18 June, and SA exposure is significant across government, banking, retail, and ISPs. Splunk Enterprise CVE-2026-20253 (CVSS 9.8), a pre-authentication RCE via an unauthenticated PostgreSQL sidecar endpoint, is confirmed exploited in the wild with a KEV deadline of 21 June — Splunk is the SIEM of record across SA banks and telcos, and a compromised Splunk blinds the SOC. And in a striking attribution, Google and Palo Alto Networks tied the year’s most damaging open-source supply-chain campaign (~3,800 internal GitHub repos stolen in 11 minutes) to a single operator based in South Africa (TeamPCP / ResoluteXBF).

The Bottom Line: The ransomware count was corrected to 109 and is FLAT for a sixth week — the longest plateau of 2026 — but three structural exposures dominate: FortiBleed credential exposure at national scale, an actively-exploited RCE in the SIEM layer itself, and a globally significant supply-chain actor operating from SA soil. If you run FortiGate or Splunk, this was not a quiet week. Check your domain at hudsonrock.com/fortinet and rotate every FortiGate credential now.

The Week in Numbers

  • 109 cumulative SA ransomware victims — count corrected against a live 21 June screenshot; FLAT for the sixth consecutive week.
  • ~74,000 FortiGate firewalls — with valid plaintext credentials on an attacker-controlled server; ~50% of all internet-exposed FortiGates, across 21,632 domains in 194 countries.
  • CVSS 9.8 — Splunk Enterprise CVE-2026-20253 pre-auth RCE; in-the-wild exploitation confirmed 18 June, KEV deadline 21 June.
  • ~3,800 GitHub repositories stolen in 11 minutes — the 2026 npm/GitHub supply-chain campaign now attributed to SA-based operator TeamPCP/ResoluteXBF.
  • 5 new CISA KEV entries — Joomla JCE (10.0), Splunk (9.8), LiteSpeed cPanel (8.5), SolarWinds Serv-U (7.5), Cisco SD-WAN (7.2).
  • ~88,000 SA identities — exposed in the ~985,000-record global Cannabis Club “CannaLeaks” breach.
  • 297 GB / 429,000 files — Council of Europe hit as ShinyHunters’ PeopleSoft campaign escalates; Cl0p now also exploiting CVE-2026-35273.
  • 10-day comply-or-prosecute order — Information Regulator PAIA enforcement against Gauteng Health (Tembisa, 16 June).
  • 5+ weeks — AVBOB in partial restoration with still no leak-site claim or attribution.

Major Incidents: Who Was Hit and How

FortiBleed — ~74,000 Firewalls With Plaintext Credentials

Roughly 74,000 internet-facing Fortinet FortiGate firewalls have valid usernames and plaintext passwords circulating on an attacker-controlled server — about half of all internet-exposed FortiGate devices globally. CISA issued an emergency alert on 18 June. SA exposure is significant across government, banking, retail, and ISPs. Check your organisation’s domain at hudsonrock.com/fortinet, rotate ALL VPN and admin credentials, enable phishing-resistant MFA, and upgrade to FortiOS 7.2.11 / 7.4.8 / 7.6.1+ (which triggers a PBKDF2 re-hash on next admin login).

Splunk Enterprise — Pre-Auth RCE in the SIEM Layer

CVE-2026-20253 (CVSS 9.8) allows pre-authentication RCE via an unauthenticated PostgreSQL sidecar endpoint (/v1/postgres/recovery/backup and /restore). Splunk PSIRT confirmed limited in-the-wild exploitation on 18 June; watchTowr Labs published the full exploit chain on 12 June; the CISA KEV deadline was 21 June. Splunk is the SIEM of record across SA banks and telcos — a compromised Splunk blinds the SOC. Patch to 10.0.7 or 10.2.4; if you cannot patch immediately, disable the PostgreSQL sidecar and restrict management-interface access. Splunk Cloud Platform is not affected.

TeamPCP / ResoluteXBF — Supply-Chain Campaign Attributed to a SA Operator

Google and Palo Alto Networks publicly attributed the most damaging open-source software supply-chain campaign of 2026 — compromising Trivy, Bitwarden CLI, TanStack, SAP and Red Hat npm packages and ultimately stealing ~3,800 internal GitHub repositories in 11 minutes — to a single operator based in South Africa (handle ResoluteXBF, also TeamPCP). CISA, SANS and multiple global vendors are now tracking the operator. This is a law-enforcement-relevant SA development: SA DevSecOps teams should audit dependency provenance and rotate any tokens that touched compromised registries.

Carryovers — AVBOB, PeopleSoft Escalation, CannaLeaks

AVBOB remains in partial restoration five-plus weeks post-attack with no leak-site claim or attribution. The PeopleSoft campaign escalated: the Council of Europe lost 297 GB / 429,000 files, and Cl0p is now also exploiting CVE-2026-35273 alongside ShinyHunters — SA universities running PeopleSoft remain at elevated risk. The global Cannabis Club “CannaLeaks” breach exposed ~88,000 SA identities among ~985,000 records.

POPIA and Regulatory

The Information Regulator issued a 10-day comply-or-prosecute PAIA order against Gauteng Health (Tembisa) on 16 June, and an independent senior SAPS officer was appointed to lead the SAPS Western Cape medical-records investigation. The SuppCenter MSSP listing (M3RX) carries supply-chain implications for SA public-sector customers. With FortiBleed exposing credentials for SA government and banking infrastructure, POPIA section 19 (security safeguards) obligations around credential management are squarely in scope — document your rotation response.

Full Intelligence Report

The complete Week 26 technical report covers the FortiBleed exposure analysis and remediation checklist, the Splunk exploit-chain breakdown, the TeamPCP/ResoluteXBF attribution timeline, the overdue Joomla JCE and LiteSpeed KEV items, the PeopleSoft/Cl0p escalation, the sector threat heatmap, and structured hunt missions with full IOC tables.

What Your Business Should Do Right Now

  • FortiBleed triage (CISA alert 18 June): Check your organisation’s domain at hudsonrock.com/fortinet; force-rotate ALL FortiGate VPN and admin credentials; enable phishing-resistant MFA on admin interfaces; upgrade FortiOS to 7.2.11 / 7.4.8 / 7.6.1+; remove management interfaces from the public internet; and review logs for unexpected successful admin logins.
  • Patch Splunk Enterprise (CVE-2026-20253, CVSS 9.8): Update to 10.0.7 or 10.2.4 immediately — the pre-auth RCE via the unauthenticated PostgreSQL sidecar is confirmed exploited in the wild. If patching is not immediately possible, disable the PostgreSQL sidecar and restrict network access to the management interface.
  • Clear overdue KEV items: Joomla JCE CVE-2026-48907 (10.0) is OVERDUE and under automated mass exploitation since 9 June — verify version, review the #__wf_profiles table and images/, media/, tmp/ directories for rogue PHP. Apply the LiteSpeed cPanel CVE-2026-54420 (8.5) fix, deploy the Exchange OWA permanent patch KB5094139 if not yet done, and apply the Oracle June CPU to any internet-accessible PeopleSoft.
  • Audit dependency provenance: With the npm/GitHub supply-chain campaign attributed and still being unwound, review lockfiles for compromised Trivy, Bitwarden CLI, TanStack, SAP and Red Hat npm package versions, and rotate any CI/CD or registry tokens that touched affected ecosystems.
  • PeopleSoft estates: assume continued targeting: With both ShinyHunters and Cl0p now exploiting CVE-2026-35273, universities and public-sector HCM teams should complete remediation and review logs from 27 May onward for compromise indicators.