June 19, 2026
FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
44 sources → 1077 gathered → 400 triaged → 42 clustered → 42 written
A Russian-speaking crew industrialized SSL-VPN credential harvesting against tens of thousands of FortiGates, and a single forgotten GitHub token cost Danish pharma giant Novo Nordisk 1.3TB of drug formulas and internal AI models. Elsewhere: out-of-band critical NGINX RCE, more actively-exploited Cisco and Splunk bugs, and a busy day for AI-pipeline supply-chain attacks.
Threat Activity & Intrusions
- FortiBleed exposed working SSL-VPN credentials for roughly 70,000–74,000 internet-facing Fortinet firewalls and VPN gateways across ~194 countries, prompting urgent hardening advisories from CISA and the NCSC-UK (CISA, BleepingComputer). Researcher Volodymyr Diachenko traced the operation — surfaced via Hunt.io open-directory intel — to a Russian-speaking group intercepting SSL-VPN auth at scale, cracking hashes offline on a GPU cluster (~1.16B attempts against 320K+ FortiGates, plus 2.1B against 160K+ MSSQL servers), and reusing plaintext creds for Active Directory lateral movement; at least four orgs including a NATO defense contractor were fully compromised (Dark Reading). Rotate VPN credentials and hunt for post-auth AD access now.
- Novo Nordisk was breached after FulcrumSec found a GitHub token left in a repo for two months, ultimately exfiltrating 1.3TB including unreleased drug formulas and internal AI models; the company refused a $25M extortion demand and the data is now being sold (Dark Reading, SecurityWeek). A clean reminder that secrets management is an identity problem, not a tooling one.
- DragonForce ransomware affiliates deployed a custom Go RAT (Backdoor.Turn) that hides C2 traffic inside legitimate Microsoft Teams relay infrastructure, evading network detection during lateral movement and exfiltration at a major US services firm, per Symantec/Carbon Black (The Hacker News, The Register).
- Operation Endgame disrupted the SocGholish/FakeUpdates chain tied to Evil Corp, remediating 14,971 infected WordPress sites and taking down 106 servers/domains; police flagged leaked credentials tied to ~1.4M sites (SecurityWeek, BleepingComputer).
- ShinyHunters claims to have published 441,408 internal records (4.7GB) from the Council of Europe, allegedly via an Oracle PeopleSoft zero-day, alongside a fresh batch of high-profile victims (The Register, FalconFeeds).
- Microsoft detailed a self-spreading Windows clipper campaign active since February 2026 that uses USB LNK worms plus a bundled Tor proxy for hidden-service C2 to swap crypto wallet addresses on the clipboard (The Hacker News, BleepingComputer).
- Rokarolla, a new Android banking trojan, targets 217 banking/crypto apps with 137 remote commands — overlays, keylogging, clipboard hijacking and near-total device control — spread via fake TikTok and Chrome downloads (The Hacker News, Dark Reading).
Cloud & Identity
- The Icarus Salesforce data-theft campaign claimed another OAuth-integrated app: a breach of market-intelligence platform Klue (Battlecards) let attackers pull Salesforce CRM data from multiple downstream customers, including Huntress — the third compromised integration in this extortion wave (BleepingComputer, Dark Reading).
Vulnerabilities & Exploits
- F5 shipped out-of-band patches for two critical NGINX Open Source flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module (
ngx_http_v3_module) that a remote unauthenticated attacker can trigger for code execution (The Hacker News, BleepingComputer). - Squidbleed (CVE-2026-47729) is a 29-year-old Heartbleed-style memory disclosure affecting every version of Squid Proxy in its default config — notable also because it was surfaced by Anthropic’s Claude Mythos Preview code-auditing (calif.io).
- CVE-2026-20262, a “make-me-root” flaw in Cisco Catalyst SD-WAN Manager, is under active exploitation; CISA set a June 29 federal remediation deadline (SecurityWeek, The Register).
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar that can chain to RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window (SecurityWeek, Horizon3).
- Joomla JCE CVE-2026-48907 (CVSS 10.0), an improper-access-control bug enabling arbitrary PHP code execution, was added to CISA’s KEV catalog amid active exploitation (The Hacker News).
- Cisco ISE got a critical command-execution patch (CVE-2026-20833) where insufficient input validation grants OS access and root privilege escalation (SecurityWeek, NCSC-NL).
- Apple patched CVE-2025-20701 (CVSS 8.8) in the Airoha Bluetooth SDK used by Beats Studio Buds, which allowed nearby attackers to pair without consent and eavesdrop via the microphone (The Hacker News).
AI & Model Security
- Varonis disclosed SearchLeak (CVE-2026-42824), a one-click chain in Microsoft 365 Copilot Enterprise Search combining prompt injection, a race condition and a CSP bypass to exfiltrate emails, files and even MFA codes — using a real
microsoft.comlink that defeats URL filtering. Now patched (The Hacker News, Dark Reading). - LiteLLM, the widely deployed open-source AI gateway, can be taken over by chaining three bugs that let a default low-privilege account escalate to admin and RCE — exposing every provider key it brokers, per Obsidian Security (The Hacker News).
