June 20, 2026
FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
43 sources → 1078 gathered → 400 triaged → 43 clustered → 43 written
A Russian-speaking credential-harvesting campaign has compromised roughly half the internet-exposed Fortinet fleet, while a single leaked secret handed attackers Novo Nordisk’s drug formulas and internal models. Supply-chain and identity abuse dominated the day, alongside a fresh batch of AI-infrastructure flaws and EDR-killer tradecraft.
Initial Access & Credential Theft
- FortiBleed has compromised credentials for ~86,644 internet-facing FortiGate firewalls and SSL VPN gateways — about half of all exposed Fortinet devices — prompting CISA, NCSC-UK, and CERT.dk to issue hardening advisories. Researcher Volodymyr Diachenko, who broke the story, documented SSL VPN authentication intercepted at scale, offline GPU hash-cracking, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor. The Hacker News, CISA, BleepingComputer
- Affected operators should rotate all device, VPN, and admin credentials, hunt for AD lateral movement, and treat any cracked plaintext as fully burned — the dataset spans nearly 200 countries.
Cloud, Identity & Supply Chain
- A leaked GitHub token left in a repo for two months gave extortion group FulcrumSec access to Novo Nordisk, who exfiltrated 1.3TB including unreleased drug formulas and internal AI models, then demanded $25M; the Danish pharma giant declined and the data is now being sold. A textbook reminder that secrets sprawl in dev pipelines is an identity problem. Dark Reading, SecurityWeek
- 145 Mastra npm packages (
@mastra/*, a popular AI-app framework) were trojanized after a contributor account was hijacked, witheasy-day-js@1.11.22dropping a postinstall remote payload. Microsoft attributes the campaign to Sapphire Sleet (North Korea–nexus, lineage to the Axios/APT38 npm activity); Nextron flagged related infostealer packages whose Rust second stage hunts crypto seed phrases,.env/.npmrc/SSH keys, and enumerates SentinelOne, Defender, and Little Snitch on macOS. The Hacker News, Microsoft - The Klue OAuth breach keeps widening: stolen Salesforce OAuth tokens from the Battlecards app integration — the third such integrated-app compromise in the ongoing extortion wave — have hit Huntress and Recorded Future, with the new Icarus group claiming the attack. Salesforce has disabled the integration. BleepingComputer, SecurityWeek
AI & Model Security
- SearchLeak (CVE-2026-42824) chained prompt injection, a race condition, and a CSP bypass in Microsoft 365 Copilot Enterprise Search into a one-click exfiltration of emails, calendar data, indexed files, and even MFA codes — all via a genuine microsoft.com link that defeated URL filtering. Now patched. The Hacker News, SC World
- Unit 42’s “Pickle in the Middle” abused predictable staging-bucket names in the Google Vertex AI SDK (
google-cloud-aiplatform1.139.0–1.140.0) to hijack victim model uploads via bucket squatting and pickle deserialization, achieving cross-tenant RCE inside Google’s serving infrastructure. Fixed in v1.148.0. Unit 42, The Hacker News - AutoJack (Microsoft research) turns an AI browsing agent into a host-RCE delivery vehicle: steer the agent to a malicious page and its JavaScript reaches a privileged local service to spawn a process — no credentials or further interaction once the agent loads the page. The Hacker News
- A three-bug chain in LiteLLM, the widely deployed open-source AI gateway, lets a default low-privilege account escalate to admin and run code on the server, exposing every provider key it brokers. The Hacker News
- A coordinated campaign published 15 malicious JetBrains Marketplace plugins posing as DeepSeek-based AI coding assistants to exfiltrate AI provider API keys, paired with Chrome extensions capturing chatbot conversations. The Hacker News
Ransomware & Extortion
- ESET dissected GentleKiller, the in-house EDR-killer at the core of the Gentlemen RaaS portfolio — eight variants, each impersonating a legitimate product, collectively targeting 400+ processes mapped to 48 security products, and combined with externally sourced HexKiller, ThrottleBlood, and HavocKiller. A leak of Gentlemen’s own data also linked an affiliate to a stealer ESET named OxideHarvest; IoCs are published. The Hacker News, WeLiveSecurity
- DragonForce affiliates deployed a custom Go RAT, Backdoor.Turn, that hides C2 inside legitimate Microsoft Teams relay infrastructure, observed by Symantec/Carbon Black against a major U.S. services firm. The Hacker News, SecurityWeek
