daily cyber × ai intelligence

index

tagged

[fortigate]

2 editions · 1 item

July 3, 2026

Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire

Sysdig documented the first end-to-end ransomware operation run by an LLM, with an operator dubbed JADEPUFFER exploiting CVE-2025-3248 in Langflow to break in, steal credentials, move laterally, and encrypt a production database. Adobe patched seven CVSS 10.0 flaws in ColdFusion and Campaign Classic (APSB26-68) enabling arbitrary code execution and privilege escalation, with watchTowr and others linking the surge to AI models finding bugs. Google and the FBI disrupted the NetNut/Popa residential proxy botnet affecting ~2 million devices and linked to 316 distinct threat clusters running cybercrime and espionage. Multiple critical vulnerabilities in SharePoint (CVE-2026-45659), NetScaler (CVE-2026-8451), Oracle E-Business Suite (CVE-2026-46817), and WinRAR (CVE-2026-14191) are under active exploitation, with CitrixBleed-successor CVE-2026-8451 exploited within days of disclosure using public PoC code.

June 20, 2026

  • FortiBleed has compromised credentials for ~86,644 internet-facing FortiGate firewalls and SSL VPN gateways — about half of all exposed Fortinet devices — prompting CISA, NCSC-UK, and CERT.dk to issue hardening advisories. Researcher Volodymyr Diachenko, who broke the story, documented SSL VPN authentication intercepted at scale, offline GPU hash-cracking, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor. The Hacker News, CISA, BleepingComputer · Initial Access & Credential Theft

in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token