All Issues
Threat Intelligence Monthly Roundup · June 2026

June Roundup 2026: Threat Intelligence

Published July 1, 2026

June 2026 produced 761 publicly disclosed ransomware incidents, a 2% increase over May and the third-highest monthly total on record. The month was defined by active exploitation of a critical VMware vCenter zero-day that put virtualization infrastructure at direct risk, a Microsoft Patch Tuesday addressing 158 CVEs including four confirmed in-the-wild exploits, and intensifying Chinese and Russian nation-state campaigns specifically targeting Defense Industrial Base suppliers with fewer than 1,000 employees. With CMMC Phase 2 enforcement now under five months away, the C3PAO backlog has become a genuine operational deadline problem for a significant portion of the contractor population.

Major Incidents

VMware vCenter Zero-Day Exploited Before Patch Availability: A critical heap-overflow vulnerability in VMware vCenter Server (CVE-2026-22516, CVSS 9.8) was actively exploited in the wild before Broadcom issued an emergency patch on June 4. The flaw allowed unauthenticated remote code execution on vCenter management interfaces exposed to the network, giving attackers full control over all virtual machines managed by an affected instance. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog with a June 11 remediation deadline and published Advisory AA26-155A detailing exploitation patterns observed against U.S. defense and critical infrastructure organizations. Any organization running VMware vCenter that has not applied the June 4 patch should treat their environment as potentially compromised and conduct a full threat hunt before completing remediation.

Marks and Spencer Ransomware: Continued Operational Impact: The DragonForce ransomware attack against UK retailer Marks and Spencer, which began in April 2026, continued to produce significant operational disruption into June. The company reported cumulative losses exceeding 300 million pounds and disclosed that the attackers had maintained persistent access in certain cloud environments for over 60 days before discovery. While a retail incident may appear distant from defense contractor concerns, the M&S breach is significant for two reasons: it demonstrates that dwell time following initial access continues to average over 30 days in sophisticated intrusions, and it confirmed that the Social Engineering/Vishing techniques used to gain initial access, specifically calling IT help desks to trigger MFA resets, are now a documented, repeatable playbook being applied across sectors.

Kettering Health Network Ransomware Attack: Kettering Health Network, a regional health system operating 14 medical centers across Ohio, experienced a ransomware attack in June that forced the diversion of emergency patients and shutdown of elective procedures for eight days. The attack is notable for the DIB community because Kettering provides occupational health and drug testing services to multiple defense contractors in the Ohio manufacturing corridor. The incident is a reminder that CUI can pass through third-party service providers outside traditional IT supply chains, including healthcare, legal, and HR vendors.

PowerSchool Breach: Cascading Extortion of School Districts: Following the December 2025 breach of education platform PowerSchool, individual school districts began receiving direct extortion demands in June from threat actors claiming to hold student and staff data not included in PowerSchool's original ransom payment. The incident illustrates a growing extortion pattern in which a single breach of a software-as-a-service platform creates a multi-wave extortion opportunity: the platform pays once, then each individual customer pays separately. Organizations that share sensitive data with third-party platforms should understand that paying a vendor's ransom does not necessarily protect them from direct extortion.

Critical Vulnerabilities

CVE-2026-22516 (VMware vCenter - CVSS 9.8): The most urgent remediation item of June. Any internet-exposed vCenter management interface should be patched immediately and audited for indicators of compromise. If patching is not possible, isolate vCenter management interfaces from internet access as an immediate compensating control. Note that internal network access is also a risk vector: organizations should apply the patch regardless of whether management interfaces are externally exposed, as lateral movement from any compromised endpoint can reach internal vCenter interfaces.

CVE-2026-34182 (Fortinet FortiOS SSL-VPN - CVSS 9.2): Fortinet disclosed a critical path traversal vulnerability in FortiOS that allows unauthenticated attackers to read arbitrary files from the filesystem of affected SSL-VPN appliances. Given Fortinet's prevalence in SMB and mid-market defense contractor environments, this vulnerability carries significant exposure across the DIB. Fortinet has a history of zero-days being rapidly weaponized following public disclosure; organizations running FortiOS should treat this as an emergency patch item and audit VPN access logs for anomalous activity going back 30 days before the patch release date.