- Unit 42 detailed “Pickle in the Middle,” a bucket-squatting flaw in the Google Cloud Vertex AI Python SDK (1.139.0–1.140.0) that let an unauthorized attacker hijack a victim’s model upload for cross-tenant RCE in Google’s serving infra; fixed in 1.148.0 (The Hacker News, Unit 42).
- The Mastra npm org (AI app framework,
@mastra/*) was hit by the easy-day-js supply-chain attack: a hijacked maintainer account republished ~145 packages with trojanized dependencies that drop a Rust infostealer post-install, hunting wallet seed phrases,.env/.npmrc, SSH and cloud creds (The Hacker News, Endor Labs). - A coordinated campaign published 15+ malicious JetBrains Marketplace plugins posing as DeepSeek-based AI coding assistants to exfiltrate AI provider keys, paired with Chrome extensions that capture chatbot sessions (The Hacker News).
- Unit 42 warns that third-party agent “skills” with privileged access frequently deviate from declared behavior, opening multi-stage attack chains; separately, “orphaned” AI agents left running after their creators leave create standing-privilege blind spots (Unit 42, The Hacker News).
- Mandiant shared red-team lessons for AI apps: defend the pipeline end-to-end, verify all front-end data, lock down system prompts, keep AppSec fundamentals, and build early-warning telemetry (Mandiant).
- A malware author is now embedding fake “nuclear/biological weapons” system-instruction text in JS payload comments specifically to trip AI-based analysis tooling — adversarial evasion aimed at the analyst’s LLM, not the runtime (Schneier).
- GLM-5.2 landed from Zhipu/Z.ai, described as the most capable text-only open-weights LLM to date and drawing comparisons to Opus and GPT-5.5 — worth tracking for both offensive and defensive local-inference use (Simon Willison).
Ransomware
- ESET dissected the Gentlemen RaaS EDR-killer framework: in-house GentleKiller (8 variants, each impersonating a legit product, targeting 400+ processes) plus externally sourced HexKiller, ThrottleBlood and HavocKiller; a recent data leak confirmed the toolset and linked an affiliate to a stealer dubbed OxideHarvest. The gang focuses on Southeast Asia, South America and Western Europe (BleepingComputer, ESET/WeLiveSecurity).
- INC ransomware has grown into a top-tier RaaS with 830+ victims since August 2023, capitalizing on the LockBit/BlackCat collapse and leaning on healthcare for payment pressure (The Hacker News, Dark Reading).
- KRYBIT, a new double-extortion strain built on the leaked Babuk codebase, went from zero to 49 victims across 20+ countries since early April (Nextron, DarkFeed).
- DeadLock now hosts its data-leak site on Polygon smart contracts — a first ESET is aware of — combining on-chain DLS resilience with a clearweb mirror and interactive HTML ransom notes (ESET).
Nation-State & APT
- Gamaredon is weaponizing WinRAR path-traversal CVE-2025-8088 against Ukraine: a malicious NTFS alternate data stream plants a
.lnkdirectly into the Startup folder on archive extraction, then runs a hidden anti-analysis PowerShell stager. Campaign active since February 2026 with military/conscription lures (Nextron). - ESET attributed two undocumented Windows variants of the SprySOCKS backdoor (WIN_DRV, WIN_PLUS) to China-nexus FishMonger, with a kernel driver redirecting traffic to a hidden passive TCP backdoor for stealth against government targets (WeLiveSecurity, Dark Reading).
- Mandiant detailed PRC-nexus UNC6508 spending over two years inside North American medical/defense research networks via vulnerable REDCap servers, deploying INFINITERED malware and abusing enterprise admin tools for covert exfil (Mandiant, Security Affairs).
- North Korea’s ScarCruft (APT37) is impersonating Microsoft account security alerts to deploy a new NarwhalRAT, while Contagious Interview weaponizes developer-recruitment and code-review lures as malware delivery (The Hacker News, SCWorld).
- Dropping Elephant has run one continuous China-themed LNK loader line for three-plus years (44 samples, 2023–2026) delivering an in-memory RAT via PDF-masquerading shortcuts and hidden PowerShell stagers (Rapid7, Nextron); SideCopy (APT36) swapped in a “Minutes Of Meeting” double-extension
.lnklure dropping a .NET RAT with HKCU Run persistence (Nextron).
Supply Chain
- The AtomicArch attack hijacked ~1,500 orphaned Arch Linux AUR packages, backdooring
PKGBUILD/.installhooks (invokingnpm installvia bun) to deploy a Rust infostealer and eBPF rootkit; Arch suspended new AUR registrations, and Nextron published detection YARA (SecurityWeek, Nextron rules).
New Tools & Releases
- Offensive Azure Security Cheatsheet — a practical quick-reference of Azure/Entra ID/M365 attack commands and notes distilled from CloudBreach’s Breaching Azure courses (GitHub).
- Certificate of Compromise — a whitepaper on offensive operations against Active Directory Certificate Services (AD CS) (GitHub).
Industry & Policy
- Denmark’s CERT.dk flagged an FBI operation dismantling an AI-driven phishing ecosystem and its malware-delivery chains (CERT.dk).
- Krebs and multiple firms linked the four-year-old Android Popa botnet — millions of consumer TV boxes relaying ad-fraud and account-takeover traffic — to NetNut, a residential proxy provider run by NASDAQ-listed Alarum Technologies (Krebs).
Topics
Vendors
Threat actors
CVEs
Malware
Models