FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale
CISA added critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The US federal patching deadline is Sunday, but active exploitation means UK organisations should treat this as immediate priority. A newly published Windows local privilege escalation vulnerability called LegacyHive works on fully patched systems with no fix available, creating serious risk when combined with active ClickFix campaigns delivering initial access. ClickFix techniques now support at least five concurrent malware operations including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A Huntress case study documents how one ClickFix compromise spread to eleven hosts before detection. The episode provides specific, actionable guidance for SMBs: verify FortiSandbox patch status with IT providers today, brief staff on ClickFix lures immediately, review user permissions to execute scripts, and ensure endpoint detection monitors for HTA execution and PowerShell spawning from browser processes. The convergence of mature exploit infrastructure, public zero-day proof-of-concept, and active campaigns targeting European users represents a significant immediate threat to UK small business networks.
Chapters
IntroductionMauven opens the seventeenth of July briefing with three urgent stories. Two require immediate technical action before the weekend, whilst the third demands procedural response to an unpatched vulnerability.
FortiSandbox Active ExploitationCISA confirmed active exploitation of critical FortiSandbox command injection vulnerabilities, ordering US federal agencies to patch by Sunday. FortiSandbox is a threat analysis appliance, not the firewall, creating particular concern as the security tool itself becomes attack surface. Guidance covers immediate patching requirements, how to verify MSP compliance, and the importance of asset inventory for unknown Fortinet deployments.
Call to ActionBrief appeal to follow the show and share with colleagues who need threat intelligence.
LegacyHive Zero-Day VulnerabilityA public proof-of-concept for Windows local privilege escalation called LegacyHive works on fully patched systems with no available fix. The vulnerability requires initial access first, which current ClickFix campaigns are actively providing across European targets. Defence recommendations focus on preventing initial compromise through application allow-listing, endpoint detection configuration, and staff awareness of ClickFix techniques.
ClickFix Campaign InfrastructureAt least five distinct malware operations now use ClickFix delivery techniques, including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A detailed Huntress case study shows one ClickFix compromise spreading to eleven hosts. Practical guidance includes immediate staff briefing, permission reviews to block arbitrary script execution, and verification that managed detection providers monitor relevant observable behaviours.
ConclusionThe convergence of mature ClickFix infrastructure, public Windows zero-day exploitation capability, and continuing Fortinet vulnerability exploitation represents the gap between published guidance and implemented defences. Two immediate actions: verify FortiSandbox patch status and brief staff on ClickFix lures before Friday.
Links
https://www.cisa.gov/known-exploited-vulnerabilities-cataloghttps://www.theregister.com/https://www.ncsc.gov.uk/https://www.bleepingcomputer.com/https://www.huntress.com/https://www.microsoft.com/