Threat Analysis: ServiceNow RCE Under Active Exploitation, Passkey Vishing, and the FortiBleed Credential Campaign
Hello, Mauven here.
This is your Daily Threat Analysis for 20th July 2026.
Three items today. One is a critical vulnerability under active exploitation. One is a social engineering campaign that has quietly been undermining phishing-resistant authentication since April. And one is a credential harvesting operation that tells you a great deal about how attackers approach internet-facing VPN infrastructure, none of it flattering to defenders.
Let us go through them.
CVE-2026-6875: ServiceNow AI Platform RCE, Active Exploitation Confirmed
This is the priority item. CVE-2026-6875 is a critical remote code execution vulnerability in the ServiceNow AI Platform, and as of today, threat intelligence firm Defused has confirmed it is being actively exploited in the wild.
ServiceNow is widely deployed across UK professional services, NHS-adjacent organisations, financial services, and mid-market IT operations. It handles ITSM workflows, HR case management, procurement approvals, and increasingly, AI-assisted automation. The attack surface is not trivial.
What the advisory says: critical RCE, patch available, exploitation observed.
What the advisory does not say: ServiceNow instances are frequently managed by third-party MSPs or are embedded in supplier environments that your organisation interacts with. The direct exposure risk is obvious. The indirect risk, through a managed service provider or a software vendor who has not yet patched their own instance, is less visible and, in my experience, is where most SMBs get caught out.
If you use ServiceNow directly, this is a patching emergency. Contact your provider today and confirm patch status. Do not accept “we are working on it” as an answer. Get a time and date.
If you use a managed service provider who uses ServiceNow to manage your tickets and workflows, ask them the same question. They are your exposure.
The exploitation window on critical RCE vulnerabilities in widely-deployed SaaS platforms is now measured in hours, not days. We are past the comfortable period.
O-UNC-066: Vishing Actors Defeating Microsoft 365 Passkey Enrolment
This one has been running since April. Okta’s threat intelligence team has documented a campaign attributed to a group they track as O-UNC-066, and the methodology is straightforward enough to explain in a paragraph, which is part of what makes it effective.
Attackers register domains containing the word ‘passkey’, the sort of domain that looks plausible in a browser tab when someone is already expecting an enrolment flow. They then call the target, claim to be Microsoft support, and walk the victim through registering a new passkey. The victim visits the attacker-controlled phishing kit, which mimics Microsoft’s legitimate enrolment interface. While the victim is on the call, the attacker simultaneously registers their own passkey to the victim’s account. The victim believes they have completed a security process. The attacker now has persistent, phishing-resistant access.
Let that land for a moment. The whole point of passkeys is that they are supposed to be phishing-resistant. They are, against automated credential-harvesting attacks. They are not resistant to a patient human attacker on the phone who walks your receptionist or your finance manager through enrolling an attacker-controlled credential.
The NCSC has published guidance on vishing. The fact that we are still seeing campaigns of this sophistication succeed tells you everything about the gap between published guidance and operational implementation.
The targets here are primarily Microsoft 365 tenants. UK SMBs running M365 are squarely in scope. This is not a campaign aimed at government networks or critical national infrastructure. It is aimed at businesses that have done the right thing and adopted phishing-resistant MFA, and then not trained their staff on the social engineering that circumvents it.
What to do:
- Restrict passkey enrolment so that it can only occur through verified in-person or pre-authenticated flows. Microsoft Entra allows you to configure enrolment policies. Use them.
- Brief staff explicitly: Microsoft will not call them to help them register a passkey. Neither will their IT provider, unless that call was pre-arranged and the provider can verify identity through an agreed code word or prior ticket reference.
- Flag any inbound call requesting account security actions as requiring verification through a separate, known-good channel before any steps are taken.
This is a social engineering problem with a technical partial-fix available. Deploy both.
FortiBleed: What the Exposed Server Tells Us About VPN Credential Harvesting at Scale
CloudSEK has published analysis of what they are calling FortiBleed: a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The exposure of the attacker’s staging server has given researchers an unusually clear picture of the operation.
The methodology involved credential reuse, brute force, and distributed GPU-accelerated hash cracking. The infrastructure included approximately 36 rented GPUs running Hashtopolis, a legitimate distributed password cracking framework. The exposed directory contained 319 files, giving researchers a detailed view of scale and methodology.
This is not a sophisticated nation-state operation. It is a well-resourced criminal operation that has treated FortiGate credential harvesting as an industrial process. Rent GPU time, automate credential testing, harvest access, sell or exploit.
FortiGate devices are among the most common VPN gateway solutions in UK SMB and mid-market environments. They are also, historically, among the most persistently unpatched. Every major Fortinet advisory of the past three years has been followed by evidence of continued exploitation months after patches were available. FortiBleed appears to be the industrialised consequence of that patching culture.
The advisory for FortiGate SSLVPN vulnerabilities is not new. What is new is the documentation of what the post-exploitation operation looks like when credentials are harvested at this scale: initial access broker activity, likely sale to ransomware operators, and the kind of quiet dwell time that precedes a destructive attack by weeks or months.
If your FortiGate device has not been patched and reviewed in the past 30 days, treat it as a potentially compromised asset until you have verified otherwise. Rotate VPN credentials. Review authentication logs for anomalous access patterns. If you cannot do that in-house, call your MSP today.
Also on the Radar
The Cruciferra crypter service documented by Proofpoint this week is worth awareness even if it does not require immediate operational response from most UK SMBs. It is a malware-as-a-service crypter used by multiple unrelated criminal clusters to deliver remote access trojans and infostealers, with extensive endpoint detection evasion capabilities including BYOVD-based EDR tampering and Process Ghosting. It tells you something about the current state of the criminal tooling market: high-quality evasion is now a bought service, not a capability that requires technical expertise in the buying group. The barrier to deploying endpoint-evading malware is falling. That is a direction of travel worth tracking.
The Hugging Face breach, disclosed today, is a different category of concern. An autonomous AI agent system was used to breach Hugging Face’s production infrastructure, accessing internal datasets and credentials. The direct SMB exposure is low unless you are pulling models or datasets from Hugging Face repositories. The indirect exposure, through supply chain dependencies on AI tooling that sources from Hugging Face, is less clear and worth asking your software vendors about. This is early and I will return to it when there is more detail on what was accessed and how.
What to Do Today
- ServiceNow: Confirm patch status with your provider or MSP. Today, not this week.
- Microsoft 365 passkeys: Review Entra enrolment policies. Brief any staff who handle IT support calls or respond to inbound requests for account security actions.
- FortiGate: Check patch status. Rotate VPN credentials if the device has not been reviewed recently. Review authentication logs.
Before the next briefing: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s brief lands automatically. And if you know someone who should be hearing this, a business owner, an IT manager, a colleague who is still convinced they are too small to be a target, pass it on. The briefing does not work if it stays in the room.