daily cyber × ai intelligence

index

tagged

[fortinet]

13 editions · 12 items

July 2, 2026

Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US

A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.

June 24, 2026

Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland

Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.

June 23, 2026

  • FortiBleed update: custom FortiGate sniffers and 86k confirmed creds — SOCRadar reports the campaign deployed custom sniffers on compromised firewalls to harvest authentication secrets, and Unit 42 frames it as broad password spraying against Fortinet, Sophos, and MSSQL using a curated list built from prior breaches; Fortinet says ~86,000 working credentials were validated. BleepingComputer · SecurityWeek · Threat Activity

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces

June 21, 2026

  • FortiBleed has compromised credentials tied to 86,644 FortiGate firewalls and SSL-VPN gateways — about half of all internet-accessible Fortinet devices — in a campaign CISA, NCSC-UK, and CERT.dk all flagged this week (The Hacker News, CISA). Researcher Volodymyr Diachenko, who broke the story, traced an open directory showing SSL-VPN auth intercepted at scale, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), offline hash-cracking on a GPU cluster, and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor (Hunt.io via Florian Roth). · Credential Theft & Initial Access

in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

June 20, 2026

  • FortiBleed has compromised credentials for ~86,644 internet-facing FortiGate firewalls and SSL VPN gateways — about half of all exposed Fortinet devices — prompting CISA, NCSC-UK, and CERT.dk to issue hardening advisories. Researcher Volodymyr Diachenko, who broke the story, documented SSL VPN authentication intercepted at scale, offline GPU hash-cracking, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor. The Hacker News, CISA, BleepingComputer · Initial Access & Credential Theft

in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

June 19, 2026

  • FortiBleed exposed working SSL-VPN credentials for roughly 70,000–74,000 internet-facing Fortinet firewalls and VPN gateways across ~194 countries, prompting urgent hardening advisories from CISA and the NCSC-UK (CISA, BleepingComputer). Researcher Volodymyr Diachenko traced the operation — surfaced via Hunt.io open-directory intel — to a Russian-speaking group intercepting SSL-VPN auth at scale, cracking hashes offline on a GPU cluster (~1.16B attempts against 320K+ FortiGates, plus 2.1B against 160K+ MSSQL servers), and reusing plaintext creds for Active Directory lateral movement; at least four orgs including a NATO defense contractor were fully compromised (Dark Reading). Rotate VPN credentials and hunt for post-auth AD access now. · Threat Activity & Intrusions

in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

June 18, 2026

  • Fortinet FortiSandbox is under active attack via three critical bugs — CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 (path traversal + privesc, CVSS 9.1) — with CERT.dk flagging the attacks for Nordic defenders. Upgrade immediately (The Register). · Vulnerabilities & Exploits
  • FortiBleed — SOCRadar uncovered an industrialized credential-harvesting operation against Fortinet firewalls/VPNs: ~30,791 compromised devices, 8,316 organizations, across 194 countries, with attacker tooling, automation, and a verified-credential database recovered. Notably not a new zero-day — it's reused/leaked credential abuse at scale, so rotate creds and audit admin access (BleepingComputer, Dark Reading). · Threat Activity & Ransomware

in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel