SAMURAI CYBER WATCH
Issue #9 — June 27, 2026
Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations
THIS WEEK'S BRIEFING
FortiBleed Hits Japan — and Overseas Subsidiaries Are the New Frontline
Japanese organizations confirmed among FortiBleed victims, three overseas subsidiaries of major Japanese groups hit in a single week, and kernel-level backdoors targeting Asia-Pacific — this week's incidents converge on a structural gap that has been ignored for too long.
THE KEY DEVELOPMENT
FORTIBLEED HITS JAPAN — A SILENT CREDENTIAL BREACH IN PROGRESS
The most critical development to watch this week is the confirmed presence of Japanese organizations among victims of "FortiBleed," a large-scale credential leak tied to Fortinet devices. Reported by security-next.com on June 26, 2026, this incident goes far beyond a routine vendor vulnerability disclosure. The breach is attributed to the exploitation of multiple known vulnerabilities, including CVE-2022-40684 and CVE-2023-27997, affecting Fortinet products including FortiGate firewalls and FortiClient VPN clients. The core issue is this: credentials may already be in the hands of threat actors.
Fortinet VPN and firewall products are widely deployed across Japanese government agencies, financial institutions, and manufacturers. The confirmation of credential exposure means unauthorized access attempts against affected networks may be happening right now. Responding with nothing more than password resets and MFA reconfiguration is dangerous. Retroactive log analysis is essential to determine whether stolen credentials have already been weaponized.
Over my 20 years in this field, I have repeatedly witnessed the same pattern: an organization concludes that credentials were exposed but finds no evidence of unauthorized access, only for a breach to surface weeks or months later. Sometimes the initial investigation lacked sufficient depth. Sometimes log retention periods were too short for meaningful retrospective analysis. The reasons vary, but the outcome is always the same. Responding to FortiBleed demands both speed and depth. The moment you mark patching and credential resets as "complete," the real risk begins.
JAPAN LENS: OVERSEAS SUBSIDIARIES IN MANUFACTURING AND FOOD SECTORS TARGETED — ATTACKERS EXPLOIT THE "WEAK OUTER WALL" STRATEGY
This week saw a cluster of attacks against overseas subsidiaries of major Japanese corporate groups. Nidec's Taiwan subsidiary suffered a ransomware attack. Daikyo Nishikawa's Indonesia subsidiary experienced confirmed unauthorized data exfiltration. And two overseas group companies under Sapporo Holdings publicly disclosed cyberattack incidents. Three separate cases in a single week. I do not believe this is coincidence.
While Japanese parent companies have invested heavily in strengthening domestic security postures, the security capabilities of their manufacturing and sales subsidiaries across the Asia-Pacific region have consistently lagged behind. This structural gap has been left unaddressed for years. Attackers understand this asymmetry precisely. Rather than striking the hardened core, they target the weaker perimeter first. This week's three incidents are textbook examples of that approach.
In the manufacturing sector in particular, subsidiary production systems are often tightly integrated with parent company procurement and logistics platforms. Executive leadership must recognize that a breach at an overseas subsidiary is not merely a cost center problem — it is a threat to business continuity at the enterprise level, with the potential to cascade into full supply chain disruption or intellectual property theft. If your organization currently treats overseas subsidiary security budgets as a line item for reduction, take this week's three incidents not as someone else's problem, but as a prompt to assess your own overseas operations immediately.
BEYOND THE EPICENTER: THIS IS NOT JUST A LARGE ENTERPRISE STORY — WHAT SMALL BUSINESSES SHOULD TAKE FROM THIS WEEK
Alongside FortiBleed, this week brought the publication of CVE-2025-1021 affecting Synology MailPlus Server, along with three critical-severity vulnerabilities in pgAdmin 4: CVE-2025-2946, CVE-2025-2947, and CVE-2025-2948. If those names make this sound like a complex problem relevant only to large enterprises, that perception itself is a risk.