- 2026 leaderboards put Qilin far ahead at 651 attacks, followed by Gentlemen (430), Akira (282), DragonForce (243), and INC (233); separately, INC has claimed 830+ victims since 2023, absorbing affiliates after the LockBit/BlackCat collapses. Ido Cohen, The Hacker News
- Newcomer KRYBIT racked up 49 victims across 20+ countries in weeks; Nextron’s YARA profiling shows heavy overlap with the leaked Babuk codebase, another build on that foundation with double-extortion notes and a Tor leak blog. Nextron
- DeadLock is expanding its use of Polygon smart contracts — now hosting its leak-site entries on-chain (75 victims since February) in addition to chat-proxy rotation, with notes fetching victim data live from the contracts. ESET
- ShinyHunters added more high-profile victims, including the Council of Europe, where it claims a 297GB theft via an Oracle PeopleSoft zero-day. The Register
Vulnerabilities & Exploits
- Cisco patched CVE-2026-20262, a Catalyst SD-WAN Manager (vManage) web-UI flaw enabling authenticated arbitrary file writes and root privilege escalation, under active exploitation — CISA set a June 29 federal deadline. SecurityWeek, The Register
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar enabling RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window. Fixed in 10.0.7+/10.2.4+. BleepingComputer, Horizon3
- CISA added Joomla Content Editor (JCE) flaw CVE-2026-48907 (CVSS 10.0, improper access control → arbitrary PHP execution) to KEV amid active exploitation. The Hacker News
- F5 shipped out-of-band fixes for two critical NGINX Open Source RCE flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module triggerable by a remote unauthenticated attacker. No exploitation reported yet, but the QUIC path warrants prompt patching. The Hacker News, CVE
- Paradigm Shift published usbliter8, a working — and unpatchable — SecureROM exploit achieving arbitrary code execution on Apple A12/A13 silicon. Physical/USB access required, but the boot-chain flaw is burned into silicon for the life of affected devices. The Hacker News
Threat Intelligence & Espionage
- ESET attributed two undocumented Windows variants of the previously Linux-only SprySOCKS backdoor (WIN_DRV, WIN_PLUS) to China-nexus FishMonger; WIN_DRV weaponizes a kernel driver for a passive, hidden-port TCP backdoor triggered by crafted packets, used against governments in Honduras, Taiwan, Thailand, and Pakistan. The Hacker News, WeLiveSecurity
- Gamaredon is weaponizing CVE-2025-8088 (WinRAR path traversal) against Ukrainian military/conscription targets since February 2026: a malicious NTFS alternate data stream plants a
.lnkinto the Startup folder on extraction, firing a hidden PowerShell stager with anti-analysis checks on next logon. Nextron - China-linked UNC6508 spent two years inside North American medical and defense research networks via backdoored REDCap servers, then rewired victims’ own Google Workspace rules to auto-forward email and deployed InfiniteRed malware. The Hacker News, Security Affairs
- Rapid7 and Nextron tracked a three-year-running Dropping Elephant (APT-C-48) LNK-loader line — 44 samples of PDF-masquerading shortcuts firing self-deleting PowerShell stagers behind China-energy, aerospace, and South Asia military lures. Nextron, blackorbird
- ScarCruft (APT37) is delivering the new NarwhalRAT via spear-phishing impersonating Microsoft account security alerts. The Hacker News
- Operation Endgame dismantled 106 SocGholish C2 servers/domains and cleaned ~15,000 infected WordPress sites tied to Evil Corp, in a Dutch/Canadian/German/U.S. action. The Hacker News, SecurityWeek
- The Android Popa botnet — millions of TV boxes relaying ad-fraud and account-takeover traffic for four years — was linked by multiple firms to NetNut/Alarum Technologies (NASDAQ: ALAR), a publicly traded Israeli residential-proxy provider. Krebs on Security
- New Android banking trojan Rokarolla targets 217 banking/crypto apps with 137 remote commands, lifting lock-screen PINs, intercepting SMS, and rewriting the clipboard to redirect crypto, spread via fake TikTok and Chrome downloads. The Hacker News
New Tools & Releases
- CloudBreach published an Offensive Azure Security Cheatsheet distilled from its Breaching Azure courses — quick-reference commands and tradecraft for Entra ID, Microsoft 365, and Azure attack paths. GitHub
Industry & Policy
- Norway is imposing a near-total ban on generative AI in elementary schools from late August: no AI for grades 1–7 and supervised-only use in secondary school, on the rationale that children must first master reading, writing, and math. Reuters, The Decoder
Topics
Vendors
Threat actors
Malware
Models