daily cyber × ai intelligence

index

tagged

[fortinet]

10 items

July 27, 2026

Two Live Exploits and a Bench of Fresh Offensive Tooling

GitLab default-config RCE received a full technical write-up detailing memory-corruption bugs in the Oj JSON parser, and a working NGINX RCE exploit (CVE-2026-42533) was open-sourced. A Linux kernel local privilege-escalation flaw (CVE-2026-31431) affects all mainstream distributions with no vendor patches yet, while a Fortinet FortiClient kernel driver vulnerability enables credential theft. Multiple new offensive tools emerged including Nocturne (Windows loader), NaX (C2 beacon), beignet (macOS shellcode), Waypoint (EDR-bypass driver), and RootHound (Linux privilege-escalation mapper). Claude Opus 5 achieved 30.2% on ARC-AGI-3 benchmark while WallBreaker jailbreak claims emerged targeting the model. Supply-chain attacks continued with malicious npm/PyPI packages including a Shai-Hulud worm variant and a disguised @copilot-mcp/apex macOS infostealer.

July 18, 2026

A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

WordPress core suffers an unauthenticated remote code execution chain affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, exploitable on default installs with working proof-of-concept code now public. Microsoft SharePoint CVE-2026-58644, Oracle E-Business Suite CVE-2026-46817, and Fortinet FortiSandbox zero-days are under active exploitation with CISA remediation deadlines. Finland's security service revealed a multi-year Russian FSB campaign targeting critical infrastructure via internet-exposed legacy devices like Cisco Smart Install. NadMesh Go botnet harvests cloud credentials from exposed AI services including Langflow, Ollama, and Gradio, claiming over 3,800 unique AWS keys and Kubernetes tokens.

July 2, 2026

Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US

A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.

June 24, 2026

Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland

Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.

June 23, 2026

Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces

The Five Eyes intelligence alliance warns that frontier AI models could reshape offensive cyber operations within months, lowering barriers to high-impact attacks. Meanwhile, dirkjanm disclosed a critical Entra ID Conditional Access bypass via resource exclusion, and researchers demonstrated multiple AI security flaws including DifyTap vulnerabilities in the Dify platform and AutoGen Studio RCE. The Klue data breach fallout expanded to include major security vendors like HackerOne, Huntress, Recorded Future, and Snyk, while a decade-old infostealer credential was used to hijack Brazil's Emergency Alert System at national scale.

June 21, 2026

FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.

June 19, 2026

FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.

June 18, 2026

ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel

A critical vulnerability blitz dominates this digest: Oracle PeopleSoft CVE-2026-35273, Splunk CVE-2026-20253, and an unpatched Microsoft Defender RoguePlanet zero-day are actively exploited, with ShinyHunters and other threat actors targeting higher education and enterprise networks. The AI/security layer has emerged as a major attack surface, exemplified by Microsoft 365 Copilot SearchLeak (one-click data exfiltration), Google Vertex AI cross-tenant RCE, and the Novo Nordisk breach that exposed proprietary AI model checkpoints and training infrastructure as ransomware extortion payload—underscoring that AI IP is now a strategic target.

June 17, 2026

Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists

A critical day for AI and enterprise security: Microsoft 365 Copilot was patched for the "SearchLeak" one-click exfiltration vulnerability (CVE-2026-42824), while Novo Nordisk confirmed a breach exposing trained AI models and proprietary training data to extortionists. Multiple actively-exploited flaws emerged in Fortinet FortiSandbox, Joomla JCE, Cisco Catalyst SD-WAN Manager, LiteSpeed cPanel, and Palo Alto GlobalProtect, alongside supply-chain compromises affecting Arch Linux AUR, JetBrains Marketplace, and npm packages. Major APTs including UNC6508, SprySOCKS (FishMonger), ScarCruft, and SideCopy expanded targeting of medical research, defense, and developer communities.