Synology NAS devices are widely adopted by small and medium-sized businesses across the Asia-Pacific region as cost-effective file and mail servers. The newly disclosed MailPlus Server vulnerability can be exploited remotely if left unpatched. pgAdmin 4 is equally relevant — it is a tool used daily by database administrators in organizations of every size, and the presence of critical-rated vulnerabilities in that tool is a concern that does not scale with company size. The belief that "we are not a target" remains, after 20 years, the single most dangerous assumption in cybersecurity.
The disruption of Amadey botnet and Stealc infrastructure through Operation Endgame is one of the few encouraging developments this week. However, when these tools are taken offline, successor infrastructure inevitably emerges to replace them. The action for small businesses is straightforward: check your software for available updates right now. The majority of this week's incidents could potentially have been prevented with that single step.
STATE ACTOR WATCH: NATION-STATE INDICATORS CONFIRMED THIS WEEK
This week's incident data includes activity attributed to multiple suspected state-sponsored threat groups. The information presented here is based on a technical analysis report published by ESET on June 25, 2026. Final determinations regarding state involvement rest with individual organizations and relevant government authorities. My role is to convey confirmed technical threats from a defensive standpoint.
The Gamaredon APT group, attributed to Russia, has continued operations using a new toolset that leverages legitimate online services to conceal command-and-control infrastructure. The combination of tunneling, worker processes, and dead-drop resolvers is designed to evade conventional communication detection methods, reflecting a notable increase in technical sophistication. While Gamaredon has historically focused on Ukraine-linked organizations, its toolset and techniques are transferable to other regions and target profiles.
The FishMonger APT, attributed to China, has developed a new Windows backdoor designated SprySOCKS, which employs kernel driver abuse for detection evasion and primarily targets government and private-sector organizations across the Asia-Pacific region. ESET's analysis explicitly identifies Japanese organizations as potential targets, warranting heightened vigilance from government agencies and defense-related companies. Kernel-level tools present significant detection challenges for conventional security products, and defensive planning should be built on that assumption.
My position remains politically neutral. Attributing blame to any specific nation-state is not my objective. However, as someone responsible for supporting organizational defense, I consider it a professional obligation to act on confirmed technical threats regardless of the actor's affiliation or motivation.
DEFEND WITHOUT CHOOSING SIDES
Practical defensive actions drawn from this week's incidents
① Organizations running Fortinet VPN or firewall products should confirm their remediation status for CVE-2022-40684 and CVE-2023-27997, then immediately pull and review the last 30 days of VPN logs. Unfamiliar IP addresses or login activity outside expected hours are your starting points for investigation. Do not treat credential resets as a complete response. In my experience, declaring "remediation complete" without retroactive log analysis is a decision that tends to carry a significant cost later.
② Administrators responsible for Cisco Unified Communications Manager and PTC products should verify patch status today, based on the emergency advisory issued by CISA on June 24, 2026. Active exploitation in the wild does not allow for a "we will get to it eventually" posture.
③ For Synology MailPlus Server and pgAdmin 4, complete updates to the latest vendor-provided versions this week. Systems administrators at smaller organizations in particular should reconfirm that these products are critical components of your internal infrastructure. Once a CVE is published, development of working exploit code may already be underway.
④ Review the security posture of overseas subsidiaries and affiliated group companies this week. As the Nidec, Daikyo Nishikawa, and Sapporo Holdings incidents demonstrate, the point of initial compromise is increasingly an overseas subsidiary rather than the domestic headquarters. At a minimum, verify three things: EDR deployment status, patch management practices, and incident reporting workflows.
⑤ To prepare against kernel-level threats such as SprySOCKS from the FishMonger APT, strengthen kernel driver signature validation on endpoints and review alert configurations for anomalous driver load events. Assume signature-based detection will not catch these threats, and confirm that behavioral detection capabilities are active.
NEXT ISSUE
Next week, we continue tracking the evolving threat landscape — including any further developments on FortiBleed affecting Japanese organizations and ongoing FishMonger APT activity across Asia-Pacific. See you Friday.
About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-aligned state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.
Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.
© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.