
Beyond the Perimeter
June 18, 2026Cycle: June 2026 Focus: Securing healthcare collaboration and identity layers
June saw the center of gravity move up the stack. Where May was defined by exploitation of the network edge, this cycle the most consequential activity centered on the collaboration and identity layer that healthcare organizations rely on for care coordination and vendor communication.
An actively exploited SharePoint vulnerability was added to the CISA Known Exploited Vulnerabilities catalog and corroborated by independent incident reporting, while phishing that abuses SharePoint and Microsoft 365 to hijack session tokens was observed passing cleanly through mainstream email security. Identity abuse, edge exposure, and help-desk social engineering all persisted. The through-line for healthcare is that the systems holding and moving protected health information are now the systems under the most direct pressure.
The Non-Technical Takeaway: Attackers are moving past the digital “front door” (firewalls, routers) and are now targeting the internal rooms where staff collaborate, share files, and manage patient data. Securing individual user identity and session tokens is now just as critical as securing the network edge perimeter.
Key Judgments
-
The collaboration and identity layer is now the primary battleground. An actively exploited SharePoint flaw (CVE-2026-45659) and a token-hijacking phishing pattern against Microsoft 365 both surfaced this cycle, corroborated across CISA, incident-response reporting, and practitioner community observations. For healthcare, this is the layer where ePHI is created, shared, and coordinated.
-
Identity abuse remains one of the fastest paths to serious compromise. Session and token theft continue to bypass multifactor authentication after login, and cloud identity came under direct pressure this cycle through password-spray activity against Azure command-line access. Post-authentication monitoring matters as much as the login itself.
-
Edge and remote-access exposure has not receded. FortiGate credentials were reported circulating through access brokers, and a newly disclosed pair of Ivanti Sentry vulnerabilities carries no public indicators yet. Remote-access and mobile gateways common in healthcare should be treated as active watch items.
-
Help-desk and user-directed social engineering is a proven, now-prosecuted intrusion path. Guilty pleas tied to the Transport for London attack confirm that help-desk impersonation is not a theoretical risk but a repeatable route to ransomware. The same techniques have been used against healthcare and rely on verification gaps rather than technical flaws.
-
Public-facing patient services are under automated pressure. A large-scale credential-stuffing bot campaign was reported this cycle. Patient portals, scheduling, and telehealth logins are natural targets for this kind of volume-driven credential abuse.
What Changed Since May
May’s dominant story was the network edge, anchored by the actively exploited PAN-OS GlobalProtect authentication bypass. In June, the most urgent activity shifted to the collaboration and identity layer: an actively exploited SharePoint vulnerability, phishing that hijacks Microsoft 365 tokens, and password-spray pressure on cloud identity.
|
May 2026 Focus
|
June 2026 Shift
|
|
Network Edge Perimeter Exploitation of external firewalls, VPNs, and authentication gateways (e.g., PAN-OS GlobalProtect). |
Collaboration & Identity Core Exploitation of internal document systems (SharePoint), token hijacking (M365), and identity layer compromise. |
Edge exposure did not go away. It persisted through the FortiGate credential exposure and the unpatched Ivanti Sentry disclosures, but it moved from the headline to the supporting cast. The net effect is that defenders now must hold both the perimeter and the collaboration core at the same time.
At-a-Glance Threat Table
Priority items this cycle, ranked by immediacy of healthcare relevance.
|
Threat / Item
|
Type
|
Status
|
Why it matters for healthcare
|
|
SharePoint RCE (CVE-2026-45659) |
Collaboration / RCE |
Active / KEV |
SharePoint is core to care coordination and document workflows; patch and hunt now. |
|
Nested SharePoint / M365 Phishing |
Phishing / Identity |
Reported Active |
Clean-looking links from trusted partners can lead to ePHI-exposing token theft. |
|
Azure CLI Password Spray |
Identity / Cloud |
Reported Active |
Cloud identity is the new perimeter; enforce MFA and alert on spray patterns. |
|
FortiGate Credentials |
Edge / VPN |
Circulating |
Remote-access gateways are common in healthcare; rotate credentials and review access. |
|
Ivanti Sentry (CVE-2026-10520 / -10523) |
Edge / Mobile Gateway |
Disclosed |
Common in clinical mobility; treat as an unpatched-exposure watch item. |
|
Scattered Spider Help-Desk Tactics |
Social Engineering |
Prosecuted |
Help-desk impersonation is a proven route to ransomware; harden verification. |
|
Credential-Stuffing Campaign |
Bot / Patient Portal |
Large-Scale |
Patient portals and telehealth logins are prime targets; add bot defenses. |
AI Threat Spotlight
AI-related activity remained a steady undercurrent rather than the headline this cycle, and it continues to fall into three categories that healthcare leaders should treat separately:
-
In the hands of attackers: Adversaries continue to use large language models to speed exploit development and generate convincing phishing content. The practical effect is compression of the time between disclosure and usable exploitation, which raises the value of fast patching and proactive hunting.
-
As a new attack surface: AI features and AI-generated applications keep entering environments faster than they are reviewed. Any AI capability exposed to untrusted input, or shipped without security review, should be scoped and tested like any other internet-facing system.
-
Ungoverned use inside the enterprise: Shadow AI use and the movement of production data into non-production and AI pipelines remain the most immediate internal risk for healthcare because both create direct HIPAA and PHI exposure that most security stacks are not configured to detect.
Priority Actions for Healthcare Organizations
-
Patch SharePoint Exposure: Patch actively exploited SharePoint exposure immediately and hunt for the associated attack chain on SharePoint and IIS hosts, prioritizing internet-facing and care-coordination systems.
-
Harden Microsoft 365: Harden Microsoft 365 against token and session theft: move toward device-based authentication, shorten session lifetimes for sensitive roles, and alert on anomalous token use, not just failed logins.
-
Secure Cloud Identity: Treat cloud identity as a monitored perimeter: enforce phishing-resistant MFA, disable legacy authentication, and alert on password-spray patterns against Azure and command-line access.
-
Rotate Gateway Credentials: Rotate credentials and review access on remote-access and mobile gateways (FortiGate, Ivanti Sentry), and baseline normal admin activity so unauthorized configuration changes stand out while indicators are still limited.
-
Harden Help-Desk Verification: Strengthen help-desk identity verification with out-of-band call-back for password resets, MFA re-enrollment, and remote-support requests, and rehearse the impersonation scenario.
-
Implement Bot Defenses: Add bot and credential-stuffing defenses to patient portals, scheduling, and telehealth logins, including rate limiting, device signals, and monitoring for distributed login volume.
-
Govern Enterprise AI: Keep AI usage governed: prohibit PHI in ungoverned tools, review AI-generated applications before production, and mask or synthesize production data used in non-production and AI pipelines.
STIG Closing View
The healthcare organizations most likely to reduce real-world risk this cycle are the ones that can defend the collaboration core and the perimeter at once. That means patching what is actively exploited, governing identity and session integrity with discipline, verifying the people and processes that request access, and proving they can recover. June’s shift up the stack does not change those priorities. It moves them closer to the systems that hold protected health information.