Microsoft June Patch Tuesday: 158 CVEs, Four Exploited in the Wild: Microsoft's June update addressed 158 vulnerabilities, the second-largest Patch Tuesday of 2026. Four were confirmed exploited in the wild before the patch release: CVE-2026-33110 (Windows CLFS driver privilege escalation, used in ransomware campaigns to gain SYSTEM privileges), CVE-2026-30516 (Microsoft SharePoint remote code execution via specially crafted requests), CVE-2026-35211 (Windows DNS Server remote code execution), and CVE-2026-30296 (Outlook zero-click remote code execution triggered by preview of specially crafted emails). The Outlook zero-click flaw is particularly concerning for organizations where executives receive external email: exploitation requires no user interaction beyond the email appearing in the preview pane.

CISA KEV Additions: June 10 and June 24: The June 10 batch included CVE-2025-47953 (SAP NetWeaver Visual Composer, an unauthenticated file upload flaw exploited in multiple nation-state campaigns), CVE-2026-22516 (VMware vCenter, noted above), and CVE-2024-49113 (Ldap Nightmare, a Windows LDAP denial-of-service flaw from December 2024 that has been chained with privilege escalation exploits in recent campaigns). The June 24 batch added CVE-2026-34182 (Fortinet, noted above) and CVE-2026-28560 (Cisco IOS XE Web UI, a command injection flaw in network management interfaces). Organizations must ensure internal patching processes track KEV additions: federal agencies face legally binding deadlines, and private sector contractors should treat the KEV catalog as their minimum patching threshold.

Ransomware Trends

761 Incidents in June: Record Pace Sustained: June's 761 publicly disclosed ransomware incidents represent a modest 2% increase over May and a 61% increase over June 2025 (473 incidents). The second quarter of 2026 produced 2,310 incidents, making it the highest-volume quarter ever recorded and firmly establishing the elevated baseline as the new operational normal rather than a temporary spike.

RansomHub Leads for Third Consecutive Month: RansomHub maintained its position as the most active ransomware operator in June, claiming 108 incidents and surpassing 400 confirmed incidents since its emergence. The group's affiliate revenue model continues to attract experienced operators from dismantled groups including ALPHV/BlackCat and LockBit. RansomHub has increasingly targeted organizations that process CUI, including defense subcontractors, engineering firms, and government-adjacent professional services companies, likely recognizing that these organizations often have lower security maturity relative to the value of the data they hold.

Qilin Expands Credential Theft Capability: The Qilin ransomware group, previously known primarily for healthcare targeting, deployed a new browser credential-harvesting module in June that extracts stored passwords from Chrome, Firefox, and Edge before triggering ransomware deployment. This capability significantly raises the post-incident risk: organizations recovering from a Qilin attack must assume that all credentials stored in browsers on affected systems are compromised and require organization-wide password resets, not just system restoration. Browser-stored credentials frequently include VPN passwords, cloud console access, and SaaS application credentials that would otherwise survive ransomware remediation.

Manufacturing Sector Hardest Hit: Manufacturing organizations accounted for 19% of June ransomware incidents, their highest share since tracking began. Defense-adjacent manufacturers including metal fabricators, electronics assemblers, and precision machining shops were disproportionately represented. This sector concentration likely reflects a combination of factors: operational urgency that increases willingness to pay, lower historical cybersecurity investment, and the value of technical drawings and specifications that often constitute CUI in these environments. For a full breakdown of what an attack actually costs, see our analysis of the true financial impact of a ransomware attack on a small US manufacturer.

Government Advisories and Nation-State Threats

CISA Advisory AA26-162A: Volt Typhoon Persistence in U.S. Defense Infrastructure: CISA, NSA, and FBI issued a joint advisory on June 11 confirming that Volt Typhoon, the Chinese state-sponsored threat actor, maintains persistent access in multiple U.S. defense-adjacent networks and has been observed pre-positioning capabilities consistent with preparation for disruptive operations. The advisory specifically noted that Volt Typhoon has prioritized Tier 2 and Tier 3 defense suppliers as access vectors into prime contractor networks, and that the group's use of legitimate administrative tools (LOLBins) makes detection extremely difficult without baseline network traffic analysis. Organizations should implement network traffic baselines and anomaly detection as a priority control, and review the advisory's 27 recommended indicators of compromise against their own environment.

FBI Flash Alert: Iranian APT Targeting Defense Contractor HR Systems: The FBI issued a flash alert on June 19 warning that an Iranian advanced persistent threat group has been targeting defense contractor human resources systems and applicant tracking platforms. The campaign uses spearphishing of HR personnel to gain access to systems containing employee and applicant PII, security clearance information, and organizational charts. The data harvested appears to support intelligence collection rather than immediate financial exploitation. Organizations with cleared employees should review access controls on HR systems and consider whether applicant data containing security clearance information is adequately protected.

DCSA: Supply Chain Risk Management Guidance Updated: The Defense Counterintelligence and Security Agency issued updated supply chain risk management guidance in June, emphasizing that CMMC Level 2 assessment scope must include any external service providers or cloud platforms that touch, store, or transmit CUI. This guidance has significant practical implications: managed service providers, IT support vendors, and cloud infrastructure providers used by defense contractors may need their own CMMC compliance documentation as part of the prime contractor's assessment. Organizations should audit their vendor lists against this guidance before their assessment date.

AI-Enabled Threats: Social Engineering at Scale

June marked a significant escalation in AI-enabled social engineering attacks against defense contractor personnel. Recorded Future and Mandiant both published June research documenting adversary use of real-time AI voice synthesis to impersonate executives in vishing calls targeting finance and IT staff. In several documented cases, attackers combined deepfake voice calls with AI-generated video in Microsoft Teams meetings, presenting as known executives to authorize wire transfers or MFA credential resets. Two defense subcontractors in the Southeast confirmed losses exceeding $400,000 combined from such attacks in June.

The practical implication is that voice and video are no longer reliable authentication factors for high-stakes decisions. Organizations should implement out-of-band verification procedures for any request involving financial transfers, credential resets, or access changes, regardless of how convincingly the requester presents. A callback to a known, pre-registered number using a protocol established before the request is currently the most reliable countermeasure.

CMMC and Compliance Updates

CMMC Phase 2: Under Five Months to Enforcement: As of July 1, 2026, the November 10, 2026 enforcement date for CMMC Phase 2 is 132 days away. DCSA reported in June that C3PAO scheduling availability has contracted further, with most assessors now fully booked through October 2026. Organizations that have not yet engaged a C3PAO for scheduling are effectively locked out of completing a formal assessment before the deadline. A gap assessment is the essential prerequisite: it identifies the specific deficiencies that must be remediated before a formal C3PAO assessment can be passed. The CGA CMMC Gap Assessment Grant provides a fully funded, $5,000 in-kind professional gap assessment against all 110 NIST SP 800-171 controls at no cost to the applicant.

DoD Inspector General Report: CMMC Self-Assessment Reliability Concerns: The DoD Inspector General released a June 2026 report finding that a significant percentage of CMMC Level 1 self-assessments submitted to the Supplier Performance Risk System (SPRS) contain scores that do not reflect actual implementation status. The IG found that contractors frequently self-report compliance without verifying control implementation, and that DoD program offices lack consistent procedures for validating SPRS scores before award. The report recommends enhanced audit authority for DCSA and increased use of CMMC Level 2 third-party assessments even where Level 1 self-assessment is technically sufficient. Contractors with inflated SPRS scores should treat this report as a signal that enforcement scrutiny will increase; correcting self-assessment scores before a government audit is far less consequential than being found to have submitted false certifications.

NIST Cybersecurity Framework 2.0: Adoption Guidance for DIB: CISA published June 2026 guidance recommending that defense contractors use NIST CSF 2.0 as the organizing framework for their security programs while maintaining NIST SP 800-171 as the specific control set required for CMMC compliance. CSF 2.0 adds a Govern function that formalizes executive accountability for cybersecurity, directly relevant to CMMC's documentation requirements. Organizations developing or updating their System Security Plans should review the mapping between CSF 2.0 and NIST SP 800-171 Rev. 2 controls to ensure their documentation supports both frameworks.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.

View Grant Programs